Full-Time

Security Researcher

Posted on 10/31/2025

Truffle Security

Truffle Security

51-200 employees

Open-source scanning for credential secrets

Compensation Overview

$141.5k - $166.4k/yr

+ Bonus + Stock Options + Benefits

Remote in USA

Remote

Applicants outside the U.S. must maintain sufficient working-hour overlap with the U.S.-based team.

US Citizenship, US Top Secret Clearance, UK Citizenship, UK Top Secret Clearance Required

Category
Developer Relations
Requirements
  • 3+ years of experience in application security, or another category such as Cloud Security, DevSecOps, Data Analytics, Blue Team, or other relevant area
  • Background in security research – Ideally, you have experience investigating security issues (through professional roles, side projects, or open-source contributions)
  • Public-facing research – Ideally, you’ve shared findings externally (blog posts, talks, etc.), or you’re excited to build that muscle here
  • Excellent technical writing skills that demonstrate clarity, depth, and accuracy
  • Intermediate programming skills – your code doesn’t need to be production-ready, but you should be comfortable prototyping and building proof-of-concept tools
  • We work primarily in Python and Golang
  • Familiarity with LLM tools and how to effectively incorporate them into research and programming workflows
  • Strong collaboration abilities – You’re equally good at respectfully asking for help and humbly providing it
  • Ability to juggle multiple long-term research projects – We often run 5 or 6 projects simultaneously without compromising quality or timelines
  • High ethical standards and integrity – We find many security vulnerabilities in our research, and it takes maturity to handle interactions with the organizations we disclose to
  • Attention to Detail – There are many moving parts during research projects, and this role requires patience and extreme attention to detail
Responsibilities
  • Conduct cutting-edge open-source security research in areas broadly related to secrets (application security, cloud security, DevSecOps, etc.)
  • Create engaging content to showcase research findings, including blog posts, technical documentation, videos, and whitepapers
  • Present at conferences and industry events to share your discoveries, represent Truffle Security, and build community interest/trust
  • Contribute to open source by sharing research-driven improvements or small proof-of-concept tools to Truffle’s projects
  • Collaborate with engineering to share insights and help track down the occasional bug
  • Maintain a positive, respectful, and ethical attitude in all external and internal interactions. There\'s no room for egos or “gotchas” when dealing with security research.
Desired Qualifications
  • None

TruffleSecurity develops cybersecurity tooling focused on protecting sensitive data. Its flagship product, TruffleHog, scans codebases, version histories, and other hidden content to locate exposed credentials across an organization. The open-source engine checks more than 700 credential types against the key provider, which reduces false positives and speeds up accurate detection. It also automates the remediation of discovered secrets to shorten response time. Compared with competitors, TruffleHog’s open-source nature, broad credential type coverage, and automated remediation set it apart, along with open integrations that support transparency and collaboration. The company's goal is to help organizations discover and secure leaked or stored secrets quickly, lowering the risk of credential theft and data breaches across various industries and business sizes.

Company Size

51-200

Company Stage

Series B

Total Funding

$40M

Headquarters

San Francisco, California

Founded

2019

Simplify Jobs

Simplify's Take

What believers are saying

  • Raised $25M Series B in 2024 from Intel Capital and a16z to expand enterprise features.
  • Hugging Face partnership prevents sensitive leaks in ML code repositories.
  • Open-source TruffleHog drives community contributions and industry-standard adoption.

What critics are saying

  • GitGuardian and Snyk replicate open-source detectors, eroding pricing power within 24 months.
  • Customer concentration risks 25% revenue loss from single top client churn in 18 months.
  • AI code from GitHub Copilot spikes false positives, causing alert fatigue in 12 months.

What makes Truffle Security unique

  • TruffleHog verifies 700+ credential types against providers to eliminate false positives.
  • GCP Analyze add-on reveals blast radius of leaked Google Cloud secrets instantly.
  • Relaunched XSS Hunter integrates TruffleHog for scanning secrets on XSS pages.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Flexible Paid Time Off

Paid Holidays

Comprehensive health benefits

401(k) Company Match

Health & wellness stipend

Learning & development stipend

Remote work stipend

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

1%

2 year growth

-3%
Truffle Security Co.
Nov 7th, 2025
TruffleHog Analyze press release ◆ Truffle Security Co.

