Bechtel Corporation
Cybersecurity Engineer Job Details | Bechtel
We tailor your resume to this role and apply for you in seconds.
Apply to Cybersecurity Engineer Job Details | Bechtel at Bechtel CorporationJob details
- Work type
- Remote
- Visa
- Sponsorship available
- Posted
- 3 days ago
- Apply on
- bechtel.jobs.hr.cloud.sap
About this role
Bechtel is a global company delivering projects across infrastructure, energy, environmental, mining, manufacturing, and technology markets. The Cybersecurity Engineer will perform hands-on penetration testing of web, network, cloud, and AI-based systems while supporting autonomous red-team agents, vulnerability validation, risk assessments, incident response, and security recommendations.
What you'll do:
- Executes hands-on penetration tests of web applications, networks, cloud environments, and AI-based systems under the direction of senior penetration testers
- Supports the development and operation of the team's autonomous red-team agents; helps steer multi-agent campaigns and validates AI-generated findings against real-world exploitability
- Tests and validates the security controls that maintain the confidentiality, integrity, and availability of information systems
- Identifies and prioritizes threats to critical business assets and infrastructure, and provides stakeholders with practical recommendations to mitigate them
- Assists with security assessments across a range of issues including network traffic, firewalls, identity and directory services, and network access
- Triages scanner, tooling, and agent output; reproduces findings, evaluates exploitability and business impact, and documents clear reproduction steps
- Assists in converting test findings and requirements into end-to-end solutions that acknowledge technical, schedule, and cost constraints
- Helps align current security testing coverage with business requirements and emerging threats
- Supports risk assessments of applications and infrastructure and contributes findings-based recommendations to application and platform owners
- Participates in computer incident response team efforts and supports the investigation of cybersecurity incidents
- Researches current offensive security techniques, tooling, and threat actor tradecraft, and shares what is learned with the team
What they're looking for:
- Typically requires a Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Electrical/Computer Engineering, or a closely related field and 5 + years of relevant experience OR equivalent demonstrated experience through CTF participation, bug bounty contributions, self-directed security education, or a relevant junior security role
- 0–2 years of hands-on experience in cybersecurity, penetration testing, vulnerability or exposure management, security operations, or equivalent practical security training. University hires with strong self-directed learning portfolios (home lab, CTF write-ups, bug bounty reports, security projects on GitHub) are considered on par with formal experience. Equivalency is judged on demonstrated hands-on capability, not years of service — candidates with more years in adjacent technical disciplines qualify under the demonstrated-experience path
- Network protocols — TCP/IP, DNS, HTTP/S, and common enterprise identity and directory protocols
- Cryptography fundamentals — symmetric vs. asymmetric encryption, hashing, PKI, common weaknesses and misuse patterns
- Web technologies — HTTP, cookies/sessions, authentication and session management fundamentals, OWASP Top 10 and the OWASP Testing Guide
- Vulnerability assessment — triage scanner output, prioritize findings, and evaluate exploitability and business impact; familiarity with CVSS, and awareness of exploitability signals such as EPSS and CISA KEV
- Cloud fundamentals — core compute, storage, identity, and networking concepts in at least one major cloud (AWS/Azure/GCP)
- Operating systems — proficient Linux command line; Windows and Active Directory fundamentals
- Scripting & integration — proficient in Python or Bash: writing automation, consuming REST APIs, processing scanner and log data, building small tooling; fluency grows with the platform work
- Data literacy — comfort joining, deduplicating, and reasoning over findings and asset data from multiple sources
- Hands-on exploitation capability — ability to manually exploit vulnerabilities in a controlled lab, not just run scanners and read output
- Software systems literacy — comfort reading, extending, and debugging software systems that run automated discovery and testing: agent workflows, integrations, state, and failure modes
Benefits:
- Full-Time Telework
Ready to apply to Bechtel Corporation?
ApplyBolt finds matching jobs, tailors your resume, and submits applications for you.