Back to jobs
New

Senior Application Security Engineer

Torrance, California, United States

About Valar Atomics

At Valar Atomics, we're redefining what's possible in energy. Our mission is to make clean, high-temperature nuclear power scalable—unlocking abundant energy for industry, hydrogen, and next-generation manufacturing. We are a team of builders, engineers, and operators who believe nuclear energy should be fast to deploy, factory-made, and built for the real world. Our first pilot plant in Orangeville, Utah will demonstrate how advanced nuclear systems and fuel fabrication can power the future. Joining Valar Atomics means becoming part of a company where autonomy, ownership, and impact exist at every level.

The Team 

As part of the Business organization, IT & Enterprise Software delivers the technology infrastructure, enterprise applications, and digital tools that power Valar's operations. The team ensures secure, reliable, and scalable technology solutions that support every function across the company. 

The Role 

We are seeking a Senior Application Security Engineer to embed security directly into the software development lifecycle for custom applications handling Controlled Unclassified Information (CUI) and ITAR-regulated data, in an environment governed by CMMC 2.0, Department of Energy (DOE) cybersecurity requirements, and Nuclear Regulatory Commission (NRC) cyber security standards. This role partners closely with software engineering teams building custom applications and APIs primarily in Python and Java, deployed on AWS, Azure, Palantir Foundry, Kubernetes, and GitHub, and helps establish secure, compliant patterns for integrating AI tools (Claude, OpenAI) into engineering workflows without compromising data protection, safeguards, or regulatory obligations. 

You will be the security subject-matter expert embedded with development teams — reviewing designs, threat-modeling new features, hardening pipelines, and ensuring every system handling CUI/ITAR/UCNI data meets DOE order requirements, 10 CFR 73.54, NRC Regulatory Guide 5.71, and CMMC 2.0 (NIST SP 800-171/800-172) controls by design, not as an afterthought. This role also contributes lightweight security architecture guidance — reference patterns, boundary/trust-zone diagrams, and control mappings — to keep new systems aligned with the broader security architecture as they're designed, without owning full enterprise architecture responsibilities. 

This position is fully on-site at our Torrance, CA location. Relocation assistance is not available.

Key Responsibilities 

  • Partner with software engineers throughout design, development, and deployment to identify and remediate security risks in custom applications processing CUI, ITAR, and Unclassified Controlled Nuclear Information (UCNI). 
  • Perform threat modeling, secure architecture reviews, and design reviews for new features and services, with particular attention to data flows across AWS, Azure, and Palantir Foundry. 
  • Conduct manual and tool-assisted secure code review of Python and Java codebases, identifying issues such as injection flaws, insecure deserialization, broken authentication/authorization, and insecure cryptographic usage. 
  • Review and harden API design and implementation (REST/GraphQL) — authentication and authorization schemes (OAuth 2.0/OIDC, mTLS), input validation, rate limiting, schema validation, and API gateway configuration — across internally built and third-party-integrated APIs, including AI service APIs (Claude, OpenAI). 
  • Contribute light-touch security architecture artifacts — data flow diagrams, trust-zone/boundary diagrams, and control-to-requirement mappings — to help engineering teams design new systems in alignment with existing security architecture and reference patterns; escalate to enterprise/security architecture as needed for larger initiatives. 
  • Own and mature the application security program aligned to CMMC 2.0 Level 2 (NIST SP 800-171, and 800-172 where required), including SSP and POA&M maintenance for application-layer scope. 
  • Support DOE cybersecurity program requirements (e.g., DOE O 205.1, DOE O 471.6, RMF per NIST SP 800-37) for systems and applications supporting DOE contracts or facilities. 
  • Support NRC cyber security program alignment (10 CFR 73.54, Regulatory Guide 5.71) for applications supporting critical digital assets, including defense-in-depth boundary controls and access-control requirements. 
  • Secure CI/CD pipelines in GitHub (branch protection, secrets management, signed commits/artifacts, dependency and supply-chain risk controls) to satisfy CMMC/DOE/NRC audit and traceability requirements. 
  • Define and enforce security guardrails for Kubernetes workloads (pod security standards, network policies, image scanning, admission controls, secrets/config management) consistent with system security plan boundaries. 
  • Establish security and data-handling guidelines for the use of AI coding/productivity assistants (Claude, OpenAI/Azure OpenAI) — covering data residency, prompt/data leakage prevention, model access controls, and audit logging consistent with CUI/ITAR/UCNI and safeguards information (SGI) boundaries. 
  • Work with data engineering/platform teams to ensure Palantir Foundry pipelines, ontologies, and access controls correctly enforce data classification, need-to-know, least privilege, and export-control/safeguards boundaries. 
  • Lead or contribute to incident response, vulnerability triage, and remediation prioritization for application-layer findings, including reporting obligations under applicable DOE/NRC incident reporting timelines. 
  • Prepare and maintain evidence artifacts, control narratives, and documentation to support CMMC C3PAO assessments, DOE reviews, and NRC inspections. 
  • Build and deliver secure coding training and threat-modeling workshops for engineering teams, incorporating CMMC/DOE/NRC-specific handling requirements. 
  • Evaluate new tools and cloud services for security posture and regulatory suitability prior to adoption, including AI/LLM-based tooling. 

