{"schemaVersion":"jobsearcher.job.v1","id":"c71e281c75ae727691b06788","url":"https://jobsearcher.com/jobs/c71e281c75ae727691b06788","canonicalUrl":"https://jobsearcher.com/jobs/c71e281c75ae727691b06788","title":"Application Security Engineer","description":"(https://everus.com)\n\nAt Everus, employees come first. We provide great pay, benefits and growth opportunities to more than 9,000 highly skilled team members across the country who are united by the common goal of safely Building America’s Future®. We take great pride in the work our employees do each day, which drives our success as one of the Top 12 largest specialty contractors in the nation, and we will ensure you have the tools, training and opportunities for a successful career. We look forward to having you on the team!\n\nJOB SUMMARY\n\nEverus Construction Group is hiring a hands-on Application Security Engineer to build, run, and continuously improve the security tooling and code review practices across our software development lifecycle (SDLC) — including the growing surface of AI-assisted (\"vibe\") coding from tools like GitHub Copilot, Cursor, and Claude Code.\n\nThis is an engineering role, not a policy role. You'll spend your time in pipelines, repositories, and code — wiring up scanners, writing custom rules, reviewing pull requests, and partnering with developers on remediation. Policy and governance work exists, but it's downstream of the technical work you produce. Our existing GRC and security leadership functions own the audit-facing artifacts; you own the things that actually run in production.\n\nWe are a recently spun-off public company (NYSE: ECG) building modern AppSec capabilities from the ground up. You will not inherit a mature program — which means you get to make the technical decisions that shape how we build software for the next decade.\n\n Responsible for understanding, upholding, and promoting the Everus 4EVER Strategy.\nEmployees | Value | Execution | Relationships\n\nMINIMUM QUALIFICATIONS\n\nA working knowledge of Information Technology at a level normally acquired through completion of a Bachelor’s degree in Information Technology, Cybersecurity, Computer Science or related field; and\nFour years’ experience in application security, DevSecOps, or a software engineering role with substantial security responsibility\n\nJOB RESPONSIBILITIES\n\nSDLC Security Tooling & Automation (~50%)\n\nDeploy, integrate, and tune SAST, DAST, SCA, IaC, container, and secrets-scanning tooling across our CI/CD pipelines (GitHub Actions, Azure DevOps)\nWrite and maintain custom rules (Semgrep, CodeQL, or equivalent) tailored to our codebases and the recurring issues we actually see\nBuild security gates, pre-commit hooks, and PR automation that catch issues early without breaking developer flow\nDevelop and maintain SBOM generation and dependency-update automation (Dependabot, Renovate, or custom)\nAutomate secret rotation and detection workflows, including post-leak revocation paths\nBuild dashboards and metrics on findings, MTTR, coverage, and pipeline health\nCreate secure-by-default project templates, starter repos, and reusable workflows for our development teams\nContinuously evaluate and replace tooling — we expect this stack to evolve\n\nHands-On Code Review & Developer Partnership (~25%)\n\nPerform manual security code reviews on high-risk changes, new applications, and pre-production releases\nConduct lightweight threat modeling on new applications and major changes — focused on producing actionable findings, not artifacts\nPair with developers on remediation, including writing the fix when that's the fastest path\nReview architecture for in-house applications, integrations, and Azure-hosted workloads (App Service, Functions, Key Vault, Storage, AI services)\nTriage, validate, and route findings from automated scanners and external researchers\nMaintain reusable secure-coding patterns and code samples developers can copy\n\nAI-Generated Code Detection & Guardrails (~15%)\n\nBuild technical guardrails around AI coding tool usage in our repositories — what gets allowed, what gets flagged, what gets blocked\nImplement detection for common AI-generated insecurity patterns (insecure deserialization, missing authz, hardcoded secrets, weak crypto, prompt-injection-prone patterns in agentic code)\nStand up telemetry to attribute and assess AI-generated code, especially in SOX-relevant systems\nBuild automated PR review tooling that flags AI-generated code requiring deeper human review\nApply the same scanning and review rigor to AI features in our own applications (RAG pipelines, agents, LLM-integrated workflows like our internal ESIconnect platform)\nProvide technical input to the policy and governance work owned by Security Leadership and GRC — but you build, they publish\n\nVulnerability Operations (~10%)\n\nRun the application vulnerability backlog: triage, prioritization, exception workflow, SLAs\nContribute to incident response for application-layer events\nSupport audit and SOX evidence collection by ensuring tooling output is retainable and queryable — the goal is automation, not screenshots\n\nKEY SKILLS & COMPENTENCIES\n\nStrong working code in at least one of: Python, JavaScript/TypeScript, C#/.NET, or Go — you can write tooling, not just read it\nProduction experience integrating