TC-CS-CTM-Pentest-Senior
EY
EY
Join EY's Cyber Security team as a Senior Security Consultant, specializing in Attack and Penetration Testing. You'll play a pivotal role in developing a new service offering and contribute to building a better working world. This role offers the chance to grow your career within a supportive, inclusive, and global environment, leveraging technology and continuous learning.
At EY, we empower you to build a career as unique as you are, with the global scale, support, and inclusive culture to help you become your best. We value your unique voice and perspective in making EY even better. Join us to create an exceptional experience for yourself and contribute to a better working world for everyone.
Execute comprehensive penetration tests across various environments including internet, intranet, wireless, web applications, and physical systems. Conduct red team assessments to identify critical security gaps. Analyze penetration testing results, detailing findings, exploitation techniques, associated risks, and actionable recommendations. Communicate complex security concepts effectively to both technical and non-technical stakeholders, including executive leadership.
Develop automated solutions to mitigate organizational risks. Support Secure Software Development Lifecycle (SDLC) and agile methodologies through application security testing and source code reviews. Provide technical guidance and mentorship to junior team members on attack and penetration test engagements.
A Bachelor's degree in Engineering (BE/B.Tech), Computer Applications (MCA), or an equivalent qualification is required. A minimum of 6 years of experience in penetration testing is essential, with at least three years focusing on internet, intranet, web application tests, wireless, social engineering, physical, or Red Team assessments. Possession of a relevant certification such as OSCP, OSCE, OSEP, OSWE, CREST, CRTE, eCPTX, or eWPTX is mandatory.
Solid understanding of web vulnerabilities (OWASP Top 10), enterprise security controls in Active Directory/Windows environments, and TCP/IP network protocols is crucial. Experience with operational technology/IoT, cloud platforms (AWS, Azure, GCP), Active Directory, and 802.1x penetration testing is highly desirable. Proficiency in Windows, Linux, UNIX, and other major operating systems is expected. Demonstrated skills in technical writing, including engagement reports and presentations, along with strong Excel and PowerPoint capabilities, are key.
EY Global Delivery Services ( EY GDS)
Management Consulting