Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber - Attack & Penetration Testing - Senior - Consulting

$125.8k - $209.7k

Ernst & Young Oman

Location: Anywhere in Country At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. The Opportunity Cyber threats, social media, artificial intelligence, privacy requirements, and continuity of the business as usual require heavy information security measures. As a Senior Attack & Penetration Tester, you will contribute to our client’s resilience through the execution of sophisticated offensive security operations. Your key responsibilities As a Senior on the Attack & Penetration Testing team, you will plan, lead, and execute complex penetration testing and advanced red team engagements across diverse client environments. You will apply an intelligence‑led, threat‑informed approach to emulate realistic adversary behaviors, identify exploitable attack paths, and evaluate preventive, detective, and responsive security controls. Your work will span external and internal networks, Active Directory, Microsoft Entra ID, web and mobile applications, application programming interfaces (APIs), cloud environments, wireless networks, social engineering, and physical security scenarios, as permitted by the rules of engagement. You will translate technical testing results into clear, actionable insights for technical and executive audiences. You will work collaboratively with client technical teams to validate identified weaknesses and develop practical remediation or mitigation strategies, including Active Directory security improvements, system‑hardening measures, and compensating controls aligned with the client environment and operational constraints. You will also lead technical workstreams, coordinate testing activities, mentor junior team members, contribute to methodology and capability development, and remain current on emerging vulnerabilities, adversary tactics, offensive security tooling, and industry research. Skills and attributes for success To thrive in this role, you'll need a blend of technical and business skills, along with the ability to navigate complex problems and make informed decisions. Your professional knowledge and experience will guide you in adhering to broad policies and tackling issues with in‑depth evaluations. Demonstrate advanced problem‑solving and critical‑thinking skills when developing and executing attack paths. Plan and conduct penetration tests and advanced red team engagements within defined scopes, rules of engagement, and safety constraints. Identify, validate, and exploit vulnerabilities across external and internal networks, Active Directory, Microsoft Entra ID, cloud, wireless, web, mobile, and API environments. Apply threat‑informed testing techniques aligned with the MITRE ATT&CK framework and relevant adversary tactics, techniques, and procedures. Lead technical testers, coordinate distributed workstreams, and provide hands‑on coaching and quality review for junior team members. Recognize when to esc… Produce high‑quality technical work products, evidence, client reports, and executive‑ready presentations that clearly explain risk and remediation priorities. Communicate complex offensive security concepts clearly to technical stakeholders, business leaders, and executives. Work collaboratively in cross‑functional, culturally diverse, and geographically dispersed teams while adhering to service quality and engagement management requirements. To qualify for the role, you must have: A bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Management Information Systems, Information Technology, Engineering, or a related field, and at least five years of relevant offensive security experience. Hands‑on experience planning and executing advanced red team engagements, including adversary emulation, objective‑based operations, attack‑path development, and testing against mature security monitoring and response capabilities. Advanced experience conducting external and internal network penetration testing, including host and service enumeration, exploitation, privilege escalation, lateral movement, and post‑exploitation activities. Experience assessing Active Directory environments, including domain and trust configurations, privileged access, authentication protocols, delegation, Group Policy, credential exposure, certificate services, security configurations, and other identity‑based attack paths. Experience performing cloud security testing, including identity and access management, exposed services, configuration weaknesses, privilege escalation, and attack‑path analysis. Experience conducting wireless security assessments, including enterprise and guest wireless configurations, authentication controls, segmentation, and authorized wireless attack techniques. Experience testing web applications, mobile applications, and APIs using manual techniques and industry‑recognized testing methodologies. Experience evaluating security configurations and system‑hardening requirements and working with client technical teams to develop practical remediations, mitigations, compensating controls, and validation approaches for identified findings. Experience with scripting or programming languages used to automate testing, analyze data, or develop offensive security tooling, such as Python, PowerShell, Bash, C#, Go, Rust, or Java. Experience using commercial and open‑source penetration testing tools while adapting techniques to client‑specific environments and constraints. Familiarity with endpoint detection and response (EDR), security information and event management (SIEM), network