June 17, 2026

Staff Application Security Engineer

Senior • On-site

150,000 - 173,004 USD/yr

Washington, DC

About the role

The Nuclear Company is searching for an Application Security Engineer to help secure the software, data systems, and developer workflows that power the Nuclear Operating System, internal platforms, and mission-critical applications. This is a high-ownership role for a builder comfortable reviewing architecture, threat modeling APIs, improving GitHub security controls, and partnering with engineers to ship secure software quickly.

You will work across engineering, data, infrastructure, and operations to embed security into how software is designed, built, tested, and deployed. You will define secure development standards, review product designs, harden CI/CD workflows, and guide vulnerability remediation in a practical, risk-based way.

Responsibilities

Application & Product Security

  • Perform security reviews and threat models for NOS modules, internal tools, APIs, data workflows, AI-enabled features, and cloud-connected applications.
  • Identify and remediate risks across authentication, authorization, tenant isolation, input validation, secrets handling, encryption, logging, and data access.
  • Review application designs and code changes for security issues before production.
  • Define reusable security patterns for web applications, APIs, mobile workflows, internal platforms, and data-heavy systems.
  • Establish secure-by-default approaches for regulated, high-consequence infrastructure.

Secure SDLC & Developer Enablement

  • Build and improve DevSecOps practices across the GitHub-based SDLC including code scanning, dependency review, secret scanning, branch protections, and CI/CD hardening.
  • Create secure templates, automation, documentation, and lightweight review processes.
  • Triage findings from SAST, SCA, secret scanning, penetration tests, and code reviews.
  • Develop vulnerability management workflows and remediation guidance.
  • Support secure coding education through reviews and developer collaboration.

Platform, Cloud & Data Security

  • Secure AWS workloads, infrastructure-as-code, integrations, data pipelines, and deployments.
  • Review integrations involving Palantir Foundry, partner APIs, and AI-assisted workflows.
  • Protect sensitive data flows across environments.
  • Ensure logging and security signals support investigation and response.
  • Navigate cybersecurity expectations in a regulated nuclear environment.

Cross-Functional Partnership

  • Partner with engineers, product managers, and stakeholders.
  • Communicate risk clearly while balancing delivery speed.
  • Contribute to the product security roadmap as systems scale.
  • Promote ownership, velocity, and technical rigor.

Experience

  • 4+ years in application or software security.
  • Experience securing web applications, APIs, distributed systems, or cloud-native services.
  • Strong understanding of authentication, authorization, injection, SSRF, insecure deserialization, secrets exposure, dependency risk, and API security.
  • Experience with GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, secret scanning, and CI/CD security.
  • Ability to read at least one of: Python, TypeScript, Go, Java, C#, or C++.
  • Familiarity with AWS IAM, encryption, logging, networking, secrets management, and infrastructure-as-code.
  • Strong communication skills and offensive security mindset.

Preferred Qualifications

  • Experience in regulated or mission-critical environments.
  • Familiarity with AI-assisted development, LLM applications, and prompt injection risks.
  • Experience with vulnerability management, DAST, penetration testing, or incident response.
  • Knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, or NERC CIP.
  • Security certifications such as AWS Certified Security – Specialty or OSWE.

Benefits

  • Competitive compensation packages
  • 401k with company match
  • Medical, dental, vision plans
  • Generous vacation policy plus holidays

Estimated Starting Salary Range

$150,000 - $173,000 annually, less applicable withholdings and deductions, paid bi-weekly. Actual salary may vary based on experience, qualifications, location, certifications, and other relevant factors.

EEO Statement

The Nuclear Company is an equal opportunity employer committed to an inclusive workplace. Discrimination in any aspect of employment is prohibited.

Export Control

Certain positions may involve access to information and technology subject to U.S. export controls, which may limit consideration of some applicants.

Similar jobs you might like

Technology

The Nuclear Company

Senior Platform Engineer

Senior

On-site

Washington, DC

120,996 - 165,000 USD/yr

🏢 Summary: Platform Engineer role focused on building and maintaining backend systems, CI/CD pipelines, data integrations, and platform infrastructure for a large-scale nuclear software platform. The position involves working with AI/data teams to support reliable, scalable services and AI-ready data architecture in a production environment. 🗂️ Requirements: 5+ years building and running production backend or platform systems, Bachelor's or Master's degree in Computer Science, Software Engineering, or related technical field, or equivalent experience, Strong coding skills in at least one backend language, Experience building and owning CI/CD pipelines, Experience integrating systems using REST APIs, event streams, or data pipelines, Experience with at least one major cloud platform, Experience with configuration management and infrastructure as code, Working knowledge of data modeling and system data flows, Strong written and verbal communication skills 📃 Skills: Python, Go, Java, TypeScript, CI/CD, REST, AWS, APIs, Databricks, Snowflake, React, SCADA, MCP 🏢 Description: About the role The Nuclear Company is hiring a Platform Engineer to build and run the backend, data, and integration layers that NOS depends on. You will report to the Director of Platform Integrations and work in the Platform Integration & AI/Data squad. NOS is the software platform behind one of the largest nuclear buildouts in the United States, and the platform layer is what keeps it fast, reliable, and connected to the systems around it. This is a hands-on engineering role. You will own CI/CD, build and maintain the data and application integrations that tie NOS to internal systems and external sources, and keep the unified front-end interface and platform services performing under load. You will also help shape the data ontology and MCP design that let AI agents work against NOS data safely. You will work daily with data scientists, AI/ML engineers, product engineers, and nuclear domain experts. You write production code, review pull requests, debug across the stack, and hold the line on configuration management and platform maintenance as new capabilities ship. Responsibilities • Own platform and integration engineering. Build and maintain the application and data integrations that connect NOS to internal systems, partner APIs, and external data sources, and keep them reliable as the platform grows. • Own CI/CD and release tooling. Build and run the pipelines that make NOS releases repeatable, tested, and traceable, and keep build and deployment times short. • Build and maintain the unified front-end interface. Deliver the shared interface layer that product teams build on, and keep it consistent, accessible, and fast. • Keep the platform performant and maintained. Monitor platform performance, fix bottlenecks, manage configuration baselines, and handle the maintenance that keeps NOS stable. • Support data ontology and MCP design. Help structure NOS data and design the Model Context Protocol interfaces that let AI agents read and act on platform data safely. • Partner across the squad. Work with data scientists, AI/ML engineers, and product engineers so the platform layer and the products built on it move together. Required Experience • 5+ years building and running production backend or platform systems. • Bachelor's or Master's in Computer Science, Software Engineering, or a related technical field, or equivalent production experience. • Strong coding skills in at least one backend language (Python, Go, Java, TypeScript, or similar) and solid software engineering fundamentals. • Hands-on experience building and owning CI/CD pipelines and integrations between systems (REST APIs, event streams, data pipelines). • Experience with at least one major cloud (AWS preferred) and with configuration management and infrastructure as code. • Working knowledge of data modeling and how data flows between systems. • Good written and verbal communication, able to work with engineers and non-engineers. Preferred Experience • Experience with Palantir Foundry, Databricks, or Snowflake. • Familiarity with Model Context Protocol (MCP) or other patterns for connecting AI agents to data and tools. • Experience in a regulated or safety-critical industry (nuclear, aerospace, defense, energy, medical). • Front-end experience with a modern framework such as React. • Experience with OT/IT integration, SCADA interfaces, or industrial data. Benefits • Competitive compensation packages • 401k with company match • Medical, dental, vision plans • Generous vacation policy, plus holidays Estimated Starting Salary Range The estimated starting salary range for this role is $121,000 - $165,000 annually less applicable withholdings and deductions, paid on a bi-weekly basis. The actual salary offered may vary based on relevant factors as determined in the Company's discretion, which may include experience, qualifications, tenure, skill set, availability of qualified candidates, geographic location, certifications held, and other criteria deemed pertinent to the particular role. EEO Statement The Nuclear Company is an equal opportunity employer committed to fostering an environment of inclusion in the workplace. We provide equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We prohibit discrimination in all aspects of employment, including hiring, promotion, demotion, transfer, compensation, and termination. Export Control Certain positions at The Nuclear Company may involve access to information and technology subject to export controls under U.S. law. Compliance with these export controls may result in The Nuclear Company limiting its consideration of certain applicants. Recruiting Fraud Alert Your safety is our priority. We want to ensure your job search stays secure. Please note that the team at The Nuclear Company only communicates through official @thenuclearcompany.com email addresses. We will never ask for payments or sensitive financial information at any stage of our recruitment process. For your peace of mind, please verify all openings and submit your applications directly through our official careers page.

Technology

The Nuclear Company

Senior Software Quality Engineer

Senior

On-site

Washington, DC

120,996 - 165,000 USD/yr

🏢 Summary: Senior Software Quality Engineer role focused on building automated testing, verification and validation, and compliance processes for a nuclear software platform in a regulated environment. The position involves developing test frameworks, integrating QA into CI/CD pipelines, supporting audits, and ensuring software quality and traceability standards. Candidates should have strong programming and test automation experience with modern QA tools and regulated systems. 🗂️ Requirements: Bachelor's or Master's degree in Computer Science, Software Engineering, or related technical field, 5+ years of experience in software quality engineering, software testing, SDET, or V&V roles, Strong programming skills in Python, Java, C#, JavaScript, or TypeScript, Experience developing and maintaining automated test frameworks, Experience with Playwright, Cypress, Selenium, TestNG, PyTest, or similar testing tools, Experience testing APIs, databases, and distributed systems, Experience integrating automated testing into CI/CD pipelines, Experience with Git, Jira, Azure DevOps, or similar engineering tools, Ability to review and understand production software code, Strong documentation and audit-ready reporting skills, Experience supporting quality or regulatory audits 📃 Skills: Python, Java, C#, JavaScript, TypeScript, Playwright, Cypress, Selenium, TestNG, PyTest, API, SQL, Git, Jira, Azure, CI/CD, QMS, IEEE, IEC 🏢 Description: About the role The Nuclear Company is seeking a Senior Software Quality Engineer to help ensure the quality, reliability, traceability, and compliance of Nuclear Operating System (NOS), the software platform supporting one of the largest nuclear construction programs in the United States. This role combines software engineering, test automation, verification and validation (V&V), and quality assurance in a highly regulated environment. You will work closely with software engineers, product teams, and compliance leaders to build automated testing capabilities, verify software requirements, support audit readiness, and ensure digital systems meet the standards required for nuclear deployment. The ideal candidate is a strong engineer who enjoys building automation, improving quality processes, and working within rigorous compliance frameworks. Responsibilities Test Automation & Quality Engineering - Design, develop, and maintain automated test frameworks for web, API, data, and backend services. - Build and execute automated unit, integration, regression, and end-to-end test suites. - Integrate testing into CI/CD pipelines and release processes. - Develop performance, load, and reliability testing capabilities. - Establish quality metrics and reporting dashboards. Verification & Validation - Execute software verification and validation activities. - Validate software against documented requirements and acceptance criteria. - Ensure requirements are traceable through design, implementation, testing, and release. - Support release readiness reviews and quality gates. Quality Assurance & Compliance - Perform quality reviews and audits of software systems and development processes. - Support compliance with ASME NQA-1 and other applicable quality standards. - Verify configuration management, change control, and records management practices. - Prepare audit-ready documentation and objective evidence packages. Defect Management & Root Cause Analysis - Lead defect triage, investigation, verification, and closure activities. - Analyze quality trends and identify opportunities for process improvement. - Support root cause investigations and corrective action programs. - Reduce defect escape rates through improved automation and quality controls. Collaboration & Continuous Improvement - Partner with software engineers to improve testability and code quality. - Participate in design reviews and code reviews. - Help establish software quality best practices across engineering teams. - Support internal audits, external audits, and regulatory inspections. Required Experience - Bachelor's or Master's degree in Computer Science, Software Engineering, or a related technical field, or equivalent practical experience. - 5+ years of experience in software quality engineering, software testing, SDET, or software verification and validation roles. - Strong programming skills in Python, Java, C#, JavaScript/TypeScript, or similar languages. - Experience developing and maintaining automated test frameworks. - Experience with modern testing tools such as Playwright, Cypress, Selenium, TestNG, PyTest, or equivalent. - Experience testing APIs, databases, and distributed systems. - Experience integrating automated testing into CI/CD pipelines. - Experience with Git, Jira, Azure DevOps, or similar engineering tools. - Ability to read, understand, and review production software code. - Strong written communication and documentation skills, the ability to produce audit-ready documentation. - Experience preparing for and supporting quality or regulatory audits. Preferred Experience - Experience working in regulated industries such as nuclear, aerospace, defense, medical devices, energy, or industrial systems. - Familiarity with ASME NQA-1 quality requirements. - Experience in nuclear or a U.S. Department of Energy environment. - Familiarity with safety-critical software standards such as IEEE 1012, IEC 61508, or IEC 60880. - Familiarity with cybersecurity, performance, or reliability testing. - Experience supporting quality audits, regulatory inspections, or compliance programs. - Experience with requirements management and traceability systems. - Experience testing AI/ML-enabled software systems. - Understanding of ITAAC, nuclear construction quality programs, or NRC-regulated environments. - Experience with quality management systems (QMS) and records control platforms. Benefits - Competitive compensation packages - 401k with company match - Medical, dental, vision plans - Generous vacation policy, plus holidays Estimated Starting Salary Range - $121,000 - $165,000 annually EEO Statement The Nuclear Company is an equal opportunity employer committed to fostering an environment of inclusion in the workplace. We provide equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We prohibit discrimination in all aspects of employment, including hiring, promotion, demotion, transfer, compensation, and termination. Export Control Certain positions at The Nuclear Company may involve access to information and technology subject to export controls under U.S. law. Compliance with these export controls may result in The Nuclear Company limiting its consideration of certain applicants.

