×
Register Here to Apply for Jobs or Post Jobs. X

Offensive Security Analyst

Job in Little Rock, Pulaski County, Arkansas, 72205, USA
Listing for: EY
Full Time position
Listed on 2026-06-27
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Data Security, Security Manager
Job Description & How to Apply Below
At EY, we're all in to shape your future with confidence.

We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.  Join EY and help to build a better working world.

Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets!

Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.

Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

** The opportunity*
* As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY's digital exposure through hands-on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY's global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses.

Your responsibilities will include supporting the validation of third-party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards applied across EY's digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk.

** Your key responsibilities*
* The Analyst will apply offensive security techniques to assess EY's external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof-of-concepts to validate exploitability and determine real-world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets.

The candidate will support third-party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams, and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks, and reporting standards within the Vulnerability Discovery and offensive security functions.

** Skills and attributes for success*
* + Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc.

+ Strong attention to detail with a methodical approach to identifying complex attack paths

+ Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context

+ Ability to manage high volumes of testing requests without compromising depth or quality

+ Flexibility to work across diverse technologies, including cloud, applications, and infrastructure

+ Effective communication skills to convey technical findings to both technical and non-technical audiences

+ Familiarity with research techniques and threat intelligence to support proactive risk identification

** To qualify for the role you must have*
* + A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security

+ Hands-on experience testing applications, APIs, cloud environments, and network infrastructure

+ Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques

+ Familiarity with offensive security methodologies and frameworks

+ Experience supporting or performing third-party risk assessments

+ Strong analytical and problem-solving skills with the ability to prioritize risks effectively

+ Strong communication and stakeholder management skills

** Ideally, you'll also have*
* + OWASP training

+ Incident response experience

** What we look for*
* We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business's externally-exposed vulnerabilities. We are seeking a seasoned analyst to improve the…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary