Global Security Engineer Offensive Operations (Remote or Onsite)

102 Crane Company

Stamford (CT)

Remote

USD 120,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Crane Company is seeking an Information Security professional to join its Global Information Security Team. The role focuses on exploitative testing to inform risk analysis, with expertise in offensive security, scripting, and security tooling.

Collaboration across the SOC and purple-team exercises will be essential to mitigate risks and address security gaps. Responsibilities include security reviews, vulnerability assessment, testing methodologies, and reporting, with a strong emphasis on

Qualifications

  • Minimum 5 years of work experience in penetration testing & application security testing.
  • Strong understanding of Linux and Windows administration.
  • Experience with offensive security tooling (Metasploit, Nmap, Burp Suite, etc.).
  • Knowledge of attack surface management and threat intelligence is a plus.

Responsibilities

  • Perform security reviews of enterprise systems, applications, and networks in coordination with local teams.
  • Evaluate systems to identify vulnerabilities, misconfigurations, and exploitation vectors.
  • Participate in vulnerability management processes and remediation planning.
  • Create reports and remediation recommendations based on findings.
  • Present findings to technical and non-technical audiences.
  • Collaborate with vendors and third parties in testing development and execution.

Skills

Penetration testing
Linux administration
Windows administration
Scripting languages
Threat analysis
Communication
Project management

Education

Degree in related field or 5 years experience
OSCP/GPEN or similar certification (desirable)

Tools

Metasploit
Nmap
Burp Suite
Impacket
Burp Suite
Pretender

Job description

Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting the company’s global information security program through exploitative testing for context-based risk analysis. The ideal candidate will possess proficiency in penetration testing methodologies and platforms, scripting and programming used for security testing, attacker tradecraft, and a strong understanding of system and network administration. Prior experience in offensive security is required. In this role, the successful candidate will collaborate closely with other Global Information Security team members, both in offensive operations and collaborative purple-team scenarios involving the SOC. This collaboration will involve testing the company’s defenses, assisting in planning exercises, and guiding the overall approach to mitigating risk and addressing security gaps.

Responsibilities and Duties
  • Perform security reviews of enterprise systems, applications, and networks in coordination with local technology and security teams to ensure effective application of security controls
  • Evaluate systems and security processes to identify vulnerabilities, misconfigurations, and exploitation vectors
  • Participate in and support vulnerability management processes
  • Manage projects, holding teams and team members accountable
  • Conduct production-safe exploitation of suspected software and hardware vulnerabilities to demonstrate business impact
  • Perform periodic network traffic analysis
  • Plan and develop penetration test methodologies, automations, and schedules
  • Create reports and remediation recommendations based on findings
  • Present findings and risks to both technical and non-technical audiences
  • Provide business and data intelligence to support threat analysis
  • Consume and triage cyber threat intelligence to provide current industry-related risk context
  • Collaborate with business and technology managers to improve data protection processes and procedures
  • Engage with vendors and third parties in security testing development and execution
  • Manage and review attack surface, assigning and delegating remediation actions to the Business
  • Participate effectively in data governance and risk compliance planning
  • Raise incidents involving potential data loss or threats to data
  • Report and provide metrics to support program objectives
Qualifications and Competencies
  • Minimum 5 years of work experience in penetration testing & application security testing
  • Strong understanding of Linux and Windows administration
  • Experience in performing security assessments using common offensive security tools such as: Metasploit, NetExec, Impacket, Nmap, Burpsuite, Pretender, etc.
  • Knowledge of command-and-control technologies and overlay networking
  • Experience in crafting spear-phishing playbooks and initial access packages
  • Proficiency in PowerShell, Perl, Ruby, Python, Go, Rust, Java, or other language(s) to create penetration testing solutions
  • Foundational knowledge of, and experience with, administering enterprise-level Information Technology systems including networks, virtualization, cloud, operating systems, Active Directory, etc.
  • Experience with Attack Surface Management tools and processes
  • Ability to work both independently and as part of a small, distributed team
  • Experience in Breach/Attack simulations and tabletop exercises
  • Flexibility to work outside regularly scheduled/normal business hours as required
  • Commitment to security training and earning corresponding certifications
  • Highly motivated and self-directed
  • Excellent verbal and written communication skills
  • Passion for solving complex problems and a drive for continuous learning
  • Ability to prioritize, schedule and track to deadlines
Requirements
  • Degree in a related field or at least 5 years relevant professional experience
  • Desired: Technical professional security certification such as OSCP, GPEN, or similar; US Person as defined under EAR PART 772 AND ITAR 120.15

Crane Company. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, gender, sexual orientation, general identity, national origin, disability or veteran status.

At Crane, we believe that attracting and retaining the highest quality people is the best insurance of success. Our goal is to recruit talented people and train them within a culture that calls for performance with trust and respect.

Join us. The unique backgrounds and differences of our associates make us stronger, more capable, and more successful.

Beyond an associate's base compensation, we reward and reinforce wellbeing with a compelling package of both cash and non-cash benefits, including comprehensive health, wellness incentives, assistance with retirement savings, paid time off, paid holidays, and tuition reimbursement - as well as performance-based bonus programs for certain positions.

Crane prioritizes career development for our associates. All associates receive an annual development plan that includes a mixture of on-the-job coaching and formal training experiences to support individual development needs. We firmly believe in associate growth that supports career progression and we will proactively support your ongoing career development.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Lead (Remote or Onsite)
SOC Lead (Remote or Onsite)

102 Crane Company • Stamford (CT)

Remote
USD 140,000 - 180,000
Sr SOC and IR Manager (Remote or On Site)
Sr SOC and IR Manager (Remote or On Site)

102 Crane Company • Stamford (CT)

Remote
USD 140,000 - 180,000
Comprehensive health
Wellness incentives
Retirement savings
+4
Global Network Security Engineer (Remote)
Global Network Security Engineer (Remote)

102 Crane Company • Stamford (CT)

Hybrid
USD 130,000 - 180,000
Global Offensive Security Engineer
Global Offensive Security Engineer

102 Crane Company • Stamford (CT)

Remote
USD 120,000 - 180,000
SOC Lead (Remote or Onsite)
SOC Lead (Remote or Onsite)

Crane Company • Stamford (CT)

On-site
USD 90,000 - 130,000
IT Site Operations Lead
IT Site Operations Lead

744 Crane ChemPharma & Energy Corp • Cincinnati (OH)

On-site
USD 110,000 - 150,000
Global Network Security Engineer (Remote)
Global Network Security Engineer (Remote)

Crane Company • Stamford (CT)

On-site
USD 90,000 - 120,000
Global Security Intelligence Manager
Global Security Intelligence Manager

Crane Worldwide Logistics LLC • Houston (TX), Northern (KY)

On-site
USD 120,000 - 190,000
Quarterly Incentive Plan
Paid Time Off (17 days)
Excellent Medical, Dental and Vision
+5
Export and Industrial Security Compliance Manager
Export and Industrial Security Compliance Manager

Crane Co. • Fort Walton Beach (FL), Northern (KY)

Hybrid
USD 95,000 - 135,000
Health care
401k retirement plan
Education reimbursement
+1
Global Security Operations Center Analyst (Physical Security)
Global Security Operations Center Analyst (Physical Security)

Crane Worldwide Logistics • Houston (TX)

On-site
USD 65,000 - 95,000
Quarterly Incentive Plan
Paid Time Off (PT0)
Medical, Dental and Vision benefits
+5