SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Software Security Engineer

Valar Atomics - Torrance, CA, United States - In-office - posted 2026-09-08

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Valar Atomics is building scalable, factory-made advanced nuclear power systems to unlock abundant clean energy for industry and next-generation manufacturing. The company is developing its first pilot plant in Orangeville, Utah, and operates from a Series A funding stage. As a Senior Software Security Engineer embedded within the Business/IT & Enterprise Software organization, you will own security integration across the full software development lifecycle. Your role bridges two critical phases: early architectural design reviews and post-development code security validation. In design and planning, you'll participate in architecture discussions before implementation, perform lightweight threat modeling on new features and services, identify trust boundaries and attack surfaces, flag risky design patterns (authentication schemes, data handling, third-party integrations, database access), and embed security requirements directly into planning tickets. In code review, you'll conduct manual and tool-assisted secure code reviews across C#, Python, and React. For Postgres, you'll review queries and schemas for injection risks, access control issues, and data exposure. For React, you'll assess front-end code for XSS, insecure state handling, and client-side authentication assumptions. For C#, you'll review backend code for deserialization flaws, input validation gaps, authorization issues, and unsafe reflection/dynamic code patterns. You'll provide clear, actionable remediation guidance directly to engineers. You'll also support CMMC 2.0 compliance alignment, maintain and refine secure coding guidelines specific to the tech stack, track recurring vulnerability patterns to inform training and design guidance, and partner with engineering leads to balance security rigor against delivery timelines. The role requires strong proficiency reading and reasoning about C# and Python code, working knowledge of React and front-end/web security issues, experience reviewing relational database queries and schemas for security, and a background in application security, software security engineering, or related security-focused engineering roles. Experience in large-scale technology organizations or the defense sector is strongly valued.

Similar roles