> Markdown version of [/jobs/ext/1287852-senior-software-engineer-application-security](https://www.wearedevelopers.com/jobs/ext/1287852-senior-software-engineer-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer, Application Security - **Company:** Anduril Industries - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $191,000.0 - $253,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Amazon Web Services, Amazon S3, Cloud Computing, Static Program Analysis, Continuous Integration, Data Systems, Distributed Systems, Github, Python (Programming Language), Queueing Systems, Software Engineering, Tripwire, Software Vulnerability Management, Policy as Code, Circleci, Software Security, Backend, Event Driven Architecture, Build Management, Kubernetes, Build Tools, Functional Programming, Amazon Simple Queue Service (SQS), Terraform, Data Pipelines, Vulnerability Analysis - **Published:** July 16, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9033831/senior-software-engineer-application-security ## About the Role * 5+ years of experience designing and developing production software systems * Strong proficiency in Go - this is the team's primary language for backend services * Experience building distributed systems or data pipelines (event-driven architectures, message queues, APIs, worker systems) * Proficiency with Python for scripting, automation, and tooling * Experience with cloud infrastructure (AWS preferred: Lambda, SQS, S3, ECR, or equivalent) * Ability to read and understand security tool output (vulnerability reports, SBOMs, static analysis results) and build systems around it * Strong communication skills with the ability to work across teams * Eligible to obtain and maintain active U.S. Secret security clearance * Experience with CI/CD systems (CircleCI, GitHub Actions) and building integrations for developer workflows * Familiarity with container security concepts, SBOM generation tools (Syft), and vulnerability scanners (Trivy, Grype, Semgrep) * Experience with Terraform and infrastructure-as-code * Experience with policy-as-code frameworks (OPA/Rego, Conftest) * Background in application security or product security engineering * Experience with Kubernetes and container orchestration * Familiarity with Nix build systems ## Description We're looking for a senior software engineer to design and build the systems that keep Anduril's software secure. This is a software engineering role first - you'll architect distributed systems, write production Go and Python, build APIs, and operate services at scale. The domain is security, but the work is building real software: custom scanning orchestration pipelines, policy engines that evaluate thousands of configurations against security rules, and data systems that track vulnerabilities across an entire product ecosystem. If you want to write code that solves hard engineering problems in the security space rather than configure off-the-shelf tools, this is the role. * Design and build distributed services for vulnerability scanning, policy enforcement, and remediation workflows * Develop and extend the team's scanning orchestration platform - an event-driven architecture built on AWS (SQS, Lambda, S3, ECR) that processes scan events at org-wide scale * Build and maintain policy-as-code systems that programmatically enforce security policy in CI/CD pipelines and deployment configurations * Design APIs and CLIs that integrate security tooling into developer workflows without creating friction * Develop data pipelines that aggregate, normalize, and route findings from multiple scanning engines into vulnerability management systems * Collaborate with engineering teams across Anduril to understand their security needs and build tooling that addresses them * Evaluate third-party security tools and build custom integrations or replacements where needed * Participate in on-call rotation for security tooling infrastructure, To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind: * No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Serverless: Past, Present and Future](https://www.wearedevelopers.com/videos/34-serverless-past-present-and-future) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)