security scanners into CI/CD (GitHub Actions or Azure DevOps preferred); you've configured them, tuned them, and replaced them\nHands-on experience writing custom rules in Semgrep, CodeQL, or a comparable engine\nWorking knowledge of OWASP Top 10, common vulnerability classes, and how they manifest in modern frameworks\nPersonal, hands-on experience using AI coding tools (Copilot, Cursor, Claude Code, or equivalent) - you can speak credibly about what they do well and where they fail\nWorking knowledge of cloud security fundamentals (Azure preferred — Entra ID, Key Vault, App Service, Storage, Defender for Cloud)\nComfort with Git, branching strategies, and modern PR-driven workflows\n\nCOMPENSATION & BENEFITS PACKAGE\n\nSalary: $118,020 - $147,520\nAnnual short-term incentive bonus of up to 30% of eligible wages based on eligibility and company goal achievement.\nMedical insurance (health savings account), including free programs Hinge Health and Omada\nEnhanced mental health and work-life services through Lyra Health\nVirtual care through Doctor on Demand\nPrescription delivery service\nDental insurance\nVision insurance\nLife insurance for employees, spouses, and dependents\nAccidental death and dismemberment (AD&D) insurance\nFlexible spending accounts\n401(k) plan with matching contribution and retirement contribution\nHospital Insurance\nAccident Insurance\nCritical Illness Insurance\nDisability insurance\nSick leave\nVacation\n11 paid holidays\nFlexible work hours, where feasible\nEmployee discount programs\n\nADDITIONAL INFORMATION\n\nBackground check, MVR and drug screen are required\nMay be required to maintain a valid driver's license\n\nAPPLICATION DEADLINE - September 14, 2026\n\n(This position may close early if a sufficient number of applications are received.)\n\nJOIN THE EVERUS TEAM\nEverus Construction is proud to provide exceptional opportunities to professionals nationwide. We are confident that you will find challenging and rewarding work with us. We hope to see your application soon!\n\nCurrent Everus employees: Ask HR about our referral program!\n\n(https://www.facebook.com/EverusConstruction/)\n(https://twitter.com/everuscg)\n(https://www.linkedin.com/company/everusconstruction)\n\n(https://everus.com/)\n\nEqual Opportunity Employer/Protected Veterans/Individuals with Disabilities\nThis employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights (https://www.eeoc.gov/poster) notice from the Department of Labor.","company":"Everusconstructiongroup","rawCompany":"everusconstructiongroup","city":"Bismarck","state":"ND","isRemote":false,"isActive":false,"createdAt":"2026-09-04T11:10:53.203Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security Engineer","description":"(https://everus.com)\n\nAt Everus, employees come first. We provide great pay, benefits and growth opportunities to more than 9,000 highly skilled team members across the country who are united by the common goal of safely Building America’s Future®. We take great pride in the work our employees do each day, which drives our success as one of the Top 12 largest specialty contractors in the nation, and we will ensure you have the tools, training and opportunities for a successful career. We look forward to having you on the team!\n\nJOB SUMMARY\n\nEverus Construction Group is hiring a hands-on Application Security Engineer to build, run, and continuously improve the security tooling and code review practices across our software development lifecycle (SDLC) — including the growing surface of AI-assisted (\"vibe\") coding from tools like GitHub Copilot, Cursor, and Claude Code.\n\nThis is an engineering role, not a policy role. You'll spend your time in pipelines, repositories, and code — wiring up scanners, writing custom rules, reviewing pull requests, and partnering with developers on remediation. Policy and governance work exists, but it's downstream of the technical work you produce. Our existing GRC and security leadership functions own the audit-facing artifacts; you own the things that actually run in production.\n\nWe are a recently spun-off public company (NYSE: ECG) building modern AppSec capabilities from the ground up. You will not inherit a mature program — which means you get to make the technical decisions that shape how we build software for the next decade.\n\n Responsible for understanding, upholding, and promoting the Everus 4EVER Strategy.\nEmployees | Value | Execution | Relationships\n\nMINIMUM QUALIFICATIONS\n\nA working knowledge of Information Technology at a level normally acquired through completion of a Bachelor’s degree in Information Technology, Cybersecurity, Computer Science or related field; and\nFour years’ experience in application security, DevSecOps, or a software engineering role with substantial security responsibility\n\nJOB RESPONSIBILITIES\n\nSDLC Security Tooling & Automation (~50%)\n\nDeploy, integrate, and tune SAST, DAST, SCA, IaC, container, and secrets-scanning tooling across our CI/CD pipelines (GitHub Actions, Azure DevOps)\nWrite and maintain custom rules (Semgrep, CodeQL, or equivalent) tailored to our codebases and the recurring issues we actually see\nBuild security gates, pre-commit hooks, and PR automation that catch issues early without breaking developer flow\nDevelop and maintain SBOM generation and dependency-update automation (Dependabot, Renovate, or custom)\nAutomate secret rotation and detection workflows, including post-leak revocation paths\nBuild dashboards and metrics on findings, MTTR, coverage, and pipeline health\nCreate secure-by-default project templates, starter repos, and reusable workflows for our development teams\nContinuously evaluate and replace tooling — we expect this stack to evolve\n\nHands-On Code Review & Developer Partnership (~25%)\n\nPerform manual security code reviews on high-risk changes, new applications, and pre-production releases\nConduct lightweight threat modeling on new applications and major changes — focused on producing actionable findings, not artifacts\nPair with developers on remediation, including writing the fix when that's the fastest path\nReview architecture for in-house applications, integrations, and Azure-hosted workloads (App Service, Functions, Key Vault, Storage, AI services)\nTriage, validate, and route findings from automated scanners and external researchers\nMaintain reusable secure-coding patterns and code samples developers can copy\n\nAI-Generated Code Detection & Guardrails (~15%)\n\nBuild technical guardrails around AI coding tool usage in our repositories — what gets allowed, what gets flagged, what gets blocked\nImplement detection for common AI-generated insecurity patterns (insecure deserialization, missing authz, hardcoded secrets, weak crypto, prompt-injection-prone patterns in agentic code)\nStand up telemetry to attribute and assess AI-generated code, especially in SOX-relevant systems\nBuild automated PR review tooling that flags AI-generated code requiring deeper human review\nApply the same scanning and review rigor to AI features in our own applications (RAG pipelines, agents, LLM-integrated workflows like our internal ESIconnect platform)\nProvide technical input to the policy and governance work owned by Security Leadership and GRC — but you build, they publish\n\nVulnerability Operations (~10%)\n\nRun the application vulnerability backlog: triage, prioritization, exception workflow, SLAs\nContribute to incident response for application-layer events\nSupport audit and SOX evidence collection by ensuring tooling output is retainable and queryable — the goal is automation, not screenshots\n\nKEY SKILLS & COMPENTENCIES\n\nStrong working code in at least one of: Python, JavaScript/TypeScript, C#/.NET, or Go — you can write tooling, not just read it\nProduction experience integrating security scanners into CI/CD (GitHub Actions or Azure DevOps preferred); you've configured them, tuned them, and replaced them\nHands-on experience writing custom rules in Semgrep, CodeQL, or a comparable engine\nWorking knowledge of OWASP Top 10, common vulnerability classes, and how they manifest in modern frameworks\nPersonal, hands-on experience using AI coding tools (Copilot, Cursor, Claude Code, or equivalent) - you can speak credibly about what they do well and where they fail\nWorking knowledge of cloud security fundamentals (Azure preferred — Entra ID, Key Vault, App Service, Storage, Defender for Cloud)\nComfort with Git, branching strategies, and modern PR-driven workflows\n\nCOMPENSATION & BENEFITS PACKAGE\n\nSalary: $118,020 - $147,520\nAnnual short-term incentive bonus of up to 30% of eligible wages based on eligibility and company goal achievement.\nMedical insurance (health savings account), including free programs Hinge Health and Omada\nEnhanced mental health and work-life services through Lyra Health\nVirtual care through Doctor on Demand\nPrescription delivery service\nDental insurance\nVision insurance\nLife insurance for employees, spouses, and dependents\nAccidental death and dismemberment (AD&D) insurance\nFlexible spending accounts\n401(k) plan with matching contribution and retirement contribution\nHospital Insurance\nAccident Insurance\nCritical Illness Insurance\nDisability insurance\nSick leave\nVacation\n11 paid holidays\nFlexible work hours, where feasible\nEmployee discount programs\n\nADDITIONAL INFORMATION\n\nBackground check, MVR and drug screen are required\nMay be required to maintain a valid driver's license\n\nAPPLICATION DEADLINE - September 14, 2026\n\n(This position may close early if a sufficient number of applications are received.)\n\nJOIN THE EVERUS TEAM\nEverus Construction is proud to provide exceptional opportunities to professionals nationwide. We are confident that you will find challenging and rewarding work with us. We hope to see your application soon!\n\nCurrent Everus employees: Ask HR about our referral program!\n\n(https://www.facebook.com/EverusConstruction/)\n(https://twitter.com/everuscg)\n(https://www.linkedin.com/company/everusconstruction)\n\n(https://everus.com/)\n\nEqual Opportunity Employer/Protected Veterans/Individuals with Disabilities\nThis employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights (https://www.eeoc.gov/poster) notice from the Department of Labor.","datePosted":"2026-09-04T11:10:53.203Z","dateModified":"2026-09-04T11:10:53.203Z","hiringOrganization":{"@type":"Organization","name":"Everusconstructiongroup","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Bismarck","addressRegion":"ND","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"c71e281c75ae727691b06788"},"url":"https://jobsearcher.com/jobs/c71e281c75ae727691b06788"}}