Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber - AI-Enabled Vulnerability Management - Senior - Consulting

$104.8k - $218.5k
Full-time

Ernst & Young

Location: Anywhere in Country

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The Opportunity

Cyber threats, social media, artificial intelligence, privacy requirements, and continuity of the business as usual require heavy information security measures. As a Senior Attack & Penetration Tester, you will contribute to our client’s resilience through the execution of sophisticated offensive security operations.

Your key responsibilities

As a Senior on the Attack & Penetration Testing team, you will plan, lead, and execute complex penetration testing and advanced red team engagements across diverse client environments. You will apply an intelligence-led, threat-informed approach to emulate realistic adversary behaviors, identify exploitable attack paths, and evaluate preventive, detective, and responsive security controls. Your work will span external and internal networks, Active Directory, Microsoft Entra ID, web and mobile applications, application programming interfaces (APIs), cloud environments, wireless networks, social engineering, and physical security scenarios, as permitted by the rules of engagement. You will translate technical testing results into clear, actionable insights for technical and executive audiences. You will work collaboratively with client technical teams to validate identified weaknesses and develop practical remediation or mitigation strategies, including Active Directory security improvements, system-hardening measures, and compensating controls aligned with the client environment and operational constraints. You will also lead technical workstreams, coordinate testing activities, mentor junior team members, contribute to methodology and capability development, and remain current on emerging vulnerabilities, adversary tactics, offensive security tooling, and industry research.

Skills and attributes for success

To thrive in this role, you'll need a blend of technical and business skills, along with the ability to navigate complex problems and make informed decisions. Your professional knowledge and experience will guide you in adhering to broad policies and tackling issues with in-depth evaluations.

  • Demonstrate advanced problem-solving and critical-thinking skills when developing and executing attack paths.
  • Plan and conduct penetration tests and advanced red team engagements within defined scopes, rules of engagement, and safety constraints.
  • Identify, validate, and exploit vulnerabilities across external and internal networks, Active Directory, Microsoft Entra ID, cloud, wireless, web, mobile, and API environments.
  • Apply threat-informed testing techniques aligned with the MITRE ATT&CK framework and relevant adversary tactics, techniques, and procedures.
  • Lead technical testers, coordinate distributed workstreams, and provide hands-on coaching and quality review for junior team members.
  • Recognize when to escalate risks, issues, testing impacts, and opportunities to appropriate client and EY leadership.
  • Produce high-quality technical work products, evidence, client reports, and executive-ready presentations that clearly explain risk and remediation priorities.
  • Communicate complex offensive security concepts clearly to technical stakeholders, business leaders, and executives.
  • Work collaboratively in cross-functional, culturally diverse, and geographically dispersed teams while adhering to service quality and engagement management requirements.

To qualify for the role, you must have:

  • A bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Management Information Systems, Information Technology, Engineering, or a related field, and at least five years of relevant offensive security experience.
  • Hands-on experience planning and executing advanced red team engagements, including adversary emulation, objective-based operations, attack-path development, and testing against mature security monitoring and response capabilities.
  • Advanced experience conducting external and internal network penetration testing, including host and service enumeration, exploitation, privilege escalation, lateral movement, and post-exploitation activities.
  • Experience assessing Active Directory environments, including domain and trust configurations, privileged access, authentication protocols, delegation, Group Policy, credential exposure, certificate services, security configurations, and other identity-based attack paths.
  • Experience performing cloud security testing, including identity and access management, exposed services, configuration weaknesses, privilege escalation, and attack-path analysis.
  • Experience conducting wireless security assessments, including enterprise and guest wireless configurations, authentication controls, segmentation, and authorized wireless attack techniques.
  • Experience testing web applications, mobile applications, and APIs using manual techniques and industry-recognized testing methodologies.
  • Experience evaluating security configurations and system-hardening requirements and working with client technical teams to develop practical remediations, mitigations, compensating controls, and validation approaches for identified findings.
  • Experience with scripting or programming languages used to automate testing, analyze data, or develop offensive security tooling, such as Python, PowerShell, Bash, C#, Go, Rust, or Java.
  • Experience using commercial and open-source penetration testing tools while adapting techniques to client-specific environments and constraints.
  • Familiarity with endpoint detection and response (EDR), security information and event management (SIEM), network monitoring, and other defensive controls, including how those controls influence authorized stealth and evasion testing.
  • Experience with red team command-and-control (C2) platforms and associated operational infrastructure, payload development, redirectors, logging, and campaign management.
  • Experience evaluating and bypassing EDR and other defensive controls during explicitly authorized engagements, including memory, execution, credential access, lateral movement, and persistence techniques designed for stealth testing against mature client environments.
  • Working knowledge of the MITRE ATT&CK framework, current vulnerabilities, exploits, adversary tactics, techniques, and procedures, and security remediation practices.
  • Experience leading remote and on-site technical teams, managing testing activities within approved rules of engagement, and communicating testing risks or potential operational impacts.
  • The ability to develop clear technical findings that describe evidence, exploitation paths, business risk, and actionable remediation guidance.
  • Any two relevant offensive security certifications, such as Offensive Security Certified Professional (OSCP), Offensive Security Wireless Professional (OSWP), Offensive Security Experienced Penetration Tester (OSEP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), GIAC Mobile Device Security Analyst (GMOB), GIAC Cloud Penetration Tester (GCPN), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Red Team Professional (GRTP), GIAC Defending Advanced Threats (GDAT), Certified Red Team Operator (CRTO), Certified Red Team Professional (CRTP), Certified Red Team Expert (CRTE), CREST Registered Penetration Tester (CREST CRT), or Certified Cybersecurity Attack Specialist (CCSAS).

