Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Analyst

Ernst & Young Oman

The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses. Your responsibilities will include supporting the validation of third‑party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards are applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk. Your key responsibilities The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof‑of‑concepts to validate exploitability and determine real‑world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets. The candidate will support third‑party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks and reporting standards within the Vulnerability Discovery and offensive security functions. Skills and attributes for success Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc. Strong attention to detail with a methodical approach to identifying complex attack paths Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context Ability to manage high volumes of testing requests without compromising depth or quality Flexibility to work across diverse technologies, including cloud, applications and infrastructure Effective communication skills to convey technical findings to both technical and non‑technical audiences Familiarity with research techniques and threat intelligence to support proactive risk identification To qualify for the role you must have A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security Hands‑on experience testing applications, APIs, cloud environments and network infrastructure Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques Familiarity with offensive security methodologies and frameworks Experience supporting or performing third‑party risk assessments Strong analytical and problem‑solving skills with the ability to prioritize risks effectively Strong communication and stakeholder management skills Ideally, you’ll also have OWASP training Incident response experience What we look for We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally‑exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization. What we offer you We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is 76,400 to 138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team‑led and leader‑enabled hybrid model. Our expectation is for most people in external, client‑serving roles to work together in person 40‑60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial and emotional well‑being. EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io. #J-18808-Ljbffr Ernst & Young Oman

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Analyst in Washington DC vacancy
  •  ...The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure... 
    Suggested
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Washington DC
    2 days ago
  • $76.4k - $138.6k

     ...central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost...  ...to market and business value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key... 
    Suggested
    Summer holiday
    Local area
    Flexible hours

    EY

    Washington DC
    6 days ago
  • Ernst & Young Oman is seeking an Offensive Security Analyst for the Attack Surface Management team to evaluate and reduce digital exposure through penetration testing. You will identify and assess vulnerabilities across EY’s global attack surface, working to improve security... 
    Suggested
    Flexible hours

    Ernst & Young Oman

    Washington DC
    2 days ago
  • A progressive technology company is seeking an Offensive Security & Code Analysis Engineer. In this role, you will conduct penetration testing and security assessments to identify vulnerabilities in web applications and networks. The ideal candidate should possess 3+ years... 
    Suggested
    Remote job

    Districttechgroup

    Washington DC
    3 days ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ..., including threat analysis, vulnerability assessments, and offensive security techniques Design and solve security-focused... 
    Suggested
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Washington DC
    2 days ago
  • $116k - $175k

     ...are seeking a talented individual to join AIS as a Principal Facility Security Officer. As your initial project assignment, you will support the unique needs of our client as a Personnel Security Analyst. Project Summary The Personnel Security Specialist will support the... 
    Work at office

    AIS (Applied Information Sciences)

    Washington DC
    12 hours ago
  •  ...We are seeking a highly skilled and experienced Security Analyst to join our team. The Security Analyst will be responsible for ensuring the security and protection of our organization's sensitive information and technology systems. This is a full-time position with competitive... 
    Full time

    Vigorcare Pediatric Services

    Arlington, VA
    1 day ago
  • Enterprise credentialing / Smart ID systems IAM integration and identity standards (NIST 800-63, FIPS 201, PKI) RFID, NFC, smart cards Zero Trust architecture and modern authentication (FIDO2, passwordless) Justification This role provides specialized expertise in enterprise...

    Integration International Inc

    Washington DC
    12 hours ago
  • $60k - $130k

    Personnel Vetting (PV) Specialist In this role you will be part of a federal agency team that provides personnel security program support for the vetting, investigation, and adjudication of individuals seeking access to federal employment, national security information... 
    Hourly pay
    Contract work
    For contractors
    Work experience placement
    Work at office
    Local area

    Watermark Risk Management International, LLC

    Washington DC
    2 days ago
  • $110k - $160k

    Defensive Security Analyst - Washington, DC Hybrid, Washington DC SpecterOps is looking for candidates to support Security Operations at a SpecterOps customer site working directly with client personnel and systems. Candidates will independently support the client engineering... 
    Remote work
    Home office
    Monday to Friday
    Flexible hours
    Weekend work

    Specter Ops, Inc.

    Washington DC
    1 day ago
  • Arenatechnologies is seeking an Operations Research Analyst to support systems engineering and testing at our headquarters in Alexandria...  ...along with opportunities to work with DHS and contribute to critical national security initiatives. #J-18808-Ljbffr Arenatechnologies
    Work at office

    Arenatechnologies

    Alexandria, VA
    1 day ago
  • $60k - $130k

    Physical Security Analyst In this role you will be part of the U.S. Coast Guard headquarters team that provides policy and security program support for the security and resilience of critical USCG missions, infrastructures, and assets. In this high visibility, demanding... 
    Contract work
    Local area
    Worldwide

    Watermark Risk Management International, LLC

    Washington DC
    3 days ago
  •  ...located in the Metropolitan Police Department (MPD), Homeland Security Branch (HSB), Joint Strategic and Tactical Analysis Command Center...  ...and domestic security intelligence. This Homeland Security Analyst position is covered under the National Association of Government... 
    Temporary work
    Work experience placement
    Work at office
    Local area
    Worldwide
    Shift work
    Rotating shift
    Weekend work

    DC Government

    Washington DC
    1 day ago
  • The Naval Facilities Engineering Systems Command (NAVFAC) is seeking a Program Analyst (Global Portfolio Manager) in Washington, DC. This role involves managing Security Cooperation and Security Assistance programs throughout their life cycle. As a Program Analyst, you... 

    Naval Facilities Engineering Systems Command (NAVFAC)

    Washington DC
    3 days ago
  •  ...: Washington, DC Overtime Exempt: Yes Reports To: ARMADA HQ Security Clearance Required: Secret Clearance CONTINGENT UPON AWARD****...  ...**** Duties & Responsibilities The Physical Security (PHYSEC) Analyst provides expert-level support for physical security policy development... 
    Full time
    For contractors
    Work at office
    Local area
    Relocation

    ARMADA, Ltd.

    Washington DC
    12 hours ago
  • A security solutions provider in Washington, DC is seeking a Personnel Security Specialist II to support FBI investigations by processing e-QIP packets and conducting analysis. This role requires a Bachelor's Degree and a Current Top Secret security clearance, along with... 

    Protection Strategies Incorporated

    Washington DC
    4 days ago
  •  ...Security Analyst – Forensics/Malware Analysis Full-time Clearance Requirement: Secret Founded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions,... 
    Full time
    Contract work
    Work at office
    Worldwide
    Monday to Friday
    Weekend work
    Afternoon shift

    SOSi

    Washington DC
    3 days ago
  • $80 per hour

     ...Request-ID: 27419-1 ***Onsite Washington - DC *** Max rate $80 SENIOR SECURITY ANALYST (ARTIFICIAL INTELLIGENCE) Job Summary As a Senior Security Analyst specializing in Artificial Intelligence (AI), you will play a crucial role in safeguarding our AI systems... 
    Work experience placement

    Keylent Inc

    Washington DC
    2 days ago
  • $136k - $187k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted...  ...customers so they can effectively manage their risk. As a senior level analyst of Customer Assurance, you will support prioritizing and... 
    Work experience placement
    Local area
    Worldwide
    Flexible hours

    Okta, Inc.

    Washington DC
    2 days ago
  • $30 - $33 per hour

     ...Insight Global is seeking a Jr. Security Specialist in Arlington, Virginia to support the security of the Joint Worldwide Intelligence Communications Systems at the Pentagon. The role involves assisting DoD personnel with clearance issues, running DISS queries, and providing... 
    Hourly pay
    Worldwide

    Insight Global

    Arlington, VA
    2 days ago
  •  ...IT Security Analyst 2 Individual is able to work without assistance; is able to manage medium complexity work efforts; has some industry experience; can provide limited leadership to others. Maximum Vendor Submittal Rate is $$/hr. Job Description: The IT Security... 
    For contractors

    InstantServe LLC

    Washington DC
    12 hours ago
  • $86.8k - $198k

     ...The Opportunity As a systems security analyst, you know the key to detecting and deterring malicious activity is quality risk‑based intel that maps to a tactical behavior. At Booz Allen you can apply your expertise to investigate the most pressing systems security impacting... 
    Local area

    Phase2 Technology

    Alexandria, VA
    2 days ago
  •  ...Category: OPS \Employee Type: Exempt \Required Degree: 4 Year Degree \Travel Requirement: 100% \Description \ As a Senior Security Operations Analyst, you play a critical role in safeguarding our organization's digital assets. You lead efforts to detect, analyze, and... 
    Temporary work
    Local area
    Flexible hours

    Goebel Fixture Company

    Washington DC
    2 days ago
  • $166k - $220k

     ...networking technology to the military in months, not years. ABOUT THE TEAM Anduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defense technologies. As a SecOps Analyst on the detection and response team,... 
    Full time
    Work experience placement
    Relocation package

    Slope

    Washington DC
    3 days ago
  •  ...Security Operations Center (SOC) Analyst Washington, District of Columbia, United States About the job Security Operations Center (SOC) Analyst Job Description: We are seeking a skilled and detail-oriented Security Operations Center (SOC) Analyst to join our team. As... 

    10xTalents

    Washington DC
    4 days ago
  •  ...Looking for an innovative organization and the opportunity to learn and grow professionally? We can help! We are seeking a IT Security Operations Analyst for the IT Technology Services contract. This project will provide IT service desk, systems, network, and security... 
    Full time
    Contract work
    Part time
    Work at office
    Remote work
    Monday to Friday

    Terrestris Global Solutions

    Washington DC
    3 days ago
  •  ...Senior Security Operations Center (SOC) Analyst We seek a highly motivated Senior Security Operations Center (SOC) Analyst to join our dynamic team. This vital role involves supporting the security of enterprise-wide information systems through comprehensive monitoring... 
    Immediate start
    Flexible hours

    Novul Solutions

    Alexandria, VA
    2 days ago
  • $102.06k - $158.18k

     ...inadvertent access, harm, or destruction. The primary responsibilities include assisting in the development and implementation of security standards, procedures and guidelines for multiple platforms and diverse systems environment. The incumbent updates, maintains, and... 
    Night shift

    National Education Association

    Washington DC
    2 days ago
  • $100k - $121k

     ...address their most significant and complex challenges in science, security and sustainability. Our people apply undaunted curiosity,...  ...than 70 countries across all 7 continents. The Data Security Analyst specializes in securing enterprise data warehouses; ETL/ELT pipelines... 
    Hourly pay
    Contract work
    Local area

    Amentum

    Washington DC
    1 day ago
  •  ...Location: Washington, DC Overtime Exempt: Yes Reports To: ARMADA HQ Security Clearance Required: Secret Clearance Conditional: Contingent upon award Duties & Responsibilities The Information Security Analyst provides expert‑level support for information security policy... 
    Full time
    For contractors
    Work at office
    Local area
    Relocation

    Armada

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!