Technology

The Nuclear Company

AI/ML Engineer

Senior

On-site

Washington, DC

120,996 - 165,000 USD/yr

🏢 Summary: AI Engineer role focused on building and deploying ML models, LLM workflows, and AI agents inside a nuclear industry software platform. The position involves production-grade AI engineering, model evaluation, data pipeline development, and collaboration with engineering and domain experts on operational and safety-critical systems. Candidates will work with modern ML tooling, cloud platforms, and agent frameworks to support large-scale nuclear infrastructure projects. 🗂️ Requirements: Bachelor's or Master's degree in Computer Science, Machine Learning, Statistics, or related technical field, 5+ years of professional experience shipping ML or AI features into production, Strong Python experience, Hands-on experience with modern ML and LLM tooling, Production experience with LLMs and AI agents, Experience with prompting, fine-tuning, RAG, evals, and tool use, Data engineering and data pipeline development experience, Experience working with large datasets, Experience with at least one major cloud platform, Strong written and verbal communication skills 📃 Skills: Python, PyTorch, HuggingFace, LLM, RAG, AWS, MLflow, SageMaker, VertexAI, MCP, Foundry, AIP, CI/CD 🏢 Description: About the role The Nuclear Company is hiring an AI Engineer to ship the machine learning and agent capabilities inside NOS, the software platform behind one of the largest nuclear buildouts in the United States. You'll work in the Platform Integration & AI/Data squad and report to the Director of Platform Integrations. This is a hands-on engineering role. You'll embed ML models and LLM-driven workflows directly into the NOS applications our internal teams and partners use every day: site evaluation, red flag analysis, scheduling, lessons learned, and the stakeholder and project tools that run across active TNC projects. You'll work close to the metal: training and fine-tuning models, designing agent workflows against NOS data and tools, wiring up MCP interfaces, and standing up the evals and monitoring that keep AI features safe in production. You'll partner daily with platform engineers, product engineers, and the nuclear domain experts who use what you ship. The team is small, the pace is fast, and the work is visible, what you build will be demoed to utilities, regulators, and financial partners making 20-to-30-year decisions about the future of American nuclear power. Responsibilities - Ship ML and AI features inside NOS. Train, fine-tune, and deploy models and LLM-based workflows into production, with the evals, monitoring, and safety controls that make them trustworthy. - Build AI agents and agent workflows. Design agents that operate against NOS data and tools, including the MCP interfaces and tool-use frameworks they depend on. - Own model quality end-to-end. Define eval criteria, acceptance thresholds, and regression suites for AI features. Keep results reproducible and the bar high. - Partner across the squad. Work directly with platform engineers and product engineers so models reach production instead of staying in notebooks. - Contribute to the data ontology. Help shape how NOS data is structured so models and agents can use it reliably. - Build predictive and anomaly-detection models that support operations and engineering decisions, including time-series analysis of sensor and operational data from active projects. Required Experience - Bachelor's or Master's in Computer Science, Machine Learning, Statistics, or a related technical field, or equivalent production experience. - 5+ years of professional experience shipping ML or AI features into production. - Strong Python and hands-on experience with modern ML and LLM tooling (PyTorch, Hugging Face, or similar). - Production experience with LLMs and agents: prompting, fine-tuning, RAG, evals, tool use. - Solid data engineering fundamentals, comfortable building data pipelines and working with large, messy datasets. - Experience with at least one major cloud, AWS preferred. - Strong written and verbal communication. Preferred Experience - Experience with Palantir Foundry and AIP. - Experience building agent systems with MCP or similar tool-use frameworks. - MLOps experience (MLflow, SageMaker, Vertex AI) and CI/CD for models. - Experience in a regulated or safety-critical industry: nuclear, aerospace, defense, energy, or medical. - Background in time-series, sensor, or operational data. - Comfortable doing exploratory data analysis and translating findings into product decisions, in addition to shipping production models. Benefits - Competitive compensation packages - 401k with company match - Medical, dental, vision plans - Generous vacation policy, plus holidays Estimated Starting Salary Range The estimated starting salary range for this role is $121,000 - $165,000 annually less applicable withholdings and deductions, paid on a bi-weekly basis. The actual salary offered may vary based on relevant factors as determined in the Company's discretion, which may include experience, qualifications, tenure, skill set, availability of qualified candidates, geographic location, certifications held, and other criteria deemed pertinent to the particular role. EEO Statement The Nuclear Company is an equal opportunity employer committed to fostering an environment of inclusion in the workplace. We provide equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We prohibit discrimination in all aspects of employment, including hiring, promotion, demotion, transfer, compensation, and termination. Export Control Certain positions at The Nuclear Company may involve access to information and technology subject to export controls under U.S. law. Compliance with these export controls may result in The Nuclear Company limiting its consideration of certain applicants.

