Executive brief
Grenoble has thousands of software jobs. It has very few where the code you write is examined by a nuclear safety authority, a rail signalling assessor or a refinery's operating licence. CORYS — a SAS registered at 44 rue des Berges, owned per its own reactor-vendor shareholder by Framatome, EDF and IFP Training — is one of those places. This dossier does not describe the company's culture or its salaries, because no openable source publishes either. It does something more useful: it reads the company's products and its actual job postings and derives the competence families they require. Three emerge, and they are not the ones a generic engineering CV advertises: physical-process modelling against a real installation, real-time and safety-adjacent software engineering in C++ and Qt around signalling standards such as ERTMS/ETCS, and validation and delivery engineering — the CI/CD, test-harness and acceptance work that turns a model into something a regulator will accept. Every salary band, headcount total and career-path claim is refused below, with the reason.
I. Why this employer is worth reading carefully
Most career analysis about a software employer starts from the job title and ends at the stack. That approach produces nothing here, because the distinguishing feature of this work is not the language but the burden of proof attached to the output. A full-scope simulator for a nuclear unit, a process trainer for a refinery, or a driver-training platform for a metro line are all artefacts that somebody outside the company must be willing to accept as faithful. That acceptance is what an engineer is paid to make possible.
The consequence for a career is specific and under-appreciated. In ordinary application development, correctness is judged by users and by revenue. Here it is judged by comparison with a physical installation and by a documented validation trail. Engineers who spend years in that regime acquire a habit — write down the assumption, bound it, and be able to defend it — that is portable to every regulated industry in the region: reactor engineering at the vendor and the operator, signalling and rolling stock, process safety, medical devices, and the qualification side of semiconductor manufacturing. That portability is the real return on the job, and it is why the absence of published salary data matters less than it appears.
II. The company's product lines, read as competence demands
The public product record is the most reliable evidence available, and it maps cleanly onto three families of engineering skill.
| Product line | Domain | Competence it implies |
|---|---|---|
| ALICES Plus | Nuclear power plant simulation | Thermal-hydraulics and neutronics model integration; control-room instrumentation logic; configuration management across plant variants |
| INDISS PLUS | Process and refining industries | Dynamic process modelling — unit operations, hydraulics, control loops — and the tuning discipline that keeps a model stable across operating envelopes |
| Ultra Light Simulators / rail platforms | Rail and urban transit | Real-time software in C++ and Qt, driver-interface fidelity, and interfacing to signalling of the OCTYS/CBTC family |
Read together, these lines share one engineering core and diverge only at the physics. That is the structural reason a modelling engineer here is not locked into one industry: the solver, the configuration discipline, the instructor-station architecture and the validation apparatus are common, while the equations change. It is a rarer form of internal mobility than most software employers can offer, and it is visible in the product record rather than asserted in a careers page.
III. What the work demands, read from what the company ships
We looked for the openings themselves first. The company recruits through a hosted careers portal that renders no page a crawler or a reader can cite, and every aggregator carrying its name returned a dead or blocked address on the day of consultation. So we do not quote postings we cannot link. Instead the competence demands below are derived from two things the company does publish and does date: its product lines, and eleven simulator deliveries announced between February and August 2026. That is a weaker source for job titles and a stronger one for what the work actually is.
1. Real-time and interface fidelity around live signalling standards
The published rail deliveries name their signalling content explicitly: CBTC, ETCS Level 2 and conventional AWS/TPWS on the Elizabeth line simulators, Class 68 ETCS for a UK freight operator, a cross-border ETCS demonstrator at InnoTrans. A driver-training interface has to reproduce timing, indication states and failure behaviour well enough that trained reflexes transfer to the real cab, which makes latency, determinism and state-machine correctness functional requirements rather than performance niceties. An engineer who wants to be paid for the difference between "usually fast" and "bounded" is describing this work.
2. Configuration and validation of a qualified artefact
Every simulator instance is a configured product: a specific plant, a specific control-room revision, a specific model baseline. The EDF COCASE announcements make the shape visible — 900 MW CP1 and CP2 stages, then 1300 MW P4, then PP4 VD4, each a variant of the same platform passing factory acceptance in sequence. Reproducible builds, versioned baselines and automated regression across configurations are the mechanism by which a validated artefact stays validated after a change. It is the least glamorous competence in this file and probably the most transferable, because the same discipline is the entry ticket to qualification work across the region's regulated employers.
3. Real hardware and real plant equipment in the loop
The Flamanville 3 fuel-handling simulator is published as blending 3D environments with real plant programmable logic controllers and hardware identical to plant equipment; the Framatome Ugine simulator models a complete zirconium ingot melt on a vacuum arc remelting furnace. Work of that kind is not pure software: it demands people who can read an installation's control system, instrument it, and defend the boundary between what is modelled and what is wired. That boundary is where a regulator's questions land.
4. Image generation as an engineering discipline
The Epic Games certification is the company's own quantification of this: three years of research and development from early 2023, a team of more than fifteen engineers, a rebuilt asset production pipeline with proprietary tooling for the nuclear and railway sectors. Real-time 3D at that scale is a career track in its own right here, and unusually for the region it is documented with a date and a team size rather than asserted.
IV. The delivery cadence, read from three dated 2026 projects
What a job posting cannot tell you is the tempo an engineer will actually work at. Three announcements from 2026 can, and they are the most career-relevant evidence in this file.
- 13 July 2026 — Direct Rail Services, United Kingdom. Class 68 ETCS simulators commissioned: one replica simulator and eight Ultra-Light Simulators, delivered so that the operator is ready as ETCS goes live on its network. The company attributes the speed of commissioning to factory testing and validation completed before delivery.
