Cyber Defense Analyst
EY · Cleveland, OH · 2 days ago
On-siteInformation TechnologyFull-time
Key Responsibilities
- Design and engineer automated attack-path discovery and validation capabilities
- Build scalable vulnerability detection and verification pipelines that combine enterprise scanning sources with custom validation logic
- Operationalize continuous offensive validation by engineering testing routines that can run with minimal human prompting
- Fuse Vulnerability Intelligence and Cyber Threat Intelligence into detection and prioritization—tracking exploit maturity/availability, active exploitation signals, and technique trends, etc
- Produce high-fidelity deliverables that enable remediation and decisioning: reproducible evidence, attack-path narratives, severity/exploitability rationale, compensating control notes, and clear remediation/mitigation recommendations
- Partner across Red Team, Exposure Assessment, Threat Detection, and VM stakeholders
Skills And Attributes For Success
- Expert attention to detail
- Demonstrated ability to think critically
- Flexibility and comfortability pivoting between diverse environments
- Exceptional communication and rapport building skills
- Extensive experience augmenting offensive security
Minimum Qualifications
- Combined 8 years of experience in vulnerability management, exposure management, offensive security, and security engineering
- Deep understanding of attack paths, misconfigurations, and control failures that lead to material risk
- Proven ability to build scalable solutions to vulnerability and exposure challenges
- Experience operating at a strategic level, balancing technical depth with organizational risk context
- Strong analytical skills with the ability to evaluate large volumes of data to influence solution development
- Excellent communication skills, with comfort engaging senior stakeholders and security leadership
- Ability to manage competing priorities and operate independently in a complex, global environment