Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber - Attack & Penetration Testing - Senior - Consulting

$125.8k - $209.7k

Jobleads-US

Location: Anywhere in Country

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The Opportunity

Cyber threats, social media, artificial intelligence, privacy requirements, and continuity of the business as usual require heavy information security measures. As a Senior Attack & Penetration Tester, you will contribute to our client’s resilience through the execution of sophisticated offensive security operations.

Your key responsibilities

As a Senior on the Attack & Penetration Testing team, you will plan, lead, and execute complex penetration testing and advanced red team engagements across diverse client environments. You will apply an intelligence-led, threat-informed approach to emulate realistic adversary behaviors, identify exploitable attack paths, and evaluate preventive, detective, and responsive security controls. Your work will span external and internal networks, Active Directory, Microsoft Entra ID, web and mobile applications, application programming interfaces (APIs), cloud environments, wireless networks, social engineering, and physical security scenarios, as permitted by the rules of engagement. You will translate technical testing results into clear, actionable insights for technical and executive audiences. You will work collaboratively with client technical teams to validate identified weaknesses and develop practical remediation or mitigation strategies, including Active Directory security improvements, system-hardening measures, and compensating controls aligned with the client environment and operational constraints. You will also lead technical workstreams, coordinate testing activities, mentor junior team members, contribute to methodology and capability development, and remain current on emerging vulnerabilities, adversary tactics, offensive security tooling, and industry research.

Skills and attributes for success

To thrive in this role, you'll need a blend of technical and business skills, along with the ability to navigate complex problems and make informed decisions. Your professional knowledge and experience will guide you in adhering to broad policies and tackling issues with in-depth evaluations.

  • Demonstrate advanced problem-solving and critical-thinking skills when developing and executing attack paths.

  • Plan and conduct penetration tests and advanced red team engagements within defined scopes, rules of engagement, and safety constraints.

  • Identify, validate, and exploit vulnerabilities across external and internal networks, Active Directory, Microsoft Entra ID, cloud, wireless, web, mobile, and API environments.

  • Apply threat-informed testing techniques aligned with the MITRE ATT&CK framework and relevant adversary tactics, techniques, and procedures.

  • Lead technical testers, coordinate distributed workstreams, and provide hands‑on coaching and quality review for junior team members.

  • Recognize when to escalation risks, issues, testing impacts, and opportunities to appropriate client and EY leadership.

  • Produce high‑quality technical work products, evidence, client reports, and executive‑ready presentations that clearly explain risk and remediation priorities.

  • Communicate complex offensive security concepts clearly to technical stakeholders, business leaders, and executives.

  • Work collaboratively in cross‑functional, culturally diverse, and geographically dispersed teams while adhering to service quality and engagement management requirements.

To qualify for the role, you must have:

  • A bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Management Information Systems, Information Technology, Engineering, or a related field, and at least five years of relevant offensive security experience.

  • Hands‑on experience planning and executing advanced red team engagements, including adversary emulation, objective‑based operations, attack‑path development, and testing against mature security monitoring and response capabilities.

  • Advanced experience conducting external and internal network penetration testing, including host and service enumeration, exploitation, privilege escalation, lateral movement, and post‑exploitation activities.

  • Experience assessing Active Directory environments, including domain and trust configurations, privileged access, authentication protocols, delegation, Group Policy, credential exposure, certificate services, security configurations, and other identity‑based attack paths.

  • Experience performing cloud security testing, including identity and access management, exposed services, configuration weaknesses, privilege escalation, and attack‑path analysis.

  • Experience conducting wireless security assessments, including enterprise and guest wireless configurations, authentication controls, segmentation, and authorized wireless attack techniques.

  • Experience testing web applications, mobile applications, and APIs using manual techniques and industry‑recognized testing methodologies.

  • Experience evaluating security configurations and system‑hardening requirements and working with client technical teams to develop practical remediations, mitigations, compensating controls, and validation approaches for identified findings.

  • Experience with scripting or programming languages used to automate testing, analyze data, or develop offensive security tooling, such as Python, PowerShell, Bash, C#, Go, Rust, or Java.

  • Experience using commercial and open‑source penetration testing tools while adapting techniques to client‑specific environments and constraints.

