About the job
About Helion
Helion is at the forefront of energy innovation, striving to create the world's first fusion power plant based in Everett, WA. Our mission is to provide limitless clean electricity, contributing to a future where energy is both reliable and affordable for all.
Founded in 2013, Helion has successfully garnered over $1 billion in investments from notable investors such as Sam Altman, Mithril, and Capricorn Investment Group, along with newer partnerships from SoftBank and Lightspeed, to advance our initiatives. Our latest prototype, Trenta, has already achieved 10,000 high-power pulses and reached plasma temperatures of 100 million degrees Celsius (9 keV). We are currently advancing our Polaris prototype, stepping closer to realizing our vision of the first fusion power plant.
Joining Helion at this critical juncture means engaging in meaningful challenges alongside a team committed to urgency, rigor, and transparency—values that are fundamental to our mission. We are dedicated to transforming the future of energy, as the world cannot afford to wait.
Your Role:
As a Cybersecurity Software Engineer focused on product security, you will be instrumental in ensuring that the firmware, software, and server infrastructure supporting our fusion technology are fortified against potential threats. Collaborating with firmware, software, and infrastructure engineers, you'll integrate security into all phases of the development lifecycle—reviewing designs, auditing code and dependencies, and embedding security checks within CI/CD pipelines. You will spearhead initiatives in encryption, secrets management, and secure authentication to safeguard sensitive operations. This role is perfect for a professional eager to combine extensive cybersecurity knowledge with practical engineering to protect cutting-edge energy technology. This position is based on-site and reports directly to the Lead Electrical Engineer at our Everett, WA office.
Your Responsibilities:
Evaluate firmware, software, and infrastructure designs to pinpoint and mitigate security vulnerabilities prior to implementation.
Promote and apply security best practices across engineering including encryption, key rotation, and secure authentication methods.
Deploy and oversee application security tools (e.g., Snyk, Trivy, Docker image scanners) to assess dependencies, supply chain vulnerabilities, and security risks.
Define and uphold product-level security standards and practices throughout the organization.

