Skip to main content
← Back to jobs
Truffle Security logo

Manager, Security Research

Truffle SecurityRemote Full Time

Job Description

About us

TruffleHog is a popular open source tool used by security researchers all over the world to find leaky API keys and responsibly disclose them to affected companies. This provides income through bug bounty platforms like HackerOne to individuals that may otherwise have a hard time finding employment. This also prevents breaches from occurring, which can be very costly for companies to resolve.

When we founded Truffle Security Co. in February of 2021, we committed to continue to grow a community with security researchers around the world, and continue to provide free and open resources to support those that make the world more secure. We have a strong commitment to open source and to the community. We’re looking for help supporting our mission to prevent leaking credentials and build the best products for machine identity protection.

At Truffle, you’ll have the opportunity to join a fully remote, collaborative team contributing to meaningful advancements in cybersecurity.

About the role

This is a research leadership role at the core of Truffle’s mission to eliminate credential leakage and secure non-human identities. Reporting directly to the CEO, you will lead and scale a small, high-impact research team while defining how modern secret scanning actually works in practice. You’ll uncover novel attack surfaces, model real attacker behavior, and turn those insights into product capabilities that materially improve how organizations detect and remediate credential exposure. This is a role for someone who wants their research to shape both the product and the category.

What you'll be working on

  • Owning and driving the research roadmap, focusing on the highest-impact problems in leaked credentials, secrets exposure, and non-human identity security.
  • Leading a team of experienced researchers, setting direction, assigning ownership of critical initiatives aligned to the roadmap, and ensuring research output consistently translates into product and company impact.
  • Identifying and validating novel leak surfaces across code, SaaS tools, logs, datasets, and emerging ecosystems (including AI/LLMs).
  • Designing and running large-scale scans and experiments to uncover real-world exposures, validate impact, and understand attacker behavior.
  • Developing verification systems at scale to distinguish real, exploitable secrets from noise—improving precision without sacrificing coverage.
  • Publishing high-quality technical research (blogs, reports, disclosures) and representing Truffle externally through talks, conferences, and community engagement.
  • Acting as a bridge between research and product, ensuring insights turn into shipped capabilities and roadmap decisions.
  • Collaborating cross-functionally with marketing, sales, and developer relations to turn research into clear, compelling narratives for customers and the broader security community.

What we're looking for

  • Proven experience leading and growing a research team, with strong ownership over direction and outcomes.
  • Strong product instincts: you know the difference between interesting research and work that actually improves customer outcomes.
  • Deep expertise in secret scanning, including detection techniques (regex, entropy, ML-assisted), and especially verification at scale.
  • Track record of discovering non-obvious, high-impact vulnerabilities or leak surfaces and validating their real-world exploitability.
  • Experience turning research into shipped product improvements, not just standalone findings.
  • Strong attacker mindset—you think in terms of how systems break, not just how they’re designed.
  • Ability to work with messy, high-volume data (credentials, tokens, secrets) and turn it into clear insights and system improvements.
  • Experience building or working on security scanners, detection systems, or large-scale data pipelines.
  • Experience defining metrics, benchmarks, and evaluation frameworks for detection quality (precision, recall, verification accuracy).
  • Strong technical communication skills, with experience publishing research or speaking publicly.
  • Experience working cross-functionally with product, engineering, and go-to-market teams.
  • Familiarity with non-human identity systems (API keys, service accounts, OAuth tokens).

Bonus points!

  • Background in offensive security, bug bounty, or vulnerability research
  • Experience contributing to or maintaining open-source security tools
  • Interest in emerging attack surfaces in AI/LLM ecosystems
  • Existing presence in the security community through research, talks, or content

Salary Range: The target base salary range for this position is between $225,000 to $260,000 for candidates in the United States. Starting salary will vary based on job-related skills, knowledge, and experience. Leveling will be determined during the interview process. You may also be offered a bonus, stock options, and benefits. These salary ranges are subject to change, and we encourage candidates outside of this salary range to apply.

How we support our team

  • Fully remote within the U.S. – We believe opportunity shouldn’t be limited by geography. Our remote-first approach lets us hire the best people across the United States and empowers them to do their best work from wherever they are.
  • A culture of mentorship, equity, and psychological safety – We’re committed to fostering an environment where you can thrive, learn, and feel valued.
  • Competitive salary & meaningful equity – Be rewarded for your contributions with a strong compensation package and a stake in our shared success.
  • Flexible paid time off – We operate with a high level of autonomy and trust, giving you the flexibility to take time off as needed—no strict limits, just the expectation that you’re meeting your commitments and getting your work done.
  • 14 paid holidays – Including Thanksgiving, Winter Break, and "Truffle Holidays" when the entire company takes a well-deserved day off together.
  • Comprehensive health benefits – Medical, dental, and vision coverage with 80% of premiums covered for you and your dependents.
  • Remote work stipend – Get set up for success with an $800 new hire stipend and $100/month to keep your workspace comfortable.
  • Health & wellness stipend$1,200/year to support your physical, mental, and emotional well-being— we believe that feeling good helps you do great work.
  • Learning & development stipend$2,000/year to invest in your growth, whether it’s courses, certifications, or industry conferences.
  • 401(k) match – We match 100% of the first 6% of your contributions on every paycheck, helping you build financial security for the future.
  • 100% remote + company off-sites – Twice a year, we come together in amazing locations like Hawaii, Cabo, and the Rocky Mountains to collaborate and connect.


We’re looking for folks who are interested in being part of the journey to make the internet more secure. The internet is for all, and we believe that diverse experiences and people from all walks of life can contribute to this mission. That said, if what we’re doing resonates with your values, we’d love to have you apply even if you don’t check all of the boxes or match the job description to a tee.

Truffle strives to promote an equitable, inclusive, and psychologically-safe workplace for all who are interested in working with us. All job applicants will be considered throughout the employment process without regard to race, color, ethnicity, religion, sex, sexual orientation, gender perception/identity, age, pregnancy or parental status, disability status, or any other basis prohibited by law. If you are an individual with disabilities and reasonable accommodation is needed throughout the interview process, or to perform essential job functions, please let your recruiter know.

Lastly, we ask that all applicants consider the opportunity to answer a few voluntary demographic questions on the job application. This helps us track the inclusivity of our recruiting initiatives. Answering these questions is entirely optional and your answers will not be shared with the hiring team and will not impact the hiring decision.

Note: Our organization participates in the US federal E-Verify program. We will provide the Social Security Administration, and if necessary, the Department of Homeland Security, with information from each new employee’s Form I-9 to confirm work authorization. We do not use this information to pre-screen job applicants.

Optimize Your Resume for This Job

Get a match score and see exactly which keywords you're missing

Optimize Resume

Job Details

Category
Security
Employment Type
Full Time
Location
Remote (Remote Available)
Posted
Apr 27, 2026, 05:21 PM
Listed
Apr 27, 2026, 05:21 PM

About Truffle Security

Part of the growing frontier tech ecosystem pushing the edges of what's possible.

Found this role interesting?

Manager, Security Research
Truffle Security
Apply ↗

Shipping like we're funded. We're not. No affiliation.

Sequoia logo
Y Combinator logo
Founders Fund logo
a16z logo