Senior Software Engineer, Application SecurityActive$253K
The opportunity
Anduril Industries is a defense technology company with a mission to transform U. S.
What you'll do
Design and build distributed services for vulnerability scanning, policy: enforcement, and remediation workflows
Develop and extend the team's scanning orchestration platform: an event-driven architecture built on AWS (SQS, Lambda, S3, ECR) that processes scan events at org-wide scale
Build and maintain policy-as-code systems that programmatically enforce: security policy in CI/CD pipelines and deployment configurations
Design APIs and CLIs that integrate security tooling into developer workflows without creating friction
Develop data pipelines that aggregate, normalize, and route findings from: multiple scanning engines into vulnerability management systems
Collaborate with engineering teams across Anduril to understand their: security needs and build tooling that addresses them
What they're looking for
- Experience with CI/CD systems (CircleCI, GitHub Actions) and building integrations for developer workflows
- Familiarity with container security concepts, SBOM generation tools (Syft),: and vulnerability scanners (Trivy, Grype, Semgrep)
- Experience with Terraform and infrastructure-as-code
- Experience with policy-as-code frameworks (OPA/Rego, Conftest)
- Background in application security or product security engineering
- Experience with Kubernetes and container orchestration
- Familiarity with Nix build systems