Burns & McDonnell logo
Burns & McDonnellSecurity Analyst
Updated · Reviewed by the Dataford team

Burns & McDonnell Security Analyst interview questions & guide 2026

Every question Burns & McDonnell interviewers actually ask, the frameworks that win the room, and the language hiring managers respond to.

2 rounds · ≈ 2-4 weeks
1
Asynchronous Video Interview
2
Panel Interview

1. What is a Security Analyst at Burns & McDonnell?

The Security Analyst role at Burns & McDonnell—particularly within the 1898 & Co. practice—is a mission-driven position focused on protecting the world’s most vital infrastructure. You will work at the intersection of Information Technology (IT) and Operational Technology (OT), safeguarding systems that power our cities, energy grids, and transportation networks. This is not just a standard security role; it is an opportunity to solve complex, high-stakes problems that impact public safety and industrial reliability.

You will be expected to navigate the unique challenges of securing industrial control systems (ICS) and SCADA environments while maintaining compliance with rigorous frameworks like the NIST Cybersecurity Framework (CSF) and Risk Management Framework (RMF). Whether you are performing vulnerability assessments, designing secure system architectures, or assisting with federal accreditation packages, your work will directly influence the resiliency of critical infrastructure. Successful candidates are those who possess both technical rigor and the ability to communicate risk effectively to non-technical stakeholders.

2. Common Interview Questions

The following questions are representative of the patterns observed in recent Burns & McDonnell interview cycles. While specific technical questions will vary based on your focus area (e.g., GRC, automation, or industrial security), these categories reflect the core competencies the team evaluates.

Behavioral & Workplace Values

These questions assess your alignment with the company culture, your interpersonal style, and your ability to contribute to a collaborative, professional environment.

  • What does equality in the workplace mean to you?
  • What would be your ideal workplace environment?
Preparing for a niche company?

Access the full Security Analyst prep plan

  • Every Security Analyst question, updated weekly
  • Model answers with SQL and Python solutions
  • Recent, real interview reports
Get my prep plan

3. Getting Ready for Your Interviews

Preparation for Burns & McDonnell should be strategic. You are not just being measured on your technical knowledge; you are being evaluated on your ability to function as a consultant in a client-facing, high-stakes environment.

Role-Related Knowledge – You must demonstrate a solid grasp of NIST CSF, RMF, and the fundamental differences between IT and OT security. Be prepared to explain how you would apply these controls in an industrial setting, such as securing PLCs or managing firewall rules for critical systems.

Analytical & Critical Thinking – The nature of this work requires deep problem-solving skills. You will be evaluated on your ability to break down complex security issues, identify business implications, and propose practical, secure solutions under pressure.

Communication & Professionalism – Because you will interact with federal clients and operational departments, you must articulate technical concepts clearly. Your ability to document findings, such as POA&Ms or dataflow diagrams, is just as critical as your ability to identify the vulnerability in the first place.

4. Interview Process Overview

The interview process at Burns & McDonnell is designed to be rigorous and efficient. Candidates typically begin with an asynchronous, remote video interview. In this stage, you will record responses to a set of pre-determined questions. Following this, successful candidates move to a panel interview, which often consists of multiple stakeholders who represent the team you would be joining.

The process is structured to assess your technical aptitude and cultural fit early on. Because this firm operates in the critical infrastructure sector, they prioritize candidates who are reliable, detail-oriented, and capable of operating in both corporate and industrial site environments.

05 · The loop

The interview process, end to end

≈ 2-4 weeks · 2 rounds
1
Asynchronous Video Interview

Candidates record responses to a set of pre-determined questions remotely.

2
Panel Interview

Successful candidates participate in a panel interview with multiple stakeholders from the team.

This visual timeline illustrates the progression from the initial digital screening to the final panel interview. Use this to pace your preparation, ensuring you are ready to articulate your experience both in a recorded format and in a live, conversational setting.

5. Deep Dive into Evaluation Areas

Technical Competency & Compliance

You will be evaluated on your ability to apply security controls within specific regulatory environments. Strong performance involves demonstrating a working knowledge of NIST RMF and the ability to explain how technical artifacts support accreditation.

Be ready to go over:

  • Compliance Frameworks – Familiarity with NIST CSF and RMF.
  • System Hardening – Practical knowledge of securing workstations, servers, and PLCs.
Preparing for a niche company?

Access the full Security Analyst prep plan

  • Every Security Analyst question, updated weekly
  • Model answers with SQL and Python solutions
  • Recent, real interview reports
Get my prep plan
07 · Topic breakdown

What they actually test for

Topic distribution
All topics
OT/ICS SecurityInformation Security (General)Risk Management Framework (RMF)Penetration TestingNIST Cybersecurity Framework (CSF)

6. Key Responsibilities

As a Security Analyst, your day-to-day will involve a blend of technical assessment and project support. You will frequently assist in the planning and implementation of technical controls, ensuring that systems are not only secure but also compliant with federal or industry-specific regulations.