A valid U.S. driver's license and the willingness and flexibility to travel up to 80 percent, domestically and internationally, to meet client needs.

Ideally, you’ll also have

Hands-on cloud penetration testing and identity security assessment experience across Amazon Web Services (AWS), Microsoft Azure, Microsoft Entra ID, and Google Cloud Platform (GCP), including cloud-native identity, privileged access, service, configuration, and privilege-escalation attack paths in hybrid and fully cloud-based environments.

  • Experience assessing Microsoft Entra ID environments, including identity and access management, privileged roles, authentication controls, application registrations, service principals, conditional access, external identities, and cloud-based attack paths for clients operating fully in the cloud without on-premises Active Directory infrastructure.
  • Experience applying artificial intelligence (AI) and machine learning capabilities to support testing, including developing automation for reconnaissance, analysis, evidence processing, repeatable test execution, and offensive security workflows.
  • Advanced experience with API and application security testing, including authentication, authorization, business logic, data exposure, injection, and platform-specific attack paths.
  • Experience evaluating security baselines and hardening standards for Windows, Linux, cloud, and identity environments and helping clients prioritize remediation activities based on risk, feasibility, and operational impact.
  • Experience conducting authorized social engineering and physical penetration testing to evaluate personnel, facility, and access-control risks. This includes direct interaction with targeted personnel to assess susceptibility to credential disclosure, unauthorized access requests, and controlled execution of remote access tooling used for command-and-control testing, as well as evaluating physical security controls through lock bypass, access-control evasion, automated security system testing, tailgating, and radio-frequency identification (RFID) badge cloning techniques.
  • The ability to develop custom tooling, modify public exploits, build proof-of-concept code, and safely operationalize new offensive techniques.
  • Contributions to the security community through research, public vulnerability disclosures, bug bounty acknowledgments, open-source projects, conference presentations, publications, or technical blogs.
  • Strong knowledge of Windows, Linux, Unix, TCP/IP networking, common enterprise protocols, and modern identity and security architectures.
  • Exemplary verbal and written communication skills, including the ability to facilitate workshops and translate complex technical information into concise, executive-level deliverables.

Proficiency with consulting engagement methodologies, including estimating effort, prioritizing activities, managing dependencies, and aligning technical testing to client objectives.

What we look for

We seek top performers with a passion for cybersecurity and a proven track record of success. Ideal candidates are those who demonstrate agility, critical thinking, and the ability to work collaboratively in a dynamic environment.

What we offer you
At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment and an inclusive culture. Learn more at ey.com/us/careers.

  • The salary range for this job is:
    • New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices – $125,800 to $209,700
    • Bay Area California offices – $131,100 to $218,500
    • All other offices locations in the US, including Sacramento – $104,800 to $192,200
  • Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.

Are you ready to shape your future with confidence? Apply today.

