Offensive Security Analyst
$76.4k - $138.6kEY
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands-on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses.Your responsibilities will include supporting the validation of third-party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk.
Your key responsibilities
The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof-of-concepts to validate exploitability and determine real-world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets.The candidate will support third-party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams, and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks, and reporting standards within the Vulnerability Discovery and offensive security functions.
Skills and attributes for success
Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc.
Strong attention to detail with a methodical approach to identifying complex attack paths
Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context
Ability to manage high volumes of testing requests without compromising depth or quality
Flexibility to work across diverse technologies, including cloud, applications, and infrastructure
Effective communication skills to convey technical findings to both technical and non-technical audiences
Familiarity with research techniques and threat intelligence to support proactive risk identification
To qualify for the role you must have
A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security
Hands-on experience testing applications, APIs, cloud environments, and network infrastructure
Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques
Familiarity with offensive security methodologies and frameworks
Experience supporting or performing third-party risk assessments
Strong analytical and problem-solving skills with the ability to prioritize risks effectively
Strong communication and stakeholder management skills
Ideally, you’ll also have
OWASP training
Incident response experience
What we look for
We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally-exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.
What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $91,700 to $157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .
- A global consulting firm in Cleveland is seeking an Offensive Security Analyst to evaluate and manage its digital security exposure. Your role will involve assessing vulnerabilities, managing third-party risks, and collaborating with teams to implement defense strategies...SuggestedFlexible hours
$76.4k - $138.6k
A leading professional services firm located in Cleveland, Ohio is hiring an Offensive Security Analyst to enhance its cybersecurity posture. The successful candidate will have at least three years of experience in vulnerability management and be familiar with cloud services...SuggestedFlexible hours- ...Security Analyst Pittsburgh, PA, Cleveland, OH, Strongsville, Birmingham, AL, Dallas, TX, Phoenix, AZ Roles & Responsibilities Perform tasks related to mainframe security administration Evaluate and manage ACF2 rules associated with Systemware...Suggested
$75k - $137.5k
...culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a Security Analyst within PNC’s Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; or Birmingham, AL. The work shift...SuggestedFull timeTemporary workPart timeWork experience placementWork at officeShift work- ...Security Analyst At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all...SuggestedWork experience placementWork at officeShift work
- ...IT Security Analyst Supervised by: IT Infrastructure Team Lead Status: Full-Time, Exempt POSITION SUMMARY. The IT Security Analyst's role is to monitor computer networks and systems for security incidents and events and remediate them to the best of their ability...Full timeCasual workWork at officeHome officeMonday to FridayAfternoon shift
- ...Security Analyst At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all...Work at office
- ...departments and more than 20 health centers. Summary: Responsible for execution and operation of components that make up the IS Security Program. Ensures that security policies, standards and procedures are followed. Operational responsibility for deployed security...Work at officeShift work
- * Provides technical evaluation and analysis. Supports activities, process, and tools needed to improve overall security posture of the organization.* Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, and creates...Shift work
- A healthcare organization in Cleveland is seeking an individual to manage the IS Security Program. Responsibilities include ensuring security policies and standards are adhered to, maintaining operational responsibility for security products, and helping to develop a security...
- ...will require you to be in Cleveland, OH We are in a hybrid schedule, 2 days on campus and 3 days WFH OverDrive is hiring a Security Engineer to help build, tune, and respond to SIEM detections for our environment. You'll be responsible for connecting the dots...Work from home
$90.32k - $121.93k
...Essential Duties and Responsibilities ~ Architects and authors System Security Plans (SSPs), the "source of truth" for the client's security posture, detailing exactly how each NIST 800-171 control is implemented. ~ Develops and manages the Plan of Action and Milestones...Full timeLocal area$27.43 - $34.71 per hour
...across the state. What You'll Do At DBH: Maintain the safety and security of (NBH) Northcoast Behavioral Healthcare Patrol grounds and... ...7-21, "Background check on applicants," outlines disqualifying offenses that will preclude an applicant from being employed by the...Hourly payPermanent employmentFull timeContract workPart timeWork experience placementWork at office- ...Qualifications Experience Required: 0 to 1 year Experience Desired: Experience working in a retail grocery environment/law enforcement or security experience Education Desired: High school diploma or equivalent Lifting Requirement: Up to 50 pounds Travel Required: Regional -...
