We Are Nucleus

We transform vulnerability and exposure management programs to help enterprises and government agencies prioritize and mitigate risks faster, at scale.

By Practitioners, For Practitioners

Founded by former Department of Defense security experts, Nucleus set out to address the inefficiencies and risks of manual vulnerability management. Today, organizations like Motorola, Paychex, and Marathon rely on Nucleus to unify their vulnerability data and automate workflows to prioritize vulnerabilities, mitigate risks, and prevent breaches.

2019

Founded

5.5
%

Top of the INC 5000 List

500
+

Private and public sector clients

200
+

Integrations

Nucleus Founders

Steve Carter

Steve Carter

Co-founder, CEO

Scott Kuffer

Scott Kuffer

Co-founder, CPO

Nick Fleming

Co-founder, Chief Engineer

Leadership Team

Will Gorman

Will Gorman

CTO

Jeff Gouge

Jeff Gouge

CISO

Tamir Hardof

Tamir Hardof

CMO

Dave Smith

David Smith

CRO

Kunal Desai

Kunal Desai

SVP of Finance

Adam Dudley

Adam Dudley

VP of Strategy and Alliances

Rob Gibson

Rob Gibson

VP of Product

David Reardon

David Reardon

SVP of Global Sales

Heidi Roberts

Heidi Roberts

Head of People

Scott Underwood

Scott Underwood

VP of Customer Experience

Our Investors

Delta-V

RECOGNITION

Celebrating Excellence

From our award-winning platform to being recognized as a top workplace and one of the fastest-growing companies, we are proud to lead in innovation, teamwork, and impact. These achievements reflect the dedication of our team and our commitment to our customers and partners.

Cybersecurity Excellence 2026 WIN Index Partner Deloitte Fast 500 2025

Join Our Team

Interested in driving cybersecurity innovation? In joining a winning culture? Check out our open positions.

Frequently Asked Questions About Nucleus Security

What does Nucleus Security do?

Nucleus Security is a Unified Exposure Management platform that helps enterprises and government agencies reduce cyber risk at scale. The platform continuously unifies security data from 200+ sources, prioritizes vulnerabilities using AI-powered threat intelligence, and automates remediation workflows so security teams can close the gap between finding exposures and fixing them.

Who founded Nucleus Security?

Nucleus was founded in 2019 by former Department of Defense security experts who experienced firsthand how vulnerability and exposure management break down in large, complex environments. That practitioner background shapes how the platform is built: focused on execution, not just data aggregation. Today, 500+ enterprise and public sector organizations rely on Nucleus to drive measurable exposure reduction.

Who is Nucleus Security’s current CEO?

The CEO of Nucleus Security is co-founder Steve Carter, who has led the company since the company launched in 2019.

What kinds of organizations use Nucleus Security?

Nucleus is built for large enterprises, federal agencies, state and local government, and government contractors where scale and compliance requirements make exposure management especially difficult. Customers include Fortune 500 companies, defense and civilian agencies, and MSSPs. Organizations like Motorola, Paychex, and Autodesk use Nucleus to manage exposure across complex, distributed environments.

How is Nucleus Security different from other vulnerability management tools?

Nucleus is the largest pure-play vendor focused exclusively on vulnerability and exposure management, which means deeper domain expertise and a platform purpose-built for program execution. Unlike flexible-but-complex platforms that put DIY responsibility on the buyer, or point solutions that address single features without a full execution layer, Nucleus orchestrates the entire lifecycle from data to action without requiring custom engineering to maintain it.

Is Nucleus Security FedRAMP authorized?

Yes. Nucleus Security is FedRAMP authorized, making it one of the few exposure management platforms built to meet the security and compliance requirements of federal agencies and regulated environments. Nucleus also supports multi-tenant architecture for complex organizational structures and integrates POA&M processing directly into the platform.

What results do Nucleus Security customers see?

Nucleus customers see an average 60% reduction in mean time to remediate (MTTR) within six months of implementation. They can scale their programs effectively; for example, one Fortune 500 customer manages 1.9 billion active vulnerabilities on the platform. Customers can also accelerate action for critical exposures, with newly exploited vulnerabilities routed to ticket owners in under 15 minutes.

See Nucleus in Action

Discover how unified, risk-based automation can transform your vulnerability management.