Jobs Companies Crane Company Global Security Engineer Offensive Operations (Remote or Onsite)

Über diese Global Security Engineer Offensive Operations (Remote or Onsite) Stelle bei Crane Company

Crane Company · Vor Ort · Stamford, Connecticut

Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting the company’s global information security program through exploitative testing for context-based risk analysis. The ideal candidate will possess proficiency in penetration testing methodologies and platforms, scripting and programming used for security testing, attacker tradecraft, and a strong understanding of system and network administration. Prior experience in offensive security is required.

In this role, the successful candidate will collaborate closely with other Global Information Security team members, both in offensive operations and collaborative purple-team scenarios involving the SOC. This collaboration will involve testing the company’s defenses, assisting in planning exercises, and guiding the overall approach to mitigating risk and addressing security gaps.

Responsibilities and Duties:

  • Perform security reviews of enterprise systems, applications, and networks in coordination with local technology and security teams to ensure effective application of security controls
  • Evaluate systems and security processes to identify vulnerabilities, misconfigurations, and exploitation vectors
  • Participate in and support vulnerability management processes
  • Manage projects, holding teams and team members accountable
  • Conduct production-safe exploitation of suspected software and hardware vulnerabilities to demonstrate business impact
  • Perform periodic network traffic analysis
  • Plan and develop penetration test methodologies, automations, and schedules
  • Create reports and remediation recommendations based on findings
  • Present findings and risks to both technical and non-technical audiences
  • Provide business and data intelligence to support threat analysis
  • Consume and triage cyber threat intelligence to provide current industry-related risk context
  • Collaborate with business and technology managers to improve data protection processes and procedures
  • Engage with vendors and third parties in security testing development and execution
  • Manage and review attack surface, assigning and delegating remediation actions to the Business
  • Participate effectively in data governance and risk compliance planning
  • Raise incidents involving potential data loss or threats to data
  • Report and provide metrics to support program objectives

Qualifications and Competencies:

  • Minimum 5 years of work experience in penetration testing & application security testing
  • Strong understanding of Linux and Windows administration
  • Experience in performing security assessments using common offensive security tools such as: Metasploit, NetExec, Impacket, Nmap, Burpsuite, Pretender, etc.
  • Knowledge of command-and-control technologies and overlay networking
  • Experience in crafting spear-phishing playbooks and initial access packages
  • Proficiency in PowerShell, Perl, Ruby, Python, Go, Rust, Java, or other language(s) to create penetration testing solutions
  • Foundational knowledge of, and experience with, administering enterprise-level Information Technology systems including networks, virtualization, cloud, operating systems, Active Directory, etc.
  • Experience with Attack Surface Management tools and processes
  • Ability to work both independently and as part of a small, distributed team
  • Experience in Breach/Attack simulations and tabletop exercises
  • Flexibility to work outside regularly scheduled/normal business hours as required
  • Commitment to security training and earning corresponding certifications
  • Highly motivated and self-directed
  • Excellent verbal and written communication skills
  • Passion for solving complex problems and a drive for continuous learning
  • Ability to prioritize, schedule and track to deadlines
  • Required: Degree in a related field or at least 5 years relevant professional experience
  • Desired: Technical professional security certification such as OSCP, GPEN, or similar
  • US Person as defined under EAR PART 772 AND ITAR 120.15

This description has been designed to indicate the general nature and level of work being performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.

Crane Company. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, gender, sexual orientation, general identity, national origin, disability or veteran status.

Bereit, sich bei Crane Company zu bewerben?
Bei Crane Company bewerben

Über Crane Company

The unique backgrounds and differences of our associates make us stronger, more capable, and more successful. Beyond an associate’s base compensation, we reward and reinforce wellbeing with a compelling package of both cash and non-cash benefits, including comprehensive health, wellness incentives, assistance with retirement savings, paid time off, paid holidays, and tuition reimbursement — as well as performance-based bonus programs for certain positions. Crane prioritizes career development for our associates. All associates receive an annual development plan that includes a mixture of on-the-job coaching and formal training experiences to support individual development needs. We firmly be

Alle Jobs bei Crane Company ansehen →

Ähnliche Jobs

GI
Cybersecurity Engineer
Grayscale Investments
⚡ Früh bewerben Stamford, Connecticut, United... Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
CC
Global Network Security Engineer (Remote)
Crane Company
⚡ Früh bewerben Stamford, Connecticut Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 5 Mon.
Accenture
Azure Cloud Security Engineer
Accenture
⚡ Früh bewerben Matosinhos, Broadway Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
Trend Micro
Security Engineer
Trend Micro
⚡ Früh bewerben Singapore Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
Hewlett Packard Enterprise
Pre-Sales Engineer, Cybersecurity
Hewlett Packard Enterprise
⚡ Früh bewerben All, Washington, United States... Vor Ort $146,000–$343,000
● Neu 👁 Gesehen ✓ Beworben vor 4 Std.
Gramian Consulting Group
Senior DevSecOps Engineer (Cloud Security / AI Platforms)
Gramian Consulting Group
⚡ Früh bewerben Poland · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 8 Std.
Epignosis
Security Engineer
Epignosis
⚡ Früh bewerben Athens, Attica, Greece Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 9 Std.
Neko Health
Information Security Engineer Lead
Neko Health
⚡ Früh bewerben Stockholm Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 9 Std.
HackerOne
Senior Security Engineer, Detection and Response
HackerOne
⚡ Früh bewerben London · standortgebunden £100,000–£110,000
● Neu 👁 Gesehen ✓ Beworben vor 9 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Crane Company

Alle Jobs bei Crane Company ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos