Application Security Engineer

MDU Construction Services Group, Inc

Bismarck (ND)

On-site

USD 118,000 - 148,000

Full time

13 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
401(k) with matching
Flexible work hours
Sick leave
Vacation

Job summary

Everus Construction Group is seeking a hands-on Application Security Engineer to build, run, and improve security tooling across the SDLC, including AI-assisted coding tools.

This is an engineering role focused on pipelines, code, and remediation; you will own technical outcomes and shape security practices as we scale our modern AppSec capabilities.

Qualifications

  • Bachelor’s degree in IT, cybersecurity, CS or related field
  • 4 years of application security, DevSecOps, or security-focused software engineering
  • Experience integrating security scanners into CI/CD pipelines
  • Ability to write custom security rules and review code

Responsibilities

  • SDLC security tooling and automation across CI/CD pipelines
  • Manual security code reviews on high-risk changes
  • Threat modeling on new apps and major changes
  • Develop secure-by-default templates and reusable workflows
  • Vulnerability operations and incident response support

Skills

Python
JavaScript/TypeScript
C#/.NET
Go
CI/CD security integration
Threat modeling
Code review
AI coding tools experience
Cloud security fundamentals
Git

Education

Bachelor's degree in Information Technology, Cybersecurity, Computer Science or related field

Tools

Semgrep
CodeQL
GitHub Actions
Azure DevOps
Dependabot
Renovate

Job description

JOB SUMMARY

At Everus, employees come first. We provide great pay, benefits and growth opportunities to more than 9,000 highly skilled team members across the country who are united by the common goal of safely Building America's Future. We take great pride in the work our employees do each day, which drives our success as one of the Top 12 largest specialty contractors in the nation, and we will ensure you have the tools, training and opportunities for a successful career. We look forward to having you on the team!

Everus Construction Group is hiring a hands-on Application Security Engineer to build, run, and continuously improve the security tooling and code review practices across our software development lifecycle (SDLC) - including the growing surface of AI-assisted ("vibe") coding from tools like GitHub Copilot, Cursor, and Claude Code.

This is an engineering role, not a policy role. You'll spend your time in pipelines, repositories, and code - wiring up scanners, writing custom rules, reviewing pull requests, and partnering with developers on remediation. Policy and governance work exists, but it's downstream of the technical work you produce. Our existing GRC and security leadership functions own the audit-facing artifacts; you own the things that actually run in production.

We are a recently spun-off public company (NYSE: ECG) building modern AppSec capabilities from the ground up. You will not inherit a mature program - which means you get to make the technical decisions that shape how we build software for the next decade.

Responsible for understanding, upholding, and promoting the Everus 4EVER Strategy.
Employees | Value | Execution | Relationships

MINIMUM QUALIFICATIONS
  • A working knowledge of Information Technology at a level normally acquired through completion of a Bachelor's degree in Information Technology, Cybersecurity, Computer Science or related field; and
  • Four years' experience in application security, DevSecOps, or a software engineering role with substantial security responsibility
JOB RESPONSIBILITIES

SDLC Security Tooling & Automation (~50%)

  • Deploy, integrate, and tune SAST, DAST, SCA, IaC, container, and secrets-scanning tooling across our CI/CD pipelines (GitHub Actions, Azure DevOps)
  • Write and maintain custom rules (Semgrep, CodeQL, or equivalent) tailored to our codebases and the recurring issues we actually see
  • Build security gates, pre-commit hooks, and PR automation that catch issues early without breaking developer flow
  • Develop and maintain SBOM generation and dependency-update automation (Dependabot, Renovate, or custom)
  • Automate secret rotation and detection workflows, including post-leak revocation paths
  • Build dashboards and metrics on findings, MTTR, coverage, and pipeline health
  • Create secure-by-default project templates, starter repos, and reusable workflows for our development teams
  • Continuously evaluate and replace tooling - we expect this stack to evolve

Hands-On Code Review & Developer Partnership (~25%)

  • Perform manual security code reviews on high-risk changes, new applications, and pre-production releases
  • Conduct lightweight threat modeling on new applications and major changes - focused on producing actionable findings, not artifacts
  • Pair with developers on remediation, including writing the fix when that's the fastest path
  • Review architecture for in-house applications, integrations, and Azure-hosted workloads (App Service, Functions, Key Vault, Storage, AI services)
  • Triage, validate, and route findings from automated scanners and external researchers
  • Maintain reusable secure-coding patterns and code samples developers can copy

AI-Generated Code Detection & Guardrails (~15%)

  • Build technical guardrails around AI coding tool usage in our repositories - what gets allowed, what gets flagged, what gets blocked
  • Implement detection for common AI-generated insecurity patterns (insecure deserialization, missing authz, hardcoded secrets, weak crypto, prompt-injection-prone patterns in agentic code)
  • Stand up telemetry to attribute and assess AI-generated code, especially in SOX-relevant systems
  • Build automated PR review tooling that flags AI-generated code requiring deeper human review
  • Apply the same scanning and review rigor to AI features in our own applications (RAG pipelines, agents, LLM-integrated workflows like our internal ESIconnect platform)
  • Provide technical input to the policy and governance work owned by Security Leadership and GRC - but you build, they publish

