> Markdown version of [/jobs/ext/1471220-global-security-engineer-offensive-operations](https://www.wearedevelopers.com/jobs/ext/1471220-global-security-engineer-offensive-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Global Security Engineer Offensive Operations - **Company:** Crane Company - **Location:** Stamford, CT, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Active Directory, Software System Penetration Testing, Cloud Computing, Cyber Security, Computer Programming, Data Governance, Data Loss, Linux, Perl (Programming Language), Information Security Management, Data Intelligence, Python (Programming Language), Network Administration, Nmap, Windows PowerShell, Phishing, Ruby, Virtualization Technology, Software Vulnerability Management, Rust (Programming Language), Information Technology, Metasploit, Burpsuite, Golang - **Published:** July 28, 2026 - **Apply:** https://www.dice.com/job-detail/712f6cdf-241e-4ac2-ba48-247050a0c8d9 ## About the Role Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting the company's global information security program through exploitative testing for context-based risk analysis. The ideal candidate will possess proficiency in penetration testing methodologies and platforms, scripting and programming used for security testing, attacker tradecraft, and a strong understanding of system and network administration. Prior experience in offensive security is required., * Minimum 5 years of work experience in penetration testing & application security testing * Strong understanding of Linux and Windows administration * Experience in performing security assessments using common offensive security tools such as: Metasploit, NetExec, Impacket, Nmap, Burpsuite, Pretender, etc. * Knowledge of command-and-control technologies and overlay networking * Experience in crafting spear-phishing playbooks and initial access packages * Proficiency in PowerShell, Perl, Ruby, Python, Go, Rust, Java, or other language(s) to create penetration testing solutions * Foundational knowledge of, and experience with, administering enterprise-level Information Technology systems including networks, virtualization, cloud, operating systems, Active Directory, etc. * Experience with Attack Surface Management tools and processes * Ability to work both independently and as part of a small, distributed team * Experience in Breach/Attack simulations and tabletop exercises * Flexibility to work outside regularly scheduled/normal business hours as required * Commitment to security training and earning corresponding certifications * Highly motivated and self-directed * Excellent verbal and written communication skills * Passion for solving complex problems and a drive for continuous learning * Ability to prioritize, schedule and track to deadlines * Required: Degree in a related field or at least 5 years relevant professional experience * Desired: Technical professional security certification such as OSCP, GPEN, or similar * US Person as defined under EAR PART 772 AND ITAR 120.15 ## Description In this role, the successful candidate will collaborate closely with other Global Information Security team members, both in offensive operations and collaborative purple-team scenarios involving the SOC. This collaboration will involve testing the company's defenses, assisting in planning exercises, and guiding the overall approach to mitigating risk and addressing security gaps., * Perform security reviews of enterprise systems, applications, and networks in coordination with local technology and security teams to ensure effective application of security controls * Evaluate systems and security processes to identify vulnerabilities, misconfigurations, and exploitation vectors * Participate in and support vulnerability management processes * Manage projects, holding teams and team members accountable * Conduct production-safe exploitation of suspected software and hardware vulnerabilities to demonstrate business impact * Perform periodic network traffic analysis * Plan and develop penetration test methodologies, automations, and schedules * Create reports and remediation recommendations based on findings * Present findings and risks to both technical and non-technical audiences * Provide business and data intelligence to support threat analysis * Consume and triage cyber threat intelligence to provide current industry-related risk context * Collaborate with business and technology managers to improve data protection processes and procedures * Engage with vendors and third parties in security testing development and execution * Manage and review attack surface, assigning and delegating remediation actions to the Business * Participate effectively in data governance and risk compliance planning * Raise incidents involving potential data loss or threats to data * Report and provide metrics to support program objectives ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)