Skip to main content

Security research should be a public good.

We publish our tools, share our methods, and advance the field with every engagement. The best way to protect our clients is to raise the security bar for everyone.

We are a security research and consulting firm working across defense, technology, finance, and blockchain. Our teams take on our clients' hardest problems: designing and building new security technology, researching techniques that move the field forward, and reviewing high-stakes products before they ship.

Research model

Founding story

Trail of Bits launched in 2012 because the security industry had a knowledge-hoarding problem. Firms competed on secrecy while the same vulnerabilities kept showing up everywhere. We took the opposite approach: solve the problem once, build a tool, and release it. Today we maintain 100+ open-source projects used by security teams worldwide.

Core principles

Publish everything means exactly that. Our blog posts become reference material, our internal tools become community standards, and when we find a new attack pattern we build the detection for it and put it in everyone's hands. We do this because we think it is how security should work.

What makes us different

Most consultancies sell hours and hand you a report. We sell the output of work that shapes where the field goes next. We run multi-year DARPA programs, finish among the top teams in contests like the AI Cyber Challenge and the Cyber Grand Challenge, and disclose vulnerabilities in systems that dedicated security teams could not protect. When you hire us, you get the benefit of all of it.

Top talent

A team that builds tools, publishes methods, and works together across difficult security domains.

Our engineers are researchers first. Every one of them gets dedicated time to build tools, study what they find, and present it publicly, and that time is what keeps the bench sharp. The people who maintain Slither or write our post-quantum guidance are the same people who show up on your engagement.

"Our team is the most important investment we make. We take real pride in only accepting work we find genuinely interesting, engaging, and hard."

Dan Guido, CEO and co-founder

Alex Sotirov

Leadership

Alex Sotirov

Co-CEO

Leadership
Artem Dinaburg

Leadership

Artem Dinaburg

Chief Scientist, Research

Leadership

Also Engineering

Benjamin Samuels

Leadership

Benjamin Samuels

Engineering Director, Blockchain

Leadership

Also Engineering

Dan Guido

Leadership

Dan Guido

CEO

Leadership
Jim Miller

Leadership

Jim Miller

Engineering Director, Cryptography

Leadership

Also Engineering

Trent Brunson

Leadership

Trent Brunson

Head of Research & Engineering

Leadership

Also Engineering

Lindsay Rakowski

Sales & Partnerships

Lindsay Rakowski

Sales Manager II

Sales & Partnerships
Amanda Stickler

Operations

Amanda Stickler

Project Manager

Operations
LaKisha Jackson

Operations

LaKisha Jackson

Contract Support Specialist

Operations
Mary O'Brien

Operations

Mary O'Brien

Staff Program Manager

Operations
Akshay Kumar

Engineering

Akshay Kumar

Staff Security Engineer

Engineering
Alessandro Gario

Engineering

Alessandro Gario

Senior Software Engineer

Engineering
Artur Cygan

Engineering

Artur Cygan

Principal Security Engineer

Engineering
Billy Mason Jr

Engineering

Billy Mason Jr

Staff Security Engineer

Engineering
Brad Swain

Engineering

Brad Swain

Senior Security Engineer

Engineering
Bruno Produit

Engineering

Bruno Produit

Senior Security Engineer

Engineering
David Pokora

Engineering

David Pokora

Principal Security Engineer

Engineering
Dominik Czarnota

Engineering

Dominik Czarnota

Staff Security Engineer

Engineering
Emilio López

Engineering

Emilio López

Senior Security Engineer

Engineering
Eric Kilmer

Engineering

Eric Kilmer

Principal Security Engineer

Engineering
Evan Sultanik

Engineering

Evan Sultanik

Principal Security Engineer

Engineering
Filipe Casal

Engineering

Filipe Casal

Principal Security Engineer

Engineering
Francesco Bertolaccini

Engineering

Francesco Bertolaccini

Senior Security Engineer

Engineering
Fredrik Dahlgren

Engineering

Fredrik Dahlgren

Principal Security Engineer

Engineering
Graham Sutherland

Engineering

Graham Sutherland

Senior Security Engineer

Engineering
Henrik Brodin

Engineering

Henrik Brodin

Principal Security Engineer

Engineering
Jay Little

Engineering

Jay Little

Principal Security Engineer

Engineering
Joop van de Pol

Engineering

Joop van de Pol

Principal Security Engineer

Engineering
Josh Hofing

Engineering

Josh Hofing

Senior Security Engineer

Engineering
Maciej Domański

Engineering

Maciej Domański

Principal Security Engineer

Engineering
Marc Ilunga

Engineering

Marc Ilunga

Security Engineer II

Engineering
Nick Sellier

Engineering

Nick Sellier

Senior Security Engineer

Engineering
Octavio Galland

Engineering

Octavio Galland

Security Engineer II

Engineering
Opal Wright

Engineering

Opal Wright

Security Engineer II

Engineering
Paweł Płatek

Engineering

Paweł Płatek

Senior Security Engineer

Engineering
Riccardo Schirone

Engineering

Riccardo Schirone

Senior Security Engineer

Engineering
Sam Moelius

Engineering

Sam Moelius

Staff Security Engineer

Engineering
Sam Sharps

Engineering

Sam Sharps

Principal Security Engineer

Engineering
Scott Cohen

Engineering

Scott Cohen

Senior Security Engineer

Engineering
Skylar Rampersaud

Engineering

Skylar Rampersaud

Staff Security Engineer

Engineering
Stefano Bonicatti

Engineering

Stefano Bonicatti

Senior Security Engineer

Engineering
Thomas Chauchefoin

Engineering

Thomas Chauchefoin

Senior Security Engineer

Engineering
Tjaden Hess

Engineering

Tjaden Hess

Engineering Director, Machine Learning

Engineering
Vasco Franco

Engineering

Vasco Franco

Staff Security Engineer

Engineering

Trail of Bits timeline

Milestones that shaped the team and the way it works.

These milestones explain why the roster is organized around published tools, research programs, and public artifacts rather than generic practice lines.

  1. 2012

    Trail of Bits founded

    We set out to publish security research and tooling to raise the bar for everyone.

  2. 2015

    Qualified for DARPA's Cyber Grand Challenge

    Competed to build autonomous vulnerability discovery systems as part of DARPA's Cyber Grand Challenge.

  3. 2016

    Partnered with Facebook to port osquery to Windows

    Expanded osquery to support cross-platform endpoint security monitoring.

  4. 2017

    Open-sourced Manticore

    Open-sourced Manticore, a symbolic execution framework used in DARPA research.

  5. 2018

    Released Slither and Echidna

    Released Slither and Echidna, now industry-standard tools for smart contract security.

  6. 2019

    Launched iVerify for iPhone

    Launched iVerify and co-founded the osquery Foundation with the Linux Foundation.

  7. 2024

    Selected for DARPA's AI Cyber Challenge (AIxCC)

    Selected for AIxCC and awarded $1M to build an AI-powered Cyber Reasoning System.

  8. 2025

    Won $3M second-place prize at DARPA AIxCC finals

    Won second place at DEF CON 33 and open-sourced Buttercup.

Work on problems that matter

Join Trail of Bits

Novel research, practical security work, and a remote-first operating model.

Our mix of novel research and practical work reduces the risks our clients face from emerging technology, and it pushes the whole industry's understanding forward.

Join a team of experts

Tired of being the smartest person in the room? Trail of Bits is full of research engineers who break security problems and ship open-source fixes every day.

Work on problems that matter

From securing blockchains to DARPA programs, our teams have touched nearly every kind of product that depends on a secure foundation.

Remote first, always

While the rest of the industry calls people back to the office, we believe the best work happens where people work best. Annual off-sites bring the team together to build and learn.