Crane Company is seeking an Information Security professional to join its Global Information Security Team. This role involves supporting the company’s global information security program through exploitative testing for context-based risk analysis. The ideal candidate will possess proficiency in penetration testing methodologies and platforms, scripting and programming used for security testing, attacker tradecraft, and a strong understanding of system and network administration. Prior experience in offensive security is required.In this role, the successful candidate will collaborate closely with other Global Information Security team members, both in offensive operations and collaborative purple-team scenarios involving the SOC. This collaboration will involve testing the company’s defenses, assisting in planning exercises, and guiding the overall approach to mitigating risk and addressing security gaps.Responsibilities and Duties:Perform security reviews of enterprise systems, applications, and networks in coordination with local technology and security teams to ensure effective application of security controlsEvaluate systems and security processes to identify vulnerabilities, misconfigurations, and exploitation vectorsParticipate in and support vulnerability management processesManage projects, holding teams and team members accountableConduct production-safe exploitation of suspected software and hardware vulnerabilities to demonstrate business impactPerform periodic network traffic analysisPlan and develop penetration test methodologies, automations, and schedulesCreate reports and remediation recommendations based on findingsPresent findings and risks to both technical and non-technical audiencesProvide business and data intelligence to support threat analysisConsume and triage cyber threat intelligence to provide current industry-related risk contextCollaborate with business and technology managers to improve data protection processes and proceduresEngage with vendors and third parties in security testing development and executionManage and review attack surface, assigning and delegating remediation actions to the BusinessParticipate effectively in data governance and risk compliance planningRaise incidents involving potential data loss or threats to dataReport and provide metrics to support program objectivesQualifications and Competencies: Minimum 5 years of work experience in penetration testing & application security testingStrong understanding of Linux and Windows administrationExperience in performing security assessments using common offensive security tools such as: Metasploit, NetExec, Impacket, Nmap, Burpsuite, Pretender, etc.Knowledge of command-and-control technologies and overlay networkingExperience in crafting spear-phishing playbooks and initial access packagesProficiency in PowerShell, Perl, Ruby, Python, Go, Rust, Java, or other language(s) to create penetration testing solutionsFoundational knowledge of, and experience with, administering enterprise-level Information Technology systems including networks, virtualization, cloud, operating systems, Active Directory, etc.Experience with Attack Surface Management tools and processesAbility to work both independently and as part of a small, distributed teamExperience in Breach/Attack simulations and tabletop exercisesFlexibility to work outside regularly scheduled/normal business hours as requiredCommitment to security training and earning corresponding certificationsHighly motivated and self-directedExcellent verbal and written communication skillsPassion for solving complex problems and a drive for continuous learningAbility to prioritize, schedule and track to deadlinesRequired: Degree in a related field or at least 5 years relevant professional experienceDesired: Technical professional security certification such as OSCP, GPEN, or similarUS Person as defined under EAR PART 772 AND ITAR 120.15This description has been designed to indicate the general nature and level of work being performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.Crane Company. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, gender, sexual orientation, general identity, national origin, disability or veteran status.SummaryLocation: Stamford, ConnecticutType: Full time