Offensive Security Analyst
About the role
At EY, we’re committed to shaping your future with confidence. As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands-on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess, and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing, and assessing the true impact of security weaknesses.
You will support the validation of third-party risk assessments, identify misconfigurations and exposed assets, and ensure security standards are applied across EY’s digital ecosystem. Additionally, you will contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk.
Responsibilities
- Apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure.
- Test proof-of-concepts to validate exploitability and determine real-world impact.
- Emulate adversary tactics to test detection and response capabilities.
- Conduct reconnaissance and asset discovery to uncover unmanaged or exposed assets.
- Support third-party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required.
- Collaborate closely with security engineering, blue teams, and business stakeholders to prioritize remediation efforts based on risk severity and exploitability.
- Contribute to enhancing processes, playbooks, and reporting standards within the Vulnerability Discovery and offensive security functions.
Requirements
- A minimum of 4 years of experience in penetration testing, red teaming, purple teaming, or offensive security.
- Hands-on experience testing applications, APIs, cloud environments, and network infrastructure.
- Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques.
- Familiarity with offensive security methodologies and frameworks.
- Experience supporting or performing third-party risk assessments.
- Strong analytical and problem-solving skills with the ability to prioritize risks effectively.
- Strong communication and stakeholder management skills.
Skills
- Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus, etc.
- Strong attention to detail with a methodical approach to identifying complex attack paths.
- Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context.
- Ability to manage high volumes of testing requests without compromising depth or quality.
- Flexibility to work across diverse technologies, including cloud, applications, and infrastructure.
- Effective communication skills to convey technical findings to both technical and non-technical audiences.
- Familiarity with research techniques and threat intelligence to support proactive risk identification.
Qualifications
Ideally, you’ll also have certifications such as OSCP, GPEN, GWAPT, or equivalent offensive security credentials.
Benefits
- Comprehensive medical and dental coverage.
- Pension and 401(k) plans.
- Flexible vacation policy, allowing you to decide how much vacation time you need based on personal circumstances.
- Designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence to support your well-being.
Pay
The base salary range for this job in all geographic locations in the US is $76,400 to $138,600. The base salary range for New York City Metro Area, Washington State, and California (excluding Sacramento) is $91,700 to $157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills, and geography.
Schedule
Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client-serving roles to work together in person 40-60% of the time over the course of an engagement, project, or year.