Offensive Security Analyst
Ernst & Young Oman
The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses. Your responsibilities will include supporting the validation of third‑party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards are applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk. Your key responsibilities The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof‑of‑concepts to validate exploitability and determine real‑world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets. The candidate will support third‑party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks and reporting standards within the Vulnerability Discovery and offensive security functions. Skills and attributes for success Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc. Strong attention to detail with a methodical approach to identifying complex attack paths Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context Ability to manage high volumes of testing requests without compromising depth or quality Flexibility to work across diverse technologies, including cloud, applications and infrastructure Effective communication skills to convey technical findings to both technical and non‑technical audiences Familiarity with research techniques and threat intelligence to support proactive risk identification To qualify for the role you must have A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security Hands‑on experience testing applications, APIs, cloud environments and network infrastructure Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques Familiarity with offensive security methodologies and frameworks Experience supporting or performing third‑party risk assessments Strong analytical and problem‑solving skills with the ability to prioritize risks effectively Strong communication and stakeholder management skills Ideally, you’ll also have OWASP training Incident response experience What we look for We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally‑exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization. What we offer you We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is 76,400 to 138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team‑led and leader‑enabled hybrid model. Our expectation is for most people in external, client‑serving roles to work together in person 40‑60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial and emotional well‑being. EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io. #J-18808-Ljbffr Ernst & Young Oman
$76.4k - $138.6k
...central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost... ...to market and business value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key...SuggestedSummer holidayLocal areaFlexible hours$76.4k - $138.6k
A global consulting firm is seeking an Offensive Security Analyst in Austin, Texas. The candidate will evaluate and manage vulnerabilities, ensuring security standards are upheld. This role requires at least 3 years of experience in vulnerability management and a strong...Suggested- Ernst & Young Oman is seeking an Offensive Security Analyst to evaluate and mitigate vulnerabilities across EY’s digital ecosystem. You will conduct penetration testing, identify vulnerabilities, and help prioritize remediation efforts. The ideal candidate should have...SuggestedFlexible hours
$128.1k - $239.6k
...more than 140 countries, all of whom rely on secure technology to be able to do their job every... .... We are seeking an Active Defense Analyst with a strong information security background and a passion for using offensive security techniques to improve defensive outcomes...SuggestedSummer holidayLocal areaRemote workFlexible hoursNight shiftWeekend work- HackerOne, a leader in offensive security solutions, is seeking a Product Security Analyst to work with top security researchers. This role involves evaluating vulnerability reports, reproducing vulnerabilities in applications, and ensuring quality communication. The ideal...SuggestedRemote jobFlexible hours
$85k
Job Description The Senior Security Operations Center Analyst will be responsible for planning and implementing security measures to protect computer... ...more experience in information security administration, offensive tactics, monitoring, and IR. required. Three (3) years...Full timeWork at office- ...and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.Job Title: Network Security Analyst 1Location(s): Austin, TX Summary: A public-sector transportation agency is seeking a Network Security Analyst I to...
$30 - $35 per hour
Job Description A customer of Insight Global is looking to hire a Security Analyst to come onboard! This individual will support enterprise vulnerability management efforts by coordinating remediation activities across multiple engineering teams, validating vulnerability...- Insight Global is seeking a Security Analyst to support enterprise vulnerability management by coordinating remediation across engineering teams, validating findings, and ensuring SLA compliance. You will review data in Ivanti, track risk in Archer GRC, create Jira tickets...
- ...CAPPS Program. Responsible for the IAM (TDIS) and ERP (CAPPS) security framework, which includes but is not limited to: Provides oversight... ...and processes. 5 Required Experience serving in a security analyst role with responsibility overseeing a Managed Services provider...Contract workWork at officeLocal area
$75k - $95k
...Overview What You'll Be Doing This Junior Security Analyst role will have client facing responsibilities that encompass security analyst, engineering, and operations skill sets. Responsibilities include ensuring security and FISMA compliance of Cadmus's client's...Permanent employmentWork experience placementLocal areaWorldwide- ...together Simplicity is our strength Our reputation is priceless Hard work pays of AlertMedia is looking for an IT Security Analyst to join our Information Security team. This is a hands-on, tier one role for someone building a career in security operations...Work at officeFlexible hours
- ...Security Operations Center Analyst Austin, Texas Description Sygnia is a top-tier cyber technology and services company that partners with organizations around the world to proactively strengthen their cyber resilience and respond to advanced threats. We help...