Technology

The Nuclear Company

AI Engineer 1 - Platform Integration & AI/Data

Junior

On-site

Washington, DC

80,004 - 150,000 USD/yr

🏢 Summary: Entry-level AI Engineer role focused on building and maintaining backend services, CI/CD pipelines, and data/application integrations for a large-scale nuclear software platform (NOS). The position involves hands-on development, DevOps tasks, and contributing to AI-enabled data tooling while working closely with senior engineers. Candidates will gain experience with Palantir Foundry, cloud environments, and production-grade AI and integration systems. 🗂️ Requirements: Computer Science degree or equivalent, 0-2 years professional experience (internships, co-ops, projects), Strong fundamentals in at least one backend language (Python, TypeScript, Go, or Java), Hands-on exposure to CI/CD, version control, REST APIs, or system integrations, Experience building AI-based solutions beyond basic chat assistants, Ability to write production code and tests, Willingness to work in regulated industry context 📃 Skills: Python, TypeScript, Go, Java, CI/CD, REST, Git, DevOps, Palantir, Foundry, AWS, Databricks, Snowflake, LLM, AI, MCP 🏢 Description: About the role The Nuclear Company is hiring an AI Engineer 1 to help build and run the backend, data, and integration layers that NOS depends on. You will report to the Director of Platform Integrations and work in the Platform Integration & AI/Data squad. NOS is the software platform behind one of the largest nuclear buildouts in the United States, and the platform layer is what keeps it fast, reliable, and connected to the systems around it. This is a hands-on, entry-level role. You will work alongside the Platform Engineer and other senior engineers on CI/CD, backend services, and the data and application integrations that tie NOS to internal systems and external sources, taking well-scoped features end to end under senior code review. You will ramp on Palantir Foundry and the team's AI and data tooling, write production code, open pull requests, and grow into a specialization over time. Responsibilities First 90 Days: - Help build and maintain the application and data integrations that connect NOS to internal systems, partner APIs, and external data sources, working from well-scoped tickets under senior review. - Take ownership of scoped CI/CD and release tasks that keep NOS builds repeatable, tested, and traceable. - Do basic backend and DevOps work: build and fix backend services, write tests, and handle routine platform monitoring and maintenance. - Ramp on Palantir Foundry, the data ontology, and the MCP interfaces that let AI agents work against NOS data and start contributing to them. - Partner with the Platform Engineer, data scientists, AI/ML engineers, and product engineers, and grow from paired work toward independent delivery. Required Experience - Computer science degree or equivalent, with 0-2 years of professional experience (internships, co-ops, and project work count). - Strong fundamentals in at least one backend language (Python and/or TypeScript preferred; Go or Java also welcome). - Some hands-on exposure to basic DevOps and backend work: CI/CD, version control, REST APIs, or wiring systems together, from an internship, a job, or a personal project. - Has built something with AI beyond using a chat assistant: multi-step prompts, custom tools, AI in the codebase, or a small agentic project. - Good written and verbal communication, and willingness to learn the nuclear and regulated-industry context. Preferred Experience - Exposure to a major cloud (AWS preferred), including coursework or personal projects. - Coursework or project work in CI/CD, infrastructure as code, or configuration management. - Coursework or project work in LLMs, agentic systems, or data modeling. - Familiarity with Palantir Foundry, Databricks, or Snowflake. - Internship or project work in a regulated or mega-project industry (nuclear, aerospace, defense, energy, medical). Benefits - Competitive compensation packages - 401k with company match - Medical, dental, vision plans - Generous vacation policy, plus holidays Estimated Starting Salary Range The estimated starting salary range for this role is $80,000 - $150,000 annually less applicable withholdings and deductions, paid on a bi-weekly basis. The actual salary offered may vary based on relevant factors as determined in the Company's discretion, which may include experience, qualifications, tenure, skill set, availability of qualified candidates, geographic location, certifications held, and other criteria deemed pertinent to the particular role. EEO Statement The Nuclear Company is an equal opportunity employer committed to fostering an environment of inclusion in the workplace. We provide equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We prohibit discrimination in all aspects of employment, including hiring, promotion, demotion, transfer, compensation, and termination. Export Control Certain positions at The Nuclear Company may involve access to information and technology subject to export controls under U.S. law. Compliance with these export controls may result in The Nuclear Company limiting its consideration of certain applicants.