monitoring, and other defensive controls, including how those controls influence authorized stealth and evasion testing. Experience with red team command‑and‑control (C2) platforms and associated operational infrastructure, payload development, redirectors, logging, and campaign management. Experience evaluating and bypassing EDR and other defensive controls during explicitly authorized engagements, including memory, execution, credential access, lateral movement, and persistence techniques designed for stealth testing against mature client environments. Working knowledge of the MITRE ATT&CK framework, current vulnerabilities, exploits, adversary tactics, techniques, and procedures, and security remediation practices. Experience leading remote and on‑site technical teams, managing testing activities within approved rules of engagement, and communicating testing risks or potential operational impacts. The ability to develop clear technical findings that describe evidence, exploitation paths, business risk, and actionable remediation guidance. Any two relevant offensive security certifications, such as Offensive Security Certified Professional (OSCP), Offensive Security Wireless Professional (OSWP), Offensive Security Experienced Penetration Tester (OSEP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), GIAC Mobile Device Security Analyst (GMOB), GIAC Cloud Penetration Tester (GCPN), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Red Team Professional (GRTP), GIAC Defending Advanced Threats (GDAT), Certified Red Team Operator (CRTO), Certified Red Team Professional (CRTP), Certified Red Team Expert (CRTE), CREST Registered Penetration Tester (CREST CRT), or Certified Cybersecurity Attack Specialist (CCSAS). A valid U.S. driver's license and the willingness and flexibility to travel up to 80 percent, domestically and internationally, to meet client needs. Ideally, you’ll also have Hands‑on cloud penetration testing and identity security assessment experience across Amazon Web Services (AWS), Microsoft Azure, Microsoft Entra ID, and Google Cloud Platform (GCP), including cloud‑native identity, privileged access, service, configuration, and privilege‑escalation attack paths in hybrid and fully cloud‑based environments. Experience assessing Microsoft Entra ID environments, including identity and access management, privileged roles, authentication controls, application registrations, service principals, conditional access, external identities, and cloud‑based attack paths for clients operating fully in the cloud without on‑premises Active Directory infrastructure. Experience applying artificial intelligence (AI) and machine learning capabilities to support testing, including developing automation for reconnaissance, analysis, evidence processing, repeatable test execution, and offensive security workflows. Advanced experience with API and application security testing, including authentication, authorization, business logic, data exposure, injection, and platform‑specific attack paths. Experience evaluating security baselines and hardening standards for Windows, Linux, cloud, and identity environments and helping clients prioritize remediation activities based on risk, feasibility, and operational impact. Experience conducting authorized social engineering and physical penetration testing to evaluate personnel, facility, and access‑control risks. This includes direct interaction with targeted personnel to assess susceptibility to credential disclosure, unauthorized access requests, and controlled execution of remote access tooling used for command‑and‑control testing, as well as evaluating physical security controls through lock bypass, access‑control evasion, automated security system testing, tailgating, and radio‑frequency identification (RFID) badge cloning techniques. The ability to develop custom tooling, modify public exploits, build proof‑of‑concept code, and safely operationalize new offensive techniques. Contributions to the security community through research, public vulnerability disclosures, bug bounty acknowledgments, open‑source projects, conference presentations, publications, or technical blogs. Strong knowledge of Windows, Linux, Unix, TCP/IP networking, common enterprise protocols, and modern identity and security architectures. Exemplary verbal and written communication skills, including the ability to facilitate workshops and translate complex technical information into concise, executive‑level deliverables. Proficiency with consulting engagement methodologies, including estimating effort, prioritizing activities, managing dependencies, and aligning technical testing to client objectives. What we look for We seek top performers with a passion for cybersecurity and a proven track record of success. Ideal candidates are those who demonstrate agility, critical thinking, and the ability to work collaboratively in a dynamic environment. What we offer you At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment, and an inclusive culture. Learn more at ey.com/us/careers . The salary range for this job is: New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices – $125,800 to $209,700 Bay Area California offices – $131,100 to $218,500 All other offices locations in the US, including Sacramento – $104,800 to $192,200 Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. EY | Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi‑disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. All in to shape the future with confidence. EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io . #J-18808-Ljbffr Ernst & Young Oman