- ...Senior SecOps Analyst Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art... ...detection and response operations, triaging and investigating security alerts across endpoint, cloud, identity, network, and SaaS telemetry...Permanent employmentTemporary workWork at office
- ...(USVs) to enhance maritime operations for defense and national security. We're looking for a hands-on Security Engineer to join our Security... ...senior engineers in building response playbooks, runbooks, and analyst workflow documentation ~ Run targeted threat hunts to...Permanent employmentTemporary workInternshipWork at office
- ...Network Security Analyst Location: Austin, TX Duration: 12 Months A network security analyst ensures that information systems and computer networks are secure. This includes protecting the company against hackers and cyber-attacks, as well as monitoring network...Shift work
- ...Network Security Analyst 1 Austin, Texas 78751 (Onsite) 7 months Contract with possibility to extension Administer and Operate a RSA Netwitness Platform, a SIEM cyber security tool. The interview and job is onsite. Candidate Skills and Qualifications:...Contract workTemporary work
- ...Job Title Key Responsibilities Demonstrate strong knowledge in IT controls, risk assessments, and testing of security measures Identify opportunities to continuously innovate and improve the program and value delivered to organization Ensure successful...
- ...Job Description Job Description Description: The Senior IT & Security Governance Analyst is responsible for advancing technology governance, security, and operational maturity initiatives across corporate IT, cloud and product environments, and operational systems...
- ...NAVA Software solutions is looking for a Data Security Analyst Details: Data Security Analyst Location : Austin, TX (Hybrid, 3 days onsite) Duration: 12 months Details: Data Security analyst tasked with implementing and operating IT security...Bank staff
- A leading fintech firm in Austin is looking for a detail-oriented Analyst to support software applications within the organization. In this role, the Analyst will collaborate with teams to troubleshoot application issues, manage Epic Configuration, and ensure solutions...
- As an Entry-Level Security Engineer at Epicor, you will be part of a dynamic Security Engineering team where you will help protect enterprise systems, applications, and data-including AI-driven systems and services-while gaining hands-on experience across a modern and...Permanent employmentRelocation
- ...come in. Join our team and help us continue to make Cirrus Logic an exceptional place to grow your career! We are seeking a seasoned security professional to join our Information Security team and help strengthen Cirrus Logic’s overall security posture. In this role, you...Full timeWork at officeRemote workWork visa2 days per week
- ...inclusive workplace where people are encouraged to come as they are and do their best work. What We Need 2K Security is looking for a motivated Lead Security Analyst for high-profile incidents, directing the team and effectively communicating with cross-team stakeholders...
- Saronic Technologies is seeking a hands-on Security Engineer to join our Security Operations team in Austin. You will triage security alerts, perform root-cause analysis, and own initial response for scoped incidents across endpoints, cloud, and identity. You will tune...
- ...with diverse backgrounds, experiences, and perspectives to join our network of industry subject matter experts. The Logistics Security Analyst, assigned to one of Pinkerton's largest global clients, will be a part of a diverse team within the centralized hub of prototype...Work at officeLocal areaWeekend work
- ...-level consultant for the CAPPS Program in Texas. The role involves advanced consultative services while ensuring compliance with security frameworks and accessibility standards. Candidates must have extensive experience in Texas public sector roles, technical project...
$30 - $35 per hour
...range $30.00/hr - $35.00/hr Skills & Experience 3-5 years of Security Incident Response, Security Operations Center, and/or threat analysis... ...an enterprise and/or cloud Security SIEM technologies as an analyst Ability to support and work across multiple customer and...Contract workShift workNight shiftWeekend work- AlertMedia, a leading security and risk intelligence company, seeks an IT Security Analyst in Austin to join our Information Security team. This hands‑on role focuses on monitoring, incident response, and securing access across the environment. You will triage alerts in...
- AlertMedia is seeking an IT Security Analyst to join our Information Security team in Austin, TX. This hands-on, tier one role monitors our environment for threats, investigates incidents, and supports SOC 2 and ISO certifications. You will work daily with Microsoft Defender...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!
- rate analyst Austin, TX
- work from home security analyst Austin, TX
- entry level information security analyst Austin, TX
- national security analyst Austin, TX
- application security analyst Austin, TX
- information security analyst Austin, TX
- entry level security analyst Austin, TX
- security analyst Austin, TX
- security operations analyst Austin, TX
- information security compliance analyst Austin, TX