- 6 July 2026 — RATP Dev, Caen. Site Acceptance Test run from 22 to 26 June, less than five months after project kick-off: ten ultra-light simulators, one instructor station, one scenario-preparation station, with two weeks of on-site support after acceptance and first driver sessions in early July, ahead of a July 2027 service takeover.
- 31 August 2026 — InnoTrans demonstrator. A cross-border ETCS simulator integrating eye tracking and AI so instructors can assess trainee performance objectively, plus light-rail tram simulation described as following recent tender wins.
Read as a career signal, three things follow. First, the unit of work is a site acceptance with a date, not a release train — an engineer's calendar is set by a customer's training schedule, and a five-month kick-off-to-SAT cycle is fast for a regulated deliverable. Second, the commercial argument is validate in the factory, not on the customer's site, which is precisely why the continuous-integration and test-harness roles above are load-bearing rather than support functions. Third, the InnoTrans demonstrator shows where the skill frontier is moving: instrumented human-factors assessment — eye tracking, model-based inference of trainee attention — is a competence adjacent to modelling and not yet commoditised anywhere in the region.
V. The employer is now inside the training pipeline itself
The single most important item for anyone planning a career here is not a job posting. On 27 February 2026 the company's cloud-hosted C EPR simulator was selected as a teaching tool for N2G2V — New Generations of Nuclear Graduates in Grenoble and Valence — a France 2030 consortium chaired by the Université des Métiers du Nucléaire alongside Grenoble INP-UGA and Université Grenoble Alpes. The consortium's published target is to raise five-year nuclear graduate output by more than 50%, from 130 to 218 graduates a year by 2028, in neutron physics, thermal-hydraulics, materials, control systems, nuclear safety and decommissioning.
Three consequences follow for a student or an early-career engineer in this city. First, the competence list above is not this newsroom's construction — it is the consortium's own, and it names the same physics-plus-control-systems combination the company's products demand. Second, a student who trains on a cloud simulator built by a local employer arrives at interview already fluent in that employer's tooling; the pipeline and the recruiter are the same institution. Third, the target quantifies scarcity: an 88-graduate-a-year national shortfall being closed by 2028 is the reason validation-capable engineers in this field can expect to negotiate from strength — and it is a published number, not a sentiment.
Two governance facts belong here too, because both are published rather than inferred. The company holds ISO 9001, ISO 14001 and ISO 27001 certifications; the information-security one has a direct daily consequence, since a simulator baseline embeds a customer's plant or signalling configuration and is handled as sensitive data. And it states a homeworking agreement and a sustainable-transport policy as corporate commitments — the agreement's existence is published, its terms are not, and we do not invent them.
VI. The modelling engineer's competence ladder
From the product and posting evidence, four capabilities separate a junior contributor from someone the organisation cannot easily replace. None of these is a certification; all of them are demonstrable in an interview.
- Model against a reference, not against intuition. The ability to take plant data or design documentation and state what the model must reproduce, within what tolerance, before writing the solver call.
- Bound your assumptions in writing. Every simplification in a dynamic model is a claim about the operating envelope. Engineers who record those claims survive audits; engineers who carry them in their heads become single points of failure.
- Own the validation, not just the feature. Building the test case that would falsify your own model is the core professional act in this trade, and it is exactly what the CI/CD postings are for.
- Speak the customer's domain. Whether the counterpart is a reactor operator, a refinery shift supervisor or a metro signalling engineer, credibility comes from using their vocabulary correctly. This is the skill that converts a competent developer into a project lead.
VII. The honest risks of this career path
A dossier that only listed upside would not be worth reading. Three risks are visible in the same evidence.
Concentration. The company's owners are its principal industrial counterparties. That is a stability argument and a dependency argument at once: a strategic reorganisation among shareholders is a governance event an employee cannot see coming, and no press release is required for one.
Cycle exposure. Demand tracks nuclear new build and lifetime extension, transit capital plans and refinery investment. These cycles are long and political. They are also uncorrelated with each other, which is the portfolio argument — but an engineer specialised in only one of the three vertical stacks does not benefit from that diversification personally.
Opacity as a negotiating handicap. Because no salary band appears in any published posting and no revenue figure exists in public, a candidate here has less market information than a candidate at a listed employer. The practical response is to benchmark against comparable regulated-engineering roles in the Grenoble basin rather than against generic developer surveys, and to ask about validation responsibility explicitly — that is where the seniority, and the pay, actually sit.
VIII. What we refuse to publish
- Any salary or salary band. No published listing carries one; none is estimated, and no regional developer average is substituted.
- Any headcount as a single number. Three publishers give 291, a 200–249 bracket, and "over 380" worldwide; they count different things and are printed as a spread in the companion dossier.
- Any hiring volume, attrition rate, or growth in engineering staff. No source measures any of them.
- Any named school, apprenticeship or internship partnership. None was found in an openable source.
- Any internal career-path, promotion timeline or team structure. Nothing published describes them, and inventing an org chart would be the easiest and most damaging fabrication available here.
- The terms of the homeworking arrangement. The company states that a homeworking agreement exists; no source we opened gives its days, eligibility or scope, and none is inferred.
- Any assertion that a named project is currently staffed in Grenoble. Project awards are published; their staffing location is not.
IX. Conclusion: the value is the burden of proof
The reason to take this employer seriously is not that it is large, fast-growing or well-paid — three things no openable source establishes. It is that the work imposes a standard of evidence on software that almost no other local employer imposes, and that the standard is the transferable asset. An engineer who leaves after five years takes with them the ability to state what a model claims, bound it, and prove it to somebody with the authority to say no. In a regional economy built on nuclear, transit, process industry and semiconductors, that is one of the most durable competences on offer — and it is available in a building in central Grenoble that most of the city has never heard of.
