Cybersecurity Engineer

Requisition ID: 298943 

  • Relocation Authorized: None 
  • Telework Type: Full-Time Telework 
  • Work Location: Glendale, AZ

 

Extraordinary teams building inspiring projects:

Since 1898, we have helped customers complete more than 25,000 projects in 160 countries on all seven continents that have created jobs, grown economies, improved the resiliency of the world's infrastructure, increased access to energy, resources, and vital services, and made the world a safer, cleaner place. 

Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers' objectives to create a lasting positive impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals, and the Manufacturing and Technology markets. Our services span from initial planning and investment, through start-up and operations. 

Core to Bechtel is our Vision, Values and Commitments. They are what we believe, what customers can expect, and how we deliver. Learn more about our extraordinary teams building inspiring projects in our Impact Report

Project Overview:

Bechtel is refreshing its Continuous Threat Exposure Management (CTEM) and internal penetration testing capability from first principles. The team builds the capability itself: an agentic CTEM platform that continuously discovers, contextualizes, prioritizes, validates, and drives remediation of exposure across the enterprise; an agentic red-teaming platform that orchestrates autonomous attacker agents at scale; and the human-led exploitation work that keeps both grounded in reality.

 

The program is built agent-first. AI agents handle continuous discovery, correlation, enrichment, prioritization, and high-volume repeatable attack execution across the exposure surface. Our engineers do the complex, creative, context-dependent work machines cannot yet do — business logic flaws, chained vulnerabilities, social engineering, and novel attack paths — along with attacks on the AI systems we build and deploy that no legacy tooling covers: prompt injection, agent tool abuse, and MCP interface exploitation.

Job Summary:

This is a hands-on build-and-break role for someone early in their security career who thrives on figuring out how systems fail. Working under the direction of senior testers, you will find, validate, and exploit vulnerabilities in traditional and AI-based systems, and you will support the development and operation of the team's autonomous red-team agents — steering multi-agent campaigns and validating AI-generated findings against real-world exploitability.

 

You will also perform the nuanced exploitation work AI is fundamentally bad at: business logic flaws, social engineering, chained vulnerabilities, and novel attack vectors. Standard toolkit: commercial and open-source offensive security tooling covering web application testing, network assessment, exploitation, and cloud security; CTEM-stack tooling spanning CNAPP, ASM, vulnerability management, CMDB and asset intelligence, and third-party risk; plus emerging agentic tooling and the team's own platforms. Prior tool familiarity is not required — the ability to learn new tooling quickly is what matters.

Major Responsibilities:

  • Executes hands-on penetration tests of web applications, networks, cloud environments, and AI-based systems under the direction of senior penetration testers.
  • Supports the development and operation of the team's autonomous red-team agents; helps steer multi-agent campaigns and validates AI-generated findings against real-world exploitability.
  • Tests and validates the security controls that maintain the confidentiality, integrity, and availability of information systems.
  • Identifies and prioritizes threats to critical business assets and infrastructure, and provides stakeholders with practical recommendations to mitigate them.
  • Assists with security assessments across a range of issues including network traffic, firewalls, identity and directory services, and network access.
  • Triages scanner, tooling, and agent output; reproduces findings, evaluates exploitability and business impact, and documents clear reproduction steps.
  • Assists in converting test findings and requirements into end-to-end solutions that acknowledge technical, schedule, and cost constraints.
  • Helps align current security testing coverage with business requirements and emerging threats.
  • Supports risk assessments of applications and infrastructure and contributes findings-based recommendations to application and platform owners.
  • Participates in computer incident response team efforts and supports the investigation of cybersecurity incidents.
  • Researches current offensive security techniques, tooling, and threat actor tradecraft, and shares what is learned with the team.

Education and Experience Requirements:

  • Typically requires a Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Electrical/Computer Engineering, or a closely related field and 5 + years of relevant experience OR equivalent demonstrated experience through CTF participation, bug bounty contributions, self-directed security education, or a relevant junior security role.
  • 0–2 years of hands-on experience in cybersecurity, penetration testing, vulnerability or exposure management, security operations, or equivalent practical security training. University hires with strong self-directed learning portfolios (home lab, CTF write-ups, bug bounty reports, security projects on GitHub) are considered on par with formal experience. Equivalency is judged on demonstrated hands-on capability, not years of service — candidates with more years in adjacent technical disciplines qualify under the demonstrated-experience path.

Required Knowledge and Skills:

Core Skills

  • Network protocols — TCP/IP, DNS, HTTP/S, and common enterprise identity and directory protocols.
  • Cryptography fundamentals — symmetric vs. asymmetric encryption, hashing, PKI, common weaknesses and misuse patterns.
  • Web technologies — HTTP, cookies/sessions, authentication and session management fundamentals, OWASP Top 10 and the OWASP Testing Guide.
  • Vulnerability assessment — triage scanner output, prioritize findings, and evaluate exploitability and business impact; familiarity with CVSS, and awareness of exploitability signals such as EPSS and CISA KEV.
  • Cloud fundamentals — core compute, storage, identity, and networking concepts in at least one major cloud (AWS/Azure/GCP).
  • Operating systems — proficient Linux command line; Windows and Active Directory fundamentals.
  • Scripting & integration — proficient in Python or Bash: writing automation, consuming REST APIs, processing scanner and log data, building small tooling; fluency grows with the platform work.
  • Data literacy — comfort joining, deduplicating, and reasoning over findings and asset data from multiple sources.

