Full-Time

Offensive Security Engineer

Central Hudson

Central Hudson

1-10 employees

Utility energy savings platform with marketplace

Compensation Overview

$73k - $171.3k/yr

Company Does Not Provide H1B Sponsorship

Poughkeepsie, NY, USA

In Person

Bachelor's, Associate's

Category
Cybersecurity (1)
Required Skills
PowerShell
Bash
Python
Microsoft Windows
Threat modeling
Cybersecurity
C#
Penetration Testing
Linux/Unix

Get referred to Central Hudson

See people who can refer or advise you

Requirements
  • A bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field of study is required. In lieu of a bachelor's degree, an associate degree in the aforementioned fields and 3 years of information security engineering or related experience, or a high school diploma or equivalency degree and 5 years of information security engineering or related experience, will be considered.
  • Strong knowledge of network, application, and cloud security, including Windows and Linux operating systems.
  • Working knowledge of common offensive-security tools, including Metasploit, Cobalt Strike or equivalent tools, Burp Suite, Nmap, BloodHound, and CrackMapExec.
  • Knowledge of vulnerability-remediation testing and validating the effectiveness of security controls.
  • Demonstrated experience collaborating closely with Security Operations Center or Blue Team functions to improve detection and incident-response maturity.
  • Ability to develop scripts or tools using Python, PowerShell, Bash, or C#.
  • Solid understanding of security operations and detection technologies, including Security Information and Event Management, Endpoint Detection and Response, Intrusion Detection and Prevention Systems, and endpoint protection, to support adversary-emulation and purple-team activities.
  • Familiarity with industry security frameworks and methodologies, including MITRE ATT&CK, NIST 800-61 Incident Response, and SANS or CIS Critical Security Controls.
  • Strong analytical and problem-solving skills with the ability to assess complex security issues.
  • Excellent written and verbal communication skills, including the ability to document findings clearly and communicate risk to technical and non-technical audiences.
  • Ability to work independently with minimal supervision and respond professionally to constructive feedback.
  • Ability to work nights, weekends, and holidays during a critical cyber incident or event.
  • Valid driver's license.
Responsibilities
  • Conduct targeted offensive testing activities in support of threat emulation and detection validation across networks, applications, cloud environments, and endpoints.
  • Execute intelligence-driven threat-emulation exercises that replicate real-world adversaries, campaigns, and tactics, techniques, and procedures.
  • Perform vulnerability-remediation testing to validate the effectiveness of fixes and compensating controls.
  • Map emulated activity to MITRE ATT&CK techniques and track detection coverage and gaps.
  • Develop and maintain custom tools, scripts, and payloads to support testing activities.
  • Safely exercise adversary techniques to evaluate the effectiveness of security controls and detections.
  • Partner with Blue Team, Security Operations Center, and engineering teams to test detection and response capabilities.
  • Implement, maintain, and enhance red-team tooling and infrastructure to support penetration testing, adversary emulation, and purple-team exercises.
  • Lead and execute purple-team exercises in close coordination with the Security Operations Center and Blue Team, sharing findings, techniques, and actionable recommendations to strengthen detection, response, and recovery capabilities.
  • Assist in tuning and validating security controls, alerts, analytics, and incident-response playbooks based on threat-emulation outcomes.
  • Validate security detections across Security Information and Event Management, Endpoint Detection and Response, identity, and cloud platforms using repeatable and measurable testing scenarios.
  • Produce clear, actionable reports detailing emulated adversary behavior, detection gaps, response gaps, and prioritized remediation guidance.
  • Present results to technical teams and leadership, translating technical risk into business terms.
  • Track remediation progress and retest identified issues.
  • Stay current on emerging threats, adversary techniques, and offensive-security tooling.
  • Contribute to the development of red-team methodologies, frameworks, and documentation.
  • Support threat-intelligence-driven testing aligned with real-world attack trends.
  • Consume and operationalize threat intelligence to inform adversary selection, scenario design, and testing priorities.
  • Educate others about the importance of cybersecurity.
  • Build relationships with government and local agencies to promote collaborative information sharing.
  • Stay updated with the latest cybersecurity trends, threats, and technologies.
  • Participate in on-call coverage as needed to respond to security incidents outside regular working hours.
  • Provide support for storm-restoration efforts.
Desired Qualifications
  • At least 3 years of hands-on experience performing offensive security activities such as penetration testing, detection validation, adversary emulation, red teaming, or exploitation of applications, networks, and cloud environments.
  • Familiarity with evaluating security controls and risk exposure through an attacker’s lens, including validation of compensating controls and secure design assumptions.
  • Experience identifying security weaknesses through threat modeling, attack simulations, and exploitation, with the ability to translate findings into actionable remediation guidance.
  • Experience in the Energy and Utilities or services industry.
  • Relevant certifications such as Certified Information Systems Security Professional, Certified Ethical Hacker, GIAC Penetration Tester, GIAC Certified Incident Handler, Offensive Security Certified Professional, Offensive Security Web Expert, or similar offensive-security-focused credentials.

