Offensive Security Analyst
$76.4k - $138.6kErnst & Young
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands-on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses.Your responsibilities will include supporting the validation of third-party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk.
Your key responsibilities
The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof-of-concepts to validate exploitability and determine real-world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets.The candidate will support third-party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams, and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks, and reporting standards within the Vulnerability Discovery and offensive security functions.
Skills and attributes for success
Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc.
Strong attention to detail with a methodical approach to identifying complex attack paths
Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context
Ability to manage high volumes of testing requests without compromising depth or quality
Flexibility to work across diverse technologies, including cloud, applications, and infrastructure
Effective communication skills to convey technical findings to both technical and non-technical audiences
Familiarity with research techniques and threat intelligence to support proactive risk identification
To qualify for the role you must have
A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security
Hands-on experience testing applications, APIs, cloud environments, and network infrastructure
Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques
Familiarity with offensive security methodologies and frameworks
Experience supporting or performing third-party risk assessments
Strong analytical and problem-solving skills with the ability to prioritize risks effectively
Strong communication and stakeholder management skills
Ideally, you’ll also have
OWASP training
Incident response experience
What we look for
We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally-exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.
What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $91,700 to $157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .
$40 per hour
...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback... ..., including threat analysis, vulnerability assessments, and offensive security techniques Design and solve security-focused...SuggestedHourly payFull timePart timeRemote work$40 per hour
...A cybersecurity solutions company is seeking experienced professionals to evaluate AI-generated security content and solve technical problems. This role offers the flexibility to work remotely and choose projects, with compensation starting at $40 per hour. Candidates...SuggestedHourly payRemote workFlexible hours$40 per hour
...A leading AI training firm is looking for experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. This remote role requires at least 2 years of hands-on cybersecurity experience and coding skills. You will provide...SuggestedHourly payRemote work- ...Security Analyst The Security Analyst is responsible for managing third-party vulnerability data, executing scans using Sompo’s proprietary tools, and partnering with IT teams to prioritize remediation efforts. The role requires strong technical expertise in vulnerability...Suggested
$90.78k
...We are seeking a seasoned Security Governance/Risk professional to support and strengthen enterprise security governance for Federal and DoD customers. This role is responsible for performing complex risk analyses, establishing and advising on Information Assurance and...SuggestedWork at office$40 per hour
...A technology company is seeking experienced cybersecurity professionals to evaluate AI-generated security content. In this remote role, you will solve technical problems and enhance AI models' reasoning about cybersecurity threats. Ideal candidates should have at least...Hourly payRemote workFlexible hours$30 per hour
...the Oracle Government, Defense & Intelligence team supporting Federal Compliance and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management team to ensure documentation, processes and policies up to date...Hourly payTemporary workInternshipFlexible hours$90.32k - $121.93k
...Essential Duties and Responsibilities ~ Architects and authors System Security Plans (SSPs), the "source of truth" for the client's security posture, detailing exactly how each NIST 800-171 control is implemented. ~ Develops and manages the Plan of Action and Milestones...Full timeLocal area- ...Experienced Operations Analyst Opportunity Security Benefit is a leader in the U.S. retirement market with more than $60 billion in assets under management. We offer opportunities to thrive, innovate, and make an impact. As part of our team, you'll play a key role in...Temporary workRemote workHome officeFlexible hours
$129.3k - $177.8k
...being of our employees and their families. We design competitive and flexible packages to give our employees a sense of financial security-both today and in the future, including: ~ Health benefits effective day 1 ~ Paid time off, holidays, volunteer time and jury duty...Bi-weekly payFull timeTemporary workApprenticeshipWork experience placementWork at officeRemote workWork from homeHome officeFlexible hours$143k - $243k
...business solutions to clients' complex pharmacy benefit challenges.Every employee must understand, comply with and attest to the security responsibilities and security controls unique to their job, and comply with all applicable legal, regulatory, and contractual requirements...Work experience placementLocal areaRemote workVisa sponsorshipWork visa- ...opportunities be, too? The Opportunity This role is Detroit Hybrid preferred; however, remote option possible. The Senior Actuarial Analyst is responsible for developing and supporting a robust reserving framework at Ally Insurance. The Senior Actuarial Analyst will be...Permanent employmentWork experience placementRemote workFlexible hours
