At EY, we believe in empowering your career and helping you succeed in a globally connected powerhouse of diverse teams. Join us to help build a better working world.
The Opportunity
In this dynamic role, you will lead and execute penetration testing, red teaming, and security assessments for our clients. Collaborating closely with cross-functional teams, you will pinpoint vulnerabilities, develop effective mitigation strategies, and ensure adherence to industry security standards. Your expertise will be pivotal in automating security processes, contributing to a more secure operational environment for clients.
Your Key Responsibilities
- Lead and manage various penetration testing projects for web applications, networks, cloud environments, hardware, and firmware, utilizing black box, white box, and gray box assessments.
- Design and execute red team and purple team simulations to uncover weaknesses in security postures and offer actionable recommendations.
- Conduct thorough assessments, crafting comprehensive reports that outline findings, exploitation methods, associated risks, and detailed recommendations.
- Stay abreast of new security threats, vulnerabilities, and best practices, while fostering an atmosphere of continual learning within the team.
- Assist in configuring and maintaining penetration testing software and supporting infrastructure to ensure peak performance and security.
- Contribute to the development and updating of operational metrics for client meetings, sharing insights on tool efficacy and security findings.
Skills and Attributes for Success
Significant experience in penetration testing and offensive security, with at least 5 years in the field.Strong understanding of automation tools and processes related to offensive security and application security.Exceptional problem-solving skills, with the ability to manage multiple security projects concurrently.Outstanding communication skills to effectively interact with clients and internal stakeholders, simplifying complex technical concepts.To Qualify for the Role, You Must Have
A Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.A minimum of 3 years experience in incident response or conducting penetration tests, or at least 1 year in electric utilities focused on penetration testing.Hands-on experience with manual penetration testing, covering web applications, networks, and cloud environments.Proficiency in scripting languages such as Python, Bash, or PowerShell for automation tasks.Strong knowledge of major operating systems, including Windows, Linux, and Unix.Ideally, You’d Also Have
Relevant certifications such as CCSP, CSSLP, OSCP, OSWP, GPEN, GWAPT, OSCE, OSEE, GXPN, CISSP, or CISM.Active contributions to the security community, including research, public CVEs, bug bounty acknowledgments, or open-source project involvement.Strong analytical capability with the ability to interpret complex information clearly.A keen interest in keeping updated on the latest cybersecurity trends and a commitment to continuous learning.What We Look For
We seek passionate top performers grounded in cybersecurity principles, equipped with relevant certifications and experience. A proactive approach, the ability to foster high-performing teams, and adaptability to evolving threats are vital attributes we value.
What We Offer
Continuous learning opportunities to develop future-focused skills.Flexibility in how you make a meaningful impact.Transformative leadership with insights, coaching, and encouragement to excel in high-performing teams.A diverse and inclusive culture that celebrates individuality and empowers you to share your voice.Join us in a collaborative environment that encourages innovation and professional growth.
We offer a competitive compensation and benefits package where performance is recognized. The base salary for this role ranges from $61,200 to $100,500 in all US locations, with specific ranges for select regions. Total Rewards includes comprehensive medical and dental coverage, pension plans, 401(k), and generous paid time off.
Are you ready to shape your future with confidence? Apply today to be part of our team-driven, hybrid model!