This job post is closed and the position is probably filled. Please do not apply. Work for Trail of Bits and want to re-open this job? Use the edit link in the email when you posted the job!
๐ค Closed by robot after apply link errored w/ code 403 1 year ago
\nAbout Trail of Bits\nTrail of Bits helps secure the worldโs most targeted organizations and products. We combine high-end security research with a real-world attacker mentality to reduce risk and fortify code.\nย \nAs a cybersecurity research and consulting firm, we serve clients in the defense, tech, finance, and blockchain industries. We help with their most difficult security challenges by designing and building new technology, researching new techniques to advance the state of practice, and reviewing the security of the latest available technology products before they hit the market.\nย \nOur team consumes, produces, and presents research as a natural part of doing business. When we make new discoveries or developments, we strive to share our knowledge and release our tools as open source. Itโs a practice thatโs earned us industry accolades and helped contribute to our double-digit bottom-line growth.\n\nRole\nTrail of Bits is looking for experienced software engineers interested in making high-impact security improvements to high-profile open-source codebases. The primary responsibilities of this role are developing security-focused software updates and features in Python packages, managing their packaging and deployment, and engaging with commercial clients / open-source communities. The focus areas include supply chain security, applied cryptography (related to code signing), CI/CD systems, vulnerability triage and remediation, build systems, and associated security infrastructure.ย \nSoftware development will be primarily in Python, with occasional C/C++ required for native Python extensions. The role involves frequent creative and analytic challenges to design features and review existing implementations with a critical lens. Most of the work is on active, popular open-source projects, and involves frequent coordination with members of the open-source community.ย \nย \nThis is an engineering position, where the focus is to integrate novel features into production systems. It may also involve maintenance of preexisting code and infrastructure.ย \nย \nYou will typically work in teams of 2-4 people, all from remote locations, operating in a continuous delivery model regularly communicating with our clients. Technical leads will assign responsibilities to you and other team members, and you will develop proofs of concept, prototypes, and enhancements to existing tools in support of a project's goals. You will have opportunities to work for a variety of clients throughout a typical year. Frequent communication with team members and clients is essential to success, and writing about your work publicly is encouraged and incentivized.\nย \nThis is a fully remote position (travel rarely required).\nย \nThe base salary range for this role is $125,000-$200,000 DOE.\nย \nResponsibilities\n\n\n\n* Designing and building solutions that balance performance, security, and functionality requirements.\n\n* Root-cause analysis and debugging on low-level technical issues.\n\n* Contributing fixes and enhancements to large open-source codebases.\n\n* Interpreting customer requirements, decomposing tasks, and making engineering estimates.\n\n* Speaking daily with your team typically within core hours and coordinating asynchronously outside of core hours to organize tasking.\n\n* Describing and explaining technical concepts to clients, community, and co-workers.\n\n\n\n\nRequirements & Skills\n\n\n* 3+ years of experience in professional software development focused on library and package development, Python packaging software and packaging processes, or managing supply chain security for a Python codebase.\n\n* Proficiency in system-level programming in modern Python (required).\n\n* Familiarity with the C-Python interface and with C++ development is preferred.ย \n\n* Ability to work remotely and independently to set goals and find solutions.\n\n* Composure speaking or writing directly to customers to give status reports on progress and to solicit feedback and new requirements.\n\n\n\n\nDesirable Pluses (non-mandatory skills)\n\n\n* Experience with Go or Java.\n\n* Related development experience in a security monitoring, security testing, security response, cryptography engineering or other security role.\n\n* Previous experience in DevOps or managing CI/CD systems.\n\n\n* Previous experience in package management and supply chain security.\n\n\n* Previous experience in open-source projects.\n\n\n\n\n\n\nCompany Perks\n\n\n* Before, during and after COVID-19, our workforce works flexibly. Many employees choose to work from home around the globe. As long as you deliver against your goals, we encourage you to harness your personal working style to let you work best.\n\n* Liberal expense policy for acquiring the equipment and software that help you do your job. If we need hardware to work effectively, we buy it.ย \n\n* We offer exceptional and tailored technical, leadership and organizational training for our team members. Everyone is encouraged to identify additional opportunities for personal professional growth with working at Trail of Bits.\n\n* We routinely highlight the amazing work our employees do via our blog, product offerings, and conference talks. We celebrate you!\n\n* We're at the forefront of a number of markets and have the internal expertise and the ambition to capitalize on those opportunities. Our employees see their work in use and valued by many others.\n\n\n\n\n\nBenefits for US Employees\n\n\n* Multiple generous health, vision, and dental insurance plans including no-monthly-premium options supporting individuals and families through JustWorks.\n\n* Ancillary benefits including life and disability insurance, pre-tax commuter benefits, free Citi Bike membership, access to a HealthAdvocate, a healthcare Flexible Spending Account (FSA), and a free One Medical membership.\n\n* 4 months paid parental leave.\n\n* 401k with 5% company matching through Betterment.\n\n* Moving expenses: $5,000 one-time.\n\n* Charitable donations matching up to $2,000.\n\n* One time $1,000 at home office expense stipend.\n\n* $500/year personal learning & development budget.ย \n\n* Executive coaching for managers and above.\n\n* Options for coworking space (some restrictions may apply).ย \n\n* Bonuses for recruiting, public speaking, tool releases, blog posts, academic posters, proposals, and whitepapers, and end-of-year bonuses based on company, team, and personal performance.\n\n* 20 days of Paid Time Off (PTO) per year.\n\n* 14 company holidays per year.\n\n* Carbon offsets for your personal and corporate carbon emissions through Project Wren.\n\n* Manage your student loans right alongside your 401(k) in Betterment.\n\n\n\n\n\nBenefits for Canadian Employees\n\n\n* Premium health, vision, and dental insurance plans.\n\n* Life/AD&D Insurance options, as well as short- and long-term disability insurance plans.\n\n* RRSP plan with 5% company matching.\n\n* Charitable donation matching up to USD $2000.\n\n* Bonuses for recruiting, public speaking, tool releases, blog posts, academic posters, proposals, and whitepapers, and end-of-year bonuses based on company, team, and personal performance.\n\n* 10 days of Paid Time Off (PTO) and 10 days of sick time per year.\n\n* 14 company holidays including provincial statutory holidays and select US holidays per year.\n\n* Carbon offsets for your personal and corporate carbon emissions through Project Wren.\n\n\n\n\nDedication to diversity, equity & inclusion\n\nTrail of Bits is committed to creating and maintaining a diverse and inclusive workplace where our employees can thrive and be themselves! We welcome all persons into our community. We embrace the diversity of gender, gender identity or expression, race, color, religious creed, national origin, ancestry, age, physical and mental disabilities, medical condition, genetic characteristic, sexual orientation, marital status, family care or medical leave status, military or veteran status, or perceived membership in any of these groups.\n \n\n#Salary and compensation\n
No salary data published by company so we estimated salary based on similar jobs related to Design, Python, Consulting, DevOps, Engineer and Digital Nomad jobs that are similar:\n\n
$70,000 — $120,000/year\n
\n\n#Benefits\n
๐ฐ 401(k)\n\n๐ Distributed team\n\nโฐ Async\n\n๐ค Vision insurance\n\n๐ฆท Dental insurance\n\n๐ Medical insurance\n\n๐ Unlimited vacation\n\n๐ Paid time off\n\n๐ 4 day workweek\n\n๐ฐ 401k matching\n\n๐ Company retreats\n\n๐ฌ Coworking budget\n\n๐ Learning budget\n\n๐ช Free gym membership\n\n๐ง Mental wellness budget\n\n๐ฅ Home office budget\n\n๐ฅง Pay in crypto\n\n๐ฅธ Pseudonymous\n\n๐ฐ Profit sharing\n\n๐ฐ Equity compensation\n\nโฌ๏ธ No whiteboard interview\n\n๐ No monitoring system\n\n๐ซ No politics at work\n\n๐
We hire old (and young)\n\n
\n\n#Location\nWorldwide - Remote