Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Application Security Engineer

$150k - $173k

The Nuclear Company

Staff Application Security Engineer

Washington, DC

The Nuclear Company is the fastest growing startup in the nuclear and energy space creating a never before seen fleet-scale approach to building nuclear reactors. Through its design-once, build-many approach and coalition building across communities, regulators, and financial stakeholders, The Nuclear Company is committed to delivering safe and reliable electricity at the lowest cost, while catalyzing the nuclear industry toward rapid development in America and globally.

About the Role

The Nuclear Company is searching for an Application Security Engineer to help secure the software, data systems, and developer workflows that power our Nuclear Operating System, internal platforms, and mission-critical applications. This is a high-ownership role for a builder who is equally comfortable reviewing application architecture, threat modeling an API, improving GitHub security controls, and partnering directly with engineers to ship secure software quickly.

You will work across product engineering, platform engineering, data science, infrastructure, and operations to embed security into the way we design, build, test, and deploy software. You will help define secure development standards, review high-impact product designs, harden CI/CD workflows, and guide teams through vulnerability remediation in a practical, risk-based way.

This role reports to the Senior Manager for Application and Product Security.

Responsibilities

Application & Product Security

  • Perform security reviews and threat models for NOS modules, internal tools, APIs, data workflows, AI-enabled features, and cloud-connected applications.
  • Partner with engineering teams to identify and remediate risks across authentication, authorization, tenant isolation, input validation, secrets handling, encryption, logging, and data access.
  • Review application designs and code changes for security issues before they become production risk.
  • Define reusable security patterns for web applications, APIs, mobile workflows, internal platforms, and data-heavy systems.
  • Help establish secure-by-default approaches for applications that support regulated, high-consequence infrastructure.

Secure SDLC & Developer Enablement

  • Build and improve DevSecOps practices across the GitHub-based software development lifecycle, including code scanning, dependency review, secret scanning, branch protections, CI/CD hardening, and secure developer workflows.
  • Partner with engineering teams to create paved roads: secure templates, checklists, automation, documentation, and lightweight review processes that help teams move faster with confidence.
  • Triage and prioritize application security findings from SAST, SCA, secrets scanning, penetration tests, code reviews, and internal assessments.
  • Develop pragmatic vulnerability management workflows, remediation guidance, and engineering-facing metrics.
  • Support secure coding education through design reviews, office hours, documentation, and hands-on partnership with developers.

Platform, Cloud & Data Security

  • Collaborate with cloud and platform engineers to secure AWS workloads, infrastructure-as-code, service integrations, data pipelines, and deployment workflows.
  • Review integrations involving Palantir Foundry, partner APIs, internal data platforms, and AI-assisted engineering workflows.
  • Help secure sensitive data flows across application, platform, and operational environments.
  • Partner with infrastructure and developer teams to ensure application events, audit logs, and security signals are captured in ways that support investigation and response.
  • Navigate the security expectations of a regulated nuclear energy environment, including relevant cybersecurity frameworks and critical infrastructure considerations.

Cross-Functional Partnership

  • Serve as a trusted security partner to software engineers, product managers, data engineers, infrastructure teams, and business stakeholders.
  • Communicate risk clearly and practically, balancing security, delivery speed, product usability, and operational impact.
  • Contribute to the application and product security roadmap as the company scales from early-stage systems to fleet-scale operations.
  • Help build a culture of ownership, velocity, and technical rigor across engineering and cybersecurity.
Experience
  • 4+ years of experience in application security, product security, software security, or software engineering with a strong security focus.
  • Hands-on experience reviewing, building, or securing modern software systems, including web applications, APIs, distributed systems, or cloud-native services.
  • Strong understanding of common application security risks, including authentication, authorization, access control, injection, insecure deserialization, SSRF, secrets exposure, dependency and supply chain risk, and insecure API design.
  • Experience with secure SDLC tooling and workflows such as GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, secret scanning, CI/CD security, or equivalent platforms.
  • Ability to read and reason about code in at least one modern programming language such as Python, TypeScript, Go, Java, C#, or C++.
  • Familiarity with AWS security concepts, including IAM, logging, encryption, networking, secrets management, and infrastructure-as-code.
  • Strong communication skills and the ability to work directly with engineers to solve security problems without creating unnecessary friction.
  • Have a strong grasp of offensive security to anticipate risks from an adversary's perspective, not just check compliance boxes.
Preferred Qualifications
  • Experience securing software in regulated, industrial, energy, national security, aerospace, medical, or other mission-critical environments.
  • Familiarity with AI-assisted development tools, LLM-enabled applications, prompt-injection risks, model/tool integrations, or AI software supply chain concerns.
  • Experience with vulnerability management, penetration testing, experience with DAST tools, or incident response.
  • Familiarity with frameworks or standards such as OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, or NERC CIP.
  • Security certifications such as AWS Certified Security – Specialty or OSWE
  • Genuine interest in nuclear energy, critical infrastructure, hard-tech, and applying software security to physical systems.
Benefits
  • Competitive compensation packages
  • 401k with company match
  • Medical, dental, vision plans
  • Generous vacation policy, plus holidays

Estimated Starting Salary Range The estimated starting salary range for this role is $150,000 - $173,000 annually less applicable withholdings and deductions, paid on a bi-weekly basis. The actual salary offered may vary based on relevant factors as determined in the Company's discretion, which may include experience, qualifications, tenure, skill set, availability of qualified candidates, geographic location, certifications held, and other criteria deemed pertinent to the particular role.

EEO Statement The Nuclear Company is an equal opportunity employer committed to fostering an environment of inclusion in the workplace. We provide equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We prohibit discrimination in all aspects of employment, including hiring, promotion, demotion, transfer, compensation, and termination.

Export Control Certain positions at The Nuclear Company may involve access to information and technology subject to export controls under U.S. law. Compliance with these export controls may result in The Nuclear Company limiting its consideration of certain applicants.

Recruiting Fraud Alert Your safety is our priority. We want to ensure your job search stays secure. Please note that the team at The Nuclear Company only communicates through official @thenuclearcompany.com email addresses. We will never ask for payments or sensitive financial information at any stage of our recruitment process. For your peace of mind, please verify all openings and submit your applications directly through our official careers page.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Staff Application Security Engineer in Washington DC vacancy
  • $150.2k - $225.4k

     ...About the team: The Information Security organization advances the overall state of security at Rubrik through purposeful...  ...information. About the role: Rubrik is seeking an Application Security Engineer. In this role, you will be responsible for ensuring that... 
    Suggested
    Work experience placement
    Local area
    Remote work
    Shift work

    Rubrik

    Washington DC
    4 days ago
  •  ...Responsible for leading application security engineering efforts, designing scalable security architectures, performing advanced risk assessments, integrating security across the SDLC, driving AIrelated security controls, evaluating vendor solutions, scaling automation... 
    Suggested

    Bloomberg Industry Group

    Arlington, VA
    2 days ago
  • $135k - $200k

     ...Application Security Engineer Palantir builds the world's leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions... 
    Suggested
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    2 days ago
  • $62k - $141k

     ...Phase2 Technology is looking for an Application Security Engineer to work with clients on maintaining application security. This role involves remediating security flaws, leading discussions on best practices, and conducting dynamic and static testing using tools like... 
    Suggested
    Remote work

    Phase2 Technology

    Washington DC
    3 days ago
  •  ...SourcePro Search is conducting a search for an experienced Senior Application Security Engineer in Washington, DC. The ideal candidate will serve as subject matter expert integrating secure design for applications and services within the system development lifecycle. This... 
    Suggested

    SourcePro Search

    Washington DC
    12 hours ago
  • Responsible for supporting application security through security testing, vulnerability management, secure design collaboration, automation...  ...innovative security tools and a team of dedicated security engineers to protect our products throughout their lifecycle. Job... 

