Unlock Full Resume Report
ATS Pass
Missing keywords
Tailored AI suggestions
Job match analysis
Interview-focused insights
This position is no longer accepting applications
Positions open for more than 30 days are automatically closed and marked as expired
Don't let one closed door slow you down, here's your next move:
June 17, 2026
Staff Application Security Engineer
Senior • On-site
150,000 - 173,004 USD/yr
Washington, DC
About the role
The Nuclear Company is searching for an Application Security Engineer to help secure the software, data systems, and developer workflows that power the Nuclear Operating System, internal platforms, and mission-critical applications. This is a high-ownership role for a builder comfortable reviewing architecture, threat modeling APIs, improving GitHub security controls, and partnering with engineers to ship secure software quickly.
You will work across engineering, data, infrastructure, and operations to embed security into how software is designed, built, tested, and deployed. You will define secure development standards, review product designs, harden CI/CD workflows, and guide vulnerability remediation in a practical, risk-based way.
Responsibilities
Application & Product Security
- Perform security reviews and threat models for NOS modules, internal tools, APIs, data workflows, AI-enabled features, and cloud-connected applications.
- Identify and remediate risks across authentication, authorization, tenant isolation, input validation, secrets handling, encryption, logging, and data access.
- Review application designs and code changes for security issues before production.
- Define reusable security patterns for web applications, APIs, mobile workflows, internal platforms, and data-heavy systems.
- Establish secure-by-default approaches for regulated, high-consequence infrastructure.
Secure SDLC & Developer Enablement
- Build and improve DevSecOps practices across the GitHub-based SDLC including code scanning, dependency review, secret scanning, branch protections, and CI/CD hardening.
- Create secure templates, automation, documentation, and lightweight review processes.
- Triage findings from SAST, SCA, secret scanning, penetration tests, and code reviews.
- Develop vulnerability management workflows and remediation guidance.
- Support secure coding education through reviews and developer collaboration.
Platform, Cloud & Data Security
- Secure AWS workloads, infrastructure-as-code, integrations, data pipelines, and deployments.
- Review integrations involving Palantir Foundry, partner APIs, and AI-assisted workflows.
- Protect sensitive data flows across environments.
- Ensure logging and security signals support investigation and response.
- Navigate cybersecurity expectations in a regulated nuclear environment.
Cross-Functional Partnership
- Partner with engineers, product managers, and stakeholders.
- Communicate risk clearly while balancing delivery speed.
- Contribute to the product security roadmap as systems scale.
- Promote ownership, velocity, and technical rigor.
Experience
- 4+ years in application or software security.
- Experience securing web applications, APIs, distributed systems, or cloud-native services.
- Strong understanding of authentication, authorization, injection, SSRF, insecure deserialization, secrets exposure, dependency risk, and API security.
- Experience with GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, secret scanning, and CI/CD security.
- Ability to read at least one of: Python, TypeScript, Go, Java, C#, or C++.
- Familiarity with AWS IAM, encryption, logging, networking, secrets management, and infrastructure-as-code.
- Strong communication skills and offensive security mindset.
Preferred Qualifications
- Experience in regulated or mission-critical environments.
- Familiarity with AI-assisted development, LLM applications, and prompt injection risks.
- Experience with vulnerability management, DAST, penetration testing, or incident response.
- Knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, or NERC CIP.
- Security certifications such as AWS Certified Security – Specialty or OSWE.
Benefits
- Competitive compensation packages
- 401k with company match
- Medical, dental, vision plans
- Generous vacation policy plus holidays
Estimated Starting Salary Range
$150,000 - $173,000 annually, less applicable withholdings and deductions, paid bi-weekly. Actual salary may vary based on experience, qualifications, location, certifications, and other relevant factors.
EEO Statement
The Nuclear Company is an equal opportunity employer committed to an inclusive workplace. Discrimination in any aspect of employment is prohibited.
Export Control
Certain positions may involve access to information and technology subject to U.S. export controls, which may limit consideration of some applicants.