TruffleHog Analyze press release

SiliconANGLE Media
Nov 6th, 2025
Truffle Security secures $25M to protect codebases from leaked secrets and nonhuman identities

Truffle Security secures $25M to protect codebases from leaked secrets and nonhuman identities. Open-source security software company Truffle Security Co. announced today that it has raised $25 million in new funding to fuel continued growth of TruffleHog Enterprise, the company's enterprise-grade secrets detection, verification and remediation solution, and expand its development in secrets and nonhuman identities protection. Founded in 2019, Truffle Security provides paid solutions based on TruffleHog, an open-source tool that scans code repositories for exposed secrets such as application programming interface keys, tokens and passwords. the tool helps developers and security teams quickly identify and remediate leaked credentials before they can be exploited. Truffle Security's offering is focused on detecting exposed secrets, such as API keys, tokens, service-account credentials and other nonhuman identities, across codebases, cloud environments and repositories. The open-source engine supports hundreds of detectors and is designed to scan for signs of secret leakage or improper credentials being checked in. The company also offers verification and remediation where, once a secret is found, the platform helps determine whether it is active, what systems it could access and what the blast radius might be. The results give contextual insight that allows security teams and development teams to prioritize and respond quickly. Truffle Security's paid offering, TruffleHog Enterprise, provides monitoring, detection and integration into the software development lifecycle so that secrets don't become entry points for breaches. The Series A round was led by Intel Capital Corp. and a16z (Andreessen Horowitz). Joining the round were Abstract Ventures, Lytical Ventures and individual investors. Those included Casey Ellis, founder of BugCrowd Inc., as well as Emilio Escobar, chief information security officer at Datadog Inc. ,and Haroon Meer, founder and chief executive of Thinkst Applied Research Pty. Ltd. "As AI transforms how software is built, the security surface is expanding just as quickly," said Martin Casado, general partner at Andreessen Horowitz. "Truffle Security is tackling one of the most urgent challenges in this new era, which is protecting codebases from secret exposure at scale." Along with the funding, Truffle Security also announced a new GCP Analyze add-on for TruffleHog Enterprise that is designed to significantly reduce time to remediation when Google Cloud Platform secrets leak. With GCP Analyze, security teams get instant context, including what resources it can access, its inheritance and the blast radius of its permissions, instead of having to spend hours untangling identity and access management complexity. The new offering is built on top of TruffleHog Enterprise's verified secret detection, which eliminates false positives to help security teams remediate threats faster and more confidently across the software development lifecycle. Coming into the new funding round, Truffle Security had previously raised a $14 million Series A round in December 2021, according to data from Tracxn. Image: Truffle Security. A message from John Furrier, co-founder of SiliconANGLE: Support its mission to keep content open and free by engaging with theCUBE community. Join theCUBE's Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. * 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more * 11.4k+ theCUBE alumni - Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios - with flagship locations in Silicon Valley and the New York Stock Exchange - SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Its new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

PR Newswire
Nov 6th, 2025
Truffle Security Secures $25M for Expansion

Truffle Security announced a $25 million Series B funding round led by Intel Capital and a16z, with participation from Abstract, Lytical Ventures, and security leaders. The funding will support customer growth and product expansion, including TruffleHog GCP Analyze for detecting leaked Google Cloud secrets. The investment aims to enhance TruffleHog Enterprise's capabilities in secrets detection and NHI protection, addressing the growing security challenges in the AI-driven software development era.

CO/AI
Sep 5th, 2024
Hugging Face Partners with Truffle Security to Protect Code Repositories

Key partnership details: The collaboration between Hugging Face and Truffle Security aims to prevent accidental leaks of sensitive information in code repositories.

Trend Hunter
Aug 8th, 2024
Leaked Credentials Cybersecurity Tools

Truffle Security launches trufflehog Analyze as a solution.

INACTIVE