Application Security Engineer
Explicitly calls out AI-assisted ('vibe') coding tools like Copilot, Cursor, and Claude Code and requires building detection and guardrails for AI-generated code.
About the Role
Everus Construction Group is hiring a hands-on Application Security Engineer to build and operate AppSec tooling, integrate scanners into CI/CD, perform security code reviews, and create guardrails for AI-assisted coding across the software development lifecycle. The role focuses on technical implementation—writing custom detection rules, automations, and remediation—rather than governance alone.
Job Description
Role
Everus is seeking a hands-on Application Security Engineer to design, deploy, and maintain application security tooling and workflows across the SDLC. You will work directly in pipelines, repositories, and code—building scanners, custom rules, automation, and developer-facing remediation—to raise the security posture of the company’s software and AI-assisted coding surface.
Key Responsibilities
- Deploy, integrate, tune, and replace SAST, DAST, SCA, IaC, container, and secrets-scanning tooling across CI/CD (GitHub Actions, Azure DevOps).
- Write and maintain custom detection rules (Semgrep, CodeQL, or equivalent) and build security gates, pre-commit hooks, and PR automation.
- Develop SBOM generation and dependency-update automation (Dependabot, Renovate, or custom) and automate secret rotation and detection workflows.
- Create secure-by-default project templates, starter repos, and reusable workflows; build dashboards and metrics for findings, MTTR, coverage, and pipeline health.
- Perform manual security code reviews on high-risk changes, conduct lightweight threat modeling, and pair with developers on remediation (including implementing fixes where appropriate).
- Implement technical guardrails and detection for AI-generated code (Copilot, Cursor, Claude Code), flagging risky patterns and building PR tooling that surfaces AI-generated code for deeper review.
- Operate the application vulnerability backlog (triage, prioritization, exceptions, SLAs), support application-layer incident response, and ensure tooling outputs are audit-queryable for SOX and compliance needs.
Requirements
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field (or equivalent experience) and ~4 years of experience in application security, DevSecOps, or a software engineering role with significant security responsibility.
- Practical coding ability in at least one of: Python, JavaScript/TypeScript, C#/.NET, or Go.
- Production experience integrating and tuning security scanners in CI/CD (GitHub Actions or Azure DevOps preferred).
- Hands-on experience writing custom rules in Semgrep, CodeQL, or comparable engines.
- Working knowledge of OWASP Top 10 and common vulnerability classes and cloud security fundamentals (Azure preferred — Entra ID, Key Vault, App Service, Functions, Storage, Defender for Cloud).
- Familiarity with Git, branching strategies, PR-driven workflows, and personal experience using AI coding tools (Copilot, Cursor, Claude Code) and their failure modes.
Compensation & Benefits
- Salary: $118,020 - $147,520 (base)
- Annual short-term incentive bonus up to 30% of eligible wages (based on eligibility and company goals)
- Medical insurance (HSA-eligible) plus Hinge Health and Omada programs
- Mental health support via Lyra Health; virtual care through Doctor on Demand; prescription delivery service
- Dental, vision, life insurance (employee/spouse/dependents), AD&D
- Flexible spending accounts; 401(k) with matching contribution
- Hospital, accident, critical illness, and disability insurance
- Sick leave, vacation, 11 paid holidays, flexible work hours where feasible
- Employee discount programs
Additional Information
- Background check, MVR, and drug screen required; may be required to maintain a valid driver’s license.
- This is an engineering-focused role responsible for building technical controls; policy and audit artifacts are owned by Security Leadership and GRC.
- Application deadline: September 14, 2026 (position may close early).