Offensive Security Analyst
Ernst & Young Oman
The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses. Your responsibilities will include supporting the validation of third‑party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards are applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk. Your key responsibilities The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof‑of‑concepts to validate exploitability and determine real‑world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets. The candidate will support third‑party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks and reporting standards within the Vulnerability Discovery and offensive security functions. Skills and attributes for success Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc. Strong attention to detail with a methodical approach to identifying complex attack paths Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context Ability to manage high volumes of testing requests without compromising depth or quality Flexibility to work across diverse technologies, including cloud, applications and infrastructure Effective communication skills to convey technical findings to both technical and non‑technical audiences Familiarity with research techniques and threat intelligence to support proactive risk identification To qualify for the role you must have A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security Hands‑on experience testing applications, APIs, cloud environments and network infrastructure Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques Familiarity with offensive security methodologies and frameworks Experience supporting or performing third‑party risk assessments Strong analytical and problem‑solving skills with the ability to prioritize risks effectively Strong communication and stakeholder management skills Ideally, you’ll also have OWASP training Incident response experience What we look for We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally‑exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization. What we offer you We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is 76,400 to 138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team‑led and leader‑enabled hybrid model. Our expectation is for most people in external, client‑serving roles to work together in person 40‑60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial and emotional well‑being. EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io. #J-18808-Ljbffr
- ...A leading global professional services firm seeks an Offensive Security Analyst to join their Vulnerability Management team in Minneapolis. The role involves evaluating and managing digital risks and vulnerabilities while collaborating with various teams to enhance security...Suggested
$76.4k - $138.6k
...central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost... ...market and business value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key...SuggestedSummer holidayLocal areaFlexible hours- ...Ernst & Young Oman is seeking an Offensive Security Analyst to evaluate vulnerabilities through penetration testing and adversarial simulations. You will work closely with various teams to assess and mitigate risks across EY’s digital environment, contributing to enhanced...Suggested
- ...Ernst & Young Oman is seeking an Offensive Security Analyst to join their Attack Surface Management team in Minneapolis, Minnesota. In this role, you will conduct hands-on penetration testing and simulate threat actors to assess EY’s digital vulnerabilities. You will...SuggestedFlexible hours
$91.7k - $163.7k
...equity on a global scale. Join us to start Caring. Connecting. Growing together. We are seeking a highly skilled and resourceful offensive security assessment member to join our Physical Red Team. In this role, you will simulate real-world adversaries to evaluate and...SuggestedRemote jobMinimum wageFull timeWork experience placementLocal area$95k - $125k
...Location Minneapolis, MN or near a Legence office. Travel Yes, 10-20% Job Summary The Security Analyst is a trusted member of the Legence IT department focused on protecting the organization's computer systems, networks, users, and applications from unauthorized access...Work at officeLocal areaImmediate startFlexible hours- ...We are looking for a skilled Security Analyst to join our dynamic team and contribute to the safeguarding of our organization's assets and information. Responsibilities Policy Development and Implementation: Develop, review, and update security policies and procedures...
$124.2k - $186.2k
About the team: The Information Security organization advances the overall state of security at Rubrik through purposeful initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at...Local areaRemote work$37.76 - $63.07 per hour
...have a valid driver’s license and be free of any major traffic violations for the last three (3) years. Desirable Qualifications Security+ GSEC (SANS GIAC Security Essentials). GCIH: (SANS GIAC Certified Incident Handler). Certified Ethical Hacker (CEH). Other technology...Hourly payWork at office$72.4k - $108.6k
...Northrop Grumman is looking for an Industrial Security Analyst based in Plymouth, MN. This role involves developing and managing physical security programs and ensuring compliance with federal regulations. Candidates must possess relevant experience, certifications, and...$72.4k - $108.6k
...Northrop Grumman Defense Systems is seeking an Industrial Security Analyst for our Plymouth, MN location. Responsibilities Develop and administer physical security programs and procedures for classified or proprietary materials, documents, and equipment. Study and implement...Contract workWork at officeRemote workShift work- ...HealthPartners is hiring a Principal Epic Security IT Analyst . This position leads the coordination of Epic access activities across modules, care delivery groups, and the HealthPartners system. This role ensures the effective deployment of Epic security management by...Work experience placementLocal areaRemote work
