Cyber SDC - WAM Penetration Tester - Senior
Listed on 2026-02-07
-
IT/Tech
Cybersecurity -
Engineering
Cybersecurity
Overview
Location:
Anywhere in Country
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Title:
Cybersecurity – Attack and Penetration Tester
The Opportunity
Our security professionals possess diverse industry knowledge, along with unique technical expertise and specialized skills. The team works together in planning, pursuing, delivering and managing engagements to assess, improve, build, and in some cases operate integrated security operations for our clients. You will belong to an international team of cybersecurity specialists helping our clients with their most complex information security needs and contributing toward their business resilience.
You will be working with our Advanced Security Centers to access the most sophisticated tools available to fight against cybercrime.
We will support you with career-long training and coaching to develop your skills. As EY is a global leading service provider in this space, you will be working with the best of the best in a collaborative environment. So, whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.
Your Key Responsibilities
- As part of our Penetration Testing team, identify potential threats and vulnerabilities to operational environments. Projects here could include penetration testing and simulating physical breaches to identify vulnerabilities.
- Identify vulnerabilities through penetration testing across web applications, APIs, and other targets; perform in-depth analysis of results and prepare reports describing findings, exploitation procedures, risks and recommendations.
- Contribute to planning, pursuit, delivery and management of engagements to assess, improve, build, and in some cases operate integrated security operations for our clients.
- Research and discover the newest security vulnerabilities; participate in conferences and share knowledge on cybersecurity topics with key industry groups.
- Provide technical leadership and advise junior team members on attack and penetration test engagements
- Convey complex technical security concepts to both technical and non-technical audiences including executives
To Qualify for the Role, You Must Have
- A bachelor’s degree and at least 5+ years of related work experience
- Experience with manual attack and penetration testing
- Experience with scripting / programming skills (eg, Bash, Python, Power Shell, Java, Perl, Rust, Golang, J2EE, .NET, JavaScript, etc)
- Updated and familiarized with the latest exploits and security trends
- Any two of the following certifications: OSCP, OSWP, OSEP, OSCE, OSEE, GPEN, GWAPT, GMOB, GCPN, GXPN, GRTP, GDAT, CRTO, CRTP, CRTE, CREST CRT, CCSAS, CWEE, Burp Suite Certified Practitioner, CBBH, eWPTX, OSWA, eWPT, eMAPT
Ideally, you ll also have
- A bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Information Technology, Engineering, or a related field with at least 3+ years of related work experience or a master’s degree and at least 2+ years of related work experience in penetration testing which includes internet, intranet, web application penetration tests, wireless, social engineering, and red team assessments
- Contributions to the security community, including research, public CVE disclosures, bug bounty acknowledgments, open-source project involvement, blog posts, publications, and similar activities
- An understanding of web-based application vulnerabilities (OWASP Top 10)
- Strong analytical and problem-solving abilities
- Excellent communication skills, both written and verbal
- Ability to work collaboratively in a team environment
What We Look For
We re interested in intellectually curious people with a genuine passion for cyber security. With your specialization in attack and penetration testing, we ll turn to you to speak up with innovative new ideas that could make a lasting difference not only to us – but also to the industry as a whole. If you have the confidence in both your presentation and technical abilities to grow into a leading expert here, this is…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).