Senior Security Software Engineer
Valar Atomics · Torrance, California, United States · On-site
Pay: USD 175,000 – 200,000 a year
Posted Sep 8, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About Valar Atomics
At Valar Atomics, we're redefining what's possible in energy. Our mission is to make clean, high-temperature nuclear power scalable—unlocking abundant energy for industry, hydrogen, and next-generation manufacturing. We are a team of builders, engineers, and operators who believe nuclear energy should be fast to deploy, factory-made, and built for the real world. Our first pilot plant in Orangeville, Utah will demonstrate how advanced nuclear systems and fuel fabrication can power the future. Joining Valar Atomics means becoming part of a company where autonomy, ownership, and impact exist at every level.
The Team
As part of the Business organization, IT & Enterprise Software delivers the technology infrastructure, enterprise applications, and digital tools that power Valar's operations. The team ensures secure, reliable, and scalable technology solutions that support every function across the company.
The Role
We're looking for a Software Security Engineer to embed security into our software development lifecycle — from initial design through shipped code. This role is split across two key moments: early-stage design and planning reviews, where you'll help engineering teams make secure architectural decisions before code is written, and post-development code review, where you'll dig into implemented code to find and fix vulnerabilities before release.
You'll work closely with engineering teams across our C#, Python, and React stack, along with our Postgres data layer, acting as a security partner rather than a late-stage gatekeeper. We strongly value candidates with backgrounds in large-scale technology organizations or the defense sector, where security rigor and compliance discipline are non-negotiable.
Key Responsibilities
Design & Planning Reviews
Participate in design and architecture discussions early, before implementation begins
Perform lightweight threat modeling on new features and services — identifying trust boundaries, data flows, and likely attack surfaces
Flag risky design patterns (auth schemes, data handling, third-party integrations, database access patterns) and recommend secure alternatives
Provide security requirements and acceptance criteria that get built into planning/ticketing, not bolted on afterward
Code Review (Post-Development)
C#, Python, React: Perform manual and tool-assisted secure code review across all three
Postgres: Review queries and schema design for injection risks, access control issues, data exposure, and unsafe query patterns
React: Review front-end code for common web vulnerabilities (XSS, insecure state/data handling, unsafe use of dangerouslySetInnerHTML, client-side auth assumptions)
C#: Review backend code for issues like insecure deserialization, improper input validation, authorization flaws, and unsafe use of reflection/dynamic code
Provide clear, actionable remediation guidance directly to engineers — not just a list of flagged…