Field Notes / Jacksonville, Florida
A vulnerability scanner has the dramatic job. It finds the flaw, raises the alarm, and decorates a dashboard in urgent colors. Then comes the less cinematic part: combine results from incompatible tools, work out which asset matters, find the person who owns it, open the ticket, explain the risk, and keep asking whether anyone fixed the thing. Steve Carter built his career in that second act.
For roughly the first 15 years of his working life, Carter was a security engineer supporting federal agencies. He also came from software development. The pairing gave him a particular irritation: security processes meant to protect systems could become so slow and repetitive that they obstructed the people trying to build those systems. Vulnerability management was necessary. Its machinery was often needlessly manual.
Carter did what engineers do when a repeated annoyance becomes intolerable. He made tools. The work was not aimed at producing one more blinking console. It was aimed at the long corridor between discovery and remediation, where scan files pile up, naming conventions disagree, and a theoretically urgent problem waits for an actual owner.
“I spent the first 15 years or so of my career as a security engineer, supporting federal agencies.”Steve Carter, VM Short Cuts interview
The white paper with a pulse
In 2015, Carter co-founded Rampant Technologies with his long-time colleague Mike Nixon. The firm supplied security, systems, and software engineering services to government customers. It also became the laboratory for a more ambitious answer to the vulnerability problem.
More than two years before Nucleus officially launched, a large federal agency invited cybersecurity professionals to propose ideas that could improve federal security. Carter and his colleagues had already spent years watching agencies struggle to aggregate and normalize scanner results. Their response was a white paper describing an automated way to bring those results together, prioritize them, manage access, and make the conversations around triage and remediation less chaotic.
The proposal won a one-year research and development contract. A proof of concept followed. Carter later described himself as the original developer of the software. There was no need for theatrical customer discovery. The team had been doing the customer's job. They knew the ugly edges because those edges had been cutting into their own days.
The unglamorous middle where Nucleus lives
That origin explains the company's name better than any branding exercise could. Nucleus was intended as the center of a messy security stack, not its replacement. Scanners could keep scanning. Ticketing systems could keep ticketing. The new platform would ingest their findings, reconcile assets, add context, and direct attention toward the risks that deserved action.
Carter's advantage was proximity. A founder who has lived inside the workflow develops a hard-earned sense of which inconvenience is cosmetic and which one quietly consumes a department. He knew that a mountain of findings is not the same as a plan. He also knew that automation is only useful when it respects how teams divide responsibility.
The federal detour through enterprise
Nucleus launched with Carter, Scott Kuffer, and Nick Fleming, all shaped by work in vulnerability management for government organizations. Yet the team's federal roots did not lead to an immediate federal sales bonanza. Carter understood that a new, small software business would need experience, evidence, and considerable patience before a large agency entrusted it with an enterprise platform.
The private sector offered a useful detour. Large companies were suffering from much the same condition: abundant security data, fragmented tools, and slow remediation. Nucleus found a market among enterprises, application-security teams, and managed security providers. The context changed. The coordination problem did not.
Behind that operating thesis sits an unusually formal technical foundation. Carter studied computer science at Florida State University, completing a master's degree after participating in ACM and IEEE. His public credentials include CISSP, the architecture-focused ISSAP, Certified Ethical Hacker, and Certified Expert Independent Assessor. He has also listed affiliations with OWASP, IEEE, and AFCEA. The little joke hidden in plain sight is his LinkedIn handle, stevecarter1337. The final four digits spell “leet” in the old hacker alphabet, a wink from a chief executive who still signals where he came from.
Colleagues who recommended him publicly describe a security engineer comfortable with software tools, system configuration, operating-system hardening, testing, and policy. One praised his habit of using unconventional thinking to make security work more efficient. The range matters because Nucleus sits across those boundaries. Its problem is partly technical and partly organizational. A connector can move data; a workflow must also reflect who is allowed to see it, who can decide, and who is expected to act.
In 2020 the company raised a Series A and entered Dcode's accelerator, which helps technology companies navigate the federal market. Then came an SBIR contract and sponsorship from the Centers for Medicare and Medicaid Services for the FedRAMP process. Carter wrote that Nucleus had only about 30 employees when it began that work in November 2021. He estimated the authorization effort would absorb thousands of staff hours and more than $1 million.
This was not a nostalgic return to an old customer group. It was a strategic circle: federal experience produced the product, enterprise adoption matured it, and federal authorization made it possible to bring the matured platform back into regulated environments. Nucleus is now FedRAMP authorized.
From writing code to setting direction
As Nucleus grew, Carter's job changed. The original developer became the chief executive, spending more time on strategy, partnerships, and product direction. The technical instinct remained visible. His public explanations return to systems, bottlenecks, and outcomes. Even his preferred business vocabulary sounds engineered: a shared source of truth, measurable risk reduction, the gap between data and action.
The scoreboard moved, too. Nucleus ranked No. 267 on the 2024 Inc. 5000. Deloitte placed it No. 85 on its 2024 Technology Fast 500 and reported 1,562 percent growth over three years. In 2025, SecurityInfoWatch selected Carter as a Security Business Innovator. These are corporate achievements attached to a team, and Carter habitually describes them that way. His announcements thank employees, customers, partners, and investors with the insistence of someone wary of the lone-founder fable.
Two rankings, one year
Relative bars visualize placement within lists of 5,000 and 500 companies. A lower rank number indicates a higher placement.
His writing about company culture has the same practical cast. Culture, Carter argues, is made from daily choices. People should feel supported. Ideas should not be trapped by job titles. Trust and transparency must appear in how work gets done. It is easy to print those words on a wall. It is harder to make them survive headcount, fundraising, and a calendar crowded with deadlines.
There is a pleasing rhyme between that view of leadership and the Nucleus product. Both are concerned with handoffs. Both depend on giving the right person enough context to act. Both fail when responsibility becomes vague. Carter seems most at home when a lofty noun - security, culture, innovation - can be translated into a sequence of observable decisions.
“We started the company because we felt like it needed to exist.”Steve Carter, on Nucleus joining the Inc. 5000
A milestone, then the next ticket
In February 2026, Nucleus announced a $20 million Series C led by Delta-v Capital, with Arthur Ventures participating. Carter framed the moment around a change in customer behavior. Large organizations were no longer merely experimenting with exposure management. They were replacing homegrown systems and asking for an operational record that could connect assets, vulnerabilities, threat signals, and accountable action.
The money was designated for scale, deeper intelligence and automation, and the resilience required by cloud and AI-driven environments. The platform now says it integrates data from more than 200 tools. The number is impressive mostly because every integration represents another dialect that security teams no longer have to translate by hand.
Carter called the financing a milestone, not a finish line. It is an unsurprising phrase from a vulnerability-management lifer. A signal has arrived. Now somebody has to route it, own it, and do the work.
That is the useful thing to steal from his story. The glamorous edge of an industry often hides a valuable middle. Cybersecurity celebrates the moment a weakness is found, but organizations become safer only when the weakness is fixed. Startups celebrate the idea, the launch, and the round, but companies are made in the operational passages between them. Carter has built in those passages for more than two decades.
He began with software, a federal brief, and the conviction that an exhausting workflow could be made coherent. The ambition has widened, but not changed much: help the people responsible for security see what matters and move before another urgent finding becomes old furniture. It is serious work. It also has the dry comedy of all good automation - the machine handles the drudgery so the humans can finally attend to the emergency.