Valar Atomics
New
USD 165000-190000/yr

Senior Application Security Engineer

United StatesUnited States·Torrancesenior
EngineeringSecurity Engineer
1 views0 saves0 applied

Quick Summary

Overview

About Valar Atomics At Valar Atomics, we're redefining what's possible in energy. Our mission is to make clean, high-temperature nuclear power scalable—unlocking abundant energy for industry,

Technical Tools
EngineeringSecurity Engineer

At Valar Atomics, we're redefining what's possible in energy. Our mission is to make clean, high-temperature nuclear power scalable—unlocking abundant energy for industry, hydrogen, and next-generation manufacturing. We are a team of builders, engineers, and operators who believe nuclear energy should be fast to deploy, factory-made, and built for the real world. Our first pilot plant in Orangeville, Utah will demonstrate how advanced nuclear systems and fuel fabrication can power the future. Joining Valar Atomics means becoming part of a company where autonomy, ownership, and impact exist at every level.

As part of the Business organization, IT & Enterprise Software delivers the technology infrastructure, enterprise applications, and digital tools that power Valar's operations. The team ensures secure, reliable, and scalable technology solutions that support every function across the company. 

We are seeking a Senior Application Security Engineer to embed security directly into the software development lifecycle for custom applications handling Controlled Unclassified Information (CUI) and ITAR-regulated data, in an environment governed by CMMC 2.0, Department of Energy (DOE) cybersecurity requirements, and Nuclear Regulatory Commission (NRC) cyber security standards. This role partners closely with software engineering teams building custom applications and APIs primarily in Python and Java, deployed on AWS, Azure, Palantir Foundry, Kubernetes, and GitHub, and helps establish secure, compliant patterns for integrating AI tools (Claude, OpenAI) into engineering workflows without compromising data protection, safeguards, or regulatory obligations. 

You will be the security subject-matter expert embedded with development teams — reviewing designs, threat-modeling new features, hardening pipelines, and ensuring every system handling CUI/ITAR/UCNI data meets DOE order requirements, 10 CFR 73.54, NRC Regulatory Guide 5.71, and CMMC 2.0 (NIST SP 800-171/800-172) controls by design, not as an afterthought. This role also contributes lightweight security architecture guidance — reference patterns, boundary/trust-zone diagrams, and control mappings — to keep new systems aligned with the broader security architecture as they're designed, without owning full enterprise architecture responsibilities. 

This position is fully on-site at our Torrance, CA location. Relocation assistance is not available.

Responsibilities

~3 min read
  • Partner with software engineers throughout design, development, and deployment to identify and remediate security risks in custom applications processing CUI, ITAR, and Unclassified Controlled Nuclear Information (UCNI). 
  • Perform threat modeling, secure architecture reviews, and design reviews for new features and services, with particular attention to data flows across AWS, Azure, and Palantir Foundry. 
  • Conduct manual and tool-assisted secure code review of Python and Java codebases, identifying issues such as injection flaws, insecure deserialization, broken authentication/authorization, and insecure cryptographic usage. 
  • Review and harden API design and implementation (REST/GraphQL) — authentication and authorization schemes (OAuth 2.0/OIDC, mTLS), input validation, rate limiting, schema validation, and API gateway configuration — across internally built and third-party-integrated APIs, including AI service APIs (Claude, OpenAI). 
  • Contribute light-touch security architecture artifacts — data flow diagrams, trust-zone/boundary diagrams, and control-to-requirement mappings — to help engineering teams design new systems in alignment with existing security architecture and reference patterns; escalate to enterprise/security architecture as needed for larger initiatives. 
  • Own and mature the application security program aligned to CMMC 2.0 Level 2 (NIST SP 800-171, and 800-172 where required), including SSP and POA&M maintenance for application-layer scope. 
  • Support DOE cybersecurity program requirements (e.g., DOE O 205.1, DOE O 471.6, RMF per NIST SP 800-37) for systems and applications supporting DOE contracts or facilities. 
  • Support NRC cyber security program alignment (10 CFR 73.54, Regulatory Guide 5.71) for applications supporting critical digital assets, including defense-in-depth boundary controls and access-control requirements. 
  • Secure CI/CD pipelines in GitHub (branch protection, secrets management, signed commits/artifacts, dependency and supply-chain risk controls) to satisfy CMMC/DOE/NRC audit and traceability requirements. 
  • Define and enforce security guardrails for Kubernetes workloads (pod security standards, network policies, image scanning, admission controls, secrets/config management) consistent with system security plan boundaries. 
  • Establish security and data-handling guidelines for the use of AI coding/productivity assistants (Claude, OpenAI/Azure OpenAI) — covering data residency, prompt/data leakage prevention, model access controls, and audit logging consistent with CUI/ITAR/UCNI and safeguards information (SGI) boundaries. 
  • Work with data engineering/platform teams to ensure Palantir Foundry pipelines, ontologies, and access controls correctly enforce data classification, need-to-know, least privilege, and export-control/safeguards boundaries. 
  • Lead or contribute to incident response, vulnerability triage, and remediation prioritization for application-layer findings, including reporting obligations under applicable DOE/NRC incident reporting timelines. 
  • Prepare and maintain evidence artifacts, control narratives, and documentation to support CMMC C3PAO assessments, DOE reviews, and NRC inspections. 
  • Build and deliver secure coding training and threat-modeling workshops for engineering teams, incorporating CMMC/DOE/NRC-specific handling requirements. 
  • Evaluate new tools and cloud services for security posture and regulatory suitability prior to adoption, including AI/LLM-based tooling. 

Requirements

~1 min read
  • Competitive base salary 
  • Equity ownership in a rapidly growing advanced energy company 
  • Comprehensive medical benefits 
  • Free daily lunch and dinner provided onsite 
  • Generous PPE stipend
  • High-impact startup environment with significant ownership and autonomy 
  • Opportunities for rapid career growth and internal advancement 
  • Direct collaboration with experienced operators, engineers, and industry leaders 
  • The opportunity to help build and scale transformative energy technology from the ground up

Valar Atomics is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, age, disability, veteran status, or any other protected status under applicable law.

We are committed to providing a workplace free of discrimination and harassment and will provide reasonable accommodation as required by law.

Applicants must be legally authorized to work in the United States as a U.S. citizen or lawful permanent resident (green card holder).

Salary
$165,000$190,000 USD

Location & Eligibility

Where is the job
Torrance, United States
On-site at the office
Who can apply
US

Listing Details

Posted
August 27, 2026
First seen
August 28, 2026
Last seen
August 28, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
79%
Scored at
August 28, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Valar Atomics
Valar Atomics
greenhouse
Employees
5
Founded
2023
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Valar AtomicsSenior Application Security Engineer USD 165000-190000