Cyber SDC- Secure Design Pattern Analyst Consulting - Ernst & Youn
Listed on 2026-06-18
-
IT/Tech
Cybersecurity
Cyber SDC
- Secure Design Pattern Analyst
- Staff 2 - Consulting
- Location OPEN job at Ernst & Young. Dallas, TX.
In an ever‑evolving IT landscape, EY stands as a beacon of trust for clients across diverse industries seeking reliable solutions to address their intricate risks and vulnerabilities. As a vital member of our Secure Design Pattern team, you will play a vital role in achieving this objective by empowering clients to comprehend, navigate, and secure all applicable layers of business applications.
This is an opportunity to leverage both your technical prowess and business acumen to drive our mission and make a significant impact on global cybersecurity.
We currently offer an exciting career opportunity for a Secure Design Pattern Analyst responsible for establishing blueprints to standardize implementation of security controls across layers of business applications and architectures.
At our core, our Secure Design Pattern services play a pivotal role in assisting our clients to implement business applications securely and in line with industry best practices and client policies and standards. The ideal candidate will be responsible for documenting secure design patterns, interfacing with application owners, architects, and subject matter resources, as well as discuss and apply secure patterns, guidelines, and principles.
YourKey Responsibilities
- Create and maintain design patterns documentation and playbooks
- Coordinate and streamline the processes to create, update, manage, and control design patterns at clients.
- Engage with security architects, product owners, engineers, and subject matter resources to support new design patterns and updates to design patterns.
- Promote security best practices within discussions.
- Review and process design pattern service requests, ensuring timely resolution.
- Track and report the status of secure design pattern requests, provide regular updates on progress and outcomes.
- Proven experience writing technical documentation, standard operating procedures, policies, standards supporting the implementation of security controls and architecture patterns.
- Understanding and apply secure design concepts.
- Strong communication skills, with the ability to convey technical information in discussions and documentation.
- Knowledge of industry security frameworks and compliance standards and regulations (e.g., CMMC, NIST, ISO 27001, CIS, OWASP, TOGAF, SABSA, etc.)
- Familiarity with cloud security platforms (e.g., AWS, Azure) and cloud‑native security controls.
- Basic understanding of authentication (OAuth, SAML, OpenID), authorization (RBAC, ABAC), and Zero Trust
- Understanding of encryption algorithms, key management, digital signatures, and PKI.
- Familiarity with SIEM, SOAR, XDR, log management, and anomaly detection.
- Familiarity with secure coding practices, Dev Sec Ops , SAST/DAST tools, and software security design.
- Familiarity with firewalls, VPNs, TLS, micro‑segmentation, and intrusion detection.
- Excellent problem‑solving skills and the ability to manage multiple tasks effectively.
- Strong communication skills to collaborate with team members and stakeholders (e.g., business, information technology, product owners, cybersecurity).
- A track record of delivering high‑quality client services and work products within expected time frames.
- Ability to managing and maintain inventories of documentation
- Understanding of security principles
- Bachelor’s degree in computer science, information technology, cybersecurity, technical writing, or a related field
- Proven experience in technical writing
- Hands on experience managing or working on a security architecture and/or GRC team
- Basic knowledge of cloud platforms (AWS, Azure) and their security features
- Knowledge of common industry security frameworks and regulations (e.g., CMMC, NIST, ISO 27001, CIS, OWASP, etc.)
- Knowledge of general security concepts and methods, such as security policy creation, enterprise security strategies, architectures, governance, vulnerability assessments, privacy assessments, intrusion detection, and incident response
- Experience in leading process…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).