Senior Developer Relations Engineer (Security Advocate)
Role in brief
Trail of Bits is seeking a Senior Developer Relations Engineer to build and nurture relationships within the security community. This role involves advocating for security practices, supporting open-source projects, and translating technical research into practical guidance. Ideal candidates have deep hands-on security experience, a public body of work, and proven community credibility, with a focus on AI-native tooling.
About the role
This role focuses on expanding and deepening Trail of Bits' engagement with the security community. You will be responsible for attending and speaking at relevant conferences and meetups, fostering connections with maintainers and researchers, and becoming a trusted voice within the community. A key aspect involves supporting open-source projects by facilitating technical office hours and helping contributions land upstream, ensuring strong, lasting relationships.
A core part of the work involves transforming the company's research and releases into practical resources for practitioners. This includes collaborating on advisories, co-authored write-ups, and guidance, as well as optimizing tools for adoption. You will also teach methods through workshops and hands-on sessions, empowering others to apply security concepts independently. Publishing deep dives, tutorials, and technical write-ups under your own name is also expected.
Success in this position means actively contributing to the adoption and improvement of Trail of Bits' work. You will run published tools against unfamiliar code to provide direct feedback, ship examples and integrations, and enhance project onboarding and documentation. Additionally, you will attract external contributors to the company's projects and channel community insights back into the firm, identifying practitioner needs, research gaps, and emerging ecosystem trends.
The listed salary range for this full-time senior role is $160,000 to $200,000 USD.
Skills that matter here
- Software people actually use: This role requires the ability to interact with and contribute to existing tools, libraries, or integrations, demonstrating practical coding skills by running analyzers and making pull requests.
- Security depth: The position demands extensive hands-on security experience, typically seven or more years, to effectively engage with researchers and engineers, backed by published research or CVEs.
- AI-native in practice: Candidates must have practical experience building with agentic tooling like skills, agents, or MCP servers, not just prompt writing.
- A public body of work: The ideal candidate will have visible contributions such as talks, posts, upstream contributions, research, or documentation that demonstrate their engagement and expertise.
- Community credibility: Understanding the dynamics of security communities, where they gather, and how to authentically engage with them is crucial for this role.
- Writing and speaking that survive a skeptical audience: The role requires clear and accurate communication skills, both written and verbal, capable of withstanding scrutiny from experienced security engineers.
Who this role suits
- A person who thrives on building and maintaining relationships within technical communities.
- Someone with a strong background in hands-on security work who can translate complex research into actionable insights.
- An individual who is proactive in identifying speaking opportunities and enjoys mentoring engineers to deliver talks.
- A self-starter who can navigate ambiguity, make independent decisions, and defend their choices to both technical and leadership teams.
From the employer
What You’ll Do
- Grow the relationships we already have across the security community, and start new ones. Show up where practitioners gather, contribute alongside maintainers and researchers, and become someone the community knows and trusts.
- Own our baseline event presence. Attend and speak at the conferences and cybersecurity meetups that matter to our audiences, and help bring back successful meetups akin to Empire Hacking.
- Support the open-source projects and maintainers we work with. Facilitate technical office hours that connect maintainers directly with our engineers, help contributions land upstream, and keep those relationships strong long after an engagement ends.
- Turn our research and releases into practitioner staples. Work with Marketing and Technical Editing on advisories, co-authored writeups, and guidance other projects can reuse, and with Engineering on optimizing tools, skills, and plugins for adoption. Teach the methods behind the work through workshops and hands-on sessions, so others can apply them without us.
- Publish under your own name, and be present where that work gets discussed. You’ll write deep dives, tutorials, and technical write-ups that hold up to scrutiny from working security engineers.
- Accelerate our conference and CFP motion. Partner with Marketing to identify speaking opportunities early, and help engineers get talks submitted, prepared, and delivered.
- Use our own work the way the community does. Run what we publish against unfamiliar code, and give the teams behind it direct feedback on the research and the experience.
- Make our work easy to adopt. Ship examples people can run and integrations that fit their workflows, and contribute to the skills and plugins our teams build with every day. Improve the front door to our projects alongside the teams that own them: better onboarding, clearer documentation, and a first run that works.
- Attract contributors from outside Trail of Bits. Show where a first contribution goes, and give them a reason to make a second.
- Route what you hear back into the firm: what practitioners struggle with, what they wish existed, where our research has gaps, and which ecosystems are heating up.
What You’ll Bring
- Software people actually use. A tool, a library, an integration, a skill, or an agent, out in the world doing work. You can read unfamiliar code, run our analyzers against it, and open a pull request that gets merged. Everyone builds at Trail of Bits.
- Security depth. Deep, hands-on security experience, typically seven or more years, enough to hold your own with researchers and engineers. Published research, CVEs, and advisories all count.
- AI-native in practice. You build with agentic tooling: skills, agents, MCP servers, harnesses, and evals. If your AI experience stops at writing prompts, this is the wrong role.
- A public body of work. You’ve contributed where we can see it: talks, posts, upstream contributions, research, and documentation. We will look at your commit history rather than your follower count.
- Community credibility. You know how these communities work, where they gather, and how quickly they detect marketing wearing engineering’s clothes.
- Writing and speaking that survive a skeptical audience. We speak to practitioners who can verify everything we say. This carries the same weight as the technical bar.
- Ownership under ambiguity. You'll decide what matters and defend the choice, to engineers and to leadership.
Nice to Have
- Experience maintaining or contributing meaningfully to an open-source project.
- Depth in one of our domains: application security, blockchain and cryptography, AI/ML security, or low-level systems research. One is plenty.
- Experience running or programming a community venue at meaningful scale.
- Contributions to developer documentation that lives alongside the code and ships with it.
- Involvement with open-source foundations, grant programs, or maintainer-facing initiatives.
Benefits, Perks & Wellness
Trail of Bits is our people, not a place. With over 100+ employees working from every time zone across the globe, our remote-first culture is built on autonomy and trust (and backed by smile-worthy benefits) for full-time employees:
Empowered Living:
- Competitive salary complemented by performance-based bonuses.
- Fully company-paid insurance packages, including health, dental, vision, disability, and life.
- A solid 401(k) plan with a 5% match of your base salary.
- 20 days of paid vacation with flexibility for more, adhering to jurisdictional regulations.
Nurturing New Beginnings:
- 4 months of parental leave to cherish the arrival of new family members.
- Our team is global and remote-first. However, if you are interested in moving to NYC, we offer $10,000 in relocation assistance to support your transition.
Work & Life Enrichment:
- $1,000 Working-from-Home stipend to create a comfortable and productive home office.
- Annual $750 Learning & Development stipend for continuous personal and professional growth.
- Company-sponsored all-team celebrations, including travel and accommodation, to foster community and recognize achievements.
Community Impact:
- Philanthropic contribution matching up to $2,000 annually.
Questions about this role
What is the remote work policy for this role?
This is a remote position, and Trail of Bits operates with a remote-first culture, supporting employees across various time zones.
What level of seniority is expected for this position?
This is a senior-level role, requiring deep, hands-on security experience, typically seven or more years.
What is the salary range for this position?
The salary range for this full-time senior role is between $160,000 and $200,000 USD.