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Cyber - Attack & Penetration Testing - Senior - Consulting in Austin, TX vacancy
  • $105.4k - $207.8k

     ...Summary Our Deloitte Cyber team understands the...  ...content and testing; provide guidance on response...  ..., Threat Intelligence, Penetration Testing, etc.Knowledge...  ...understanding of possible attack activities such as network...  ...-level employees to senior leaders, we believe there... 
    Cyber
    Senior
    Work at office
    Local area
    Visa sponsorship
    Shift work
    Rotating shift

    Deloitte

    Austin, TX
    2 days ago
  • $105.4k - $207.8k

     ...Summary Our Deloitte Cyber team understands the unique...  ...firewalls, Threat Intelligence, Penetration Testing, etc.Extensive knowledge of...  ...of possible attack activities such as network probing...  ...From entry-level employees to senior leaders, we believe there’s... 
    Cyber
    Senior
    Local area
    Visa sponsorship
    Shift work
    Rotating shift

    Deloitte

    Austin, TX
    20 hours ago
  • $150k

     ...WashingtonWho We AreBoston Consulting Group (BCG) is a global consulting...  ...You'll DoAs a Cybersecurity Senior AI Tech Consultant, you'll...  ...IT architectures.Utilizing cyber risk quantification to...  ...vulnerability assessmentsPerforming penetration testing, incident management, BCP,... 
    Cyber
    Senior
    Work at office
    Local area

    The Boston Consulting Group

    Austin, TX
    3 days ago
  • $132.5k - $338.3k

     ...will help companies build cyber resilience to grow with confidence...  ...compliance. Interacts with senior client and Accenture...  ...:Experience in IT Security Testing (e.g., penetration testing, web application security...  ...assets across Strategy & Consulting, Technology, Operations,... 
    Cyber
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Austin, TX
    13 hours ago
  • $78.68k - $157.88k

     ...Assurance Information Technology Auditor - Senior Consultant Do you thrive in times of disruption?...  ...reputation, and financial risks to operational, cyber, and regulatory risks—to gain...  ...deliverables, reports, presentations, and test controls in a fast-paced environmentDemonstrated... 
    Cyber
    Senior
    Work experience placement
    Work at office
    Local area
    Visa sponsorship

    Deloitte

    Austin, TX
    4 days ago
  • $141.2k - $278.3k

     ...Oracle, data and analytics, cyber, engineering, industry, and cloud...  ..., code scanning, automated testing, and AI-assisted delivery...  ...Required Qualifications Experienced Consultant 8+ years.Five or more years...  ...entry-level employees to senior leaders, we believe there’s always... 
    Cyber
    Senior
    Full time
    Local area
    Flexible hours

    Deloitte

    Austin, TX
    20 hours ago
  •  ...help companies build cyber resilience to grow with...  ...AreThis is not a security consulting role. It is not a...  ...position. It is not a pen test engagement. A...  ...own outcomes: reduced attack surface, production-safe...  ...offensive security / penetration testing, or GRCMinimum... 
    Cyber
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Austin, TX
    2 days ago
  •  ...today's most sophisticated cyber threats - both known and unknown...  ...- and host-based firewalls, penetration-testing tools, or technologies used...  ...Denial-of-Service (DDoS) attacks, and malicious-code activity...  ...From entry-level employees to senior leaders, we believe there’s... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Austin, TX
    4 days ago
  • $125.8k - $209.7k

     ...to build a better working world. The Opportunity As a Cyber AI Engineer at the Senior Consultant level in EY's Cyber practice, you will work as a forward...  ...structured outputs, and build evaluation datasets and test harnesses to measure accuracy, false positives, task completion... 
    Cyber
    Senior