  • To make the most of your application experience, please limit yourself to two applications within a six-month period.
  • EY accepts applications for this position on an on-going basis.
  • For those living in California, please click here for additional information.
  • At EY, our values set the foundation for how we work and the behaviors we expect of our people. Any misrepresentation or falsification of information or lack of integrity at any point in the recruiting process may result in withdrawal of your candidacy, revocation of an offer or immediate termination of employment.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

All in to shape the future with confidence.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on aiapply.co.

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Cyber - AI-Enabled Vulnerability Management - Senior - Consulting in Georgia vacancy
  • $144.9k - $302.1k

     ...opportunity Cyber threats, social...  ...measures. As a Manager in the Attack &...  ...potential threats and vulnerabilities to enteprise...  ...role in mentoring senior and junior...  ...capital markets. Enabled by data, AI and advanced...  ...services in assurance, consulting, tax, strategy... 
    Cyber
    Full time
    Work experience placement
    Immediate start
    Remote work

    EY

    Georgia
    2 days ago
  • $104.8k - $218.5k

     ...Artificial Intelligence (AI) is rapidly...  ...governance, and risk management challenges. Organizations...  ...technologies. As a Senior Consultant within EY’s Cyber practice focused on...  ...frameworks that enable organizations to...  ...infrastructure, identify vulnerabilities inherent to AI... 
    Cyber
    Senior
    Full time
    Immediate start

    EY

    Georgia
    5 days ago
  • $170.6k - $390k

     ...working world. National Consulting – Microsoft Enterprise Platform – Senior Manager (Architect & Solution...  ...this capability across AI, Security, and Cloud domains...  ...Copilot Security Cyber Security Data...  ...our team-led and leader-enabled hybrid model. Our expectation... 
    Cyber
    Senior
    Summer holiday
    Work at office
    Flexible hours

    Ernst & Young

    Atlanta, GA
    12 days ago
  • $168.5k - $206k

     ...Solution Architect, Cyber Security Job...  ...Data & Research, Management Consulting, Technology &...  ...identity, data, AI, and enterprise platforms...  ...models that enable secure modernization...  ...and Influence Senior Leaders Serve as...  ...cyber risks and vulnerabilities into business risk... 
    Cyber
    Permanent employment
    Full time
    Work at office
    Local area
    Home office
    3 days per week

    Bain & Company

    Atlanta, GA
    4 days ago
  • $150k

     ...HoustonWho We AreBoston Consulting Group (BCG) is a...  ...Technology Risk Management. Our Tech...  ...limitations, and enable our clients to go...  ...a Cybersecurity Senior AI Tech Consultant,...  ...architectures.Utilizing cyber risk...  ...Designing / implementing vulnerability management, including... 
    Cyber
    Senior
    Work at office
    Local area

    The Boston Consulting Group

    Atlanta, GA
    3 days ago
  •  ...companies build cyber resilience to...  ...application security and managed service...  ...Interacts with senior management...  ...drivers and security enablement opportunities...  ...security assessments, vulnerability assessments and...  ..., data and AI with unmatched...  ...Strategy & Consulting, Technology, Operations... 
    Cyber
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Atlanta, GA
    2 days ago
  • $104.8k - $218.5k

     ...guidance on protecting information, enabling responsible data use, and managing risk. As a Senior within the Data Protection and...  ...is designed for a senior-level consulting professional who can lead...  ...endpoint, cloud, analytics, and AI governance stakeholders in complex... 
    Cyber
    Senior
    Full time
    Immediate start

    EY

    Georgia
    5 days ago
  • $144k - $176k

     ...Global Cybersecurity Senior Manager - Atlanta, United...  ...We Are Boston Consulting Group partners...  ...complex change, enabling organizations to...  ...into enterprise cyber exposure while enabling...  ...and vulnerabilities surfaced across scanning...  ...exposures Leverage AI-powered... 
    Cyber
    Senior
    Work at office
    Local area

    Boston Consulting Group

    Atlanta, GA
    more than 2 months ago
  • $87.72k - $131.58k

     ...currently seeking a Cloud Vulnerability Management Engineer (Onsite Hybrid) to...  ...CD and DevSecOps pipelines, enabling earlier identification of vulnerabilities...  ....Experience applying AI/LLM-based capabilities to...  ...application services. our consulting and Industry solutions help... 
    Full time
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    NTT DATA

