Senior Developer Relations Engineer (Security Advocate)

Posted 2 Hours Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
160K-200K Annually
Senior level
Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
High-end cybersecurity consultancy with a real-world attacker mentality.
The Role
Own developer-facing outreach for Trail of Bits: grow community relationships, support and onboard maintainers, convert research into usable tools and docs, publish deep technical content, run workshops and conference presence, and attract upstream contributions while routing practitioner feedback into product and research priorities.
Summary Generated by Built In
Who We Are

Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world.

Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers.

Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable.

Role

We are hiring a Developer Relations Engineer to amplify our public work and deepen our relationships with the security practitioners, researchers, maintainers, and open-source communities we serve. You will report to the Head of Go-to-Market and work in close partnership with our engineering practices and GTM teams.

We publish a lot of what we do: 946 publications, 620 public security reviews, and more than 200 open-source repositories. Last year our engineers landed more than 375 pull requests upstream, from cryptography libraries to the Rust compiler. Tools like Slither and resources like the Testing Handbook are used daily across the industry, and Buttercup, our AI cyber reasoning system, took second place in DARPA's AI Cyber Challenge and is now open source.

Today, most of that happens alongside client commitments. This role gives it a dedicated advocate. You take what we build and learn internally and extend its reach: you help decide what gets published, explain what was built and why it matters, and put it in the hands of people who will use it. Engineering owns research and tooling, Marketing owns channels and distribution, and Technical Editing owns editorial standards. You bring the relationships and the technical substance that make it travel, and you carry no quota and no account list. You will occasionally join a technical conversation where your expertise fits and where you judge it matters. Our interview process includes a technical conversation with our engineers and a short presentation.

What You’ll Do
  • Grow the relationships we already have across the security community, and start new ones. Show up where practitioners gather, contribute alongside maintainers and researchers, and become someone the community knows and trusts.
  • Own our baseline event presence. Attend and speak at the conferences and cybersecurity meetups that matter to our audiences, and help bring back successful meetups akin to Empire Hacking.
  • Support the open-source projects and maintainers we work with. Facilitate technical office hours that connect maintainers directly with our engineers, help contributions land upstream, and keep those relationships strong long after an engagement ends.
  • Turn our research and releases into practitioner staples. Work with Marketing and Technical Editing on advisories, co-authored writeups, and guidance other projects can reuse, and with Engineering on optimizing tools, skills, and plugins for adoption. Teach the methods behind the work through workshops and hands-on sessions, so others can apply them without us.
  • Publish under your own name, and be present where that work gets discussed. You’ll write deep dives, tutorials, and technical write-ups that hold up to scrutiny from working security engineers.
  • Accelerate our conference and CFP motion. Partner with Marketing to identify speaking opportunities early, and help engineers get talks submitted, prepared, and delivered.
  • Use our own work the way the community does. Run what we publish against unfamiliar code, and give the teams behind it direct feedback on the research and the experience.
  • Make our work easy to adopt. Ship examples people can run and integrations that fit their workflows, and contribute to the skills and plugins our teams build with every day. Improve the front door to our projects alongside the teams that own them: better onboarding, clearer documentation, and a first run that works.
  • Attract contributors from outside Trail of Bits. Show where a first contribution goes, and give them a reason to make a second.
  • Route what you hear back into the firm: what practitioners struggle with, what they wish existed, where our research has gaps, and which ecosystems are heating up.
What You’ll Bring
  • Software people actually use. A tool, a library, an integration, a skill, or an agent, out in the world doing work. You can read unfamiliar code, run our analyzers against it, and open a pull request that gets merged. Everyone builds at Trail of Bits.
  • Security depth. Deep, hands-on security experience, typically seven or more years, enough to hold your own with researchers and engineers. Published research, CVEs, and advisories all count.
  • AI-native in practice. You build with agentic tooling: skills, agents, MCP servers, harnesses, and evals. If your AI experience stops at writing prompts, this is the wrong role.
  • A public body of work. You’ve contributed where we can see it: talks, posts, upstream contributions, research, and documentation. We will look at your commit history rather than your follower count.
  • Community credibility. You know how these communities work, where they gather, and how quickly they detect marketing wearing engineering’s clothes.
  • Writing and speaking that survive a skeptical audience. We speak to practitioners who can verify everything we say. This carries the same weight as the technical bar.
  • Ownership under ambiguity. You'll decide what matters and defend the choice, to engineers and to leadership.