Collaboration is central to this role. You will work alongside engineers, project managers, and client-side operational teams to provide cybersecurity services. Whether you are uploading artifacts into government systems like eMASS, documenting dataflow diagrams, or assisting with post-event analysis of security incidents, your output must be precise and audit-ready. You are expected to maintain the highest level of integrity, as the work often involves sensitive client information and critical infrastructure data.

7. Role Requirements & Qualifications

To be competitive for this position, you need a balance of academic foundation and practical, hands-on experience.

  • Must-have skills
    • Bachelor’s degree in Cybersecurity, Computer Science, or a related engineering field.
    • Basic understanding of cybersecurity principles and technologies (firewalls, authentication, patching).
    • Strong written and oral communication skills.
    • Ability to work on-site in industrial, corporate, or government environments.
  • Nice-to-have skills
    • Internship experience in a security-focused role.
    • Industry-recognized certifications (e.g., ethical hacking, network engineering).
    • Familiarity with industrial control systems (ICS) or SCADA.

8. Frequently Asked Questions

Q: How long should I prepare for the interview? A: Dedicate at least one to two weeks to review your fundamental cybersecurity knowledge and practice articulating your technical experience. Given the panel format, ensure you are comfortable speaking about your past projects in detail.

Q: What is the most important trait for success here? A: Reliability and a commitment to detail are paramount. Because the work impacts critical infrastructure, the team looks for individuals who are thorough, analytical, and capable of maintaining security integrity under pressure.

Q: Is the remote video interview difficult? A: It can feel different than a standard phone screen because you are recording your answers alone. Treat it with the same level of professionalism as an in-person interview, ensuring your responses are concise and structured.

Q: What is the typical timeline for the process? A: While timelines can vary, the progression from the video interview to the panel stage is generally swift. Stay responsive to recruiter outreach to maintain momentum.

9. Other General Tips

  • Structure your answers: Use the STAR method (Situation, Task, Action, Result) to provide clear, concise answers during your recorded video interview.
  • Connect to the mission: Research 1898 & Co. and understand their focus on critical infrastructure; showing genuine interest in this sector will set you apart.
  • Be ready for the panel: When meeting with five or more interviewers, ensure you maintain eye contact and address the group as a whole while keeping your answers focused.
  • Know your resume: Be prepared to discuss any technical project on your resume in depth, specifically regarding the tools used and the security outcomes achieved.

10. Summary & Next Steps

The Security Analyst role at Burns & McDonnell offers a unique path to influence the reliability and safety of the world’s most critical infrastructure. By focusing on your core technical knowledge, demonstrating an understanding of security frameworks, and highlighting your analytical mindset, you will be well-positioned to succeed in the interview process. You can explore additional interview insights, practice questions, and preparation resources on Dataford.

13 · Compensation

What this role pays

6 reports
USUSD
Estimated total compLow confidence · 6 data points
$0k-$0k
Median $430k / year
Base salary · 100%Stock (RSU) · 0%Cash bonus · 0%
25thEntry / smaller markets
$340k
50thTypical offer
$430k
90thTop performers / major metros
$520k
Breakdown by component
Base salary
100% of total
$340k$520k
$430k
median
Stock (RSU)
0% of total
$0$0
$0
median
Cash bonus
0% of total
$0$0
$0
median
Aggregated from 6 self-reported salaries via Glassdoor. Estimates only. Verify against your offer.

The salary data provided reflects the compensation range for this position, which is commensurate with experience, technical certifications, and the specific requirements of the role. Candidates should interpret these figures as a market baseline for high-level security consulting roles within the firm. Compensation packages at this level often include base salary, potential performance bonuses, and benefits, reflecting the high value placed on specialized cybersecurity expertise.

16 · FAQ

Burns & McDonnell Security Analyst interview FAQ

Answered from real candidate and compensation data
How many rounds is the Burns & McDonnell Security Analyst interview process?
Candidates report 2 stages: Asynchronous Video Interview and Panel Interview. The interview process section above breaks down what each stage covers.
How much does a Security Analyst at Burns & McDonnell make?
Reported compensation for Security Analyst roles at Burns & McDonnell ranges from roughly $340k base to $520k total per year, varying by level, team, and location.
What topics come up in the Burns & McDonnell Security Analyst interview?
Burns & McDonnell Security Analyst interviews most often cover OT/ICS Security, Information Security (General), Risk Management Framework (RMF), Penetration Testing, and NIST Cybersecurity Framework (CSF), based on topics extracted from real candidate reports.