Technology

AgileEngine

Application Security Engineer

Senior

Remote

Krakow, Poland

5,600 - 7,400 USD

🏢 Summary: Senior Application Security Engineer role focused on architecting and automating security controls across the SDLC for a large-scale financial services program. The position involves building AI-enabled secure code scanning, integrating SAST/DAST/SCA tools into CI/CD pipelines, and providing code-level remediation guidance in Python and Java environments. The engineer operates autonomously, driving DevSecOps practices and secure-from-the-start adoption. 🗂️ Requirements: 6+ years of software engineering experience, Strong focus on Application Security and DevSecOps, Advanced proficiency in Python, Advanced proficiency in Java, Hands-on experience with SAST tools, Hands-on experience with DAST tools, Hands-on experience with SCA tools, Experience integrating security tools into CI/CD pipelines, Ability to build automated security runbooks independently, Upper-intermediate English level 📃 Skills: Python, Java, SAST, DAST, SCA, CI/CD, DevSecOps, AI, LLMs, ThreatModeling 🏢 Description: ID71663 AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards. Why join us If you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you! :) About the role We are looking for a Senior Application Security Engineer to architect and build automated security layers within the SDLC, engineering AI-enabled secure code scanning, hardened baseline automation, and CI/CD security tooling integration across a large-scale financial services program. You will work in Python and Java to deploy and tune SAST, DAST, and SCA tools, provide code-level remediation guidance to development teams, and operate with full autonomy building automated security runbooks. The role requires 6+ years of software engineering experience with a strong AppSec and DevSecOps focus. What you will do Engineer and deploy AI-enabled secure code scanning capabilities and Golden Images to drive secure-from-the-start adoption; Automate the development of secure coding patterns and integrate them with traditional and Agentic SDLC workflows; Architect the integration of continuous security scanning tools (SAST, DAST, SCA) into enterprise CI/CD pipelines, tuning them to eliminate noise; Act as a senior technical SME, reading and reviewing complex application code (Java/Python) to provide software engineers with highly specific, code-level remediation guidance. Must haves 3–5 years of commercial experience blending software engineering and DevSecOps/AppSec; Solid coding proficiency in Python for automation/scripting; Working knowledge of modern CI/CD orchestration tools and practical experience interacting with vulnerability scoring frameworks; Ability to operate with minimal supervision on day-to-day execution, reliably completing complex scripting and integration tasks; Upper-intermediate English level. Nice to haves Ability to comfortably read and navigate Java source code; Hands-on experience with specific CNAPP or ASPM platforms (e.g., Wiz ); Basic understanding of application threat modeling. The benefits of joining us Professional growth Accelerate your professional journey with mentorship, TechTalks, and personalized growth roadmaps Competitive compensation We match your ever-growing skills, talent, and contributions with competitive USD-based compensation and budgets for education, fitness, and team activities A selection of exciting projects Join projects with modern solutions development and top-tier clients that include Fortune 500 enterprises and leading product brands Flextime Tailor your schedule for an optimal work-life balance, by having the options of working from home and going to the office – whatever makes you the happiest and most productive. Meet Our Recruitment Process Asynchronous stage – An automated, self-paced track that helps us move faster and give you quicker feedback: Short online form to confirm basic requirements 30–60 minute skills assessment via Codility – a platform founded in Poland that helps us provide quicker feedback and streamline this stage of the process. 5-minute introduction video Synchronous stage – Live interviews Technical interview with our engineering team (scheduled at your convenience) Final interview with your future teammates If it’s a match — you’ll get an offer!

Technology

Link Group

Application Security Consultant

Mid

Hybrid

Warsaw, Poland

150 - 200 PLN

🏢 Summary: The role involves building and implementing a secure SDLC framework with embedded Application Security across enterprise platforms. It focuses on assessing current development practices, defining security standards, and rolling out controls and best practices organization-wide. The position plays a key role in standardizing and governing secure application development processes. 🗂️ Requirements: 3+ years experience in software development, DevOps, or platform engineering, Proficiency in at least one object-oriented programming language, Experience with AWS or Azure environments, Hands-on experience with Docker and Kubernetes, Understanding of CI/CD pipelines and automated deployments, Experience with Infrastructure as Code and configuration management tools, Knowledge of Git and application lifecycle management, Experience with application security and DevSecOps tools, Understanding of secure development practices within SDLC, English proficiency at C1 level or higher 📃 Skills: Java, .NET, AWS, Azure, Docker, Kubernetes, CI/CD, Terraform, Ansible, Puppet, Chef, Git, SAST, DAST, SCA, CNAPP, DevSecOps, SDLC 🏢 Description: We are looking for: For our international client, we are looking for an Application Security Consultant who will play a key role in building a secure Software Development Life Cycle (SDLC) framework, with a strong focus on Application Security (SAS) across enterprise platforms. This role is part of a strategic initiative aimed at securing source code and standardizing how application security is designed, implemented, and governed. The work will start with assessing the current state of platforms and development practices, and based on that, defining and rolling out SDLC standards, controls, and best practices across the organization. Apply if you have: 3+ years of experience in software development, DevOps, or platform engineering Strong programming skills in at least one object-oriented language (e.g. Java, .NET) Experience working with AWS and/or Azure environments Hands-on experience with Docker and Kubernetes Solid understanding of CI/CD pipelines and automated deployments Experience with Infrastructure as Code and configuration management tools (e.g. Terraform, Ansible, Puppet, Chef) Good knowledge of Git and application lifecycle management practices Experience with application security and DevSecOps tooling (e.g. SAST, DAST, SCA, CNAPP) Understanding of secure development practices within SDLC Very good English communication skills (C1 level or equivalent) Nice to have: Experience in building or improving SDLC / SSDLC frameworks in large organizations Background in conducting security assessments and defining standards based on their results Knowledge of security frameworks and standards (e.g. ISO 27001, NIST, CIS, OWASP, SOC2, GDPR) Experience working with large enterprise platforms (e.g. SAP, Salesforce, Databricks, Snowflake) Knowledge of encryption and cryptography (e.g. PKI, Vault, certificates) Experience mentoring teams in secure coding and DevSecOps practices You'll be joining: An international environment where a new SDLC framework with embedded Application Security (SAS) is being built from the ground up and rolled out across key platforms. The team is responsible for assessing current maturity, defining security standards, and implementing a consistent approach to secure development. You’ll have a direct impact on shaping how application security is integrated into development processes and how standards are adopted across engineering teams.