$129.3k - $177.8k
Become a part of our caring community The Actuary, Analytics/Forecasting analyzes and forecasts financial, economic, and other data to provide accurate and timely information for strategic and operational decisions. Establishes metrics, provides data analyses, and works...Bi-weekly payFull timeTemporary workApprenticeshipWork experience placementRemote workWork from homeHome officeShift work$143k - $243k
A leading pharmacy benefit manager is seeking a Senior Principal Actuary to provide actuarial direction and innovative solutions. This remote role requires at least 10 years of experience in actuarial work and an ASA or FSA designation. Responsibilities include leading ...Remote work$106.9k - $147k
Become a part of our caring community Reports To: Associate Director, Actuarial Analytics/Forecasting FLSA: Exempt/Salaried The Associate Actuary, Analytics/Forecasting analyzes and forecasts financial, economic, and other data to provide accurate and timely information...Full timeContract workTemporary workApprenticeshipRemote workWork from home- ...Experienced Associate Actuary Opportunity We're Looking for an Experienced Associate Actuary! About the Company: Security Benefit is a leader in the U.S. retirement market with more than $60 billion in assets under management. We offer opportunities to thrive, innovate...Full timeTemporary workWork at officeRemote workHome officeFlexible hours
$113.2k - $169.8k
...catastrophe loads-to support rate filings, performance monitoring, and profitability or ad hoc analyses. Effectively communicate to secure internal and external approval for proposed changes. Create and improve analytical tools utilizing knowledge of advanced...Temporary workWork at officeRemote work3 days per week- ...address their most significant and complex challenges in science, security and sustainability. Our people apply undaunted curiosity,... ...across all 7 continents. The Business Development Financial Analyst, Senior serves as a bridge between BD operational execution and...Hourly payContract workLocal areaRemote work
$50 - $60 per hour
...A leading AI solutions provider is seeking a Research Analyst to assist in training AI models to understand financial principles. This role offers flexibility as a part-time or full-time remote position, allowing for a personalized work schedule. Candidates should possess...Hourly payFull timePart timeRemote workFlexible hours$84.5k - $178.1k
...Job Description The Oracle Cloud Infrastructure (OCI) Product Finance team is hiring a seasoned analyst to build financial models with imperfect data and unclear solutions using sales and customer requirements. As a member of the team, you will work in partnership with...Temporary workFlexible hours- ...A technology company in the United States is seeking a Capital Markets Analyst to review and improve AI Assistant answers about financial principles. The role allows you to work remotely with flexible hours and involves evaluating AI performance on complex financial problems...Hourly payFor contractorsRemote workFlexible hours
$98k - $125k
...The Sr Program Financial Analyst demonstrates deep expertise in contract financial management. They lead and administer overall budget... ...dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions...Contract workWork experience placementFor subcontractorH1bWork at officeRemote work$70.6k - $141.2k
Job Description About Oracle Cloud Infrastructure (OCI): Oracle Cloud Infrastructure (OCI) is one of the fastest-growing businesses within Oracle. Designed to deliver the performance, control, and governance of enterprise data centers with the scale, elasticity...Temporary workFlexible hours$70.6k - $141.2k
...Job Description Oracle Cloud Infrastructure (OCI) is growing rapidly, and we are looking for a financial analyst to support our Supply Chain organization. This role focuses on financial planning, forecasting, and close support for global supply chain costs supporting...Temporary workFlexible hours$83.81k - $131.55k
.... Each line of business within UMB has their own line finance team and within the line finance team there is a Senior Financial Analyst. The Senior Financial Analyst is the one who performs a variety of financial activities including budgeting, forecasting, building...Work experience placementLocal areaFlexible hours$70.6k - $141.2k
...Job Description Sr. Financial Analyst, IaaS Workload Health Job location: US Nationwide, Remote Oracle Cloud Infrastructure (OCI) is one of the fastest growing businesses within Oracle. In OCI Finance, members of the Workload Health team are responsible for all...Temporary workRemote workFlexible hours$130.9k - $154k
Ready to be pushed beyond what you think you’re capable of? At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the...Local area$84.5k - $178.1k
...Job Description Principal Finance Analyst, Product Lead - Workload Health Oracle Cloud Infrastructure (OCI) is one of the fastest... ...It is designed to run any enterprise application and workload securely in the cloud. In a single offering, OCI combines the flexibility...Temporary workFlexible hours- ...Cytel is seeking a highly analytical and business-focused Senior Financial Analyst to support the financial planning, analysis, and operational performance of our PBS (Preclinical & Clinical Services) business unit. This role will serve as a strategic finance partner to...Contract workWorldwide
$92k - $110k
...Clearance Needed Fully remote Financial Analysis Overview GovCIO is currently hiring for a Financial Analyst to support our National Security Sector. This position will be fully remote within the United States, with the office located in Fairfax, VA. The candidate...Full timeFor subcontractorCurrently hiringWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!