    Ernst & Young Oman

    Austin, TX
    4 days ago
  • As a Senior Offensive Security Consultant on our Cyber Defense team, you will get the opportunity to lead adversarial testing engagements for clients across a range...  ...to-day may include: Penetration Testing: Plan and...  ...run, threat-informed attack simulations to validate... 
    Cyber
    Senior
    Internship
    Seasonal work
    Work at office
    Local area
    Flexible hours
    3 days per week

    Grant Thornton

    Austin, TX
    20 hours ago
  •  ...for adversary emulations that test current capabilities, processes...  ...and documentation, drive new cyber detection capability, and establish...  ...for strategic hunts. The Senior Cybersecurity Engineer will perform...  ...AWS, GCP, and Azure-related attack validation and infrastructure... 
    Cyber
    Senior
    Full time
    Local area
    Work from home
    Relocation package

    General Motors

    Austin, TX
    3 days ago
  • $105.4k - $207.8k

     ...Summary Non-Human Identity Senior ConsultantJoin Deloitte’s Cyber team to help clients secure the machine...  ...identities have become a growing attack surface. We work with clients to...  ...be available.Preferred:1+ year of consulting experienceExperience with at least... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Austin, TX
    3 days ago
  • $163.04k - $224.18k

     ...together.We are looking for a Senior Staff GRC Analyst to own Procore's Cyber Essentials and Cyber...  ...the risk of common attacks that could disrupt our customers...  ...requests, and technical testing. Well-run audits mean...  ...compliance, or security consulting, including end-to-end... 
    Cyber
    Senior
    Full time
    Work experience placement
    Work at office
    Local area

    Procore Technologies

    Austin, TX
    20 hours ago
  •  ...Are you passionate about shaping the cyber and organizational risk posture of leading...  ...) in Cyber Foundry, you will provide senior leadership to our diverse teams of passionate...  ...firewalls, threat intelligence, and penetration testing - Bachelor’s degree in computer science... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Austin, TX
    4 days ago
  • $128.65k - $214.34k

     ...goals.Job Overview:As a member of the Cyber Security team, an AVP Penetration Tester of Offensive Security will...  ...execution of internal penetration testing with a strong focus on Large Language...  ...the threat presented, and consult on remediation guidance in a way that... 
    Cyber
    Full time
    Work from home

    LPL Financial

    Austin, TX
    2 days ago
  • $87.63k - $177.5k

     ...assignments with limited direction from senior team members. Develops and maintains...  ...third party) through application security testing, penetration testing or other means to ensure...  ...Security+, Network+, CYSA+)ISC2 (Certified in Cyber Security)CERT Insider Threat Program... 
    Cyber
    Senior
    Full time
    Work experience placement

    American Electric Power

    Austin, TX
    3 days ago
  • $185k - $275k

     ...Senior Software Engineering ManagerVectra® is the leader in AI-driven...  ...platform. Powered by patented Attack Signal Intelligence, it...  ...respond to the most advanced cyber-attacks. With 35 patents in AI...  ...tools for code understanding, test generation, documentation, operational... 
    Cyber
    Senior
    Worldwide

    Vectra Networks

    Austin, TX
    2 days ago
  •  ...will help companies build cyber resilience to grow with confidence...  .... Interacts with senior management levels at a client...  ...:Experience in IT Security Testing (e.g., penetration testing, web application security...  ...assets across Strategy & Consulting, Technology, Operations,... 
    Cyber
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Austin, TX
    1 day ago
  •  ...Senior Lead Network Engineer II Employment Type...  ...project will also include consultation regarding hardware and...  ...associated systems testing, vulnerability assessments...  ...Experience with penetration testing, vulnerability...  ...testing Experience with cyber threat information... 
    Cyber
    Senior
    Full time
    Local area
    Monday to Friday
    Flexible hours

    Contact Government Services LLC

    Austin, TX
    1 day ago
  • $150k - $190k

     ...platform. Powered by patented Attack Signal Intelligence, it empowers...  ..., and respond to advanced cyber-attacks. Organizations worldwide...  ...cloud infrastructure. As a Senior Software Engineer, you will help...  ...~ Experience with automated testing, CI/CD, production debugging,... 
    Cyber
    Senior
    Work at office
    Worldwide