Similar jobs you might like
Technology
AgileEngine
Senior/Lead AppSec Engineer
Senior
Remote
Krakow, MA, Poland
6,200 - 8,069 USD
🏢 Summary: Senior Application Security Engineer role focused on building automated security controls across the SDLC for a large-scale financial services program. The position centers on Python-based security automation, AI-enabled code scanning, CI/CD security integration, and code-level remediation guidance, with autonomous execution. 🗂️ Requirements: 5+ years of software engineering experience, Python proficiency for security automation and scripting, Application Security or DevSecOps experience, Autonomous execution without daily supervision, Upper-intermediate English 📃 Skills: Python, DevSecOps, AppSec, SAST, DAST, SCA, CI/CD, Java, LLMs 🏢 Description: ID71672 AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards. Why join us If you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you! :) About the role We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration within a large-scale financial services program. You will work primarily in Python to build automated security runbooks, deploy and tune scanning tools, and provide code-level remediation guidance to development teams — operating with full autonomy and no daily supervision. AppSec and DevSecOps experience is strongly preferred; SAST/DAST/SCA and Java expertise are a plus. What you will do Engineer and deploy AI-enabled secure code scanning capabilities and "Golden Images" to drive secure-from-the-start adoption; Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows; Architect the integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise; Act as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance. Must haves 5+ years of software engineering experience, ideally with a focus on Application Security and DevSecOps; Strong coding and architectural proficiency in Python for security automation and scripting; Fully autonomous execution capability, requiring no daily supervision to map out and build automated security runbooks; Upper-intermediate English level. Nice to haves Deep, hands-on expertise deploying and tuning modern application security testing tools, including SAST, DAST, and SCA, and integrating them into complex CI/CD orchestration ecosystems; Experience integrating LLMs, AI agents, or automated coding assistants to streamline vulnerability triaging or secure code generation; Advanced application threat modeling experience; Ability to confidently read, review, and secure enterprise source Java code. The benefits of joining us Professional growth Accelerate your professional journey with mentorship, TechTalks, and personalized growth roadmaps Competitive compensation We match your ever-growing skills, talent, and contributions with competitive USD-based compensation and budgets for education, fitness, and team activities A selection of exciting projects Join projects with modern solutions development and top-tier clients that include Fortune 500 enterprises and leading product brands Flextime Tailor your schedule for an optimal work-life balance, by having the options of working from home and going to the office – whatever makes you the happiest and most productive. Meet Our Recruitment Process Asynchronous stage – An automated, self-paced track that helps us move faster and give you quicker feedback: Short online form to confirm basic requirements 30–60 minute skills assessment via Codility – a platform founded in Poland that helps us provide quicker feedback and streamline this stage of the process. 5-minute introduction video Synchronous stage – Live interviews Technical interview with our engineering team (scheduled at your convenience) Final interview with your future teammates If it’s a match — you’ll get an offer!
Technology
Euroclear
DevOps Engineer with .NET
Senior
Hybrid
Krakow, MA, Poland
🏢 Summary: Join a DevOps-focused .NET integration squad responsible for designing, implementing, securing, and operating integration products across on-premises, private-cloud, and public-cloud environments. The role covers .NET framework expertise, application configuration, CI/CD, deployment troubleshooting, performance optimization, and compliance in a regulated IT environment. 🗂️ Requirements: Hands-on Azure engineering experience, C# and .NET application development experience, Visual Studio and Azure DevOps experience, Microsoft security expertise in Windows Server environments, Kerberos and Active Directory knowledge, CI/CD concepts knowledge, PKI and certificate concepts knowledge, Azure services experience, Windows Server 2016, 2019, and 2022 experience, PowerShell experience, Experience with .NET 4.8, .NET 8, ADFS, MVC, IIS, WCF, WebAPI, NuGet, and APIs, Integration patterns and technologies knowledge, API security integration experience, Security, encryption, token-based authentication, GDPR, and compliance knowledge, Middleware and advanced IT infrastructure experience, Scrum and Agile familiarity, Risk management knowledge 📃 Skills: Azure, C#, .NET, VisualStudio, AzureDevOps, WindowsServer, Kerberos, ActiveDirectory, CICD, PKI, PowerShell, ADFS, MVC, IIS, WCF, WebAPI, NuGet, APIs, GDPR, Scrum, Agile, Middleware, OAuth, OpenID, SAML, Linux, ServiceFabric, Splunk 🏢 Description: Division: Group Technology Services (GTS) About the squad: Join the ".Net Application Integration Services" squad, consisting of 1 Product Owner, 1 Scrum Master, and 10 developers. We manage several products on-premise, in Private and Public Cloud, mainly including: Bespoke C# .Net Libraries delivered as