Technology

The Nuclear Company

Staff Software Engineer

Senior

On-site

Washington, DC

150,000 - 173,004 USD/yr

🏢 Summary: Staff Software Engineer role focused on architecting and delivering mission-critical software for a nuclear energy platform in a highly regulated environment. The position combines hands-on development with technical leadership, system integration, and rigorous quality and compliance practices. The engineer will drive scalable, reliable solutions that support safety-critical operations and cross-functional collaboration. 🗂️ Requirements: Bachelor's degree in Computer Science, Software Engineering, Electrical Engineering, or related field, 7+ years of progressive software development experience, Experience in safety-critical or highly regulated industries, Proficiency in JavaScript, TypeScript, or Python, Experience with full SDLC (Agile and Waterfall), Strong knowledge of software design patterns, data structures, and algorithms, Experience with Git and collaborative workflows, Expertise in complex software architecture design, Strong understanding of software QA and testing methodologies, Ability to debug and troubleshoot complex systems 📃 Skills: JavaScript, TypeScript, Python, Git, Agile, Waterfall, SDLC, AI, ML 🏢 Description: About the role As a Staff Software Engineer, you will serve as a technical leader responsible for architecting and delivering software that powers critical aspects of our nuclear energy platform. You'll work at the intersection of software, engineering, and operations, solving complex problems in a highly regulated environment where reliability and safety are paramount. This role requires both strategic thinking and hands-on execution, with opportunities to influence technical direction, mentor engineers, and drive cross-functional initiatives. Your work will directly contribute to advancing clean, carbon-free energy solutions and shaping the future of the nuclear industry. Responsibilities Software Design & Development: Lead the design and development of robust, scalable, and high-quality software solutions for critical nuclear energy applications. This includes architecting new features, writing clean and efficient code, and participating in code reviews. Technical Leadership: Provide technical leadership and guidance to junior and mid-level engineers, mentoring them in best practices for software development, quality, and adherence to industry standards. System Integration: Work closely with hardware engineers, control systems engineers, and other software teams to ensure seamless integration of software components with physical systems and external interfaces. Quality & Compliance: Implement and advocate for rigorous software quality assurance practices, including comprehensive testing, debugging, and documentation, ensuring compliance with nuclear industry regulations and internal quality standards. Performance Optimization: Identify and resolve complex performance issues, ensuring our software operates efficiently and reliably under demanding conditions. Problem Solving: Tackle challenging technical problems, proposing innovative solutions and driving their implementation from concept to deployment. Documentation: Create and maintain thorough technical documentation, including design specifications, architecture diagrams, and testing protocols. Experience Bachelor's degree in Computer Science, Software Engineering, Electrical Engineering, or a closely related technical field. 7+ years of progressive experience in software development, with a strong portfolio of successfully delivered projects. Experience developing software for highly regulated, safety-critical, or mission-critical industries (e.g., nuclear, aerospace, defense, medical devices, automotive safety). Direct nuclear industry experience is highly preferred. Proficiency in one or more relevant programming languages such as JavaScript, TypeScript, or Python. Demonstrated experience with full software development life cycles (SDLCs), including Agile and Waterfall methodologies. Strong understanding of software design patterns, data structures, and algorithms. Experience with version control systems (e.g., Git) and collaborative development workflows. Expertise in designing and implementing complex software architectures. Deep understanding of software quality assurance principles and testing methodologies. Ability to debug and troubleshoot intricate software systems. Exceptional problem-solving and analytical skills. Strong written and verbal communication skills, with the ability to articulate technical concepts to diverse audiences. Ability to work effectively in a collaborative, fast-paced environment. Preferred Experience Experience building offline-capable, air-gapped, or otherwise disconnected applications, and packaging them for constrained or containerized deployment environments. Hands-on experience integrating third-party physical security systems. Experience applying AI features & ML models into production workflows. Exposure to nuclear, critical infrastructure, defense, or physical security domains. Benefits Competitive compensation packages 401k with company match Medical, dental, vision plans Generous vacation policy, plus holidays Estimated Starting Salary Range The estimated starting salary range for this role is $150,000 - $173,000 annually less applicable withholdings and deductions, paid on a bi-weekly basis. The actual salary offered may vary based on relevant factors as determined in the Company's discretion, which may include experience, qualifications, tenure, skill set, availability of qualified candidates, geographic location, certifications held, and other criteria deemed pertinent to the particular role. EEO Statement The company is an equal opportunity employer committed to fostering an environment of inclusion in the workplace. We provide equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We prohibit discrimination in all aspects of employment, including hiring, promotion, demotion, transfer, compensation, and termination. Export Control Certain positions may involve access to information and technology subject to export controls under U.S. law. Compliance with these export controls may result in limiting consideration of certain applicants.

