Назад
Company hidden
7 часов назад

Global Security Engineer Offensive Operations (Cybersecurity)

Формат работы
remote (только USA)/onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Global Security Engineer Offensive Operations (Cybersecurity): Conducting penetration tests and production-safe exploitation across enterprise systems, applications, networks, and hardware with an accent on vulnerability discovery, attack surface management, and purple-team collaboration. Focus on developing offensive security automations, analyzing network traffic and threat intelligence, and presenting remediation recommendations to technical and non-technical stakeholders.

Location: Stamford, Connecticut; remote or onsite options available. US Person status as defined under EAR Part 772 and ITAR 120.15 is required.

Company

Crane Aerospace & Electronics develops aerospace and electronic systems and operates a global information security program.

What you will do

  • Conduct security reviews and penetration tests across enterprise systems, applications, networks, and hardware.
  • Identify vulnerabilities, misconfigurations, exploitation vectors, and business impact while maintaining production safety.
  • Plan penetration-testing methodologies, automations, schedules, breach simulations, and purple-team exercises with the SOC.
  • Analyze network traffic and cyber threat intelligence to support risk and threat analysis.
  • Create reports, metrics, and remediation recommendations, and present findings to technical and non-technical audiences.
  • Manage attack-surface reviews, coordinate remediation actions, and collaborate with technology teams, business managers, vendors, and third parties.

Requirements

  • US Person status under EAR Part 772 and ITAR 120.15.
  • At least five years of penetration testing and application security testing experience, or a related degree with equivalent relevant experience.
  • Strong Linux and Windows administration skills, including enterprise networks, virtualization, cloud systems, operating systems, and Active Directory.
  • Experience with offensive security tools such as Metasploit, NetExec, Impacket, Nmap, Burp Suite, and Pretender.
  • Knowledge of command-and-control technologies, overlay networking, spear-phishing playbooks, initial access packages, and attack surface management.
  • Programming or scripting proficiency in PowerShell, Perl, Ruby, Python, Go, Rust, Java, or comparable languages.

Nice to have

  • OSCP, GPEN, or a similar technical security certification.
  • Experience with breach and attack simulations and tabletop exercises.

Culture & Benefits

  • Collaborative work with a small, distributed global information security team.
  • Flexibility to work independently and outside normal business hours when required.
  • Ongoing security training and support for earning relevant certifications.
  • Full-time employee position.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →