Vulnerability Analyst
$76.4k - $138.6kErnst & Young
At EY, we're all in to shape your future with confidence.
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
As an Offensive Security Analyst on the Vulnerability Management team, you will play a supporting role in the meticulous evaluation and management of EY's digital exposure, working under the guidance of the Vulnerability Exposure Management Lead to identify and mitigate vulnerabilities in the EY digital attack surface. Your responsibilities will include aiding in the assessment and validation of third-party risk assessments and ensuring that EY's security standards are upheld across all digital assets. Additionally, the analyst will influence and implement proactive defense strategies to maintain the integrity and security of the business's digital footprint.
Your key responsibilities
The Analyst will leverage offensive security skills to evaluate the business's digital exposure, identifying and mitigating risks stemming from misconfigurations, vulnerabilities, and mismanaged assets. The candidate will play a crucial role in managing third-party risk assessments and identifying assets susceptible to exploitation and abuse by cyber threat actors. Collaborating closely with multiple functions, the analyst will work to execute the Attack Surface Management strategy to protect EY's digital assets. Additionally, the analyst will emulate cyber threat actors to conduct recon against the EY attack surface to identify threats and advise proactive measures to safeguard the business.
Skills and attributes for success
Expert attention to detail
Aptitude for thinking critically
Ability to handle high volume requests
Flexibility and comfortability pivoting between diverse environments
Developing communication Skills
Familiarity with research methodologies
To qualify for the role you must have
A minimum of 3 years of experience in vulnerability management, red team, or purple team
Familiarity with cloud services, network security, and data protection principles
Well-developed knowledge of offensive security principles
Professional-level analytical and problem-solving skills
Developing ability to translate vulnerability information to business impact
Demonstrated experience with third-party risk assessments
Strong communication and interpersonal skills
Experience providing prioritization recommendations to stakeholders
Ideally, you'll also have
OWASP training
Incident response experience
What we look for
We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business's externally-exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization's ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.
What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $91,700 to $157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.?
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .
- .... Responsibilities include performing internal and external penetration tests, simulating adversarial attacks, and identifying vulnerabilities across systems, networks, and applications. The Penetration Tester will collaborate with security teams to document findings...Suggested
- ...delivering penetration testing across web applications, APIs, infrastructure, and cloud environments. Excellent understanding of common vulnerability classes and attacker techniques, including those aligned to recognised industry guidance. Ability to apply penetration testing...SuggestedPermanent employmentFlexible hours
$500 per month
Become a Professional Game Tester We're looking for passionate gamers to join our elite team of mobile game testers. Get paid to play and test the latest games before they launch. $500+ Avg Monthly Pay 5-10 Hours/Week 100% Remote Position Requirements: ...SuggestedRemote work10 hours per week$104k - $156k
...qualifications: ~ Experience securing cloud-native applications / SaaS solutions and networks. ~ Familiarity with vulnerability scanning and threat protection. ~ Relevant certifications: ~ Microsoft Certified: Azure Security Engineer...SuggestedRemote work$1,000 per month
Join Our Team as a Website Tester at Little Wheel Little Wheel is a gambling technology company focused on researching and building products that put players first. We are currently hiring Website Testers across Michigan, New Jersey, Pennsylvania, and West Virginia...SuggestedExtra incomeTemporary workSecond jobCurrently hiringImmediate startWork from homeFlexible hours$95.5k - $149.2k
Responsibilities Noblis is hiring a Senior Network Security Engineer to support the Information Technology Operations Division (Code 104) at the Naval Surface Warfare Center Philadelphia Division. This team plays a key role in supporting the Navy's mission by delivering...Full timeContract workPart timeLocal areaRemote work- RSA Security LLC in Horsham, Pennsylvania is looking for a Penetration Tester to join the CIO Security team. In this hybrid role, you'll enhance cyber resilience through offensive security testing, protecting customers and systems by identifying risks early. The ideal candidate...Flexible hours
- Virtual Chief Information Security Officer (CISO) About the Company Flourishing provider of market research & business intelligence services Industry Market Research Type Privately Held About the Role The Company is in need of a Virtual...Part time
- ...security changes, with in various levels of an organization, ensuring compliance with published policies; conducting cybersecurity vulnerability and threat analysis; and support cyber incident[1]response by isolating potentially effected assets, initial investigation and...Contract workFor contractors
- ...Plans for assigned systems throughout their lifecycle Manage and maintain Plan of Actions and Milestones (POA&M), tracking vulnerabilities through remediation Assist with identification of security control baselines and applicable overlays Coordinate the...For contractors
- ...potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. Maintain... ...of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development, including...Full timeLocal areaFlexible hours
- ...cybersecurity for DoD systems. Implement and monitor security controls, ensuring adherence to NIST 800-53 and DoD policies. Conduct vulnerability assessments, threat analyses, and continuous monitoring using tools like ACAS, STIG Viewer, and eMASS. Support incident...Full timeContract workWork at officeLocal areaImmediate startWorldwideRelocation packageNight shift
- Chief Information Security Officer (CISO) About the Company Mission-driven online provider of musculoskeletal therapy Industry Health, Wellness and Fitness Type Privately Held, VC-backed Founded 2015 Employees 501-1000 Funding $200+ million ...
$115k - $125k
...limited process, ensuring consistency and transparency across security-related activities Conduct regular security assessments, vulnerability scans, and penetration testing to identify and mitigate risks Develop and maintain security documentation, including System...Full timePart timeWork at office- By joining Sedgwick, you'll be part of something truly meaningful. It’s what our 33,000 colleagues do every day for people around the world who are facing the unexpected. We invite you to grow your career with us, experience our caring culture, and enjoy work-life balance...Work at officeLocal area
$99k - $232k
...cybersecurity focus on protecting organizations from cyber threats through advanced technologies and strategies. They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data. Those in security architecture at PwC...Full timeH1b$89.4k - $161.3k
At T-Mobile, we invest in YOU! Our Total Rewards Package ensures that employees get the same big love we give our customers. All team members receive a competitive base salary and compensation package - this is Total Rewards. Employees enjoy multiple wealth-building opportunities...Full timeTemporary workPart timeWork experience placementLocal areaFlexible hours- ...The Network Analyst will be a member of the Field Infrastructure Services team that provides implementation and technical support for networks and network security solutions that are deployed to connect and secure the mission critical consumer technology solutions and...Remote work
- ...System Analyst Duration: 6+ Months Location: Philadelphia, PA- Hybrid Job Description: This individual will be responsible for providing first-touch technical support on several applications utilized by the Legal and Compliance team, including the following...
$84.2k - $134.6k
...hubs of 2-commerce, law, and government across North America, Asia, Europe, and the Middle East, is seeking to hire an viEval Systems Analyst. Reporting to the Senior Manager of HR Systems and Analytics, the HR Systems Analyst coordinates and manages the Firm's human...Hourly payFull timeTemporary workLocal areaRemote workShift work$104.6k - $138.6k
...discriminatory means. A Brief Overview This role will work exclusively with our Center for Healthcare Quality and Analytics (CHQA). The analyst will work on Patient Reported Outcomes and other qualityimprovementrelated requests. The ideal candidate should have extensive...Full timePart timeFor contractorsWork at officeRemote workShift work- ...Systems Analyst (3003) - Control Center Secure Your Future with SEPTA – A Leader in Transportation! The Southeastern Pennsylvania Transportation Authority (SEPTA) is the sixth-largest transportation system in the U.S., connecting communities across a 2,200-square-mile...Work at office
- ...EAM Systems Analyst III Essential Utilities, Inc. delivers safe, clean, reliable services that improve quality of life for individuals, families, and entire communities. Operating as the Aqua (water and wastewater services) and the Peoples and Delta (natural gas) brands...Work at officeLocal area
$70k - $115k
...Manhattan WMi experiance is preferred. The Sr Operations Systems Analyst (Sr WMS Analyst) role has a national salary range of $70,000 - $115,000. For roles within California the range is $70,304 - $115,000 and Washington is $80,169 - $115,000. DHL Supply Chain...- ...Facets -System Analyst Job Location: Philadelphia, PA / Remote until Covid Job Type: Contract/ Full-time Job Description: Technical consultant -system Integration: Strong technical knowledge in SQL, SSIS, SSRS. Extensive experience with writing batch routines...Full timeContract workWork experience placementRemote work
$99k - $232k
...cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data. In cloud security at PwC, you will be...Full timeH1b- IT/IAM Auditor Conexess Group is aiding a large healthcare client in their search for an IT/IAM Auditor in a hybrid capacity. This is a long-term contract opportunity with a competitive compensation package. *** This position is hybrid in Philadelphia, PA***. Responsibilities...Long term contract
$90k - $100k
...of Public Health's mission is to protect and promote the health of all Philadelphians and to provide a safety net for the most vulnerable. We provide services, set policies, and enforce laws that support the dignity of every man, woman, and child in Philadelphia. We...Contract workWork at officeLocal area- ...Operations Research Analyst Athena Technology Group, Inc. (ATG) is a Service-Disabled Veteran Owned Small Business (SDVOSB) focused on Information Technology and Communications consulting, system engineering, integration, deployment and operation of state of the art...Temporary workWork at office
$100 per hour
...Description Exelon is looking for a mid to senior level Cyber analyst to join their team out of the Philadelphia, Bethesda MD or... ...as they will be reviewing and analyzing apps data for vulnerabilities. The team is responsible for project and operational support...Hourly payContract workTemporary work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Analyst. Be the first to apply!

