GE Aerospace logo
GE Aerospace

GE Aerospace is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law. GE Aerospace will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a drug screen (as applicable).

Director – Offensive Security

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 10,001+H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

12 days ago

Salary

$152K - $220K / year

Seniority

Lead

Bachelor Degree8 yrs expEnglish

Job Description

Director – Offensive Security

GE Aerospace

• This role leads a team that delivers traditional web application penetration testing, Defense-in-Depth assessments extending beyond the web layer, and Red Team engagements • Shape an automation-first and intelligence-driven offensive security program • Ensure offensive security services evolve from point-in-time testing toward a continuous assurance model • Hire, lead, coach, and retain an expert team; establish goals, role clarity, performance expectations, and development plans • Define and execute the offensive security strategy • Own end-to-end engagement delivery for web application penetration testing, Defense-in-Depth assessments, and Red Team operations • Manage vendor relationships supporting Red Team activities • Partner with vulnerability management, product security, engineering, and infrastructure teams to ensure findings are actionable, prioritized, tracked, and re-tested as appropriate • Define and maintain assessment methodologies, reporting standards, and measurable KPIs

Job Requirements

  • Bachelor’s degree from accredited university or college with minimum of 8 years of professional experience OR Associates degree with minimum of 11 years of professional experience OR High School Diploma with minimum of 13 years of professional experience
  • Minimum of 5 years of specific experience in offensive security, penetration testing, and/or Red Team operations
  • Demonstrated people leadership experience leading and developing technical teams (including performance management and talent development)
  • Demonstrated experience overseeing penetration testing services, including web application testing and broader multi-layer (Defense-in-Depth) assessments
  • Demonstrated experience leading Red Team engagements, including safe execution, stakeholder alignment, and high-quality reporting
  • Experience managing third-party vendors/consultants supporting security delivery

Benefits

  • Healthcare benefits include medical, dental, vision, and prescription drug coverage
  • Access to a Health Coach from GE Aerospace
  • Employee Assistance Program, providing 24/7 confidential assessment, counseling, and referral services
  • Retirement benefits include the GE Aerospace Retirement Savings Plan and a 401(k) savings plan with company matching contributions
  • Tuition assistance
  • Adoption assistance
  • Paid parental leave
  • Disability insurance
  • Life insurance
  • Paid time-off for vacation or illness

Related Categories

Related Job Pages

More Security Engineer Jobs

Sowelo Consulting sp. z o.o. sp. k. logo

Security Engineer

Sowelo Consulting sp. z o.o. sp. k.

IT Recruitment | RPO | Executive Search | Headhunting | On Time, On Target, On Budget

ContractRemoteTeam 11-50H1B No Sponsor

• Lead the deployment and configuration of BeyondTrust Endpoint Privilege Management (EPM) across the organization • Design, implement, and fine‑tune EPM policies, rules, and configurations for different user groups and environments • Work with Security / IAM / IT to plan and execute a phased rollout with early adopters, business teams, and then engineering • Collaborate with internal stakeholders to gather feedback on the rollout and adjust policies and settings accordingly • Create and maintain documentation which includes configuration guides, runbooks, deployment procedures, and best practices • Contribute to testing and validation of EPM policies to minimise user disruption while maintaining strong security controls • Identify opportunities to automate deployment, configuration, and ongoing management (e.g. via scripting in PowerShell, Bash, Python, etc.) • Monitor progress against agreed project timelines and milestones, escalating risks or blockers when needed • Work closely with the wider Identity & Access Management team to align EPM configuration with existing IAM standards and processes • Provide knowledge sharing and basic enablement to internal teams on how to work effectively with the new EPM solution

Poland
Full TimeRemoteTeam 201-500Since 1993H1B No Sponsor

• Participate in daily network, firewall, and operational support. • Ability to troubleshoot network issues and failures and follow best practices and troubleshooting methodology to quickly assess current situations, find solutions, and implement changes to correct and/or update network topologies to ensure stability and functionality. • Provide technical analysis of operational issues and remediations during troubleshooting efforts to ensure documentations and procedures are followed and updated during active events. This includes the ability to report to management. • Stay up to date on emerging technologies and products, including attaining certifications and participation in industry events as appropriate. • Work with various stake holders to lead problem solving, evolve system roadmap and take critical decisions. • Provide clear communication with regular updates/reports to the management team.

Florida
Full TimeRemoteTeam 201-500Since 1993H1B No Sponsor

• Participate in daily network, firewall, and operational support. • Ability to troubleshoot network issues and failures and follow best practices and troubleshooting methodology to quickly assess current situations, find solutions, and implement changes to correct and/or update network topologies to ensure stability and functionality. • Provide technical analysis of operational issues and remediations during troubleshooting efforts to ensure documentations and procedures are followed and updated during active events. This includes the ability to report to management. • Stay up to date on emerging technologies and products, including attaining certifications and participation in industry events as appropriate. • Work with various stake holders to lead problem solving, evolve system roadmap and take critical decisions. • Provide clear communication with regular updates/reports to the management team.

United States

Role Description Implements, maintains, and assesses security controls supporting enterprise and government systems in alignment with approved baselines, organizational requirements, and federal cybersecurity standards. Supports system authorization activities, including the development, maintenance, and delivery of System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), and related security documentation required for Authorization to Operate (ATO) approval. - Monitors system security posture, identifies risks, vulnerabilities, and compliance gaps, and coordinates remediation activities with system owners, technical teams, cybersecurity operations, and governance stakeholders. - Supports continuous monitoring, vulnerability management, configuration management, change management, audit preparation, and security reporting activities. - Assesses the security impact of system changes and ensures systems are prepared for security assessments, audits, and Authorizing Official reviews. - Serves as a cybersecurity liaison between system teams, cybersecurity operations, and governance bodies to support secure system operations, compliance, and delivery of System Security Plans to the Y-12 Field Office for Approval to Operate. This is a remote position. Qualifications - Five (5+) to ten (10+) years of experience in cybersecurity, information systems security, security control assessment, ISSO support, system authorization, or programs and contracts of similar scope, type, and complexity is required. - Firm understanding of NIST SP 800-37 and NIST SP 800-53. - Experience implementing, maintaining, and assessing security controls aligned with approved security baselines and organizational requirements. - Experience supporting system authorization activities, including preparation and maintenance of System Security Plans (SSPs), POA&Ms, and other ATO-related documentation. - Experience monitoring system security posture and identifying risks, vulnerabilities, compliance gaps, and remediation requirements. - Experience tracking and managing POA&Ms and coordinating remediation activities with system owners, technical stakeholders, and cybersecurity teams. - Experience supporting continuous monitoring activities, vulnerability management, security reporting, and audit readiness. - Experience assessing the security impact of system changes and supporting configuration and change management processes. - Experience preparing systems for security assessments, audits, and Authorizing Official reviews. - Ability to serve as a security liaison between system teams, cybersecurity operations, and governance bodies. - Experience working in secure government, DOE, or federal cybersecurity environments preferred. Education, Certifications, & Credentials - Associate’s, Bachelor’s, or Master’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related technical field preferred. - Technical field experience may be weighted greater than minimum education requirements. - No clearance is required for this position. This is a remote position. All duties and responsibilities may not be captured in this job description. To find out more, please reach out to the recruiter for this role.

Worldwide