- ...assigned loss prevention representative. Communicate effectively with customers and law enforcement personnel. Perform other security and loss prevention duties to ensure a safe and secure environment for customers and Team Members. Maintain safety as the top...
$80k - $150k
...advisory and capital markets services. The Investment Banking Analyst is an integral member of deal teams, supporting the execution of... ...internship(s) (preferred) Licenses and Certifications FINRA Security Industry Essentials (SIE) (preferred) FINRA License S7 (...Work experience placementInternshipWork at officeFlexible hoursShift workNight shift- ...performing work that requires initiative and leadership skills Experience in coaching and teaching others Chartered Financial Analyst (CFA) or Certified Investment Management Analyst (CIMA) or other approved credentials or those required by law Ability to...
- ...Investment Banking Analyst The Investment Banking Analyst will support across a variety of different transactions, with an emphasis on analytical support, research, and marketing. We are looking for an Analyst with an entrepreneurial spirit and the ability to work in...Work at office
$75k - $125k
...to the company’s success. As a Portfolio Analytics & Strategy Analyst within PNC's Data, Modeling & Analytics Home Lending and Decision... ...Deposit Insurance Act (FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE...Full timeTemporary workPart timeWork experience placementWork at office- ...Inc. is a family owned and current owners are 3rd generation, with 4th generation employees. Continental is a full-service contract security company. Continental has been in business since 1919, protecting our client’s businesses or property. Continental’s corporate...Full timeContract workWork experience placementWork at officeLocal areaShift workDay shiftAfternoon shift
- ...following. Other duties may be assigned. Monitors building activity Completes patrols to ensure doors are locked and building is secure. Monitors building environment for safety concerns and makes necessary adjustments. Locks and unlocks areas of building depending...Night shift
- A prestigious hotel in Cleveland is seeking a Loss Prevention Officer for the 3rd shift. You will monitor building activity, secure the premises, and ensure safety. Responsibilities include completing daily activity reports, assisting in emergencies, and maintaining the...Night shift
- Cssb Inc is seeking full-time Security Officers for its Loss Prevention section in Cleveland, Ohio. As a Loss Prevention Officer, you will monitor surveillance cameras to deter and intercept potential shoplifters, requiring excellent communication skills and a H.S. Diploma...Full timeLocal areaShift workWeekend work
- A leading retail grocery company in Beachwood, Ohio is looking for Store Detectives to prevent shoplifting using CCTV and visual practices. The ideal candidates will have 1 to 3 years of experience in a relevant field, effective communication skills, and must be at least...
- ...role involves monitoring for shoplifters, writing reports, and interacting with customers and staff. Ideal candidates will possess security experience, a high school diploma or GED, and strong communication skills. Full-time positions are available for 1st and 2nd...Full timeWork at officeWeekend workDay shiftAfternoon shift
$110k - $130k
The Industrials Team at Brown Gibbons Lang & Company (BGL) is seeking an experienced Investment Banking Analyst to join our team in the Chicago or Cleveland office. BGL’s growing Industrials team focuses on several key areas: Building Products, Metals and Mining, Paper...Full timeWork at office$55k - $65k
...management, reporting, and trade settlements. Candidates should have a degree in Finance or Accounting, at least 3 years of experience in securities operations, and proficiency in Microsoft Office. The position emphasizes teamwork, strong communication skills, and adherence to...Work at office- A leading investment firm based in Cleveland is seeking an Investment Analyst to join its Investment Management team, focusing on portfolio management and client support. The role involves providing analytical support, monitoring client portfolios, and drafting performance...
- Townsend is searching for an Investment Analyst to join the Investment Management team in its Cleveland office, focusing on portfolio management, research, and providing client support. Providing analytical support to portfolio managers and consultants for client strategy...
- A major financial services company in Cleveland is seeking an IT Project Portfolio Analyst II to manage the full Portfolio Management Lifecycle for IT initiatives. This role demands collaboration with business and IT leadership to monitor project health and use tools like...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!
- bond analyst Cleveland, OH
- rate analyst Cleveland, OH
- network security analyst Cleveland, OH
- information security compliance analyst Cleveland, OH
- security analyst intern Cleveland, OH
- entry level information security analyst Cleveland, OH
- security analyst remote Cleveland, OH
- entry level security analyst Cleveland, OH
- security operations analyst Cleveland, OH
- information security analyst Cleveland, OH

