hirly

TRM Labs

Product Security Engineer

United States

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at TRM Labs first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Role family
Engineering
Seniority
Mid level
Country
US
Work mode
Remote-friendly
First seen by hirly
2 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Build a Safer World.

TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM's platforms enable investigators to trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure.

About the Team

The Security team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for an Application Security Engineer to build mission-critical infrastructure that ensures the highest levels of availability, performance, and application security at TRM for products as built and deployed. From designing the technical strategy to company-wide best practices and implementation, you’ll work closely with engineering and engineering leadership to ensure TRM’s products are safe and secure.

The impact you will have here:

Lead application security reviews and threat modeling, including secure code review, architectural design, and testing

Develop automated testing and mature our Secure SDLC

Own and perform application security vulnerability management

Coordinate penetration testing engagements

Support software engineers and product teams by developing application security best practices

Develop and maintain the bug bounty program

Bootstrap platform security initiatives that help protect TRM data

Inspire a culture of security across the engineering organization by fostering security champions within engineering teams and coordinating secure code training.

What we’re looking for:

Minimum 8 years of experience in Software Development and testing.

BS (or equivalent) in Computer Science, Computer Engineering, or related field.

Proficiency in software development languages: Python, NodeJS, React

Strong understanding of encryption, authentication, and authorization protocols

Deep experience with common software flaws (e.g., OWASP and CWE), testing methodologies , and using common security tooling for testing.

Professional experience with open source, commercial, or native security solutions for cloud providers such as GCP and AWS. Experience with modern secure software development lifecycles, threat modeling, and best practices.

Experience with conducting efficient and comprehensive code security reviews on a daily or weekly basis

Experience triaging and remediating vulnerabilities in software packages or libraries

Experience with Software Security tools such as Github advanced security or other SAST, DAST, and SCA tools

Experience with Web application testing frameworks such as BurpSuite, OWASP ZAP, etc.

Experience with Threat modeling tools such as OWASP Threat Dragon, etc.

Experience working in a previous agile-based software development role required

Experience Red Teaming or penetration testing applications and infrastructure

Professional experience with cloud providers (e.g., GCP and AWS), modern secure software development lifecycles, and best practices.

Strong written and verbal communication skills.

Security certifications such as OSCP, CEH, GWAPT are a plus.

Familiarity with security frameworks (e.g., NIST SP 800-171 SSDF) is a plus

About the Team:

The culture of our team is built on mutual respect, where everyone's opinion is valued and heard.

We prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.

Transparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.

Our collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.

Team’s Time Zones:

Eastern Standard Time (EST - GMT-4)

Pacific Standard Time (PST - GMT-7)

Central European Summer Time (CET - GMT+2)

Learn about TRM Speed in this position:

Prioritize Rapid Threat Assessments: Efficiently perform security risk assessments and triage vulnerabilities based on immediate risk to the business, focusing on the most critical issues with minimal delays.

Integrate Security Early in Development: Embed security testing and reviews within our Product Shipping Framework and CI/CD pipelines to ensure that security is automated and runs parallel to the fast-paced development cycle, preventing bottlenecks.

Proactively Educate Developers: Conduct just-in-time security training for developers and engineers, offering real-time advice and code reviews to help them produce secure code without interrupting their workflow.

Optimize Tools for Speed: Leverage lightweight and efficient security tools that can be quickly integrated into development environments without slowing down deployments, ensuring continuous and secure product iterations.

Application Instructions

If you’re interested in joining TRM, we encourage you to apply directly. Every application is reviewed by our Talent team.

Before applying, review the job description carefully and highlight the experience and impact that best demonstrate the required qualifications. Please also provide thoughtful and accurate answers to the application questions, as these will be used to evaluate your qualifications for the role.

If you send your resume directly to someone at TRM, we can’t guarantee it will reach the appropriate hiring team. Applying directly is the best way to ensure you’re considered.

What to Expect From Our Interview Process

Our process is designed to understand how you think, solve problems, and deliver impact, while giving you the opportunity to evaluate TRM. Most interview processes include a case study, AI skills assessment, and Leadership Principles interview.

Recruiter Intro: Explore your experience, motivations, and alignment with the role.

Hiring Manager: Dive deeper into your relevant experience, skills, and impact.

First Round: Typically 1–2 interviews focused on the skills most critical to the role.

Final Round: Meet some of the people you'd be working with. This is usually a panel-style session where we go deeper on your craft, problem-solving, and alignment with TRM.

References: We’ll speak with former colleagues who can provide perspective on your work and impact.

Offer: If it’s a mutual fit, your recruiter will walk you through your offer and answer your questions.

Welcome to TRM: Once you sign, we’ll get you ready for your first day and onboarding.

Your recruiter will share your specific interview plan and preparation guidance along the way.

Learn more about interviewing at TRM

Life at TRM

We are building a safer world. That promise shows up in how we work every day.

TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days.

Our work sits at the intersection of AI, national security, and fighting crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving.

At TRM, you should expect:

Priorities and targets to change quickly as we experiment and iterate

Work that often requires operating with a high degree of ambiguity

A high level of personal ownership and accountability

Close collaboration across teams and functions

Frequent, high-touch communication

Creative problem solving and out-of-the-box thinking

A pace that rewards urgency, adaptability, and outcomes

This environment is energizing for p

Original posting on TRM Labs's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job