Bechtel Corporation

Cybersecurity Engineer Job Details | Bechtel

RemotePosted 3 days agoVisa Sponsorship

We tailor your resume to this role and apply for you in seconds.

Apply to Cybersecurity Engineer Job Details | Bechtel at Bechtel Corporation

Job details

Work type
Remote
Visa
Sponsorship available
Posted
3 days ago
Apply on
bechtel.jobs.hr.cloud.sap

About this role

Bechtel is a global company delivering projects across infrastructure, energy, environmental, mining, manufacturing, and technology markets. The Cybersecurity Engineer will perform hands-on penetration testing of web, network, cloud, and AI-based systems while supporting autonomous red-team agents, vulnerability validation, risk assessments, incident response, and security recommendations.

What you'll do:

  • Executes hands-on penetration tests of web applications, networks, cloud environments, and AI-based systems under the direction of senior penetration testers
  • Supports the development and operation of the team's autonomous red-team agents; helps steer multi-agent campaigns and validates AI-generated findings against real-world exploitability
  • Tests and validates the security controls that maintain the confidentiality, integrity, and availability of information systems
  • Identifies and prioritizes threats to critical business assets and infrastructure, and provides stakeholders with practical recommendations to mitigate them
  • Assists with security assessments across a range of issues including network traffic, firewalls, identity and directory services, and network access
  • Triages scanner, tooling, and agent output; reproduces findings, evaluates exploitability and business impact, and documents clear reproduction steps
  • Assists in converting test findings and requirements into end-to-end solutions that acknowledge technical, schedule, and cost constraints
  • Helps align current security testing coverage with business requirements and emerging threats
  • Supports risk assessments of applications and infrastructure and contributes findings-based recommendations to application and platform owners
  • Participates in computer incident response team efforts and supports the investigation of cybersecurity incidents
  • Researches current offensive security techniques, tooling, and threat actor tradecraft, and shares what is learned with the team

What they're looking for:

  • Typically requires a Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Electrical/Computer Engineering, or a closely related field and 5 + years of relevant experience OR equivalent demonstrated experience through CTF participation, bug bounty contributions, self-directed security education, or a relevant junior security role
  • 0–2 years of hands-on experience in cybersecurity, penetration testing, vulnerability or exposure management, security operations, or equivalent practical security training. University hires with strong self-directed learning portfolios (home lab, CTF write-ups, bug bounty reports, security projects on GitHub) are considered on par with formal experience. Equivalency is judged on demonstrated hands-on capability, not years of service — candidates with more years in adjacent technical disciplines qualify under the demonstrated-experience path
  • Network protocols — TCP/IP, DNS, HTTP/S, and common enterprise identity and directory protocols
  • Cryptography fundamentals — symmetric vs. asymmetric encryption, hashing, PKI, common weaknesses and misuse patterns
  • Web technologies — HTTP, cookies/sessions, authentication and session management fundamentals, OWASP Top 10 and the OWASP Testing Guide
  • Vulnerability assessment — triage scanner output, prioritize findings, and evaluate exploitability and business impact; familiarity with CVSS, and awareness of exploitability signals such as EPSS and CISA KEV
  • Cloud fundamentals — core compute, storage, identity, and networking concepts in at least one major cloud (AWS/Azure/GCP)
  • Operating systems — proficient Linux command line; Windows and Active Directory fundamentals
  • Scripting & integration — proficient in Python or Bash: writing automation, consuming REST APIs, processing scanner and log data, building small tooling; fluency grows with the platform work
  • Data literacy — comfort joining, deduplicating, and reasoning over findings and asset data from multiple sources
  • Hands-on exploitation capability — ability to manually exploit vulnerabilities in a controlled lab, not just run scanners and read output
  • Software systems literacy — comfort reading, extending, and debugging software systems that run automated discovery and testing: agent workflows, integrations, state, and failure modes

Benefits:

  • Full-Time Telework
Ready to apply to Bechtel Corporation?
ApplyBolt finds matching jobs, tailors your resume, and submits applications for you.

About Bechtel Corporation

Bechtel Corporation