Staff Application Security Engineer

The Nuclear Company - Washington, DC

Hiring: Staff Application Security Engineer Company: The Nuclear Company Location: Washington, DC Job Posted Time: 2026-09-11 10:22:59 Target Skills & Keywords : API Design, AWS, C#, C++, CI/CD, DAST, Data Pipeline, Encryption, Foundry, GitHub, IAM, Java, LLM, OWASP, Penetration Testing, Python, SAST, SCA, SOC 2, TypeScript About the job Experience: •4+ years of experience in application security, product security, software security, or software engineering with a strong security focus. •Hands-on experience reviewing, building, or securing modern software systems, including web applications, APIs, distributed systems, or cloud-native services. •In-depth knowledge of common application security risks, including authentication, authorization, access control, injection, insecure deserialization, SSRF, secrets exposure, dependency and supply chain risk, and insecure API design. •Demonstrated capacity to read and reason about code in at least one modern programming language such as Python, TypeScript, Go, Java, C#, or C++. •Operational familiarity with AWS security concepts, including IAM, logging, encryption, networking, secrets management, and infrastructure-as-code. Required Skills: •This role reports to the Senior Manager for Application and Product Security. •Perform security reviews and threat models for NOS modules, internal tools, APIs, data workflows, AI-enabled features, and cloud-connected applications. •Partner with engineering teams to identify and remediate risks across authentication, authorization, tenant isolation, input validation, secrets handling, encryption, logging, and data access. •Review application designs and code changes for security issues before they become production risk. •Define reusable security patterns for web applications, APIs, mobile workflows, internal platforms, and data-heavy systems. •Help establish secure-by-default approaches for applications that support regulated, high-consequence infrastructure. •Secure SDLC & Developer Enablement •Build and improve DevSecOps practices across the GitHub-based software development lifecycle, including code scanning, dependency review, secret scanning, branch protections, CI/CD hardening, and secure developer workflows. Qualifications: •Operational familiarity with AI-assisted development tools, LLM-enabled applications, prompt-injection risks, model/tool integrations, or AI software supply chain concerns. •Operational familiarity with frameworks or standards such as OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, or NERC CIP. •Security certifications such as AWS Certified Security – Specialty or OSWE •Genuine interest in nuclear energy, critical infrastructure, hard-tech, and applying software security to physical systems. Compensation: •$150,000 - $173,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!