NuGet Security token services for Web based, API and Message based applications Cloud resources, middleware (runtime, hosting), Service Mesh… Our main collaborators are Euroclear software developers, system administrators, and solution architects.We prioritize integration, solving, and optimization to ensure high availability, scalability, and reliability. We also collaborate with security teams to implement vital security measures and ensure data protection. About the role: As a developer in our squad, you will focus on DevOps: Subject Matter Expert for .Net framework Analyze requirements and solutions, design, implement, and integrate our products. Drive and contribute to Application Change in a regulated IT organization Main Tasks Learn our products and adopt a T-Shaped skillset. Maintain .Net framework configuration, technical security baseline and manage the relationship with Microsoft for incident and advisory cases. Manage and optimize application configuration. Collaborate with cross-functional teams to ensure seamless integration and delivery of solutions. Troubleshoot and resolve issues related to deployment and integration in a timely manner. Provide technical guidance and support to our clients. Perform thorough testing, monitor and optimize the performance of integration solutions. Ensure compliance with data privacy regulations and internal governance policies. Maintain pragmatic documentation of integration for reference by development teams and stakeholders. Key Qualifications Integration Expertise: Comprehensive understanding of various integration patterns, approaches, and technologies Web Development: Proficiency in web development technologies and frameworks API Security Integration: Experience in integrating API security measures Security and Compliance: Understanding of security best practices, encryption, token-based authentication, and compliance requirements (e.g., GDPR) Problem Solving and Troubleshooting: Strong analytical skills to identify and resolve complex integration challenges .Net Application Development: Experience in .Net application development and testing Scrum Framework and Agile Methodologies: Familiarity with Scrum and Agile practices Middleware Experience: High experience in Middleware Advanced IT Infrastructure: Security-focused with experience in advanced IT infrastructure Independent and Team-Oriented: Ability to work independently with a strong team mindset and a focus on quality Risk Management Expertise: Strong understanding of risk management principles, methodologies, and tools. Ability to identify, assess, and mitigate various types of risks, including operational, financial, strategic, and compliance risks Mandatory Skills Azure hands-on engineering experience in .Net c# Application development , Visual Studio, Azure DevOps Microsoft Security in Windows Server environment, including Kerberos and Active Directory CICD concepts Understanding of PKI concepts and Certificates Experience with Azure services Windows Server 2016, 2019, 2022 PowerShell, .Net 4.8, .Net 8, ADFS, MVC, IIS, WCF, WebAPI, NuGet, APIs Nice to Have OAuth, OpenID Connect, and SAML .Net8 and/or Java integration on Linux Service Fabric Splunk If you have the required qualifications and are eager to join a squad with ambitious challenges, apply now! This is a great opportunity! Please note that this is a permanent position, and we do not offer freelance/contract arrangement for the role. About Us Why join us Embark on your new adventure at Euroclear, and work at the heart of the global capital markets. We connect over 2,000 financial institutions across the globe. As an open and resilient infrastructure, we contribute to the stability of the financial markets. We help clients cut through complexity, lower costs, and mitigate risks of financial transactions. At Euroclear, we have the clear ambition to use our key role to facilitate and accelerate a sustainable global financial system. What We Offer: Work closely with inspiring, supportive and engaged colleagues from more than 80 different countries. Practice your talents in a highly professional international environment. Join a learning and development environment with an emphasis on knowledge sharing and training. Competitive salary and comprehensive benefits. Ways of working Find your own optimal balance within our hybrid working model, where you can connect at the office 8 days a month and also benefit from remote working. Great Place to Work for All We are committed to creating an inclusive culture that celebrates diversity and strives to be a Great Place to Work for All. All qualified applicants will be considered for employment, regardless of any aspect that makes them unique (including race, religion, national origin, gender, sexual orientation, age, marital status, pregnancy, disability, ...). If you need any specific accommodation due to disability or any other reason, you can let the recruiter know during your application process. Our values guide how we work together and shape our future: Our mission and values - Euroclear About the Team Group Technology Services (GTS) plans, builds and runs the global infrastructure of Euroclear, and is additionally responsible for the IT service management to the operating entities of the various Group markets. Group Technology Services operates its IT systems and IT services in such a way that, at an appropriate and benchmarked cost level, it can deliver the agreed levels of service to support the requirements of the business processes, for both normal operations and during disaster recovery.