    Vectra Networks

    Austin, TX
    1 day ago
  •  ...At IBM, the Senior Manager, Cyber Threats inspires, engages and motivates their staff to deliver...  ...of cyber security threats – including attack methods, patterns and practices, adversaries...  ...one of the biggest technology and consulting employers, with many of the Fortune 50... 
    Cyber
    Senior
    Full time
    Contract work
    Temporary work
    Part time
    Shift work
    3 days per week
    1 day per week

    Jobleads-US

    Austin, TX
    20 hours ago
  • Position: RH OpenShift AI Senior Consultant Duration: 188 hours Location: 100% onsite in Greenville, TXDescription:RH OpenShift AI Senior Consultant...  ...minimum/TS preferred. Skillsets: AppDev, App Refactoring, Testing, Pipelines (AI preferred but not required)Applicant Notices &... 
    Senior

    Spectraforce Technologies

    Austin, TX
    2 days ago
  •  ...transform the finance industry together.The Senior Manager, Operational Resilience is...  ...identification, dependency mapping, scenario testing, and resilience measurement. The role also...  ...across business processes, technology, cyber, and third-party dependenciesSupport the... 
    Cyber
    Senior
    Full time
    Work at office

    The Charles Schwab Corporation

    Austin, TX
    1 day ago
  •  ...SaaS risk, and intelligently respond to cyber threats across the business. Based in...  ...Research: Conduct user research and usability testing to gather insights and iterate on designs...  ...-paced environment. This is considered a senior position and you will be Keep Aware's... 
    Cyber
    Senior
    2 days per week
    3 days per week
    1 day per week

    Keep Aware

    Austin, TX
    3 days ago
  •  ...to Deloitte applications while upholding cyber security best practices define the future...  ...multiple data sources.Experience building, testing (functional and robustness), and...  ...development From entry-level employees to senior leaders, we believe there’s always room to... 
    Cyber
    Senior

    Deloitte

    Austin, TX
    13 hours ago
  • $105.4k - $207.8k

    Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities...  ...ends on 12/31/2026.Work you'll doAs a Senior Engineering Management Specialist on the...  ...may be available.Preferred:Previous consulting or Big 4 experienceCyberArk/Beyond Trust/... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Austin, TX
    3 days ago
  •  ...apply now.We are currently seeking a ERP Senior Specialist to join our team in Los...  ...troubleshoot issues, and resolve client problems.Testing and documentation: Support User...  ...data centers and application services. our consulting and Industry solutions help organizations... 
    Senior
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Austin, TX
    2 days ago
  • $195.27k - $225k

     ...listed.***About youAs the SVP of Portfolio Strategy Consulting, Global Occupier Services, you will be a senior, client-facing leader responsible for developing,...  ...Massachusetts to require or administer a lie detector test as a condition of employment or continued... 
    Senior
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    Work from home
    Visa sponsorship
    Work visa
    Flexible hours

    Colliers International

    Austin, TX
    1 day ago
  • $105.4k - $207.8k

    Position Summary AI Security Senior ConsultantOur Deloitte Cyber team understands the unique challenges and opportunities businesses face in...  ..., and proactively manage to secure success.As a Senior Consultant, Strategy, Growth & Transformation in Deloitte Cyber's... 
    Cyber
    Senior
    Local area
    Worldwide
    Visa sponsorship

    Deloitte

    Austin, TX
    2 days ago
  • $163.4k - $322.1k

    Position Summary AI Security Senior ManagerOur Deloitte Cyber team understands the unique challenges and opportunities businesses face in...  ...combined cybersecurity, risk management, or technology consulting experience12+ years of experience advising on Artificial... 
    Cyber
    Senior
    Local area
    Worldwide
    Visa sponsorship

    Deloitte

    Austin, TX
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber - Attack & Penetration Testing - Senior - Consulting. Be the first to apply!