Cyber Defense Analyst
About the role
At EY, we’re committed to shaping your future with confidence. Join a global team of almost 950 Information Security professionals who collaborate to protect EY and client information assets. Our team enables EY to work securely, deliver secure products and services, detect and respond to security events, and build client trust. Within Information Security, we blend risk strategy, digital identity, cyber defense, application security, and technology solutions across the entire security lifecycle.
As an Attack Surface Validation & Exposure Engineer in the Attack Surface Management function, you will serve as a strategic contributor within EY’s Vulnerability Management and Exposure Assessment capability. This role focuses on attack path discovery, scalable vulnerability detection, and exposure validation through self-engineered solutions. You will develop EY’s strategy for discovering and managing vulnerabilities to keep pace with the evolving threat landscape, operating with a high degree of autonomy.
Responsibilities
- Design and engineer automated attack-path discovery and validation capabilities
- Build scalable vulnerability detection and verification pipelines that combine enterprise scanning sources with custom validation logic
- Develop controlled exploitation and exploit-chaining workflows to safely demonstrate real attacker outcomes
- Operationalize continuous offensive validation by engineering testing routines that run with minimal human prompting
- Fuse Vulnerability Intelligence and Cyber Threat Intelligence into detection and prioritization—tracking exploit maturity/availability, active exploitation signals, and technique trends
- Produce high-fidelity deliverables that enable remediation and decisioning: reproducible evidence, attack-path narratives, severity/exploitability rationale, compensating control notes, and clear remediation/mitigation recommendations
- Partner across Red Team, Exposure Assessment, Threat Detection, and Vulnerability Management stakeholders
Requirements
- Minimum combined 8 years of experience in vulnerability management, exposure management, offensive security, and security engineering
- Demonstrated experience analyzing vulnerability and security posture data
- Deep understanding of attack paths, misconfigurations, and control failures that lead to material risk
- Proven ability to build scalable solutions to vulnerability and exposure challenges
- Experience operating at a strategic level, balancing technical depth with organizational risk context
- Strong analytical skills with the ability to evaluate large volumes of data to influence solution development
- Excellent communication skills, with comfort engaging senior stakeholders and security leadership
- Ability to manage competing priorities and operate independently in a complex, global environment
Skills
- Expert attention to detail
- Demonstrated ability to think critically
- Interest in engineering creative solutions to complex issues
- Flexibility and comfortability pivoting between diverse environments
- Exceptional communication and rapport-building skills
- Extensive experience augmenting offensive security
Ideal Qualifications
- Experience leveraging AI to conduct exposure assessments
What We Look For
We are looking for a senior analyst who can operate autonomously and bring new, strategic approaches to discovering and evaluating the firm’s exposure to vulnerabilities. The ideal candidate will improve the organization’s ability to reduce the attack surface while enabling the business, seek to improve others, and continuously learn to strengthen the organization.