Burns & McDonnell logo
Burns & McDonnellSecurity Engineer
Updated · Reviewed by the Dataford team

Burns & McDonnell Security Engineer interview questions & guide 2026

Every question Burns & McDonnell interviewers actually ask, the frameworks that win the room, and the language hiring managers respond to.

3 rounds · ≈ 3-5 weeks
1
Recruiter Outreach
2
Asynchronous Video Interview
3
Panel Interview

1. What is a Security Engineer at Burns & McDonnell?

As a Security Engineer at Burns & McDonnell, you play a vital role in safeguarding critical infrastructure, industrial control systems, and enterprise IT networks. Your daily efforts directly protect high-stakes environments—such as utilities, manufacturing facilities, transportation hubs, and government systems—from evolving cyber threats. Working across specialized engineering and consulting divisions, you bridge the gap between traditional Information Technology and Operational Technology, ensuring that vital systems remain resilient, compliant, and secure.

This position demands a unique blend of technical execution and strategic risk management. You will contribute to hands-on security assessments, network penetration testing, and vulnerability evaluations, while also helping clients navigate complex compliance frameworks like the NIST Cybersecurity Framework and Risk Management Framework. Because your work impacts critical infrastructure that society relies on every day, attention to detail and a commitment to data integrity are paramount.

Expect a fast-paced, collaborative environment where your technical recommendations influence real-world industrial operations. You will routinely partner with multidisciplinary teams, project managers, and client stakeholders to design secure architectures and resolve operational issues. Whether you are hardening servers and programmable logic controllers or developing comprehensive security policies, your work will drive measurable improvements in safety and security across the globe.

2. Common Interview Questions

The following questions are representative of those reported by past candidates during the Burns & McDonnell interview process for engineering and technical roles. While exact questions vary by hiring manager and team, these examples illustrate the core themes you should expect to encounter.

Behavioral & Background

  • Tell me something about yourself.
  • What are you looking for in a future employer?
  • What makes you stand out over your peers?
Preparing for a niche company?

Access the full Security Engineer prep plan

  • Every Security Engineer question, updated weekly
  • Model answers with full code walkthroughs
  • Recent, real interview reports
Get my prep plan
03 · Question bank

The questions most likely to come up

Sorted by relevance to this company
Push Back on Risky LaunchMedium
Describe a time you delayed or challenged a launch due to security risk and how you aligned stakeholders on the decision.
Launch PlanningTrade-offsRisk Assessment
Recently asked
Penetration Testing ToolsEasy
Tests practical penetration testing methodology and tool selection.
SearchingGraphs
Access the full Security Engineer prep plan
Everything you need to walk in ready.
Get my prep plan

3. Getting Ready for Your Interviews

Preparing for your interview with Burns & McDonnell requires a balanced focus on technical aptitude, professional background, and cultural alignment. Approach your preparation by reviewing fundamental security concepts while reflecting on how your personal values align with a collaborative, engineering-driven organization.

Role-related knowledge – This criterion evaluates your foundational understanding of cybersecurity principles, networking, vulnerability assessments, and compliance frameworks. Interviewers want to see that you understand how IT and Operational Technology intersect in critical infrastructure environments. Be ready to discuss specific security controls, firewalls, and hardening techniques clearly and accurately.

Problem-solving ability – Burns & McDonnell places a high value on critical thinking and qualitative problem-solving in high-pressure scenarios. You will be evaluated on how you approach ambiguous challenges, analyze technical bottlenecks, and propose practical solutions. Demonstrate this by walking interviewers through your structured thought process when resolving complex technical issues.

Culture fit and communication – Because the interview process heavily emphasizes interpersonal dynamics, you must communicate effectively and authentically. Interviewers look for professionals who demonstrate integrity, respect for workplace equality, and strong teamwork capabilities. Show that you can collaborate seamlessly with multidisciplinary engineering groups and client stakeholders alike.

4. Interview Process Overview

The interview journey at Burns & McDonnell is structured for efficiency and thoroughness, typically beginning with a recruiter outreach within a week of submitting your qualifications. For many technical roles, the process includes an asynchronous video interview where you record responses to a series of structured questions without a live interviewer present. This digital initial screen evaluates your background, communication style, and foundational qualifications before moving forward.

06 · The loop

The interview process, end to end

≈ 3-5 weeks · 3 rounds
1
Recruiter Outreach

Recruiter contacts candidates within a week of application submission.

2
Asynchronous Video Interview

Candidates record responses to structured questions to evaluate background and qualifications.

3
Panel Interview

Comprehensive interview with multiple team members and engineering managers to discuss technical capabilities.