Vulnerability Operations (~10%)

  • Run the application vulnerability backlog: triage, prioritization, exception workflow, SLAs
  • Contribute to incident response for application-layer events
  • Support audit and SOX evidence collection by ensuring tooling output is retainable and queryable - the goal is automation, not screenshots
KEY SKILLS & COMPENTENCIES
  • Strong working code in at least one of: Python, JavaScript/TypeScript, C#/.NET, or Go - you can write tooling, not just read it
  • Production experience integrating security scanners into CI/CD (GitHub Actions or Azure DevOps preferred); you've configured them, tuned them, and replaced them
  • Hands-on experience writing custom rules in Semgrep, CodeQL, or a comparable engine
  • Working knowledge of OWASP Top 10, common vulnerability classes, and how they manifest in modern frameworks
  • Personal, hands-on experience using AI coding tools (Copilot, Cursor, Claude Code, or equivalent) - you can speak credibly about what they do well and where they fail
  • Working knowledge of cloud security fundamentals (Azure preferred - Entra ID, Key Vault, App Service, Storage, Defender for Cloud)
  • Comfort with Git, branching strategies, and modern PR-driven workflows
COMPENSATION & BENEFITS PACKAGE
  • Salary: $118,020 - $147,520
  • Annual short-term incentive bonus of up to 30% of eligible wages based on eligibility and company goal achievement.
  • Medical insurance (health savings account), including free programs Hinge Health and Omada
  • Enhanced mental health and work-life services through Lyra Health
  • Virtual care through Doctor on Demand
  • Prescription delivery service
  • Dental insurance
  • Vision insurance
  • Life insurance for employees, spouses, and dependents
  • Accidental death and dismemberment (AD&D) insurance
  • Flexible spending accounts
  • 401(k) plan with matching contribution and retirement contribution
  • Hospital Insurance
  • Accident Insurance
  • Critical Illness Insurance
  • Disability insurance
  • Sick leave
  • Vacation
  • 11 paid holidays
  • Flexible work hours, where feasible
  • Employee discount programs
ADDITIONAL INFORMATION
  • Background check, MVR and drug screen are required
  • May be required to maintain a valid driver's license

APPLICATION DEADLINE - September 14, 2026

(This position may close early if a sufficient number of applications are received.)

JOIN THE EVERUS TEAM

Everus Construction is proud to provide exceptional opportunities to professionals nationwide. We are confident that you will find challenging and rewarding work with us. We hope to see your application soon!

Current Everus employees: Ask HR about our referral program!

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

This employer is required to notify all applicants of their rights pursuant to federal employment laws.

For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Talent Acquisition Specialist I
Talent Acquisition Specialist I

Esi Electrical Contractors, Inc. • Bismarck (ND)

On-site
USD 65,000 - 90,000
Annual bonus up to 10%
Medical insurance with HSA
401(k) plan with match
+1
Talent Acquisition Specialist I
Talent Acquisition Specialist I

MDU Construction Services Group, Inc • Bismarck (ND)

On-site
USD 57,000 - 71,000
Medical insurance (HSA)
Lyra Health
Virtual care
+10
Corporate Development Analyst II
Corporate Development Analyst II

MDU Construction Services Group, Inc • Broomfield (CO)

On-site
USD 64,000 - 80,000
Medical insurance
Dental insurance
Vision insurance
+5
Talent Development Specialist II
Talent Development Specialist II

MDU Construction Services Group, Inc • Bismarck (ND)

On-site
USD 64,000 - 80,000
Medical insurance & HSA program
Lyra Health mental health support
Doctor on Demand virtual care
+3
Corporate Development Analyst II
Corporate Development Analyst II

Esi Electrical Contractors, Inc. • Broomfield (CO)

On-site
USD 90,000 - 130,000
Medical insurance
401(k) plan with matching
Vacation
+1
Talent Acquisition Specialist I
Talent Acquisition Specialist I

Everus • Bismarck (ND)

On-site
USD 57,000 - 71,000
Health benefits
401(k) plan with matching
Paid holidays
+6
Talent Development Specialist II
Talent Development Specialist II

Esi Electrical Contractors, Inc. • Bismarck (ND)

On-site
USD 55,000 - 75,000
Medical insurance
401(k) plan with matching
Flexible work hours
+1
Talent Development Specialist II
Talent Development Specialist II

Everus • Bismarck (ND)

On-site
USD 64,000 - 80,000
Medical insurance
401(k) plan with matching
Vacation
+1
Financial Analyst I – Treasury
Financial Analyst I – Treasury

Esi Electrical Contractors, Inc. • Bismarck (ND), Northern (KY)

Hybrid
USD 57,000 - 71,000
Salary range
Bonus up to 10%
Health insurance
+3
Tax Manager
Tax Manager

Esi Electrical Contractors, Inc. • Bismarck (ND)

On-site
USD 118,000 - 148,000
Salary range
Annual bonus up to 30%
Medical insurance with HSA
+8