    Atlanta, GA
    23 hours ago
  • $168k - $199k

     ...Engagment Manager Cybersecurity About...  ...: Join Gartner Consulting, where insights meet...  ...incident response plans vulnerability management , and...  ...implications of AI, machine learning,...  ...used to transform cyber security offense...  ...and the company, enabling us to multiply our... 
    Cyber
    Worldwide

    Gartner

    Atlanta, GA
    3 days ago
  •  ...Secure, Responsible AI & Data Protection professionals who enable trust, resilience,...  ...applying AI to strengthen cyber defense through...  ...advisors to senior client stakeholders. Each Senior Manager is expected to engage...  ...coaching managers and consultants through... 
    Cyber
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Atlanta, GA
    5 days ago
  • $168.5k - $206k

     ...Analytics, Data & Research, Management Consulting, Technology & Engineering...  ...architectures, and integrate AI to enable scalable end-to-end digital...  ...plans.Advise and Influence Senior Leaders Serve as a trusted...  ..., and senior executives on cyber security strategy, architecture... 
    Cyber
    Permanent employment
    Full time
    Work at office
    Local area

    Bain & Company

    Atlanta, GA
    1 day ago
  • $125k - $175k

     ...Protection Squad as a Senior Data Access Protection...  ...Engineering Specialist in Cyber to oversee the global...  ...that power our Firm, enabling our clients and...  ...security threats and vulnerabilities.What You'll Do In The...  ...Kubernetes).Experience in managing complex vendor relationships... 
    Cyber
    Senior
    Temporary work
    Local area

    Morgan Stanley

    Alpharetta, GA
    3 days ago
  •  ...will help companies build cyber resilience to grow with...  ...security, and managed service solutions to rethink...  ...AreThis is not a security consulting role. It is not a...  ...engineering teams—to make AI systems secure, governed...  ...to creating 360 value, enable us to help our clients... 
    Cyber
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Atlanta, GA
    3 days ago
  • $102k - $140k

     ...Project ManagerTitle: Senior ConsultantLocation: AtlantaWho...  .... Our focus is on enabling predictable, repeatable...  ...across domains (AI, cloud, data, platforms...  ...scalable ways of working. * Manage interdependencies, risks...  ...’ll Bring* 4+ years of consulting experience leading project... 
    Senior
    Temporary work
    Work at office
    Local area

    Slalom

    Atlanta, GA
    3 days ago
  • $148.5k - $247.5k

     ...ArchitectManagement LevelSr Manager - Non People...  ...DescriptionThe Senior Lead Cybersecurity...  ...of non-cyber architecture-related...  ...peers to incorporate vulnerability management, governance...  ...cybersecurity best practices. Consultative nature to work...  ....Collaborate with AI agents to create,... 
    Cyber
    Senior
    Full time
    Remote work
    Visa sponsorship
    Flexible hours

    Cox Enterprises

    Atlanta, GA
    3 days ago
  • $104.8k - $218.5k

     ...build a better working world. Consulting - Cybersecurity - Identity and Access Management - Senior Consultant At EY, we are all...  ...how to leverage firm-approved AI tools in a business setting,...  ...us in our team-led and leader-enabled hybrid model. Our expectation is... 
    Cyber
    Senior
    Full time
    Summer holiday
    Flexible hours

    EY

    Georgia
    2 days ago
  •  ...help companies build cyber resilience to grow...  ...security, and managed service solutions to...  ...there. You've been senior long enough to set...  ...Enterprises are deploying AI agents faster than...  ...-facing or consulting experience, including...  ...creating 360 value, enable us to help our clients... 
    Cyber
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Atlanta, GA
    2 days ago
  • $105.4k - $207.8k

     ...Our Deloitte Cyber team understands the...  ...powerful solutions and managed services that simplify complexity, we enable our clients to operate...  ...at Deloitte Consulting, you will be responsible...  ...emerging capabilities for AI agent and machine-...  ...level employees to senior leaders, we believe... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Atlanta, GA
    2 days ago
  • $245k - $321.3k

