×
Register Here to Apply for Jobs or Post Jobs. X

Application Security Engineer

Job in Bismarck, Burleigh County, North Dakota, 58502, USA
Listing for: MDU Construction Services Group, Inc
Full Time position
Listed on 2026-09-05
Job specializations:
  • Software Development
    AI Engineer (Applied/Software)
Salary/Wage Range or Industry Benchmark: 118000 - 148000 USD Yearly USD 118000.00 148000.00 YEAR
Job Description & How to Apply Below

JOB SUMMARY

At Everus, employees come first. We provide great pay, benefits and growth opportunities to more than 9,000 highly skilled team members across the country who are united by the common goal of safely Building America's Future. We take great pride in the work our employees do each day, which drives our success as one of the Top 12 largest specialty contractors in the nation, and we will ensure you have the tools, training and opportunities for a successful career.

We look forward to having you on the team!

Everus Construction Group is hiring a hands-on Application Security Engineer to build, run, and continuously improve the security tooling and code review practices across our software development lifecycle (SDLC) - including the growing surface of AI-assisted ("vibe") coding from tools like Git Hub Copilot, Cursor, and Claude Code.

This is an engineering role, not a policy role. You'll spend your time in pipelines, repositories, and code - wiring up scanners, writing custom rules, reviewing pull requests, and partnering with developers on remediation. Policy and governance work exists, but it's downstream of the technical work you produce. Our existing GRC and security leadership functions own the audit-facing artifacts; you own the things that actually run in production.

We are a recently spun-off public company (NYSE: ECG) building modern App Sec capabilities from the ground up. You will not inherit a mature program - which means you get to make the technical decisions that shape how we build software for the next decade.

Responsible for understanding, upholding, and promoting the Everus 4

EVER Strategy.
Employees | Value | Execution | Relationships

MINIMUM QUALIFICATIONS
  • A working knowledge of Information Technology at a level normally acquired through completion of a Bachelor's degree in Information Technology, Cybersecurity, Computer Science or related field; and
  • Four years' experience in application security, Dev Sec Ops , or a software engineering role with substantial security responsibility
JOB RESPONSIBILITIES

SDLC Security Tooling & Automation (~50%)

  • Deploy, integrate, and tune SAST, DAST, SCA, IaC, container, and secrets-scanning tooling across our CI/CD pipelines (Git Hub Actions, Azure Dev Ops)
  • Write and maintain custom rules (Semgrep, CodeQL, or equivalent) tailored to our codebases and the recurring issues we actually see
  • Build security gates, pre-commit hooks, and PR automation that catch issues early without breaking developer flow
  • Develop and maintain SBOM generation and dependency-update automation (Dependabot, Renovate, or custom)
  • Automate secret rotation and detection workflows, including post-leak revocation paths
  • Build dashboards and metrics on findings, MTTR, coverage, and pipeline health
  • Create secure-by-default project templates, starter repos, and reusable workflows for our development teams
  • Continuously evaluate and replace tooling - we expect this stack to evolve

Hands-On Code Review & Developer Partnership (~25%)

  • Perform manual security code reviews on high-risk changes, new applications, and pre-production releases
  • Conduct lightweight threat modeling on new applications and major changes - focused on producing actionable findings, not artifacts
  • Pair with developers on remediation, including writing the fix when that's the fastest path
  • Review architecture for in-house applications, integrations, and Azure-hosted workloads (App Service, Functions, Key Vault, Storage, AI services)
  • Triage, validate, and route findings from automated scanners and external researchers
  • Maintain reusable secure-coding patterns and code samples developers can copy

AI-Generated Code Detection & Guardrails (~15%)

  • Build technical guardrails around AI coding tool usage in our repositories - what gets allowed, what gets flagged, what gets blocked
  • Implement detection for common AI-generated insecurity patterns (insecure deserialization, missing authz, hardcoded secrets, weak crypto, prompt-injection-prone patterns in agentic code)
  • Stand up telemetry to attribute and assess AI-generated code, especially in SOX-relevant systems
  • Build automated PR review tooling that flags AI-generated code requiring deeper human review
  • Apply the same scanning and review rigor to AI features in our own applications (RAG pipelines, agents, LLM-integrated workflows like our internal ESIconnect platform)
  • Provide technical input to the policy and governance work owned by Security Leadership and GRC - but you build, they publish

Vulnerability Operations (~10%)

  • Run the application vulnerability backlog: triage, prioritization, exception workflow, SLAs
  • Contribute to incident response for application-layer events
  • Support audit and SOX evidence collection by ensuring tooling output is retainable and queryable - the goal is automation, not screenshots
KEY SKILLS & COMPENTENCIES
  • Strong working code in at least one of:
    Python, JavaScript/Type Script, C#/.NET, or Go - you can write tooling, not just read it
  • Production experience integrating security scanners into…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary