Jr. Pen Tester
Bechtel Corporation
Requisition ID: 298943 Relocation Authorized: None Telework Type: Full-Time Telework Work Location: Glendale, AZ Extraordinary teams building inspiring projects: Since 1898, we have helped customers complete more than 25,000 projects in 160 countries on all seven continents that have created jobs, grown economies, improved the resiliency of the world's infrastructure, increased access to energy, resources, and vital services, and made the world a safer, cleaner place. Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers' objectives to create a lasting positive impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals, and the Manufacturing and Technology markets. Our services span from initial planning and investment, through start-up and operations. Core to Bechtel is our Vision, Values and Commitments . They are what we believe, what customers can expect, and how we deliver. Learn more about our extraordinary teams building inspiring projects in our Impact Report . Project Overview: Bechtel is refreshing its Continuous Threat Exposure Management (CTEM) and internal penetration testing capability from first principles. The team builds the capability itself: an agentic CTEM platform that continuously discovers, contextualizes, prioritizes, validates, and drives remediation of exposure across the enterprise; an agentic red-teaming platform that orchestrates autonomous attacker agents at scale; and the human-led exploitation work that keeps both grounded in reality. The program is built agent-first. AI agents handle continuous discovery, correlation, enrichment, prioritization, and high-volume repeatable attack execution across the exposure surface. Our engineers do the complex, creative, context-dependent work machines cannot yet do — business logic flaws, chained vulnerabilities, social engineering, and novel attack paths — along with attacks on the AI systems we build and deploy that no legacy tooling covers: prompt injection, agent tool abuse, and MCP interface exploitation. Job Summary: This is a hands-on build-and-break role for someone early in their security career who thrives on figuring out how systems fail. Working under the direction of senior testers, you will find, validate, and exploit vulnerabilities in traditional and AI-based systems, and you will support the development and operation of the team's autonomous red-team agents — steering multi-agent campaigns and validating AI-generated findings against real-world exploitability. You will also perform the nuanced exploitation work AI is fundamentally bad at: business logic flaws, social engineering, chained vulnerabilities, and novel attack vectors. Standard toolkit: commercial and open-source offensive security tooling covering web application testing, network assessment, exploitation, and cloud security; CTEM-stack tooling spanning CNAPP, ASM, vulnerability management, CMDB and asset intelligence, and third-party risk; plus emerging agentic tooling and the team's own platforms. Prior tool familiarity is not required — the ability to learn new tooling quickly is what matters. Major Responsibilities: Executes hands-on penetration tests of web applications, networks, cloud environments, and AI-based systems under the direction of senior penetration testers. Supports the development and operation of the team's autonomous red-team agents; helps steer multi-agent campaigns and validates AI-generated findings against real-world exploitability. Tests and validates the security controls that maintain the confidentiality, integrity, and availability of information systems. Identifies and prioritizes threats to critical business assets and infrastructure, and provides stakeholders with practical recommendations to mitigate them. Assists with security assessments across a range of issues including network traffic, firewalls, identity and directory services, and network access. Triages scanner, tooling, and agent output; reproduces findings, evaluates exploitability and business impact, and documents clear reproduction steps. Assists in converting test findings and requirements into end-to-end solutions that acknowledge technical, schedule, and cost constraints. Helps align current security testing coverage with business requirements and emerging threats. Supports risk assessments of applications and infrastructure and contributes findings-based recommendations to application and platform owners. Participates in computer incident response team efforts and supports the investigation of cybersecurity incidents. Researches current offensive security techniques, tooling, and threat actor tradecraft, and shares what is learned with the team. Education and Experience Requirements: Typically requires a Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Electrical/Computer Engineering, or a closely related field and 5 + years of relevant experience OR equivalent demonstrated experience through CTF participation, bug bounty contributions, self-directed security education, or a relevant junior security role. 02 years of hands-on experience in cybersecurity, penetration testing, vulnerability or exposure management, security operations, or equivalent practical security training. University hires with strong self-directed learning portfolios (home lab, CTF write-ups, bug bounty reports, security projects on GitHub) are considered on par with formal experience. Equivalency is judged on demonstrated hands-on capability, not years of service — candidates with more years in adjacent technical disciplines qualify under the demonstrated-experience path. Required Knowledge and Skills: Core Skills Network protocols — TCP/IP, DNS, and common enterprise identity and directory protocols. Cryptography fundamentals — symmetric vs. asymmetric encryption, hashing, PKI, common weaknesses and misuse patterns. Web technologies — cookies/sessions, authentication and session management fundamentals, OWASP Top 10 and the OWASP Testing Guide. Vulnerability assessment — triage scanner output, prioritize findings, and evaluate exploitability and business impact; familiarity with CVSS, and awareness of exploitability signals such as EPSS and CISA KEV. Cloud fundamentals — core compute, storage, identity, and networking concepts in at least one major cloud (AWS/Azure/GCP). Operating systems — proficient Linux command line; Windows and Active Directory fundamentals. Scripting & integration — proficient in Python or Bash: writing automation, consuming REST APIs, processing scanner and log data, building small tooling; fluency grows with the platform work. Data literacy — comfort joining, deduplicating, and reasoning over findings and asset data from multiple sources. Essential skills Hands-on exploitation capability — ability to manually exploit vulnerabilities in a controlled lab, not just run scanners and read output. Software systems literacy — comfort reading, extending, and debugging software systems that run automated discovery and testing: agent workflows, integrations, state, and failure modes. Agentic tooling fluency — practical exposure to multi-agent orchestration: running a coding or security agent against a real task, chaining agents or tools, and recognizing where an orchestration breaks down. Critical evaluation of AI-generated content — ability to assess whether AI output (exploit code, vulnerability analysis, prioritization decisions, agent actions) is technically sound; spot when an agent misread evidence or over-claimed a finding; judge where a human has to stay in the loop. Adversarial thinking — demonstrated ability to approach systems from an attacker's perspective and identify attack paths not obvious from documentation. Clear technical writing — document findings, reproduce steps, and communicate risk to technical and non-technical audiences. Cross-team collaboration — ability to work findings to closure with infrastructure, cloud, application, and business-unit owners Learning agility — track record of self-directed learning in fast-evolving domains; comfort with ambiguity and new tools. Preferred Qualifications Exposure or vulnerability management exposure — hands-on time with enterprise vulnerability scanning, remediation tracking, or risk-based prioritization. CNAPP / cloud posture tooling — experience with cloud security posture, CIEM, container/Kubernetes security, or IaC scanning tooling. Attack surface management — external attack surface discovery, asset attribution, or shadow IT identification. Asset & CMDB data — CMDB or ITSM platforms, asset reconciliation, or asset data quality work. Third-party & supply-chain risk — vendor risk assessment, SBOM analysis, or dependency/component vulnerability management. Integration & automation — building API integrations, data pipelines, or workflow automation across security tools. Exploit development fundamentals — buffer overflows, use-after-free, format strings, ASLR/DEP, and memory management concepts sufficient to evaluate exploit validity. Protocol depth — enterprise identity and directory attack surfaces, credential attacks, and Linux and Windows privilege escalation pathways. Identity & access protocols — OAuth 2.0 / OIDC, SAML, JWT flows and common misconfigurations. Cloud security assessment experience — IAM misconfigurations and privilege escalation paths across AWS/Azure/GCP. Adversary simulation experience — participation in red or purple team exercises, or breach-and-attack-simulation tooling. CTF experience — HackTheBox, TryHackMe, PicoCTF, CTFtime-ranked competitions with demonstrated progression; write-ups showing independent problem-solving. Bug bounty contributions — valid submissions (HackerOne, Bugcrowd, Intigriti); preference for logic flaws, auth bypass, or novel techniques over scanner-found issues. Certifications (held or in active pursuit): eJPT, OSCP, CRTO, BSCP, CompTIA Security+, or a cloud security certification. AI-assisted security workflow experience — using LLMs for exploit development, analysis, or automation; building or operating agentic tooling (coding agents, multi-agent workflows, MCP servers) for offensive or defensive tasks. Cloud certification — AWS Cloud Practitioner, Azure Fundamentals, or equivalent. Home lab — personal environment for practicing exploitation, running CTF challenges, or experimenting with security tools. Open-source security contributions — security tooling, exploit development, or vulnerability research on GitHub. Total Rewards/Benefits: For decades, Bechtel has worked to inspire the next generation of employees and beyond! Because our teams face some of the world's toughest challenges, we offer robust benefits to ensure our people thrive. Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth. Learn more at Bechtel Total Rewards Diverse teams build the extraordinary: As a global company, Bechtel has long been home to a vibrant multitude of nationalities, cultures, ethnicities, and life experiences. This diversity has made us a more trusted partner, more effective problem solvers and innovators, and a more attractive destination for leading talent. Bechtel is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, disability, citizenship status (except as authorized by law), protected veteran status, genetic information, and any other characteristic protected by federal, state or local law. Applicants with a disability, who require a reasonable accommodation for any part of the application or hiring process, may e-mail their request to View email address on click.appcast.io #J-18808-Ljbffr Bechtel Corporation
$45 per hour
...Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies. We guarantee 15-25 hours per week with an hourly pay of between $25/hr. and $45/hr., depending on the In-Home Usage Test project....SuggestedHourly payWeekly payExtra incomeTemporary workPart timeFor contractorsSeasonal workRemote workWork from homeFlexible hours$25 - $45 per hour
...Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies. We guarantee 15-25 hours per week with an hourly pay of between $25/hr. and $45/hr., depending on the In-Home Usage Test project....SuggestedHourly payWeekly payExtra incomeTemporary workPart timeFor contractorsSeasonal workRemote workWork from homeFlexible hours- TekDoors Inc. in Scottsdale, AZ is seeking a detail-oriented Junior QA Tester with hands-on manual testing experience. You will work closely with developers, product managers, and senior QA engineers to ensure quality and reliability of our applications. The role emphasizes...Junior
$790 per week
Try products before they hit shelves — and get paid for your feedback. Focus Group Panel matches you with paid product tests and remote research from brands you already know. Active members earn up to $790 a week on the studies they qualify for. No experience needed....SuggestedFull timePart timeRemote work$25 - $45 per hour
GL Inc. is seeking In-Home Usage Testers to work from home nationwide in the United States, fulfilling contracts with national and international companies. The role offers 15-25 hours per week with pay ranging from $25/hr to $45/hr, based on the project. There is no upfront...SuggestedWeekly payFor contractorsRemote workWork from homeFlexible hours- OverviewThe Infosys Financial Services unit is a global leader in driving digital transformation for financial institutions. We specialize in leveraging advanced technologies such as AI, cloud, and data-led innovation to help our clients accelerate growth and unlock business...Full timeTemporary workRelocation
- na5-7 years of experience in Understanding and documenting data transformation, validation and reconciliation rules as necessaryShould have 5-7 years of overall experience in ETL testing Minimum of 3+ year of experience in testing data in a Datawarehouse environment Should...
- ...Mainframe Tester Client: Client/State of AZ Location: Phoenix, AZ - Remote Duration: Initial 6-month contract Role Description: Technical experience with Mainframe systems, Jobs, Schedules, JCL creation and execution Coordinate and assist testing...Contract workRemote work
- Company DescriptionSonsoft , Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled...Full timeH1b
- Job Title Experience customizing LoadRunner scripts which involves using C language or JavaScript for click and script protocol. Experience with SQL language and ability to do Performance improvement Experience with batch processing and relevant perf testing ...
$75k - $100k
Synergistic IT Job Opportunity Synergistic IT is an organization focusing on Java/J2EE domain and providing technically skilled and competent candidates to clients in Northern America and Canada since 2010. From staffing to full implementation of projects we provide...JuniorRelocation- Company DescriptionIDEALFORCE has multiple CONTRACT positions available immediately for Business Analysts to join our customer in Phoenix Arizona. This is an ONSITE position. Please find below additional details about this job. Client is considering only LOCAL CANDIDATES...Contract workWork at officeLocal areaImmediate start
- Company DescriptionIDEALFORCE has a CONTRACT position available immediately for a Quality Assurance Tester to join our customer in Phoenix Arizona. This is an ONSITE position. Please find below additional details about this job. Kindly respond with your most up to date...Contract workLocal areaImmediate start
- Company DescriptionIDEALFORCE have a Contract position available immediately for a QA Tester to join our customer in Phoenix,AZ. This is an ONSITE position. Please find below additional details about this job. Kindly respond with your most up to date resume if you would...Contract workWork at officeImmediate start
- Washington Elementary School District is seeking a Temporary Athletic Coach for Jr. High 7th Grade Boys Basketball in the Royal Palm area of Phoenix. This part-time, stipend-based role works under the principal and athletic director and requires organizing practices, games...JuniorTemporary workPart time
- Job Title: Tester Job ID: 2024-12888 Job Location: Phoenix, AZ (Onsite 3-5 times a week) Job Travel Location(s): # Positions: 3 Employment Type: W2 Duration:Long Term # of Layers: Work Eligibility: Key Technology:iOS, .NET, Testing Job Responsibilities: Will be testing...
- 5-10 years of experienceas Quality Assurance Engineer on a cloud-based Data warehousing platform. Highly proficient in SQL GCP cloud experience is preferred Proficiency in Test Automation using Jenkins. Banking/Financial Servicesexperience Experience in an Agile environment...
- Shift 2: Monday - Thursday: 2:00 pm - 12:30 am About Us: Silent-Aire, a division of Johnson Controls, is a global leader in owner equipment manufacturing (OEM) dedicated to providing custom solutions for data center customers. Our product line includes large-scale equipment...Work at officeLocal areaShift work
$500 per week
...assignment. Up to $500 per week. Location: Remote (USA) Company: ProductReviewJobs Thank you for your interest in becoming a Paid Product Tester. This opportunity is for completing market research opportunities with independent brands via online or phone. Online studies...Remote work- ...Wickenburg Ranch Golf Club , located in Wickenburg, AZ , is pleased to announce an excellent career opportunity for a Full-Time Jr. Sous Chef! We are seeking a driven individual who is eager to learn, contribute, and grow within a fast-paced hospitality-focused property...JuniorFull time
$400 per week
Type: Flexible, project-based Location: Remote (US) Pay: Earn up to $400/week, depending on the number and type of studies you complete. Share honest feedback on products and services from independent brands. Assignments include short online surveys ...Remote workFlexible hours- GCP QA TesterLocation: Preferred location: Phoenix, AZ. Can sit in: Walnut Creek, CA. Onsite: 3 days/week. Remote allowed if residing in: AZ, UT, MT, WY, Northern CA, or NV.Duration: 6 Months CTHInterview Type: VideoVisa Restrictions: NoneRequired Skills: 5-10 years of...Remote work3 days per week
- ...QA TesterIDEALFORCE have a Contract position available immediately for a QA Tester to join our customer in Phoenix, AZ. This is an ONSITE position. Please find below additional details about this job. Kindly respond with your most up to date resume if you would like to...Contract workWork at officeImmediate start
- Key Responsibilities • Provide input as required to the planning, requirements definition, and design process for new features, with an eye toward testability • Write manual tests scripts necessary to ensure the operation and correctness of new features ...
- QA TesterTech Tammina LLCJob DescriptionBachelor degree in business or technology-related field5+ years of QA experience analyzing system requirements, developing test cases, and performing manual and automated application testingComprehensive understanding and experience...Long term contractContract workH1b
- Junior Assistant Manager - Glendale, AZ Rainbow USA is recognized as one of the fastest growing junior, kids, plus, and petite, specialty apparel retail chains and has grown to over 1,000 retail stores! We have multiple retail lines that pride themselves...Junior
$50k - $55k
...Job Description Job Description Jr. Healthcare Recruiter – Entry Level Location: Phoenix, AZ (On-Site) Employment Type: Full-Time, W-2 (Base Salary of $50,000–$55,000 + Performance Bonus) | Benefits + 401(k) About the Role We're looking for an ambitious,...JuniorFull time- MINIMUM QUALIFICATIONS REQUIRED: High School diploma or GED Certificate. Bachelor's Degree in Electrical Engineering. 5 years' experience drafting, staking, surveying and design of overhead and underground electrical distribution systems, substations, and...JuniorFor contractors
- Direct message the job poster from Quantum World Technologies Inc. Responsibilities Managing cross functional delivery teams Proficient in API and UI automation tools Own the test initiative on technical aspects Perform requirement analysis and solution design Define strategies...Contract work
- ...Jr Business Analyst (32020) IDEALFORCE has a CONTRACT position available immediately for a Junior Business Analyst to join our customer in Phoenix Arizona. This is an ONSITE position. Please find below additional details about this job. Kindly respond with your most...JuniorContract workLocal areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Jr. Pen Tester. Be the first to apply!