    Bloomberg Industry Group

    Arlington, VA
    2 days ago
  • $140k - $160k

     ...Overview Edgewater is currently seeking an Application Security Engineer who will be a hands‑on subject matter expert in Microsoft Azure cloud technologies, application security, security architectures, security tools, and methodologies. The Application Security Engineer... 
    Contract work
    Local area
    Remote work

    Edgewater IT LLC Defunct

    Washington DC
    12 hours ago
  •  ...Bloomberg BNA is seeking an Application Security Engineer I to support the security of applications. Responsibilities include conducting security assessments, implementing controls, and collaborating with developers to ensure secure coding practices. This entry-level position... 

    Bloomberg BNA

    Arlington, VA
    1 day ago
  •  ...Application Security Engineer Braintrust is the AI observability platform. By connecting evals and observability in one workflow, Braintrust gives builders the visibility to understand how AI behaves in production and the tools to improve it. Teams at Notion, Stripe... 
    Flexible hours

    Brain Trust Inc

    Washington DC
    1 day ago
  •  ...Application Security Engineer Comtech is a woman-owned small business founded in 1998 and headquartered in Reston, VA. We offer IT solutions across the disciplines of program/project management, applications development, infrastructure, Cyber security, and enterprise... 

    Comtech LLC

    Washington DC
    2 days ago
  • $210k - $230k

     ...report into the Director, Information Security and build relationships with technology...  ...payment systems to identify and remediate application vulnerabilities. This individual...  ...increase our AppSec posture and enable our engineers to code safely. Innovate with AI and deliver... 
    Full time
    Work at office
    Flexible hours

    Upside

    Washington DC
    4 days ago
  • $166k - $200k

     ...Senior Technical Security Application Engineer, Secured Spaces The Senior Technical Security Application Engineer, Secured Spaces, is the technical authority for the design, commissioning, and lifecycle maintenance of the Intrusion Detection Systems (IDS) and Access... 
    Full time
    Contract work
    Work experience placement
    Immediate start

    Colorwave Inc

    Washington DC
    12 hours ago
  •  ...Ernst & Young Oman is hiring an Application Security Engineer in Arlington, Virginia. The role involves managing application development platforms and optimizing security tools while ensuring operational efficiency through automation. Ideal candidates should have a relevant... 
    Flexible hours

    Ernst & Young Oman

    Arlington, VA
    4 days ago
  •  ...Ernst & Young Oman seeks an Application Security Engineer to enhance security tools and manage development platforms. You will collaborate with teams to integrate security processes and automate deployments while ensuring optimal security measures throughout the software... 

    Ernst & Young Oman

    Washington DC
    12 hours ago
  •  ...A leading security solutions firm is seeking a Senior Application Security Engineer in Washington, DC. The ideal candidate will integrate secure design in application development and collaborate on security solutions. They should have extensive experience in cybersecurity... 

    SourcePro Search

    Washington DC
    12 hours ago
  • $210k - $230k

     ...Upside is seeking an experienced Security Engineer to identify and mitigate application vulnerabilities. This role requires expertise in application security and a deep understanding of AWS architecture. Responsibilities include innovating security solutions and conducting... 
    Work at office

    Upside

    Washington DC
    4 days ago
  •  ...customers’ business challenges, Take2 will work as a partner to best resolve client needs. Take2 is hiring a Senior Application Security Engineer. This is a fully remote role. Job Description ~6+ years of Information Technology experience ~3+ years of experience... 
    Full time
    Remote work

    Take2 Consulting LLC

    Falls Church, VA
    7 hours ago
  • $77.5k - $140.9k

     ...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. As an Application Security Engineer, you will be responsible for implementing and managing application development platforms and optimizing security tools to... 
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Arlington, VA
    3 days ago
  • SourcePro Search is seeking a Mid-Level Application Engineer - Cyber Security Analytics Engineer in Washington, DC. The ideal candidate will develop and manage software tools to support Enterprise Management, focusing on software specifications, program design, and documentation... 