Nice to Have

  • Experience maintaining or contributing meaningfully to an open-source project
  • Depth in one of our domains: application security, blockchain and cryptography, AI/ML security, or low-level systems research. One is plenty.
  • Experience running or programming a community venue at meaningful scale
  • Contributions to developer documentation that lives alongside the code and ships with it
  • Involvement with open-source foundations, grant programs, or maintainer-facing initiatives

What Won’t Work Here

  • Advocacy without building. This community checks the work, so credibility here comes from what you ship as much as from what you say. If it has been a while since you built something, the role will be a stretch.
  • Waiting to be handed a plan. We move with agility and accuracy. You will decide what matters and defend the choice.
  • Reluctance to travel. This role travels about a quarter of the year. Being in the right room is a large part of the job. You should want to be there, and you should know which rooms are worth the trip.

How We’ll Measure This

You will set targets with your manager in your first quarter and review them quarterly. We will look at ecosystem outcomes: outside contributors, upstream fixes landed with maintainers, talks accepted by you and engineers you prepared, writing that gets cited, and practitioners who would vouch for us unprompted. When your work creates commercial opportunity, you hand it off and we track it there.

The base salary for this full-time position is $160,000 to $200,000. In addition to base salary, this position is eligible for annual bonuses and benefits. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range. The presented salary range encompasses the starting salaries for all U.S. locations. For a precise salary estimate tailored to your preferred location, please discuss it with your recruiter during the hiring process.

Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. Learn more. 


BenefitsBenefits, Perks & Wellness

Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees:

Empowered Living:

  • Competitive salary complemented by performance-based bonuses.
  • Fully company-paid insurance packages, including health, dental, vision, disability, and life.
  • A solid 401(k) plan with a 5% match of your base salary.
  • 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.

Nurturing New Beginnings:

  • 4 months of parental leave to cherish the arrival of new family members.
  • Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition.

Work & Life Enrichment:

  • $1,000 Working-from-Home stipend to create a comfortable and productive home office.
  • Annual $750 Learning & Development stipend for continuous personal and professional growth.
  • Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.

Community Impact:

  • Philanthropic contribution matching up to $2,000 annually.

Skills Required

  • Seven or more years of deep, hands-on security experience (research, advisories, CVEs)
  • Public body of work: talks, posts, upstream contributions, research, and visible commit history
  • AI-native practical experience building with agentic tooling (skills, agents, MCP servers, harnesses, evals)
  • Ability to read unfamiliar code, run analyzers, open pull requests that get merged
  • Proven community credibility engaging with maintainers, researchers, and practitioner audiences
  • Strong technical writing and public speaking that withstands skeptical practitioner review
  • Willingness to travel about 25% (attend and speak at conferences and meetups)
  • Experience maintaining or contributing meaningfully to an open-source project
  • Depth in one domain: application security, blockchain/cryptography, AI/ML security, or low-level systems research
  • Experience running or programming a community venue at meaningful scale
  • Contributions to developer documentation that ships alongside code

What the Team is Saying

Skylar
Opal
Tjaden
Sam
Artem
Jim
Anish

Trail of Bits Compensation & Benefits Highlights

  • Healthcare Strength Health coverage is described as employer-paid with no monthly premiums, plus dental, vision, life, and disability. Access to Kindbody, HealthAdvocate, Teladoc, and One Medical is included.
  • Parental & Family Support Family support includes four months of paid parental leave for all parents, alongside family medical leave and a post‑parental return‑to‑work program. Access to fertility care through Kindbody further supports family planning.
  • Fair & Transparent Compensation Pay is presented as benchmarked to market with clear salary ranges shown in postings and a stated compensation philosophy. Structured opportunities for performance and other bonuses are also noted.

Trail of Bits Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Brooklyn, New York
125 Employees
Year Founded: 2012

What We Do

Deepening the Science of Security Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world. Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers. Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable.

Why Work With Us

At Trail of Bits, our 100+ global team members are the core of a remote-first, people-centric culture. Emphasizing autonomy and trust, we offer flexible work and meaningful benefits, supporting diverse talents in pursuing innovation and well-being.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Trail of Bits Offices

Remote Workspace

Employees work remotely.

Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits).

Typical time on-site: None
HQNew York, New York
Our office is situated in a vibrant and diverse neighborhood known for its blend of historic charm and contemporary urban energy. The area is dotted with charming brownstones, bustling cafes, and eclectic local shops, creating a lively yet cozy atmosphere that's quintessentially Brooklyn.

Similar Jobs

Trail of Bits Logo Trail of Bits

Editor

Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
Remote
United States
125 Employees
120K-150K Annually

Trail of Bits Logo Trail of Bits

Security Engineer

Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
Remote
United States
125 Employees
100K-160K Annually

Trail of Bits Logo Trail of Bits

Engineering Director, Application Security

Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
Remote
United States
125 Employees
250K-300K Annually

Trail of Bits Logo Trail of Bits

Security Engineer

Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
Remote
United States
125 Employees
100K-200K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account