Technology
Cornerstone OnDemand
Software Engineering Intern .NET
Intern
Hybrid
Krakow, MA, Poland
6,500 - 6,500 PLN
🏢 Summary: Software Engineering Internship focused on building and maintaining cloud-based, full-stack web applications and AI-enabled features. The role provides hands-on experience with .NET, React, AWS, databases, APIs, testing, deployment, and cross-functional Agile delivery. 🗂️ Requirements: Basic programming knowledge in an object-oriented language, Relational database and SQL knowledge, Object-oriented programming principles, React.js and modern front-end knowledge, Software development and application architecture understanding, Application performance and optimization awareness, Secure coding understanding, Software design patterns knowledge, Analytical and problem-solving abilities, Written and verbal communication skills, Foundational AI, Generative AI, LLM, and prompt-engineering knowledge, Collaborative mindset and willingness to learn 📃 Skills: Java, Python, C#, .NET, React.js, HTML, CSS, JavaScript, TypeScript, SQL, AI, LLMs, Git, AWS 🏢 Description: We are seeking a passionate and motivated Software Engineering Intern who is eager to grow their expertise in building cloud-based applications—from developing front-end interfaces to modern backend services and microservice-based applications. As a key member of our dynamic development team, you will help build innovative web applications and intelligent features powered by modern .NET Core, C#, React, AWS, and AI technologies. You will have opportunities to work on AI-enabled solutions, including Generative AI and Large Language Model (LLM)-based applications, while developing expertise across the full software development lifecycle. The ideal candidate will possess strong programming fundamentals, a good understanding of SQL databases, and an interest in applying emerging AI technologies, including Generative AI and LLM-based capabilities, to modern software solutions. In this role you will... Work closely with Development, QA, and Operations teams to ensure successful project delivery. Communicate effectively to understand project requirements and provide timely updates. Assist in designing, developing, and maintaining full-stack applications using .NET (Core/Framework), React.js, and SQL/NoSQL databases on the AWS cloud platform. Collaborate with senior engineers, product managers, and designers to understand requirements and implement solutions. Assist in developing and testing APIs and software components under the guidance of senior engineers. Write clean, maintainable, and scalable front-end and back-end code under guidance. Participate in agile ceremonies such as sprint planning and technical design reviews, and contribute ideas and feedback. Participate in code reviews, unit testing, and software deployment activities. Assist in monitoring, debugging, and improving application performance, security, and reliability. Assist in troubleshooting application issues and contribute to root cause analysis under the guidance of senior engineers. Collaborate with cross-functional teams including engineering, product, IT security, and release management. Assist in the development and integration of AI-powered features and intelligent user experiences using modern AI technologies and services. Stay updated on emerging trends in .NET, front-end technologies, cloud computing, and AI. You’ve got what it takes if you have... Basic programming knowledge in Java, Python, C#, or another object-oriented programming language. Good understanding of relational databases and SQL, including database design fundamentals, query writing, stored procedures, and data modeling. Strong understanding of object-oriented programming (OOP) principles; familiarity with design principles such as SOLID and KISS is a plus. Knowledge of React.js and modern front-end technologies (HTML, CSS, JavaScript/TypeScript). Understanding of software development concepts and application architecture principles. Familiarity with version control systems such as Git and Bitbucket is a plus. Familiarity with NoSQL databases is a plus. Awareness of application performance concepts and optimization techniques. Understanding of secure coding practices. Familiarity with software design patterns and their practical application. Strong analytical, quantitative, and problem-solving abilities. Excellent interpersonal, written, and verbal communication skills. Foundational knowledge of Artificial Intelligence (AI), Generative AI, and Large Language Models (LLMs), including prompt engineering and practical AI applications in modern software development. Collaborative mindset and eagerness to learn new technologies and grow within both AI and full-stack engineering domains. Preferred Qualifications Internship, academic project, or personal project experience with React, .NET, or web application development. Hands-on experience with Python and AI-based applications. Familiarity with AI services and frameworks such as Azure OpenAI, AWS Bedrock, LangChain, Semantic Kernel, or similar technologies. Familiarity with CI/CD pipelines, Docker, and cloud platforms (AWS, Azure, or GCP). Hands-on experience with testing frameworks such as NUnit or xUnit. Exposure to AWS cloud services and cloud-native application development. Experience analyzing and troubleshooting functional and technical issues through academic, internship, or personal projects. Exposure to Agile development methodologies. Familiarity with AWS services such as Lambda, S3, ECS, API Gateway, and related cloud-native services. Interest in user experience (UX), accessibility, and responsive web design. Experience integrating AI/LLM capabilities into applications is a plus.
Technology
Yard Corporate
Staff Software Engineer
Senior
Remote
Krakow, MA, Poland
150,000 - 205,000 USD/yr
🏢 Summary: Remote Staff Software Engineer role building high-scale cybersecurity platform features and public APIs using Ruby on Rails, Angular, and AWS. The offer emphasizes end-to-end ownership, low-latency API performance, engineering quality, and direct product impact, with compensation of approximately $150,000–$205,000 annually on a B2B contract. 🗂️ Requirements: 6+ years of commercial software development experience, Strong Ruby on Rails experience or deep Node.js expertise with ability to transition to Ruby, Experience delivering scalable, public-facing APIs, C1+ written and spoken English, Working-time overlap between UTC-5 and UTC+1, Experience in SaaS, fintech, or high-growth product environments 📃 Skills: Ruby, Rails, Node.js, Angular, AWS, APIs 🏢 Description: About Our Client On behalf of our Client - a highly profitable, US-headquartered scale-up in the Cybersecurity and Threat Prevention space—we are seeking an experienced Staff Software Engineer . Our Client builds real-time platform security solutions that protect global digital platforms from fraud, account abuse, and automated attacks. Operating at massive scale, their architecture processes high-throughput API traffic under stringent low-latency requirements. They combine deep backend scalability engineering with a heavy emphasis on intuitive product UI/UX and developer-first design. Location & Work Setup 100% Remote (requiring working overlap between UTC-5 and UTC+1 time zones). Hybrid Option: Access to a modern tech hub in Krakow, Poland if you prefer working from an office. Key Responsibilities Product Development: Architect and deliver end-to-end features using a tech stack centered on Ruby on Rails, Angular, and AWS . High-Throughput APIs: Design and optimize public-facing APIs with a focus on developer ergonomics, efficiency, and reliability. Engineering Standards: Drive continuous quality through thorough code reviews, architectural discussions, and technical mentoring. Product Impact: Work in an autonomous, streamlined engineering team where your technical decisions directly shape the platform's trajectory. Candidate Profile 6+ years of commercial software development experience, ideally within SaaS, fintech, or high-growth product companies. Backend Proficiency: Strong experience with Ruby on Rails (or deep expertise in Node.js with a fast learning agility to transition into a Ruby environment). API Ecosystems: Proven track record of shipping scale-ready, public-facing APIs optimized for developer consumption. Communication: C1+ fluent written and spoken English for daily collaboration in a distributed team. Work Culture High Autonomy: Strong emphasis on complete project ownership from concept to production release. Pragmatic & Modern: Openness to experiment, iterate, and leverage automation and modern AI tools to eliminate toil. What Is Offered Compensation: ~$150,000 – $205,000 USD / year (B2B Contract). Time Off: Unlimited PTO policy + flexible working hours focused on delivered outcomes. Benefits: Paid parental leave policy. Equipment: Full high-spec hardware setup (laptop + workstation gear).
