Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Analyst

Ernst & Young Oman

The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses. Your responsibilities will include supporting the validation of third‑party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards are applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk. Your key responsibilities The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof‑of‑concepts to validate exploitability and determine real‑world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets. The candidate will support third‑party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks and reporting standards within the Vulnerability Discovery and offensive security functions. Skills and attributes for success Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc. Strong attention to detail with a methodical approach to identifying complex attack paths Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context Ability to manage high volumes of testing requests without compromising depth or quality Flexibility to work across diverse technologies, including cloud, applications and infrastructure Effective communication skills to convey technical findings to both technical and non‑technical audiences Familiarity with research techniques and threat intelligence to support proactive risk identification To qualify for the role you must have A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security Hands‑on experience testing applications, APIs, cloud environments and network infrastructure Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques Familiarity with offensive security methodologies and frameworks Experience supporting or performing third‑party risk assessments Strong analytical and problem‑solving skills with the ability to prioritize risks effectively Strong communication and stakeholder management skills Ideally, you’ll also have OWASP training Incident response experience What we look for We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally‑exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization. What we offer you We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is 76,400 to 138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team‑led and leader‑enabled hybrid model. Our expectation is for most people in external, client‑serving roles to work together in person 40‑60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial and emotional well‑being. EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io. #J-18808-Ljbffr

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Analyst in Boston, MA vacancy
  • $76.4k - $138.6k

     ...central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost...  ...market and business value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key... 
    Suggested
    Summer holiday
    Local area
    Flexible hours

    EY

    Boston, MA
    16 days ago
  •  ...triage and investigation (EDR alerts, email security, identity)Incident response support...  ...support / help desk / junior SOC or security analyst work (any combination)Strong Microsoft 3...  ...(KnowBe4, Hoxhunt, etc.)Curiosity about offensive security there's real room to grow... 
    Suggested
    Remote work

    ForgePath Security

    Cambridge, MA
    1 day ago
  • $70k - $110k

     ...Security Analyst At WHOOP, we are on a mission to unlock human performance and extend healthspan. The security organization supports this mission by protecting the systems, data, and infrastructure that power the platform and enable trusted member experiences. WHOOP... 
    Suggested
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    20 days ago
  •  ...Security Analyst Security Boston, MA Asset Management JO-1902-1194 Overview Reporting to the manager of the IT Networking & Security team, this position is part of the IT Infrastructure group. The IT Security Engineer has responsibility for the design... 
    Suggested

    The Ceres Group

    Boston, MA
    1 day ago
  •  ...Security Analyst Headquartered in New Jersey (U.S), Cygnus Professionals Inc. is a next generation global information technology Solution and Consulting company powered by strong management and leadership team with over 30 person years of experience. Today, Cygnus... 
    Suggested
    Contract work
    Immediate start

    Cygnus Professionals

    Boston, MA
    5 days ago
  •  ...human work, shift people up, and finally focus on achieving the security outcomes that teams have been searching for. We are seeking...  ...world's first Agentic Security Platform. As a Tier 3 Security Analyst at 7AI, you will serve as the technical leader and point of escalation... 
    Shift work

    SevenAI

    Boston, MA
    1 day ago
  • $71.7k - $86k

     ...SECURITY ANALYST II, IS&T Information Security Location: BOSTON, MA, United States Position Type: Full-Time/Regular Grade: 49 – Salary Range: $71,700.00 – $86,000.00 Full Description: The University seeks a Security Analyst II responsible for responding to cyber security... 
    Full time
    For contractors
    Work at office

    Boston University

    Boston, MA
    3 days ago
  •  ...Inside Higher Ed in Boston, MA, is seeking a Security Analyst II specializing in Information Security for their IT department. The ideal candidate will monitor and analyze security events, assist with vulnerability scanning processes, and mitigate risks. This full-time... 
    Full time

    Inside Higher Ed

    Boston, MA
    3 days ago
  • $71.7k

     ...SECURITY ANALYST II, IS&T Information Security Job Description SECURITY ANALYST II, IS&T Information Security Category Charles River Campus -- Information Technology Job Location BOSTON, MA, United States Tracking Code 26500083510414 Posted Date... 
    Full time
    For contractors
    Work at office

    Boston University

    Boston, MA
    1 day ago
  •  ...Security Operations Analyst (AI Training) We're partnering with leading AI research labs to build AI systems that reason through real‑world security incidents. As a Security Operations Analyst, your hands‑on SOC experience will directly shape how AI detects, triages,... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Boston, MA
    4 days ago
  •  ...Cannon Search is seeking a Cybersecurity Analyst to join its expanding Information Security team in Boston, Massachusetts. This newly created position offers the opportunity to support vulnerability management and strengthen the security posture of a growing enterprise... 

    Cannon Search

    Boston, MA
    1 day ago
  •  ...WHOOP is looking for a Security Analyst for day-to-day operations in Boston, MA. The ideal candidate will support and maintain security operations, working closely with internal security teams and partners to investigate alerts and coordinate responses. Responsibilities... 

    Femtech Insider Ltd.