Basic Qualifications  

  • 5+ years in application security, product security, or security engineering, with demonstrated ownership of an AppSec program or major component of one. 
  • Direct working knowledge of CMMC 2.0 and its underlying NIST SP 800-171 control families, including practical experience preparing for or supporting a CMMC assessment. 
  • Experience operating within DOE or NRC regulatory environments, or comparable federal/critical-infrastructure cybersecurity frameworks (e.g., NIST SP 800-53, RMF, 10 CFR 73.54). 
  • Hands-on experience securing applications and infrastructure across AWS and Azure (IAM, network segmentation, key/secrets management, logging/monitoring, and cloud-native security tooling). 
  • Experience with Kubernetes security (RBAC, network policies, admission controllers, image/container scanning, runtime protection). 
  • Experience securing GitHub-based CI/CD pipelines (Actions, branch protections, secret scanning, SBOM/dependency management, supply-chain security practices). 
  • Practical understanding of secure SDLC practices: threat modeling (e.g., STRIDE), secure code review, SAST/DAST/SCA tooling, and remediation workflows. 
  • Proficiency reading and reviewing Python and Java code, with the ability to identify and help remediate security defects (e.g., OWASP Top 10 issues) directly in source, not just via scanner output. 
  • Experience securing REST and/or GraphQL APIs, including authentication/authorization schemes (OAuth 2.0/OIDC), input validation, and API gateway/WAF controls. 
  • Direct experience working under CUI and/or ITAR data-handling requirements. 
  • Strong communication skills and the proven ability to work embedded with engineering teams as a trusted advisor rather than a gatekeeper. 
  • Working familiarity with security architecture fundamentals (trust zones, data flow/boundary diagramming, defense-in-depth, control mapping) sufficient to guide engineering design decisions — deep enterprise security architecture experience is not required. 
  • U.S. Person status as defined by ITAR (22 CFR 120.15), due to access to export-controlled technical data. 

Preferred Skills and Experience  

  • Experience with Palantir Foundry security model — ontology-level access controls, pipeline security, data lineage, and classification enforcement. 
  • Prior experience supporting a DOE facility, national laboratory, or DOE contractor cybersecurity program.
  • Prior experience supporting an NRC-licensed facility or NRC-regulated vendor cyber security plan (10 CFR 73.54).
  • Familiarity with DFARS 252.204-7012, DoD Assessment Methodology, or Unclassified Controlled Nuclear Information (UCNI) / Safeguards Information (SGI) handling requirements.
  • Relevant certifications: CISSP, CMMC Certified Professional (CCP) / CMMC Certified Assessor (CCA), OSCP, GWAPT, GPEN, or equivalent.
  • Experience with Infrastructure-as-Code security (Terraform, CloudFormation, Bicep) and policy-as-code (OPA/Gatekeeper, Sentinel).
  • Experience with API security testing/tooling (e.g., OWASP ZAP, Postman/Newman security test suites, API-focused SAST/DAST) and API security standards such as the OWASP API Security Top 10.
  • Prior hands-on software development experience in Python and/or Java (e.g., prior developer or DevSecOps role) beyond code review.
  • Prior experience in aerospace, defense, energy, or nuclear industries. 

What We Offer  

  • Competitive base salary 
  • Equity ownership in a rapidly growing advanced energy company 
  • Comprehensive medical benefits 
  • Free daily lunch and dinner provided onsite 
  • Generous PPE stipend
  • High-impact startup environment with significant ownership and autonomy 
  • Opportunities for rapid career growth and internal advancement 
  • Direct collaboration with experienced operators, engineers, and industry leaders 
  • The opportunity to help build and scale transformative energy technology from the ground up

Equal Employment Opportunity Statement

Valar Atomics is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, age, disability, veteran status, or any other protected status under applicable law.

We are committed to providing a workplace free of discrimination and harassment and will provide reasonable accommodation as required by law.

Applicants must be legally authorized to work in the United States as a U.S. citizen or lawful permanent resident (green card holder).

Salary

$165,000 - $190,000 USD

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State.

Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Valar Atomics’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.