Offensive Security Analyst
$76.4k - $138.6kEY
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands-on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses.Your responsibilities will include supporting the validation of third-party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk.
Your key responsibilities
The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof-of-concepts to validate exploitability and determine real-world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets.The candidate will support third-party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams, and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks, and reporting standards within the Vulnerability Discovery and offensive security functions.
Skills and attributes for success
Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc.
Strong attention to detail with a methodical approach to identifying complex attack paths
Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context
Ability to manage high volumes of testing requests without compromising depth or quality
Flexibility to work across diverse technologies, including cloud, applications, and infrastructure
Effective communication skills to convey technical findings to both technical and non-technical audiences
Familiarity with research techniques and threat intelligence to support proactive risk identification
To qualify for the role you must have
A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security
Hands-on experience testing applications, APIs, cloud environments, and network infrastructure
Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques
Familiarity with offensive security methodologies and frameworks
Experience supporting or performing third-party risk assessments
Strong analytical and problem-solving skills with the ability to prioritize risks effectively
Strong communication and stakeholder management skills
Ideally, you’ll also have
OWASP training
Incident response experience
What we look for
We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally-exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.
What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $91,700 to $157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .
$76.4k - $138.6k
A leading global professional services firm is seeking an Offensive Security Analyst to manage and evaluate digital vulnerabilities. The role involves assessing third-party risks and implementing security standards across EY's digital assets. Candidates should have a minimum...Suggested- SCS Cybersecurity Offensive Security Analyst Job Description Location: This job can be located at Georgia Power HQ (Atlanta, GA) or Alabama Power HQ (Birmingham, AL). - This job requires 4 days of onsite work At Southern Company, our core objective is to ensure safe and...SuggestedFull timeLocal area
$118.31k - $177.47k
...Anticipated End Date: 2026-06-12 Position Title: Senior Offensive Security & Exposure Management Analyst Job Description: Senior Offensive Security & Exposure Management Analyst Location: This role requires associates to be in-office 1 - 2 days...SuggestedTemporary workWork experience placementWork at officeLocal areaDay shift2 days per week1 day per week$100k - $126k
...cyber-intelligence tools / methods and performs research and analysis in order to mitigate and eliminate high level data and cyber security risks. Designs, tests and implements state-of-the-art secure operating systems, networks, and database products. Conducts risk...SuggestedContract workWork at office- ...Summary of Purpose: The Senior IT Security Analyst serves as INPO's primary cybersecurity risk authority, providing oversight and guidance to protect the organization's mission-critical operations in the nuclear power industry. The position, a combination of strategic...SuggestedWork experience placement
- ...Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title : IT Security Analyst Senior. Location : Atlanta, GA. About the Role: We are seeking a Security Engineer (WAF SME) to join a dynamic...For contractorsWork experience placementRemote work
- ...IT Security Analyst Arete Technologies, Inc. offers a set of innovative consulting and outsourcing services, bridging the gap between requirements and outputs of various dexterous and facile companies worldwide. The thrust of providing global deliverables with focus...Local areaWorldwide
$70.8k - $141.6k
...divh2Senior Physical Security And Safety Analyst/h2pTriNet is a leading provider of comprehensive human resources solutions for small to midsize businesses (SMBs). We enhance business productivity by enabling our clients to outsource their HR function to one strategic...Permanent employmentFull timeWork at officeRemote workRelocation- ...we have been recognized as one of the best places to work by both Newsweek and US News & World report. The Senior IT Security Analyst is responsible for identifying risks, responding to threats, and partnering with teams across the organization to ensure our systems...Weekly payTemporary work
- ...opportunity to help our customers and prospects gain more value from our suite of software solutions. We are seeking a Senior Security Analyst / AppSec Specialist to join our Information Security & Compliance team. This is a hands-on, high-impact role responsible for strengthening...Work at officeWork from homeFlexible hours
$90.78k
...We are seeking a seasoned Security Governance/Risk professional to support and strengthen enterprise security governance for Federal and DoD customers. This role is responsible for performing complex risk analyses, establishing and advising on Information Assurance and...Work at office- ...SOC Analyst Location: New York City, Boston MA, Atlanta GA Shift: 3PM to 12AM EST Mon - Fri & participate in an on-call rotation... ...SOC Analyst serves as the first line of defense for information security operations monitoring, investigating, and responding to potential...Shift work
- Security Analyst/Engineer Security Analyst/engineer 2+ years -Splunk and Splunk ES -Creating dashboards -creating queries -using transforming commands searches -Any Cisco Security device experience -Can do through analytical investigations.
