Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Analyst

$76.4k - $138.6k

EY

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.

Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

The opportunity

As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands-on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses.Your responsibilities will include supporting the validation of third-party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk.

Your key responsibilities

The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof-of-concepts to validate exploitability and determine real-world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets.The candidate will support third-party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams, and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks, and reporting standards within the Vulnerability Discovery and offensive security functions.

Skills and attributes for success

  • Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc.

  • Strong attention to detail with a methodical approach to identifying complex attack paths

  • Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context

  • Ability to manage high volumes of testing requests without compromising depth or quality

  • Flexibility to work across diverse technologies, including cloud, applications, and infrastructure

  • Effective communication skills to convey technical findings to both technical and non-technical audiences

  • Familiarity with research techniques and threat intelligence to support proactive risk identification

To qualify for the role you must have

  • A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security

  • Hands-on experience testing applications, APIs, cloud environments, and network infrastructure

  • Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques

  • Familiarity with offensive security methodologies and frameworks

  • Experience supporting or performing third-party risk assessments

  • Strong analytical and problem-solving skills with the ability to prioritize risks effectively

  • Strong communication and stakeholder management skills

Ideally, you’ll also have

  • OWASP training

  • Incident response experience

What we look for

We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally-exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.

What we offer you

The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $91,700 to $157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.

  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.

  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

Are you ready to shape your future with confidence? Apply today.

EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. 

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .

Vacancy posted 3 hours ago
Similar jobs that could be interesting for youBased on the Offensive Security Analyst in Cleveland, OH vacancy
  • A global consulting firm in Cleveland is seeking an Offensive Security Analyst to evaluate and manage its digital security exposure. Your role will involve assessing vulnerabilities, managing third-party risks, and collaborating with teams to implement defense strategies... 
    Suggested
    Flexible hours

    EY

    Cleveland, OH
    5 days ago
  • $76.4k - $138.6k

    A leading professional services firm located in Cleveland, Ohio is hiring an Offensive Security Analyst to enhance its cybersecurity posture. The successful candidate will have at least three years of experience in vulnerability management and be familiar with cloud services... 
    Suggested
    Flexible hours

    Ernst & Young Oman

    Cleveland, OH
    4 days ago
  •  ...Security Analyst Pittsburgh, PA, Cleveland, OH, Strongsville, Birmingham, AL, Dallas, TX, Phoenix, AZ Roles & Responsibilities Perform tasks related to mainframe security administration Evaluate and manage ACF2 rules associated with Systemware... 
    Suggested

    System One Holdings, LLC

    Cleveland, OH
    4 days ago
  • $75k - $137.5k

     ...culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a Security Analyst within PNC’s Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; or Birmingham, AL. The work shift... 
    Suggested
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Shift work

    PNC

    Cleveland, OH
    3 days ago
  •  ...Security Analyst At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all... 
    Suggested
    Work experience placement
    Work at office
    Shift work

    PNC

    Cleveland, OH
    4 days ago
  •  ...IT Security Analyst Supervised by: IT Infrastructure Team Lead Status: Full-Time, Exempt POSITION SUMMARY. The IT Security Analyst's role is to monitor computer networks and systems for security incidents and events and remediate them to the best of their ability... 
    Full time
    Casual work
    Work at office
    Home office
    Monday to Friday
    Afternoon shift

    MediQuant

    Independence, OH
    3 days ago
  •  ...Security Analyst At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all... 
    Work at office

    PNC

    Cleveland, OH
    5 days ago
  •  ...departments and more than 20 health centers. Summary: Responsible for execution and operation of components that make up the IS Security Program. Ensures that security policies, standards and procedures are followed. Operational responsibility for deployed security... 
    Work at office
    Shift work

    The MetroHealth System

    Cleveland, OH
    5 days ago
  • * Provides technical evaluation and analysis. Supports activities, process, and tools needed to improve overall security posture of the organization.* Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, and creates... 
    Shift work

    PNC Financial Services Group, Inc.

    Cleveland, OH
    5 days ago
  • A healthcare organization in Cleveland is seeking an individual to manage the IS Security Program. Responsibilities include ensuring security policies and standards are adhered to, maintaining operational responsibility for security products, and helping to develop a security... 

    The MetroHealth System (Cleveland, OH)

    Cleveland, OH
    1 day ago
  •  ...will require you to be in Cleveland, OH We are in a hybrid schedule, 2 days on campus and 3 days WFH OverDrive is hiring a Security Engineer to help build, tune, and respond to SIEM detections for our environment. You'll be responsible for connecting the dots... 
    Work from home

    OverDrive

    Cleveland, OH
    3 days ago
  • $90.32k - $121.93k

     ...Essential Duties and Responsibilities ~ Architects and authors System Security Plans (SSPs), the "source of truth" for the client's security posture, detailing exactly how each NIST 800-171 control is implemented. ~ Develops and manages the Plan of Action and Milestones... 
    Full time
    Local area

    Logicalis, Inc.

    Beachwood, OH
    3 days ago
  • $27.43 - $34.71 per hour

     ...across the state. What You'll Do At DBH: Maintain the safety and security of (NBH) Northcoast Behavioral Healthcare Patrol grounds and...  ...7-21, "Background check on applicants," outlines disqualifying offenses that will preclude an applicant from being employed by the... 
    Hourly pay
    Permanent employment
    Full time
    Contract work
    Part time
    Work experience placement
    Work at office

    Ohio Jobs

    Northfield, OH
    2 days ago
  •  ...Qualifications Experience Required: 0 to 1 year Experience Desired: Experience working in a retail grocery environment/law enforcement or security experience Education Desired: High school diploma or equivalent Lifting Requirement: Up to 50 pounds Travel Required: Regional -... 

