
Staff Application Security Engineer
The Nuclear Company18 days ago
Washington, DC, USAStaff+
Base Salary
$150k - $173k/yr
Responsibilities
- Perform application security reviews and threat models for NOS modules, internal tools, APIs, data workflows, AI-enabled features, and cloud-connected applications.
- Partner with engineering teams to identify and remediate risks involving authentication, authorization, tenant isolation, input validation, secrets, encryption, logging, and data access.
- Define secure application patterns and review application designs and code changes for security issues.
- Build and improve DevSecOps practices across GitHub-based development workflows, including code scanning, dependency review, secret scanning, branch protections, and workflow hardening.
- Triage application security findings from SAST, SCA, secret scanning, penetration tests, code reviews, and internal assessments.
- Develop vulnerability management workflows, remediation guidance, metrics, secure templates, documentation, and developer education.
- Collaborate with cloud and platform engineers to secure AWS workloads, infrastructure-as-code, service integrations, data pipelines, and deployment workflows.
- Review Palantir Foundry, partner API, internal data platform, and AI-assisted engineering integrations.
- Help secure sensitive data flows and ensure application events, audit logs, and security signals support investigation and response.
- Contribute to the application and product security roadmap and serve as a practical security partner across engineering, product, data, infrastructure, operations, and business teams.
Requirements
- 4+ years of experience in application security, product security, software security, or software engineering with a strong security focus.
- Hands-on experience reviewing, building, or securing web applications, APIs, distributed systems, or cloud-native services.
- Strong knowledge of application security risks including authentication, authorization, access control, injection, insecure deserialization, SSRF, secrets exposure, dependency and supply chain risk, and insecure API design.
- Experience with secure SDLC tooling and workflows such as GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, secret scanning, and CI/CD security or equivalent platforms.
- Ability to read and reason about code in Python, TypeScript, Go, Java, C#, C++, or another modern programming language.
- Familiarity with AWS security concepts including IAM, logging, encryption, networking, secrets management, and infrastructure-as-code.
- Strong communication skills and the ability to work directly with engineers to solve security problems pragmatically.
- Strong offensive security understanding and the ability to anticipate adversary risks rather than only checking compliance requirements.
- Preferred experience securing software in regulated, industrial, energy, national security, aerospace, medical, or other mission-critical environments.
- Preferred familiarity with AI-assisted development tools, LLM-enabled applications, prompt-injection risks, model and tool integrations, AI software supply chain concerns, vulnerability management, penetration testing, DAST tools, or incident response.
- Preferred familiarity with OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, or NERC CIP.
- Security certifications such as AWS Certified Security – Specialty or OSWE are preferred.
Benefits
- Competitive compensation packages.
- 401k with company match.
- Medical, dental, and vision plans.
- Generous vacation policy plus holidays.