Technology

TechTree

Software Engineer

Mid

Remote

Warsaw, Poland

47,300 - 64,500 EUR

🏢 Summary: Software Engineer role on the Client team building secure browser extensions, desktop applications, CLI tools and SDKs for a global cybersecurity product. The position focuses on client-side engineering in a zero-trust, end-to-end encrypted environment with strong ownership across the full development lifecycle. Ideal for engineers who enjoy solving complex product and security challenges while contributing to open-source and high-quality software at scale. 🗂️ Requirements: 3+ years of experience building JavaScript applications in production, Strong client-side engineering experience with React or similar framework, Ability to design simple, robust solutions to complex problems, Experience writing and maintaining unit, integration and end-to-end tests, Ability to implement secure client-side business logic and data handling, Comfort collaborating across product, design and engineering, Interest in security, privacy or trustworthy software systems 📃 Skills: JavaScript, React, HTML, CSS, Storybook, Jest, WebdriverIO, OpenPGP, Git, Docker, Windows, macOS, Linux 🏢 Description: THE CLIENT Our client is a fast-growing cybersecurity product company rethinking how teams manage and share sensitive access. Their platform is trusted by 40,000+ organisations across 50+ countries - and growing fast. This is an engineering-led business: modern architecture, real technical challenges, and a strong focus on open source, privacy, and security. They’re building a fully remote, collaborative team and looking for engineers who take ownership and enjoy solving meaningful problems. If you want to work on a product with real impact at global scale - this is worth a conversation. THE ROLE: Our client is looking for a software engineer to join its Client team and help build the applications through which users experience the product, including browser extensions, desktop applications, command-line tools and SDKs. This is not a typical frontend role. Because their product is built around end-to-end encryption and a zero-trust model, their client applications carry significant responsibility for security, data handling and product behaviour. The role sits at the intersection of client engineering, product thinking, usability and security-sensitive application design. You would work on features used by a large open-source community, contributing across the full lifecycle: understanding the problem, shaping the approach, implementing the solution, testing it thoroughly and improving it over time. This role will suit someone who enjoys solving complex product problems, keeping solutions simple, and working in an environment where quality, openness and collaboration matter. RESPONSIBILITIES: Build and improve client applications across browser, desktop and adjacent client surfaces Translate product and user needs into secure, usable client-side solutions Implement and maintain business logic, local data handling and security-sensitive workflows on the client side Contribute to testing strategy across unit, integration and end-to-end levels Work closely with product, design and engineering peers to refine solutions before implementation Help improve code quality, performance, maintainability and documentation Contribute to open-source collaboration with the community where relevant CORE REQUIREMENTS 3+ years of experience building JavaScript applications in production Strong client-side engineering fundamentals with React or a similar framework Ability to break down complex problems and design simple, robust solutions Good testing habits and attention to quality Comfort working across product, engineering and implementation questions - not just coding tickets Strong collaboration skills, openness to feedback, and a low-ego working style Interest in security, privacy, or building trustworthy software systems NICE TO HAVE Experience building browser extensions, desktop applications or other multi-platform clients Experience with security-sensitive applications, client-side cryptography or zero-trust architectures Experience with design systems, Storybook or usability-focused product development Open-source contribution experience Experience maintaining long-lived software products Familiarity with other languages such as Go, Swift, C#, PHP, Python or Rust Tools and technologies you’ll work with: JavaScript, React, HTML/CSS, Storybook, Jest, WebdriverIO, OpenPGP-related tooling, Git and Docker across Windows, macOS and Linux environments. (We do not expect candidates to bring experience with every tool listed here) How you work You take ownership of problems, not just tasks You value simplicity and avoid over-engineering You work well in an environment where feedback is frequent and constructive

Technology

TechTree

Software Engineer

Mid

Remote

Warsaw, Poland

47,300 - 64,500 EUR

🏢 Summary: Software Engineer role focused on building and improving secure client applications including browser extensions, desktop apps, CLI tools and SDKs within a zero-trust, end-to-end encrypted product. The position combines client-side engineering, security-sensitive design and product thinking, contributing across the full development lifecycle. You will deliver secure, high-quality solutions used by a large global and open-source community. 🗂️ Requirements: 3+ years of production experience with JavaScript, Strong experience with React or similar framework, Solid client-side engineering fundamentals, Experience designing simple, robust solutions for complex problems, Hands-on experience with unit, integration and end-to-end testing, Ability to implement secure client-side data handling and business logic, Experience collaborating across product, design and engineering teams, Interest in security, privacy or secure software systems 📃 Skills: JavaScript, React, HTML, CSS, Storybook, Jest, WebdriverIO, OpenPGP, Git, Docker, Windows, macOS, Linux 🏢 Description: THE CLIENT Our client is a fast-growing cybersecurity product company rethinking how teams manage and share sensitive access. Their platform is trusted by 40,000+ organisations across 50+ countries - and growing fast. This is an engineering-led business: modern architecture, real technical challenges, and a strong focus on open source, privacy, and security. They’re building a fully remote, collaborative team and looking for engineers who take ownership and enjoy solving meaningful problems. If you want to work on a product with real impact at global scale - this is worth a conversation. THE ROLE: Our client is looking for a software engineer to join its Client team and help build the applications through which users experience the product, including browser extensions, desktop applications, command-line tools and SDKs. This is not a typical frontend role. Because their product is built around end-to-end encryption and a zero-trust model, their client applications carry significant responsibility for security, data handling and product behaviour. The role sits at the intersection of client engineering, product thinking, usability and security-sensitive application design. You would work on features used by a large open-source community, contributing across the full lifecycle: understanding the problem, shaping the approach, implementing the solution, testing it thoroughly and improving it over time. This role will suit someone who enjoys solving complex product problems, keeping solutions simple, and working in an environment where quality, openness and collaboration matter. RESPONSIBILITIES: Build and improve client applications across browser, desktop and adjacent client surfaces Translate product and user needs into secure, usable client-side solutions Implement and maintain business logic, local data handling and security-sensitive workflows on the client side Contribute to testing strategy across unit, integration and end-to-end levels Work closely with product, design and engineering peers to refine solutions before implementation Help improve code quality, performance, maintainability and documentation Contribute to open-source collaboration with the community where relevant CORE REQUIREMENTS 3+ years of experience building JavaScript applications in production Strong client-side engineering fundamentals with React or a similar framework Ability to break down complex problems and design simple, robust solutions Good testing habits and attention to quality Comfort working across product, engineering and implementation questions - not just coding tickets Strong collaboration skills, openness to feedback, and a low-ego working style Interest in security, privacy, or building trustworthy software systems NICE TO HAVE Experience building browser extensions, desktop applications or other multi-platform clients Experience with security-sensitive applications, client-side cryptography or zero-trust architectures Experience with design systems, Storybook or usability-focused product development Open-source contribution experience Experience maintaining long-lived software products Familiarity with other languages such as Go, Swift, C#, PHP, Python or Rust Tools and technologies you’ll work with: JavaScript, React, HTML/CSS, Storybook, Jest, WebdriverIO, OpenPGP-related tooling, Git and Docker across Windows, macOS and Linux environments. (We do not expect candidates to bring experience with every tool listed here) How you work You take ownership of problems, not just tasks You value simplicity and avoid over-engineering You work well in an environment where feedback is frequent and constructive

