Energy Solutions is seeking a Senior Application Security Engineer to work with our development team to manage security and risk on our internally developed applications. The engineer will make risk-based decisions on application security, including recommending and validating controls, contributing to the design and upgrade of application security controls, and leading some new projects to further secure our platforms.
Requirements
- Minimum of 5 years' experience in application security experience.
- Practice and implementation with Django/Python with a clear application-security focus.
- Engineering background (software or DevOps/SRE) with the ability to read/modify code, review PRs, and build PoCs.
- Experience with GitHub security, including reviewing static code scans, triage findings, eliminate noise, and drive remediation with owners.
- Experience embedding secure SDLC into Git-based workflows and CI/CD (pre-commit, pipeline gates, policy-as-code).
- Practical knowledge of SOC 2 and familiarity with NIST 800-53; can turn requirements into technical tasks and evidence.
- Ability to operate across code, app, and DevOps (containers, IaC basics, secrets, logging/monitoring).
- Clear, persuasive communication (verbal and written) and prioritization.
- Excellent time management skills with a proven ability to meet deadlines.
- Excellent interpersonal and negotiation skills.
Benefits
- Generous retirement package
- Medical, dental and vision insurance
- Pre-tax contribution plans
- Employee Stock Ownership Plan (ESOP)