Central Hudson offers Savingscentral to help residential and business customers manage and reduce energy use to lower bills. It provides energy-use insights, goal setting, and progress tracking, plus a Clean Energy Marketplace to compare and subscribe to projects like community solar. The platform also runs incentive programs such as Peak Perks and Custom Savings that reward reduced consumption, especially at peak times. By combining efficiency tools, clean-energy options, and incentives, Savingscentral aims to help customers save money, promote energy efficiency, and reduce grid load.

Company Size

1-10

Company Stage

N/A

Total Funding

N/A

Headquarters

Poughkeepsie, New York

Founded

N/A

Get referred to Central Hudson

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 2026 added a $200,000 Dutchess Community College clean-energy workforce grant.
  • February 2026 expanded the Home Energy Program, strengthening customer engagement and retention.
  • Peak Perks and EV ChargeSmart paid incentives in 2026 for off-peak usage reduction.

What critics are saying

  • July 2026 storms cut power to 57,000 customers, exposing fragile reliability and hardening costs.
  • February 2026 billing-system lawsuit dismissal followed years of customer trust damage and remediation spending.
  • July 1, 2026 rate hikes raised delivery charges; 2027 increases keep pushing bills higher.

What makes Central Hudson unique

  • Central Hudson bundles delivery, rebates, and Peak Perks load-control programs for customers.
  • Savingscentral-style tools let customers track usage, join community solar, and compare savings terms.
  • Fortis-backed Central Hudson serves 315,000 electric and 90,000 gas customers across eight counties.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

401(k) Retirement Plan

401(k) Company Match

Tuition Assistance

Wellness Program

Paid Holidays

Paid Vacation

Company News

Hudson Valley Press
Feb 15th, 2023
Central Hudson Ousts Charles Freni as President

On Monday, the Board of Directors of Central Hudson Gas & Electric Corporation has appointed Christopher M. Capone as the company’s new President and Chief Executive Officer.

Charter Communications
Dec 1st, 2021
Savingscentral expanded facilities to Ulster County, New York, United States on Dec 1st 21'.

Central Hudson is building a training and distribution facility in Ulster County that's received approval from the town of Ulster and state Department of Conservation (DEC).

Hudson Valley 360
Feb 22nd, 2021
Savingscentral receives award Emergency Response Award

Central Hudson Gas & Electric Corp. received the Edison Electric Institute’s (EEI) Emergency Response Award for its outstanding storm recovery performance following Tropical Storm Isaias.

Hudson Valley 360
Jan 4th, 2021
Savingscentral launches Back to Business Funding program

Central Hudson also introduced the Back to Business Funding program, committing up to $1 million in grants to help pay down new working capital loans taken with participating local banks.

Daily Energy Insider
Nov 12th, 2020
Savingscentral is developing weather forecasting tool

Orange & Rockland Utilities (O&R) and Central Hudson Gas & Electric (CHGE) are developing a new weather forecasting tool that will provide real-time predictions on storm outages, among other functions.