Candidates who successfully navigate the initial screening phase advance to a comprehensive panel interview involving multiple team members and engineering managers. This multi-person stage allows you to interact directly with peers and leaders who understand the day-id-day demands of the role. Approach this stage prepared to discuss both your technical capabilities and your ideal workplace environment, keeping in mind that the organization values structured, professional interactions and strong cultural alignment.

5. Deep Dive into Evaluation Areas

Technical Competence & Security Fundamentals

This evaluation area assesses your core understanding of network security, system hardening, and vulnerability management. Interviewers look for your ability to apply security principles to both corporate IT and industrial control systems. Strong candidates demonstrate practical familiarity with configuration standards, risk frameworks, and security tools.

Be ready to go over:

  • Network security controls – Firewalls, access control lists, authentication mechanisms, and logging practices.
  • Vulnerability assessment and penetration testing – Methods for identifying system weaknesses and conducting secure evaluations.
  • Compliance frameworks – Familiarity with the NIST Cybersecurity Framework and Risk Management Framework.
  • Advanced concepts (less common) – Specific OT/ICS protocols, eMASS artifact management, and customized threat modeling for industrial environments.

Example questions or scenarios:

  • Describe your experience with vulnerability assessments on IT or operational networks.
  • How would you approach securing a programmable logic controller against unauthorized access?
  • What steps do you take when performing post-event analysis of an unusual network occurrence?

Communication & Professional Alignment

Burns & McDonnell evaluates your ability to articulate technical concepts to non-technical stakeholders and clients. Strong candidates demonstrate active listening, clear oral and written communication, and a collaborative mindset that supports multi-departmental initiatives.

Be ready to go over:

  • Stakeholder management – Communicating technical risks and business impacts to operational teams.
  • Documentation standards – Producing clear technical artifacts, dataflow diagrams, and compliance logs.
  • Team collaboration – Working effectively across diverse engineering groups to deliver integrated solutions.

Example questions or scenarios:

  • What are you looking for in a future employer and team environment?
  • How do you explain a complex security vulnerability to a project manager or client?
08 · Topic breakdown

What they actually test for

Weighting based on 3 reported loops
Topic distribution
All topics
Cybersecurity (Information Security)OT/ICS/SCADA CybersecurityNIST Cybersecurity Framework (CSF)NIST Risk Management Framework (RMF)Penetration Testing

6. Key Responsibilities

As a Security Engineer, your day-to-day work centers on securing critical infrastructure and industrial control systems against sophisticated cyber threats. You will actively assist with network penetration testing, web application security evaluations, and comprehensive cybersecurity vulnerability assessments. Your responsibilities include designing secure system architectures, implementing technical controls, and ensuring adherence to established government and industry compliance frameworks.

You will routinely collaborate with adjacent engineering teams, project managers, and external client stakeholders to integrate security measures seamlessly into ongoing projects. This involves hands-on implementation and hardening of servers, workstations, network switches, and programmable logic controllers. Additionally, you will draft critical technical artifacts, such as control listings, dataflow diagrams, and compliance documentation, ensuring that every project maintains the highest standard of confidentiality and integrity.

7. Role Requirements & Qualifications

Meeting the qualifications for this role requires a solid foundation in computer science, cybersecurity, or related engineering disciplines, paired with a practical understanding of industrial security. Burns & McDonnell seeks candidates who combine technical capability with the adaptability needed to operate in diverse on-site corporate and industrial environments.

  • Must-have skills – A Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, or Electrical Engineering (or equivalent experience); a fundamental understanding of cybersecurity principles and control systems; familiarity with vulnerability assessments and penetration testing; and effective written and oral communication skills.
  • Nice-to-have skills – Prior internship experience in industrial cybersecurity; active industry-recognized certifications such as ethical hacking or network engineering credentials; and familiarity with government accreditation systems like eMASS.
  • Soft skills – Strong critical thinking, the ability to operate under tight project deadlines, and a proven capacity to collaborate within multidisciplinary consulting and engineering teams.

8. Frequently Asked Questions

Q: How difficult is the interview process at Burns & McDonnell? While technical requirements are rigorous, candidates often note that the primary challenge lies in adapting to the structured video screening format. Preparing thoughtful, concise answers in advance will help you navigate the recorded video stage with confidence.

Q: What is the typical timeline from initial application to an offer? Recruiters typically reach out within about a week of application submission. The complete process moves efficiently through video screenings and panel interviews, usually concluding within a few weeks depending on team scheduling.

Q: Are remote work options available for this role? Work arrangements depend heavily on specific project requirements, client locations, and team assignments, with many roles involving a hybrid balance of office, remote, and on-site industrial visits.

Q: What differentiates successful candidates during the panel interviews? Successful candidates demonstrate a genuine passion for critical infrastructure protection, clear communication skills, and an authentic alignment with the company’s collaborative and integrity-driven culture.

Q: How should I prepare for the asynchronous video interview? Treat the recorded video session as a live conversation by maintaining good eye contact with your camera, structuring your answers clearly, and practicing responses to standard behavioral prompts beforehand.

9. Other General Tips

  • Familiarize yourself with frameworks: Brush up on your working knowledge of the NIST Cybersecurity Framework and Risk Management Framework, as these guide much of the consulting practice's methodology.
  • Practice structured storytelling: When answering behavioral or situational questions, use a clear framework to highlight your problem-solving process, actions taken, and the ultimate business impact.
  • Be comfortable with video formats: Because the initial interview stage involves recording responses independently, practice talking to a camera without an interviewer present to build your comfort level.
  • Highlight industrial awareness: If you have experience with Operational Technology or industrial control systems, make sure to spotlight it prominently to align with the core mission of critical infrastructure protection.
  • Showcase your collaborative spirit: Emphasize your ability to work across different engineering disciplines and communicate technical risks clearly to non-technical stakeholders.

10. Summary & Next Steps

Stepping into a Security Engineer role at Burns & McDonnell offers a unique opportunity to protect the world's critical infrastructure while building a rewarding engineering career. By focusing your preparation on core security principles, compliance frameworks, and structured behavioral communication, you can approach every stage of the interview with confidence. Remember that interviewers value both your technical acumen and your ability to collaborate seamlessly within multidisciplinary teams.

As you continue your preparation, you can explore additional interview insights, practice questions, and preparation resources on Dataford to refine your strategy and sharpen your skills. With focused effort and a clear understanding of the evaluation criteria, you can materially improve your interview performance and position yourself as a standout candidate. Take the initiative to review your technical fundamentals, practice your delivery, and step into your upcoming interviews ready to succeed.

14 · Compensation

What this role pays

6 reports
USUSD
Estimated total compLow confidence · 6 data points
$0k-$0k
Median $430k / year
Base salary · 100%Stock (RSU) · 0%Cash bonus · 0%
25thEntry / smaller markets
$340k
50thTypical offer
$430k
90thTop performers / major metros
$520k
Breakdown by component
Base salary
100% of total
$340k$520k
$430k
median
Stock (RSU)
0% of total
$0$0
$0
median
Cash bonus
0% of total
$0$0
$0
median
Aggregated from 6 self-reported salaries via Glassdoor. Estimates only. Verify against your offer.

The compensation data reflects competitive market rates for engineering professionals in this domain, varying by location, experience level, and specific technical specialization. Candidates should evaluate these ranges alongside comprehensive benefits packages when considering career opportunities. Understanding these compensation tiers helps you set realistic expectations and negotiate effectively during the final offer stage.

15 · Candidate reports

What candidates actually reported

Interview difficulty
Easy
33%
Medium
33%
Hard
33%
33% rated it easy, the most common response.
Candidate sentiment
67%positive
Positive 67%Neutral 33%
18 · FAQ

Burns & McDonnell Security Engineer interview FAQ

Answered from real candidate and compensation data
How hard is it to get an offer for a Security Engineer role at Burns & McDonnell?
Across 6 reported interviews for this role, candidates most commonly described the experience as difficult. The reported offer rate is 0% in the aggregated data you provided, so you should assume competition and prepare as if you need to be near the top of the bar.
What are the interview rounds for Burns & McDonnell Security Engineer, and how do they flow?
The process starts with a digital, one-way video interview where you answer pre-set questions without an interviewer present. If you pass, you move to a panel interview with 4 to 5 managers and senior engineers that combines behavioral questions with technical and role-specific knowledge.
What technical topics does Burns & McDonnell test for a Security Engineer focused on OT and ICS?
Expect OT and infrastructure security coverage, including differences between securing IT versus OT, how to approach vulnerability assessments on live SCADA networks, and defense-in-depth for environments like substation networks. The role is also strongly aligned to cybersecurity plus practical security engineering topics like firewalls, penetration testing, and vulnerability assessments.
How important are compliance frameworks like NIST CSF and RMF in Burns & McDonnell Security Engineer interviews?
Compliance is a recurring theme, with tested frameworks including the NIST Cybersecurity Framework and the Risk Management Framework. You may be asked to walk through the RMF process and discuss steps such as impact level determination and how you manage a POA&M.
What pay should I expect for a Burns & McDonnell Security Engineer role?
Candidate and job-posting reports in your data show a base pay range starting at $66,481, with total compensation reported up to $80,063. Pay varies by level and location, but you can anchor your expectations around those figures.
What should I prioritize when preparing for Burns & McDonnell Security Engineer interviews?
Prioritize OT/ICS domain knowledge, including SCADA and PLC-focused thinking, and be ready to explain how security principles differ in OT versus IT. Also prepare for consulting-style communication, since the role involves translating complex security risk for non-technical stakeholders and producing structured documentation like POA&Ms.