Senior Consultant - Financial Services, Advanced Security Centre
About the role
The opportunity
As a Senior Consultant, you'll join EY Advanced Security Centre (ASC) which is a well-established, dedicated and vibrant offensive security team. Our vision is to build and bring the strongest, most diverse and highly skilled team to the market. We strive to be the market leaders in security testing services, ready to tackle any challenge that comes our way.
The ASC provides the following services to our clients:
- Web, Web services, mobile and thick client penetration testing
- Internal/External network penetration testing
- Red Team/Purple Team assessments
- Social Engineering assessments
- Application Security Consulting and Secure Code Review
- Cloud security assessments
- Wireless assessments
- Security configuration reviews
Your key responsibilities
- Deliver offensive security assessments across web, mobile, cloud, network, wireless and application environments to help clients strengthen their cyber security posture.
- Work alongside experienced security professionals on penetration testing, red team, purple team and social engineering engagements across a diverse client portfolio.
- Contribute to the growth of EY's Advanced Security Centre by continuously developing technical capabilities and helping solve complex security challenges.
Skills and attributes for success
- A minimum of 3+ years cybersecurity experience, with a majority being offensive security related (e.g. penetration testing or application security experience), beyond the use of automated tools. Show us that you know what’s happening behind the tooling.
- Strong project management and interpersonal skills.
- A commitment to build and grow your technical cybersecurity career to the next level.
- Experience in web and mobile application security testing and specialisation in one other domain would be favourable (thick application, red team/purple team or internal/external network)
- Demonstrable proficiency of at least 2 following security assessment methodologies:
- Web, Web services, mobile and thick client penetration testing
- Internal/External network penetration testing
- Application Security consulting and secure code review
- Wireless assessments
- Social engineering/red team assessments
- Demonstrable technical understanding or certifications of at least 2 of following domains:
- Common web technologies and frameworks
- Application architecture
- Cloud experience
- Networking and Network protocols
- DevOps methodology and pipelines
- Relevant (or be willing and able to pursue) professional certifications such as OSCP, SANS, CREST, PJPT, PNPT, PWPT, PJWT, CPTS, etc.
What we offer you
Career development
Flexible work arrangements
A comprehensive benefits package
Salary
Acknowledgement of Country
Are you ready to shape your future with confidence? Apply today.
EY
Not included in the source posting: about the role.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.