Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Analyst

$76.4k - $138.6k

Ernst & Young

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.

Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

The opportunity

As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands-on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses.Your responsibilities will include supporting the validation of third-party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk.

Your key responsibilities

The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof-of-concepts to validate exploitability and determine real-world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets.The candidate will support third-party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams, and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks, and reporting standards within the Vulnerability Discovery and offensive security functions.

Skills and attributes for success

  • Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc.

  • Strong attention to detail with a methodical approach to identifying complex attack paths

  • Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context

  • Ability to manage high volumes of testing requests without compromising depth or quality

  • Flexibility to work across diverse technologies, including cloud, applications, and infrastructure

  • Effective communication skills to convey technical findings to both technical and non-technical audiences

  • Familiarity with research techniques and threat intelligence to support proactive risk identification

To qualify for the role you must have

  • A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security

  • Hands-on experience testing applications, APIs, cloud environments, and network infrastructure

  • Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques

  • Familiarity with offensive security methodologies and frameworks

  • Experience supporting or performing third-party risk assessments

  • Strong analytical and problem-solving skills with the ability to prioritize risks effectively

  • Strong communication and stakeholder management skills

Ideally, you’ll also have

  • OWASP training

  • Incident response experience

What we look for

We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally-exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.

What we offer you

The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $91,700 to $157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.

  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.

  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

Are you ready to shape your future with confidence? Apply today.

EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. 

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Analyst in Philadelphia, PA vacancy
  •  ...Security Analyst Sonsoft, Inc. is a USA based corporation duly organized under the laws of the Commonwealth of Georgia. Sonsoft Inc. is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled... 
    Suggested
    Permanent employment
    Full time
    H1b

    SonSoft

    Philadelphia, PA
    a month ago
  •  ...Vulnerability Management -or- 1-2 years' experience in Data Analytics in Technology Responsibilities Analyze current security & vulnerability scanning results and prioritize remediation efforts. Continuously improve client's security posture through engaging... 
    Suggested

    Omni Inclusive

    Philadelphia, PA
    7 days ago
  •  ...where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Senior Securities Analyst Associate within PNC's Asset Management Group (AMG) Investment Office organization, you will be based in Philadelphia, PA.... 
    Suggested
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office

    PNC Financial Services Group

    Philadelphia, PA
    6 days ago
  •  ...Join Our Team as an IT Security Analyst I! Are you a proactive and detail-oriented individual with a passion for cybersecurity? Do you thrive on protecting digital assets and ensuring compliance? We're looking for an IT Security Analyst I to join our dedicated team... 
    Suggested

    CMI Media Group

    Philadelphia, PA
    6 days ago
  •  ...Security Analyst The Security Analyst is responsible for managing third-party vulnerability data, executing scans using Sompo’s proprietary tools, and partnering with IT teams to prioritize remediation efforts. The role requires strong technical expertise in vulnerability... 
    Suggested

    Argyle Infotech

    Conshohocken, PA
    6 days ago
  •  ...Overview of Role: The Security Analyst (Journeyman) is responsible for performing cybersecurity compliance assessments, vulnerability management, and security monitoring for Department of Defense network systems across multiple installations. Core duties include... 

    TM3 Solutions Inc

    Philadelphia, PA
    a month ago
  •  ...IT Security Analyst Come and Save Lives with Us! SERB is a fast-growing specialty pharmaceutical company that equips healthcare providers worldwide with life-saving medicines for patients facing rare conditions and emergencies. For over 30 years we have consistently... 
    For contractors
    Work at office
    Immediate start
    Work from home
    Worldwide
    3 days per week

    SERB Pharmaceuticals

    Conshohocken, PA
    7 days ago
  •  ...other scanning tools. Web application scanning and web application firewalls. Containers. CIS benchmarks, STIGs, or other security hardening standards. Additional Desirable Skills Or Experience SAML, Kerberos, OAuth, OIDC, LDAP. Powershell and... 

    The Dignify Solutions, LLC

    Conshohocken, PA
    5 days ago
  •  ...Security Administration Analyst Location: Philadelphia Start: ASAP Interview Process: Video & Onsite Length 6+ Months to Start Open To Conversion Yes The Security Administration Analyst is a key contributor in the Information Security Division. This individual will... 
    Local area
    Immediate start

    Marchon Partners

    Philadelphia, PA
    4 days ago
  •  ...Job Description: About the Role: The Network Security Engineer will design, implement, and manage secure network infrastructure to ensure uninterrupted business operations. Responsibilities: Configure and maintain firewalls, VPNs, and IDS/IPS systems... 

    Vurke

    Philadelphia, PA
    7 days ago
  •  ...We are looking for a Data Security Analyst to join our Information Security Architecture team in Philadelphia, PA or Overland Park, KS (Hybrid). This is an exciting opportunity to work on cutting-edge data protection and security initiatives leveraging Microsoft Purview... 
    Full time
    Work experience placement
    Work at office
    2 days per week

    Clarivate Analytics US LLC

    Philadelphia, PA
    5 days ago
  • $92k - $114k

     ...Information Security Data Protection Manager Aegon's Global Technology Services - Security (GTS-security) delivers certain information security programs across all Aegon business units. Specifically GTS-security establishes and maintains the information security policy... 
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area
    Remote work
    Work visa
    Relocation package
    3 days per week

    Transamerica

    Philadelphia, PA
    4 days ago
  •  ...The Security Analyst is responsible for the day-to-day execution of STARR's information security operations across a multi-concept restaurant and hotel portfolio of more than 40 locations. Reporting to the Director, Infrastructure and Security, this role provides hands... 
    Full time

    STARR Restaurants

    Philadelphia, PA
    20 days ago
  • $95k - $110k

     ...the return on the city’s technology investments; ensuring data security continuity; planning for continuing operations in the event of...  ...department, board, commission and agency. The Network Security Analyst is an integral position within the Network operations group.... 
    Full time
    Part time
    Work experience placement
    Work at office
    Relocation

    City of Philadelphia

    Philadelphia, PA
    24 days ago
  • We are seeking a passionate, adaptable Information Security Analyst who will serve as a subject matter expert (SME) for business areas and technical teams, and act as the customer interface for the Information Security Operations function. You will strengthen our security... 
    Work at office
    Local area
    Remote work
    Monday to Friday
    2 days per week
    3 days per week

    Independence

    Philadelphia, PA
    more than 2 months ago
  • $140k

     ...Harbor Consulting & Management, Inc is looking to hire an Information Security Compliance Analyst - CISSP/CISA. Compensation: ~140K +/DOE. Employment type: ~ FT. We are a 20+ year old professional services organization assisting our customer in staffing... 
    Full time

    Harbor Consulting & Management, Inc

    Philadelphia, PA
    more than 2 months ago
  •  ...voice, data, and managed network solutions, supporting customers across markets and geographies. We are excited to be adding a Security Analyst to our growing Information Technology team. In this role, you will support BCM Ones security operations by monitoring and... 
    Work at office
    Relocation
    2 days per week
    1 day per week

    BCM One

    Blue Bell, PA
    8 days ago
  •  ...seeking an Engineer III for the Red Team in Conshohocken, PA. The role involves executing cyber attack simulations and improving security capabilities through advanced threat emulation. Candidates should have a bachelor's degree in Cybersecurity and 6+ years of experience... 

    MWI Animal Health

    Conshohocken, PA
    2 days ago
  •  ...Location: This position is located in the Department of Homeland Security, U.S. Citizenship and Immigration Services, within Philadelphia...  ...support and/or tax obligations, as well as certain criminal offenses and illegal use or possession of drugs. The background investigation... 
    Full time
    Contract work
    Part time
    Work at office
    Immediate start
    Remote work
    Overseas
    Flexible hours

    Citizenship and Immigration Services

    Philadelphia, PA
    6 days ago
  • The DC Army National Guard is seeking a Cannon Crewmember in Plymouth Township. This role involves maintaining the U.S. battlefield superiority through the use of high-tech artillery systems. As part of your responsibilities, you will conduct operations such as identifying...

    DC Army National Guard

    Plymouth Meeting, PA
    2 days ago
  • $20 - $25 per hour

     ...Stock Replenishment Analyst Location: 190 Benigno Blvd., Bellmawr, NJ 08031 (On-Site) Schedule: Full Time | Monday–Friday | Day Shift Department: Operations – Stock Replenishment Do you love organization, details, and keeping things running smoothly behind the scenes?... 
    Full time
    Monday to Friday
    Night shift
    Weekend work
    Day shift

    General Floor Industries

    Bellmawr, NJ
    2 days ago
  •  ...OPS Security Group is seeking a Loss Prevention Officer for Cherry Hill Township, NJ. This role involves conducting covert surveillance to detect theft and fraud in retail environments. The ideal candidate will possess strong observational and communication skills, a... 
    Full time

    OPS Security Group

    Cherry Hill, NJ
    3 days ago
  • $19 per hour

     ...to detect policy violations. Coordinate own activities and functions to obtain maximum productivity and efficiency. Observe security standards by staying alert and being aware of Customer actions and behavior; report to Store Management any abnormal behavior.... 
    Local area
    Shift work

    ShopRite

    Lawnside, NJ
    6 days ago
  • $24.53 per hour

     ...incidents. Defuse guest/employee disturbances. Call for outside assistance if necessary. Complete incident reports to document all Security/Loss Prevention related incidents. Handle all interruptions and complaints. Resolve safety hazard situations. Escort any unwelcome... 
    Hourly pay
    Work experience placement
    Worldwide
    Shift work
    Night shift
    Day shift

    Marriott International Inc

    Philadelphia, PA
    2 days ago
  •  ...Loss Prevention Officer- Cherry Hill, NJ- SORA required Job Category : SECURITY SERVICES Requisition Number : LOSSP001456 Posted : May 14, 2026 Full-Time On-site Locations Cherry Hill, NJ Cherry Hill Twp, NJ, USA Position Overview OPS Security Group is seeking professional... 
    Full time
    Monday to Friday

    OPS Security Group

    Cherry Hill, NJ
    3 days ago
  •  ...Additional Information Day shift and evening shift Job Number 26049016 Job Category Loss Prevention & Security Location 1 Arrivals Rd, Philadelphia, Pennsylvania, United States, 19153 VIEW ON MAP ( Schedule Full Time Located Remotely? N Position Type... 
    Full time
    Work experience placement
    Remote work
    Shift work
    Day shift
    Afternoon shift

    Marriott

    Philadelphia, PA
    7 days ago
  •  ...theft or incorrect business procedures in a dynamic retail environment. If you are looking for an opportunity to grow your career in security and retail operations asset management with a company known for quality and big savings, apply today! Job Responsibilities As... 
    Weekly pay
    Part time
    Afternoon shift

    Boscov's

    Plymouth Meeting, PA
    3 days ago
  • $300 per month

     ...and Safe Leave accrued at 1 hour for every 30 hours worked Paid training Defined vertical mobility and promotion opportunity OPS Security Group offers competitive Medical, Dental, Vision and 401(k) benefits for eligible employees in accordance with company policy. Benefits... 

    OPS Security Group

    Cherry Hill, NJ
    3 days ago
  •  ...opportunity to contribute to the company's success. As a Portfolio Analyst - Equities within PNC's Asset Management Group Investment...  ...Deposit Insurance Act (FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE Act... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office

    PNC Financial Services Group

    Philadelphia, PA
    3 days ago
  • $24.5 - $25 per hour

    Loss Prevention Agent Salary: $24.50-$25.00/hour The Loss Prevention Agent is responsible for all initiatives and daily tasks associated with loss prevention and safety management as directed by Loss Prevention Manager to ensure the safety and well being of all employees...
    Hourly pay
    Full time
    Temporary work
    Local area
    Flexible hours
    Night shift

    Uniqlo

    Philadelphia, PA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!