    SourcePro Search

    Washington DC
    3 days ago
  • We are conducting a search for a Mid‑Level Application Engineer - Cyber Security Analytics Engineer. We are seeking an ideal candidate who can develop and manage software tools to support Enterprise Management. This role involves formulating and defining specifications... 

    SourcePro Search

    Washington DC
    3 days ago
  • $108.6k - $181k

     ...Job Description Summary About the Role: We're seeking a highly skilled and experienced Senior Application Engineer with a strong background in technical solution design, system integration, and precise cost estimation for large-scale EPC (Engineering, Procurement... 
    Contract work
    Remote work
    Relocation package

    GE Vernova

    Washington DC
    1 day ago
  •  ...Senior OCI Application Engineer (Level III) Tharseo IT is seeking a senior OCI Application Engineer (Level III) to support a federal program...  ...connectivity issues that may involve network security group (NSG) rules and related controls. Supervise software... 
    For subcontractor
    Remote work

    InstantServe LLC

    Washington DC
    1 day ago
  •  ...Role Summary: The Application Engineer is responsible for developing and maintaining software applications to support the company's business operations. Main Responsibilities and Duties: Develop and maintain software applications. Collaborate... 

    Beyond SOF

    Washington DC
    12 hours ago
  • $130k - $150k

     ...with the ultimate goal ofenabling human life on Mars. PRODUCT SECURITY ENGINEER (STARSHIELD) Starshield leverages the company’s Starlink...  ...immediately necessary upon hire, we encourage you to initiate the application process promptly upon accepting this offer. Your ability to... 
    Permanent employment
    Temporary work
    Immediate start
    Flexible hours
    Weekend work

    United States Digital Space LLC

    Washington DC
    2 days ago
  • $135k - $150k

     ...Applications Engineer III Suvi is looking for an Applications Engineer III to work in Washington, DC. We are seeking a talented Applications...  ...technologies that accomplish customers' missions safely, securely, and efficiently. As a Suvi employee, you will be... 
    Full time
    Part time
    For contractors
    Remote work

    Akima

    Washington DC
    5 hours ago
  • $105k - $130k

     ...nonprofit organizations and individuals. Applications Engineer The Applications Engineer is a highly...  ...minimal supervision, ensuring stable, secure, and scalable application solutions aligned...  .... Interact with attorneys, business staff, clients, vendors, and consultants to resolve... 
    Temporary work
    Work at office
    Remote work

    International Executive Service Corps

    Washington DC
    12 hours ago
  •  ...Antler is seeking a remote HealthShare Application Engineer to join their team in Washington, DC. The ideal candidate will have a Bachelor's degree and 10-15 years of experience in information technology with strong expertise in InterSystems, AWS, CI/CD processes, and... 
    Remote work

    Antler Ltd

    Washington DC
    4 days ago
  • $107.63k

     ...Posting Title Application Engineer II Overview Application Engineer II in Washington, D.C. Application development, integration, maintenance...  ...systems. Participate in new functionality development to ensure secure, elegant and low maintenance date designs are adopted. Email... 
    Hourly pay

    The Catholic University of America

    Washington DC
    4 days ago
  •  ...skills and experience managing complex programs in a litigation environment. Responsibilities include developing and maintaining applications, translating requirements, and refining programs to enhance efficiency. The role requires substantial programming experience and... 
    Full time

    CGS Federal (Contact Government Services)

    Arlington, VA
    4 days ago
  • $78.4k - $127k

     ...Responsible for supporting the sustainment of Applications/Services providing the backend administration and support in the Oracle Cloud...  ...administration or other IT related field. ~ CompTIA Security+ Candidates should have some experience with ReadyAPI, Loadrunner... 
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Application Security Engineer. Be the first to apply!