    Boston, MA
    3 days ago
  • $25.75 per hour

     ...Description Overview Allied Universal®, North America’s leading security and facility services company, offers rewarding careers that...  .... Job Description Allied Universal® is hiring a GSOC Analyst. The Global Security Operations Center (GSOC) Analyst supports... 
    Extra income
    Full time
    Work at office
    Local area
    Worldwide

    Allied Universal

    Brighton, MA
    21 days ago
  •  ...Alignerr is seeking a Security Operations Analyst to help build smarter AI systems for cybersecurity challenges. You'll leverage your hands-on SOC experience to analyze real-world security incidents, ensuring AI effectively responds to threats. In this fully remote... 
    Remote work
    Flexible hours

    Alignerr

    Boston, MA
    1 day ago
  • Boston University is seeking a Security Analyst II to respond to cyber security events. This role involves analyzing data from multiple security sources, monitoring threats, and collaborating with cross-functional teams to enhance security. Candidates should have at least... 

    Boston University

    Boston, MA
    2 days ago
  • $135k - $182.1k

     ...governance and operations. This role involves ensuring that privileged access controls are enforced across platforms, partnering with security leads, and influencing technology owners for enhanced solutions. The ideal candidate will have strong expertise in Active... 

    Bank of America

    Boston, MA
    2 days ago
  •  ...investigations by AI Agents. The role involves mentoring junior analysts, investigating malicious activity, and collaborating with...  ...various teams. Required qualifications include over 5 years in cyber security operations, hands-on experience with security monitoring tools,... 

    7AI

    Boston, MA
    4 days ago
  • $55 - $60 per hour

     ...Direct message the job poster from Akkodis Sr. Recruiter - GRC (Global Recruitment Center) at Akkodis Akkodis is seeking an IT Security Analyst for a Contract position with a client located in Quincy, MA. Rate Range: $55-$60/hr on W2 without benefits, The rate may be... 
    Contract work
    Temporary work
    Work experience placement
    Local area
    Remote work
    Early shift

    Akkodis

    Quincy, MA
    2 days ago
  • $40 per hour

    A cybersecurity tech company is seeking experienced cybersecurity professionals to evaluate AI-generated content and solve technical problems. Ideal candidates will have over 2 years of hands-on experience in the cybersecurity field, with strong writing and analytical skills...
    Hourly pay
    Remote work

    DataAnnotation

    Boston, MA
    3 days ago
  • $40 per hour

    A leading AI cybersecurity firm is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical cybersecurity problems. This remote role allows flexible scheduling and offers projects paid hourly starting at $40+ USD. Candidates... 
    Remote job
    Hourly pay
    Flexible hours

    DataAnnotation

    Boston, MA
    3 days ago
  •  ...Technology (IS&T) is seeking applicants with diverse skills and experiences to join our innovative and inclusive community as a Security Analyst II. In this role you will respond to cyber security events at the university, analyze data from a variety of sources—including... 
    For contractors

    Boston University

    Boston, MA
    1 day ago
  • $40 per hour

    A cybersecurity firm is looking for experienced professionals to evaluate AI-generated security content. The role involves solving technical cybersecurity problems, providing feedback to improve AI systems, and writing clear technical explanations. Candidates should have... 
    Remote job
    Hourly pay
    Flexible hours

    DataAnnotation

    Boston, MA
    4 days ago
  • A cybersecurity firm is seeking experienced professionals to provide evaluations of AI-generated security content and to resolve technical issues related to cybersecurity. The role offers flexibility as it can be performed remotely, allowing you to choose your projects... 
    Remote job

    DataAnnotation

    Boston, MA
    2 days ago
  • $40 per hour

    A cybersecurity company seeks experienced professionals to evaluate AI-generated security content and solve technical problems. The role is remote and offers flexible scheduling with projects paid hourly starting at $40+. Candidates should have 2+ years of cybersecurity... 
    Remote job
    Hourly pay
    Flexible hours

    DataAnnotation

    Boston, MA
    2 days ago
  • $71.7k - $86k

    Security Analyst II - Information Security (IS&T) Category : Charles River Campus - Information Technology Job Location : Boston, MA, United States Position Type : Full-Time / Regular Salary Grade : 49 - $71,700.00 to $86,000.00 Upon successful completion of the first... 
    Full time
    For contractors

    Inside Higher Ed

    Boston, MA
    3 days ago
  •  ...Boston University is seeking a Security Analyst II to join its Cyber Security Operations Center. The role involves monitoring and responding to security events, analyzing data from various security tools, and collaborating with teams to mitigate risks. Candidates should... 

    Boston University

    Boston, MA
    4 days ago
  • $30 per hour

     ...the Oracle Government, Defense & Intelligence team supporting Federal Compliance and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management team to ensure documentation, processes and policies up to date... 
    Hourly pay
    Temporary work
    Internship
    Flexible hours

    Oracle

    Boston, MA
    1 day ago
  •  ...SOC Analyst Location: New York City, Boston MA, Atlanta GA Shift: 3PM to 12AM EST Mon - Fri & participate in an on-call rotation...  ...SOC Analyst serves as the first line of defense for information security operations monitoring, investigating, and responding to potential... 
    Shift work

    Axelon

    Boston, MA
    1 day ago
  • $80k - $115k

     ...suffering from serious diseases. Position Overview: Beam is looking for a highly motivated and detail-oriented Security and Network Operations Analyst to join our growing IT Team. This is a junior level position designed for candidates with 2-6 years of hands-on... 
    Full time
    Work experience placement
    2 days per week
    3 days per week
    1 day per week

    Beam Therapeutics Inc.

    Cambridge, MA
    3 days ago
  • $166k - $220k

     ...technology to the military in months, not years. ABOUT THE TEAM Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defense technologies. As a SecOps Analyst on the detection and response team,... 
    Full time
    Work experience placement
    Relocation package

    Slope

    Boston, MA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!