Technology

Arcadia

Application Security Engineer

Mid

Remote

131,256 - 235,152 USD/yr

🏢 Summary: The role is for a technically hands-on Application Security Engineer responsible for owning the end-to-end vulnerability management lifecycle and embedding automated security controls into the CI/CD pipeline within a SaaS, cloud-native environment. The position focuses on SAST, DAST, SCA, container and API security, threat modeling, and partnering closely with engineering to remediate risks and mature secure SDLC practices. It is a remote-first role with strong benefits and competitive compensation. 🗂️ Requirements: 3–5 years Application Security experience in SaaS or cloud-native environments, Hands-on experience with at least two of: SAST, DAST, SCA, CSPM tools, Experience integrating and maintaining security tools in CI/CD pipelines, Proficiency with CI/CD platforms (GitHub Actions, Jenkins, or GitLab CI), Experience with container security (Docker, Kubernetes), Experience with API security (REST, GraphQL), Ability to perform vulnerability triage and drive remediation, Experience conducting threat modeling and security design reviews 📃 Skills: SAST, DAST, SCA, CSPM, Snyk, Checkmarx, Semgrep, Wiz, GitHub, Jenkins, GitLab, Docker, Kubernetes, REST, GraphQL, AWS, GuardDuty, SecurityHub, IAM, STRIDE, PASTA 🏢 Description: Arcadia is the AI-powered energy intelligence platform for businesses. We replace fragmented tools and manual workflows with one platform to pay utility bills, buy energy, and advance sustainability — across every location, at enterprise scale. Trusted by Fortune 2000 companies, Arcadia combines unified data, AI-powered analytics, and expert advisory to help enterprise teams save money, mitigate risk, and cut carbon. We deliver this through three comprehensive solutions: Utility Bill Management: Automating the entire utility bill lifecycle — from data capture and validation to payment processing and auditing. Energy Procurement Advisory: Bringing together comprehensive data, AI-powered analytics, market expertise, and a strong partner network to make sophisticated procurement options accessible to all. Sustainability Reporting — Verified emissions data with seamless integration into leading sustainability platforms. Tackling the world's most complex energy challenges requires diverse thinking. We're building teams of people from different backgrounds, industries, and disciplines — united by a belief that energy management should be simple, intelligent, and a genuine driver of business value. What we're looking for: We are seeking a technically hands-on Application Security Engineer to join the Information Security team. This individual will own the vulnerability management lifecycle across our SAST, DAST, and SCA tooling, integrate security automation into the CI/CD pipeline, perform threat modeling of product and engineering designs, and serve as a trusted advisor to our 300+ person engineering organization. The ideal candidate is a builder who would rather automate a finding than file a ticket, and who can explain a critical vulnerability to a junior developer without making them feel two inches tall. Arcadia is headquartered in Washington, DC, and open to fully remote candidates. What you'll do: Own the end-to-end vulnerability management lifecycle: triage, prioritize, and drive remediation of findings from SAST, DAST, and SCA tooling in partnership with engineering squads. Maintain, optimize, and extend security tooling integrations within the CI/CD pipeline with the goal of automating everything that can be automated. Launch and run a Security Champions program, including workshops and office hours, to embed security knowledge directly into development teams across multiple geographies. Act as the application-layer subject matter expert during security incidents, supporting triage, root cause analysis, and remediation. Partner with Product and Engineering leadership to introduce security touchpoints earlier in the SDLC, including threat modeling and design review processes. What will help you succeed: Must-haves: 3–5 years of dedicated Application Security experience in a SaaS or cloud-native environment. Hands-on proficiency with at least two of the following: SAST, DAST, SCA, or CSPM tooling (e.g., Snyk, Checkmarx, Semgrep, Wiz). Strong working knowledge of CI/CD pipelines (e.g., GitHub Actions, Jenkins, GitLab CI) and the ability to write and maintain pipeline integrations. Experience with container security (Docker, Kubernetes) and API security patterns (REST, GraphQL). Demonstrated ability to communicate technical risk to non-security engineers in a way that drives action, not anxiety. Nice-to-haves: Experience standing up or maturing a Security Champions program. Familiarity with cloud-native AWS security services (GuardDuty, Security Hub, IAM Access Analyzer). Exposure to threat modeling frameworks (STRIDE, PASTA, or lightweight equivalents). Relevant certifications (OSCP, GWAPT, CSSLP) — valued but not required. Benefits: "Remote first" culture - work anywhere in the US as long as you have a reliable internet connection Flexible PTO - no accrued hours and no limit on the number of vacation days exempt employees can take each year 12 annual holidays 10 days sick leave Up to 4 weeks bereavement leave 2 volunteer days off 2 professional development days off 12 weeks paid parental leave for all parents 75-95% employer cost coverage for medical, dental, and vision benefits for employees and dependents Target Annual Compensation Range for this role will be $131,250 to $235,156. There will also be a competitive benefits component to the package. The exact compensation at which this job is filled will be determined by the skills, experience, and location of the qualified candidate. Please note that we are unable to offer visa sponsorship for this position at this time.