     ...in this new era, we seek AI-native thinkers across every...  ...how work gets done.The Senior Delivery Director, Program Management role is part of the...  ...delivered by world class consultants that leverage our leading...  ...scaling our team to help enable and accelerate our growth... 
    Senior
    Work at office
    Remote work

    Snowflake

    Atlanta, GA
    4 days ago
  • $105.4k - $207.8k

     ...Join our Deloitte Cyber team to deliver powerful...  ...Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with...  ...include service accounts, AI agents, bots, API keys,...  .../2026.Work you'll doAs a Senior Engineering Management Specialist... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Atlanta, GA
    4 days ago
  • $170.6k

     ...The Cybersecurity Senior Manager (SM2) is responsible for driving strategic cyber solution development,...  ...priority account growth, and enabling the successful pursuit...  .... Incorporate AI, automation, analytics...  ...Mentor managers, consultants, and solution architects... 
    Cyber
    Senior
    Full time
    Contract work
    Summer holiday
    Immediate start
    Flexible hours

    EY

    Georgia
    5 days ago
  • $104.8k - $218.5k

     ...trust environments. As a Senior within the Data...  ...intended for a senior consulting professional who can lead...  ...under the direction of a Manager or senior architect for...  ...trust, cloud, data, and AI security risks. Skills...  ...capital markets. Enabled by data, AI and... 
    Cyber
    Senior
    Full time
    Immediate start
    Remote work

    EY

    Georgia
    5 days ago
  •  ...transformation investments across AI, cloud, data and...  ...selling.Develop and manage relationships with...  ...modernization, AI, cloud, cyber, and workforce transformation...  ...logo acquisition in a consulting, technology, or...  ...to creating 360 value, enable us to help our clients... 
    Cyber
    Full time
    Contract work
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Atlanta, GA
    4 days ago
  • $116.88k - $148.13k

     ...DescriptionSenior Consultant, Infosys Consulting...  ...Consulting, the management and technology consulting...  ..., including enabling technologies. A key...  ...Industry 4.0, AI/ML, GenAI, IoT, digital...  ...About the RoleThe Senior Consultant role...  ...business processes, cyber-physical systems,... 
    Cyber
    Senior
    Full time
    Temporary work
    Shift work

    Infosys Technologies

    Atlanta, GA
    1 day ago
  • $134.5k - $265.1k

    Position Summary As a Senior Consultant in Deloitte Cyber’s Digital Trust & Privacy practice, you will...  ...data protection challenges through AI-enabled engineering solutions. This role...  ...quality of work product, ability to manage and prioritize multiple tasks in a fast... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Atlanta, GA
    5 days ago
  • $8k

     ...Senior Software Engineer Active Top Secret (TS/...  ...Science and Knowledge Management, Enterprise Risk Management...  ...our nation's cyber infrastructure & providing...  ...Design and deploy agentic AI workflows that...  ...using Python Conduct vulnerability analysis and research... 
    Cyber
    Senior
    Permanent employment
    Contract work
    Temporary work
    Immediate start
    Flexible hours

    ClearanceJobs

    Augusta, GA
    1 day ago
  • $170.6k

     ...complex, organizations require senior leaders who can shape...  ...enterprise. As a Senior Manager within EY's Cyber practice focused on...  ...teams of Managers, Senior Consultants, and Consultants, fostering...  ...in capital markets. Enabled by data, AI and advanced technology,... 
    Cyber
    Senior
    Full time
    Immediate start

    EY

    Georgia
    5 days ago
  • $104.8k - $218.5k

     ...detected and contained. As a Senior Consultant within EY's Cyber practice focused on...  ...support project planning and management activities, mentor junior...  ...about designing security that enables business outcomes,...  ...markets. Enabled by data, AI and advanced technology, EY... 
    Cyber
    Senior
    Full time
    Immediate start

    EY

    Georgia
    5 days ago
  • $171.6k

     ...working world. ServiceNow – ServiceNow AI Architect Senior Manager ​In the digital economy, it takes...  ...decision-making. As a ServiceNow Consulting Senior Manager you will play a...  ...collaborate closely with our clients to enable AI-driven transformation across user... 
    Senior
    Full time
    Summer holiday
    Worldwide
    Flexible hours

    EY

    Atlanta, GA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber - AI-Enabled Vulnerability Management - Senior - Consulting. Be the first to apply!