    Giant Eagle

    Brook Park, OH
    1 day ago
  •  ...assigned loss prevention representative. Communicate effectively with customers and law enforcement personnel. Perform other security and loss prevention duties to ensure a safe and secure environment for customers and Team Members. Maintain safety as the top... 

    Giant Eagle

    Beachwood, OH
    1 day ago
  • $80k - $150k

     ...advisory and capital markets services. The Investment Banking Analyst is an integral member of deal teams, supporting the execution of...  ...internship(s) (preferred) Licenses and Certifications FINRA Security Industry Essentials (SIE) (preferred) FINRA License S7 (... 
    Work experience placement
    Internship
    Work at office
    Flexible hours
    Shift work
    Night shift

    Key Bank

    Cleveland, OH
    1 day ago
  •  ...performing work that requires initiative and leadership skills Experience in coaching and teaching others Chartered Financial Analyst (CFA) or Certified Investment Management Analyst (CIMA) or other approved credentials or those required by law Ability to... 

    CBIZ

    Cleveland, OH
    1 day ago
  •  ...Investment Banking Analyst The Investment Banking Analyst will support across a variety of different transactions, with an emphasis on analytical support, research, and marketing. We are looking for an Analyst with an entrepreneurial spirit and the ability to work in... 
    Work at office

    Suncap Technology

    Cleveland, OH
    4 days ago
  • $75k - $125k

     ...to the company’s success. As a Portfolio Analytics & Strategy Analyst within PNC's Data, Modeling & Analytics Home Lending and Decision...  ...Deposit Insurance Act (FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office

    PNC

    Cleveland, OH
    4 days ago
  •  ...Inc. is a family owned and current owners are 3rd generation, with 4th generation employees. Continental is a full-service contract security company. Continental has been in business since 1919, protecting our client’s businesses or property. Continental’s corporate... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Local area
    Shift work
    Day shift
    Afternoon shift

    Continental Secret Service Bureau

    Cleveland, OH
    2 days ago
  •  ...following. Other duties may be assigned. Monitors building activity Completes patrols to ensure doors are locked and building is secure. Monitors building environment for safety concerns and makes necessary adjustments. Locks and unlocks areas of building depending... 
    Night shift

    Metropolitan at The 9 | Autograph Collection

    Cleveland, OH
    3 days ago
  • A prestigious hotel in Cleveland is seeking a Loss Prevention Officer for the 3rd shift. You will monitor building activity, secure the premises, and ensure safety. Responsibilities include completing daily activity reports, assisting in emergencies, and maintaining the... 
    Night shift

    Metropolitan at The 9 | Autograph Collection

    Cleveland, OH
    3 days ago
  • Cssb Inc is seeking full-time Security Officers for its Loss Prevention section in Cleveland, Ohio. As a Loss Prevention Officer, you will monitor surveillance cameras to deter and intercept potential shoplifters, requiring excellent communication skills and a H.S. Diploma... 
    Full time
    Local area
    Shift work
    Weekend work

    Cssb Inc

    Cleveland, OH
    1 day ago
  • A leading retail grocery company in Beachwood, Ohio is looking for Store Detectives to prevent shoplifting using CCTV and visual practices. The ideal candidates will have 1 to 3 years of experience in a relevant field, effective communication skills, and must be at least...

    Giant Eagle, Inc.

    Beachwood, OH
    4 days ago
  •  ...role involves monitoring for shoplifters, writing reports, and interacting with customers and staff. Ideal candidates will possess security experience, a high school diploma or GED, and strong communication skills. Full-time positions are available for 1st and 2nd... 
    Full time
    Work at office
    Weekend work
    Day shift
    Afternoon shift

    Continental Secret Service Bureau

    Cleveland, OH
    1 day ago
  • $110k - $130k

    The Industrials Team at Brown Gibbons Lang & Company (BGL) is seeking an experienced Investment Banking Analyst to join our team in the Chicago or Cleveland office. BGL’s growing Industrials team focuses on several key areas: Building Products, Metals and Mining, Paper... 
    Full time
    Work at office

    Brown Gibbons Lang & Company (BGL)

    Cleveland, OH
    3 days ago
  • $55k - $65k

     ...management, reporting, and trade settlements. Candidates should have a degree in Finance or Accounting, at least 3 years of experience in securities operations, and proficiency in Microsoft Office. The position emphasizes teamwork, strong communication skills, and adherence to... 
    Work at office

    MAI Wealth Management, Inc.

    Independence, OH
    2 days ago
  • A leading investment firm based in Cleveland is seeking an Investment Analyst to join its Investment Management team, focusing on portfolio management and client support. The role involves providing analytical support, monitoring client portfolios, and drafting performance... 

    The Townsend Group

    Cleveland, OH
    2 days ago
  • Townsend is searching for an Investment Analyst to join the Investment Management team in its Cleveland office, focusing on portfolio management, research, and providing client support. Providing analytical support to portfolio managers and consultants for client strategy... 

    The Townsend Group

    Cleveland, OH
    2 days ago
  • A major financial services company in Cleveland is seeking an IT Project Portfolio Analyst II to manage the full Portfolio Management Lifecycle for IT initiatives. This role demands collaboration with business and IT leadership to monitor project health and use tools like... 

    AmTrust Financial Services, Inc.

    Cleveland, OH
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!