- ...Title: IT Security Analyst Location: Maplewood, MN Duration: 8+ Months contract The Impact You ll Make in this Role As an IT Security Analyst, you will have the opportunity to tap into your curiosity and collaborate with some of the most innovative and diverse people...Contract work
$70.8k - $131.4k
...The Thomson Reuters Information Security and Risk Management (ISRM) organization is seeking a Security Operations Analyst to join our growing global Security Operations Center (SOC). The candidate will join a team responsible for managing cybersecurity alerts, events,...Work at officeLocal areaFlexible hours2 days per week3 days per week$55k - $151.47k
...Industry/Sector: Not Applicable Time Type: Full time Travel Requirements: Up to 20% The Opportunity As a Security Operations Analyst Fixed Term, you will focus on confirming the safety and protection of people, assets, and information through the implementation...Full timeFixed term contractH1b$55k - $61.5k
...FRSecure is seeking a Security Vulnerability Analyst responsible for identifying and communicating security weaknesses across client environments. This role involves extensive collaboration with clients to provide actionable recommendations while using industry-standard...Remote workFlexible hours$96.9k - $121.1k
...The Toro Company is seeking a Cybersecurity Professional in Bloomington, Minnesota to enhance monitoring and security of operational technology systems. The ideal candidate will have a bachelor's degree in Cybersecurity and over 5 years of experience in cybersecurity...$37.76 - $63.07 per hour
...Olmsted County is seeking a skilled professional to ensure the security of its technology systems. Responsibilities include reviewing logs, coordinating audits, and educating users on security best practices. A Bachelor’s degree in computer science or related field is...Hourly pay$72.4k - $108.6k
...part of projects that will define your career, now and in the future. Roles and Responsibilities Develops and administers physical security programs and procedures for classified or proprietary materials, documents, and equipment. Studies and implements federal security...Contract workWork at officeRemote workRelocationShift work- ...A dynamic consulting firm is seeking a skilled Security Analyst to safeguard the organization's assets and information. You will develop security policies, conduct risk assessments, and provide training programs to cultivate a security-conscious culture. The ideal candidate...
- ...A leading information services company is hiring a Security Operations Analyst to monitor cybersecurity alerts and incidents within a global Security Operations Center (SOC). Responsibilities include analyzing alerts from security tools, performing malware analysis, and...Flexible hours
- ...Teradata Corporation (SE) is seeking a Compliance Analyst to support security compliance programs across cloud offerings. You will help maintain key certifications and assist with compliance activities, engaging with various internal and external stakeholders. The ideal...
$30 per hour
...the Oracle Government, Defense & Intelligence team supporting Federal Compliance and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management team to ensure documentation, processes and policies up to date...Hourly payTemporary workInternshipFlexible hours$42.7k - $79.3k
...colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued. Summer Intern – GRC Amex GBT’s Security GRC team is looking for a motivated and curious Summer Intern to support our Governance, Risk, and Compliance programs. This is an...InternshipSummer internshipImmediate startFlexible hours- ...FRSecure LLC is looking for a Security Vulnerability Analyst based in Edina, MN. This role focuses on identifying and analyzing security weaknesses across client environments to improve security posture. With a full-time remote option, we provide a flexible work environment...Full timeRemote workFlexible hours
$118.4k - $219.8k
...communications with cross‑functional teams, including other business units and other key stakeholder groups Collaborate with the security architects to discuss potential solutions supporting the business strategy In this opportunity, you will: Manage issues and track...Work at officeFlexible hours2 days per week3 days per week$120k - $130k
...Overview As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and preparedness. We are looking for a proactive professional with excellent...Temporary work$155k - $165k
...Branch is seeking an experienced Security Governance, Risk, and Compliance professional to manage their Information Security Program and ensure compliance with major regulatory frameworks. This remote role requires 5-7 years in a similar position and proven experience...Remote workFlexible hours$91.7k - $163.7k
A global care organization is seeking an Insider Senior Cybersecurity Analyst responsible for detecting insider-driven risks. The role includes monitoring user activity, performing investigations, and collaborating with cross-functional teams. Candidates should possess...Remote job$96.56k - $124.96k
...Join Dorsey's Information Security team as a GRC Information Security Systems Analyst to help safeguard our firm and clients by driving high-impact security initiatives across audits, risk, governance, and compliance. Key Responsibilities Include: Support Information Security...Contract workCurrently hiringWork at officeWorldwideFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!
- entry level security analyst Minneapolis, MN
- cloud security analyst Minneapolis, MN
- information security compliance analyst Minneapolis, MN
- application security analyst Minneapolis, MN
- security operations analyst Minneapolis, MN
- entry level information security analyst Minneapolis, MN
- information security analyst Minneapolis, MN
- bond analyst Minneapolis, MN
- work from home security analyst Minneapolis, MN
- network security analyst Minneapolis, MN