- ...of our Atlanta office. Overview The Senior Cybersecurity Analyst - CSOC is a Senior level non-management role that reports directly... ...Manager. They will be responsible for guiding a hybrid team of security analysts tasked to detect, Triage, analyze, respond, and report...Work at officeRemote workNight shift
- ...Vulnerability Analyst Our client is a global manufacturing firm that partners with their customers to provide differentiated paper and packaging solutions that help them win in the marketplace. Our client is in Atlanta they are seeking a Vulnerability Analyst is responsible...Work at officeRemote workRelocation
- ...Information Security Analyst 3 Under broad supervision, plans, directs and coordinates agency activities in the field of Information Security. Develops and enforces the organization's security policies and procedures. Incorporates the design of and develops security...Work experience placementWork at officeLocal area
- ...Opportunity We are looking for a skilled cybersecurity professional with relevant technical experience. As the Information Security Analyst 3, reporting to the CISO, the selected candidate will perform technically and lead the hands-on technical team in administering...
- ...Overview: GA DHS - Information Security Analyst (776405) Atlanta GA This role is responsible for monitoring, detecting, analyzing, and responding to security events, managing vulnerabilities, and ensuring compliance with federal, agency, and organizational...
$30 per hour
...the Oracle Government, Defense & Intelligence team supporting Federal Compliance and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management team to ensure documentation, processes and policies up to date...Hourly payTemporary workInternshipFlexible hours- ...as electrical, mechanical, lighting, air conditioning, heating, security, fire protection, and power generation systems—in virtually... ...Job Summary EMCOR Group, Inc. seeks an Information Security Analyst – Intel and Email who would be responsible for supporting the maintenance...Full timeWork at officeRemote work
- ...Job Posting Assists in planning, directing, and coordinating agency activities, specifically relative to Information Security Assists in developing and enforcing the organization's security policies, standards, and guidelines, security awareness, security information...
- ...in Threat Assessments and Mitigations. Assist in Information Security Investigations. Assist with Office of Information Security... ...IRS Office of Safeguards and other third-party assessors. The analyst will need a 4-year degree in an IT or InfoSec related field....Work at office
- ...Information Security Forensic Analyst Seeking a Information Security Forensic Analyst 1. Setup, configure, and maintain our EnCase Enterprise system. 2. Handle our forensic research for our Open Records Requests and Security Investigations. 3. Configure the eDiscovery...
- AI / Emerging Tech Security Analyst (AI Training) About The Role What if your security expertise could directly shape how the world's most advanced AI systems defend themselves against attack? We're looking for AI Security Analysts to probe, stress-test, and evaluate...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- A leading security services company is seeking an Information Security Analyst in Atlanta, Georgia. This role involves supporting the maintenance of the security program, monitoring cyber threats, and managing email security configurations. The ideal candidate will have...
$120k - $130k
...As an Information Security Staff Risk Analyst at Deluxe, you will be instrumental in maintaining our high standards of security and compliance, in particular with our cyber resilience and preparedness. We are looking for a proactive professional with excellent collaboration...Temporary work- Alignerr is looking for a Security Operations Analyst who will partner with leading AI research labs to enhance AI in cybersecurity. This role, fully remote, involves analyzing real-world incidents to teach AI how to effectively respond to threats. The ideal candidate has...Remote job
- A cybersecurity firm in Atlanta is looking for an Information Security Analyst to play a key role in monitoring, detecting, and responding to security events. The ideal candidate will have a Bachelor's degree in a related field and hands-on experience with tools such as...
$80k - $100k
Advisor Security Analyst II Location(s): Atlanta: 2300 Windy Ridge Pkwy SE, Suite750, Atlanta, GA 30339 La Vista:12325 Port Grace Blvd, La Vista, NE 68128 Oakdale: 7755 3rd St. N, Oakdale, MN 55128 Scottsdale: 18700 N Hayden Rd, Suite 255, Scottsdale, AZ 85255 St....Full timeWork at office- Alignerr is seeking an Application Security Analyst to collaborate with leading AI research labs. This role involves analyzing application security scenarios and improving how AI systems assess risks. Applicants should have at least 2 years of experience in application...Remote jobFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!
- bond analyst Atlanta, GA
- rate analyst Atlanta, GA
- network security analyst Atlanta, GA
- information security compliance analyst Atlanta, GA
- security analyst intern Atlanta, GA
- entry level information security analyst Atlanta, GA
- security analyst remote Atlanta, GA
- entry level security analyst Atlanta, GA
- security operations analyst Atlanta, GA
- information security analyst Atlanta, GA

