Jr. Pen Tester
Bechtel Corporation - Glendale, AZ
Hiring: Jr. Pen Tester Company: Bechtel Corporation Location: Glendale, AZ Job Posted Time: 2026-09-16 17:38:50 Employment Type: Full-time Target Skills & Keywords : AWS, Azure, Bash, DNS, Data Pipeline, Encryption, GCP, GitHub, IAM, IaC, JWT, Kubernetes, LLM, Linux, OAuth2, OIDC, OWASP, PKI, Penetration Testing, Python, REST, SAML, SBOM, TCP/IP About the job Required Skills: •Executes hands-on penetration tests of web applications, networks, cloud environments, and AI-based systems under the direction of senior penetration testers. •Supports the development and operation of the team's autonomous red-team agents; helps steer multi-agent campaigns and validates AI-generated findings against real-world exploitability. •Tests and validates the security controls that maintain the confidentiality, integrity, and availability of information systems. •Identifies and prioritizes threats to critical business assets and infrastructure, and provides stakeholders with practical recommendations to mitigate them. •Assists with security assessments across a range of issues including network traffic, firewalls, identity and directory services, and network access. •Triages scanner, tooling, and agent output; reproduces findings, evaluates exploitability and business impact, and documents clear reproduction steps. •Assists in converting test findings and requirements into end-to-end solutions that acknowledge technical, schedule, and cost constraints. •Helps align current security testing coverage with business requirements and emerging threats. Qualifications: •Exposure or vulnerability management exposure — hands-on time with enterprise vulnerability scanning, remediation tracking, or risk-based prioritization. •CNAPP / cloud posture tooling — experience with cloud security posture, CIEM, container/Kubernetes security, or IaC scanning tooling. •Attack surface management — external attack surface discovery, asset attribution, or shadow IT identification. •Asset & CMDB data — CMDB or ITSM platforms, asset reconciliation, or asset data quality work. •Third-party & supply-chain risk — vendor risk assessment, SBOM analysis, or dependency/component vulnerability management. •Integration & automation — building API integrations, data pipelines, or workflow automation across security tools. •Exploit development fundamentals — buffer overflows, use-after-free, format strings, ASLR/DEP, and memory management concepts sufficient to evaluate exploit validity. •Protocol depth — enterprise identity and directory attack surfaces, credential attacks, and Linux and Windows privilege escalation pathways. •Identity & access protocols — OAuth 2.0 / OIDC, SAML, JWT flows and common misconfigurations. •Cloud security assessment experience — IAM misconfigurations and privilege escalation paths across AWS/Azure/GCP. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!