 

Essential skills

  • Hands-on exploitation capability — ability to manually exploit vulnerabilities in a controlled lab, not just run scanners and read output.
  • Software systems literacy — comfort reading, extending, and debugging software systems that run automated discovery and testing: agent workflows, integrations, state, and failure modes.
  • Agentic tooling fluency — practical exposure to multi-agent orchestration: running a coding or security agent against a real task, chaining agents or tools, and recognizing where an orchestration breaks down.
  • Critical evaluation of AI-generated content — ability to assess whether AI output (exploit code, vulnerability analysis, prioritization decisions, agent actions) is technically sound; spot when an agent misread evidence or over-claimed a finding; judge where a human has to stay in the loop.
  • Adversarial thinking — demonstrated ability to approach systems from an attacker's perspective and identify attack paths not obvious from documentation.
  • Clear technical writing — document findings, reproduce steps, and communicate risk to technical and non-technical audiences.
  • Cross-team collaboration — ability to work findings to closure with infrastructure, cloud, application, and business-unit owners
  • Learning agility — track record of self-directed learning in fast-evolving domains; comfort with ambiguity and new tools.

Preferred Qualifications

  • Exposure or vulnerability management exposure — hands-on time with enterprise vulnerability scanning, remediation tracking, or risk-based prioritization.
  • CNAPP / cloud posture tooling — experience with cloud security posture, CIEM, container/Kubernetes security, or IaC scanning tooling.
  • Attack surface management — external attack surface discovery, asset attribution, or shadow IT identification.
  • Asset & CMDB data — CMDB or ITSM platforms, asset reconciliation, or asset data quality work.
  • Third-party & supply-chain risk — vendor risk assessment, SBOM analysis, or dependency/component vulnerability management.
  • Integration & automation — building API integrations, data pipelines, or workflow automation across security tools.
  • Exploit development fundamentals — buffer overflows, use-after-free, format strings, ASLR/DEP, and memory management concepts sufficient to evaluate exploit validity.
  • Protocol depth — enterprise identity and directory attack surfaces, credential attacks, and Linux and Windows privilege escalation pathways.
  • Identity & access protocols — OAuth 2.0 / OIDC, SAML, JWT flows and common misconfigurations.
  • Cloud security assessment experience — IAM misconfigurations and privilege escalation paths across AWS/Azure/GCP.
  • Adversary simulation experience — participation in red or purple team exercises, or breach-and-attack-simulation tooling.
  • CTF experience — HackTheBox, TryHackMe, PicoCTF, CTFtime-ranked competitions with demonstrated progression; write-ups showing independent problem-solving.
  • Bug bounty contributions — valid submissions (HackerOne, Bugcrowd, Intigriti); preference for logic flaws, auth bypass, or novel techniques over scanner-found issues.
  • Certifications (held or in active pursuit): eJPT, OSCP, CRTO, BSCP, CompTIA Security+, or a cloud security certification.
  • AI-assisted security workflow experience — using LLMs for exploit development, analysis, or automation; building or operating agentic tooling (coding agents, multi-agent workflows, MCP servers) for offensive or defensive tasks.
  • Cloud certification — AWS Cloud Practitioner, Azure Fundamentals, or equivalent.
  • Home lab — personal environment for practicing exploitation, running CTF challenges, or experimenting with security tools.
  • Open-source security contributions — security tooling, exploit development, or vulnerability research on GitHub.

Total Rewards/Benefits:

For decades, Bechtel has worked to inspire the next generation of employees and beyond! Because our teams face some of the world's toughest challenges, we offer robust benefits to ensure our people thrive.  Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth. Learn more at Bechtel Total Rewards

Diverse teams build the extraordinary:

As a global company, Bechtel has long been home to a vibrant multitude of nationalities, cultures, ethnicities, and life experiences. This diversity has made us a more trusted partner, more effective problem solvers and innovators, and a more attractive destination for leading talent.

We are committed to being a company where every colleague feels that they belong-where colleagues feel part of "One Team," respected and rewarded for what they bring, supported in pursuing their goals, invested in our values and purpose, and treated equitably. Click here to learn more about the people who power our legacy.

 

Bechtel is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, disability, citizenship status (except as authorized by law), protected veteran status, genetic information, and any other characteristic protected by federal, state or local law. Applicants with a disability, who require a reasonable accommodation for any part of the application or hiring process, may e-mail their request to acesstmt@bechtel.com