  • Familiarity with endpoint detection and response (EDR), security information and event management (SIEM), network monitoring, and other defensive controls, including how those controls influence authorized stealth and evasion testing.

  • Experience with red team command‑and‑control (C2) platforms and associated operational infrastructure, payload development, redirectors, logging, and campaign management.

  • Experience evaluating and bypassing EDR and other defensive controls during explicitly authorized engagements, including memory, execution, credential access, lateral movement, and persistence techniques designed for stealth testing against mature client environments.

  • Working knowledge of the MITRE ATT&CK framework, current vulnerabilities, exploits, adversary tactics, techniques, and procedures, and security remediation practices.

  • Experience leading remote and on‑site technical teams, managing testing activities within approved rules of engagement, and communicating testing risks or potential operational impacts.

  • The ability to develop clear technical findings that describe evidence, exploitation paths, business risk, and actionable remediation guidance.

  • Any two relevant offensive security certifications, such as Offensive Security Certified Professional (OSCP), Offensive Security Wireless Professional (OSWP), Offensive Security Experienced Penetration Tester (OSEP), Offensive Security Certified Expert (OSCE), Offensive Security Exploitation Expert (OSEE), GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), GIAC Mobile Device Security Analyst (GMOB), GIAC Cloud Penetration Tester (GCPN), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Red Team Professional (GRTP), GIAC Defending Advanced Threats (GDAT), Certified Red Team Operator (CRTO), Certified Red Team Professional (CRTP), Certified Red Team Expert (CRTE), CREST Registered Penetration Tester (CREST CRT), or Certified Cybersecurity Attack Specialist (CCSAS).

A valid U.S. driver's license and the willingness and flexibility to travel up to 80 percent, domestically and internationally, to meet client needs.

Ideally, you’ll also have

  • Hands‑on cloud penetration testing and identity security assessment experience across Amazon Web Services (AWS), Microsoft Azure, Microsoft Entra ID, and Google Cloud Platform (GCP), including cloud‑native identity, privileged access, service, configuration, and privilege‑escalation attack paths in hybrid and fully cloud‑based environments.

  • Experience assessing Microsoft Entra ID environments, including identity and access management, privileged roles, authentication controls, application registrations, service principals, conditional access, external identities, and cloud‑based attack paths for clients operating fully in the cloud without on‑premises Active Directory infrastructure.

  • Experience applying artificial intelligence (AI) and machine learning capabilities to support testing, including developing automation for reconnaissance, analysis, evidence processing, repeatable test execution, and offensive security workflows.

  • Advanced experience with API and application security testing, including authentication, authorization, business logic, data exposure, injection, and platform‑specific attack paths.

  • Experience evaluating security baselines and hardening standards for Windows, Linux, cloud, and identity environments and helping clients prioritize remediation activities based on risk, feasibility, and operational impact.

  • Experience conducting authorized social engineering and physical penetration testing to evaluate personnel, facility, and access‑control risks. This includes direct interaction with targeted personnel to assess susceptibility to credential disclosure, unauthorized access requests, and controlled execution of remote access tooling used for command‑and‑control testing, as well as evaluating physical security controls through lock bypass, access‑control evasion, automated security system testing, tailgating, and radio‑frequency identification (RFID) badge cloning techniques.

  • The ability to develop custom tooling, modify public exploits, build proof‑of‑concept code, and safely operationalize new offensive techniques.

  • Contributions to the security community through research, public vulnerability disclosures, bug bounty acknowledgments, open‑source projects, conference presentations, publications, or technical blogs.

  • Strong knowledge of Windows, Linux, Unix, TCP/IP networking, common enterprise protocols, and modern identity and security architectures.

  • Exemplary verbal and written communication skills, including the ability to facilitate workshops and translate complex technical information into concise, executive‑level deliverables.

Proficiency with consulting engagement methodologies, including estimating effort, prioritizing activities, managing dependencies, and aligning technical testing to client objectives.

What we look for

We seek top performers with a passion for cybersecurity and a proven track record of success. Ideal candidates are those who demonstrate agility, critical thinking, and the ability to work collaboratively in a dynamic environment.

What we offer you

At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment and an inclusive culture. Learn more at ey.com/us/careers .

  • The salary range for this job is:

  • New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices – $125,800 to $209,700

  • Bay Area California offices – $131,100 to $218,500

  • All other offices locations in the US, including Sacramento – $104,800 to $192,200

  • Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi‑disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

All in to shape the future with confidence.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .

#J-18808-Ljbffr Jobleads-US
Vacancy posted 8 hours ago
Similar jobs that could be interesting for youBased on the Cyber - Attack & Penetration Testing - Senior - Consulting in Charleston, WV vacancy
  •  ...EY is seeking a Senior Attack & Penetration Tester to strengthen client resilience through sophisticated offensive security operations. You will lead testing across AD, cloud, web, mobile, APIs, and networks, emulating real adversaries and delivering actionable remediation... 
    Senior

    Jobleads-US

    Charleston, WV
    8 hours ago
  • $150.7k - $251.2k

     ...confused-deputy and authority-escalation attacks, tool and function-call abuse, memory and...  ...restriction, resource containment, and the escape-test suite that proves the boundary holds....  ...threat classes. Client-facing or consulting background, with credibility in front of... 
    Senior
    Contract work
    Summer holiday
    Flexible hours

    Jobleads-US

    Charleston, WV
    18 hours ago
  • $71.2k - $166.1k

     ...Services is seeking a skilled Federal Senior Engineer/Architect (Principal Consultant) to join our mission-driven...  ...deployment experience • Federal Cyber understanding/experience • Engineering...  ...health mandates, and/or drug testing requirements. Range and benefit... 
    Cyber
    Senior
    Temporary work
    Flexible hours

    Oracle

    Charleston, WV
    2 days ago
  •  ...winning, AI-First digital engineering and consulting company focused on delivering high-...  ...Role: We are seeking an experienced Senior Data Engineer with deep expertise in Asset...  ...coordination. Assist with integration testing, cutover planning, and go-live readiness... 
    Senior
    Full time
    Remote work

    Quantiphi

    Charleston, WV
    1 hour ago
  • $102.5k - $187.9k

     ...Services practice assists our national consulting practices in planning, pursuing, delivering...  ...required to run their business. As a Senior in Application Design and Development, you...  ...design, architecture, development and testing Innovative and creative mind to think outside... 
    Senior
    Summer holiday
    Flexible hours

    EY

    Charleston, WV
    2 days ago
  • $125k - $150k

    Senior Solutions Consultant Req number: R8511 Employment type: Full time Worksite flexibility: Remote Who we are CAI is a global services...  ...application, interviewing, completing any pre-employment testing, or otherwise participating in the employment selection process... 
    Senior
    Full time
    Apprenticeship
    Work at office
    Local area
    Remote work
    Worldwide

    CAI

    Charleston, WV
    1 day ago
  •  ...New grad/entry level Mid-career Senior-level P.E. or PTOE/Project Manager...  ...Engineering ( is an award winning, full service consulting engineering firm with (15) locations...  ...design (bridge/roadway) , and specialized testing services to the construction industry.... 
    Senior
    Permanent employment
    Temporary work
    Local area

    Ctl Engineering

    Charleston, WV
    1 day ago
  • $79.2k - $209.5k

     ...the constantly evolving and challenging cyber-threat landscape, by developing novel solutions...  ...products to prevent and mitigate cyber-attacks on the OCI. We are looking for top...  ...occupational health mandates, and/or drug testing requirements. Range and benefit information... 
    Cyber
    Temporary work
    Flexible hours

    Oracle

    Charleston, WV
    1 day ago
  • $132.23k - $176.31k

     ...Black Lotus Labs has an opening for a Senior Lead Security Engineer that will leverage...  ...Responsibilities Research latest threat attacker tools, techniques, and procedures (TTPs)...  ...goal of automating detection. Work with cyber operators, when requested, to conduct in-... 
    Cyber
    Senior
    Full time
    Temporary work
    Work experience placement
    Work at office
    Remote work

    Lumen

    Charleston, WV
    4 days ago
  •  ...conventional drilling or in-situ testing techniques. Drill methods may...  ...techniques may include cone penetration testing (CPT), pressure meter...  ...from management or other senior level ETMs. Operate a geotechnical...  ...-owned multidiscipline consulting firm comprised of more than 8... 

    Terracon

    Charleston, WV
    1 day ago
  •  ...using conventional drilling or in-situ testing techniques. Drill methods may include auger...  ...testing techniques may include cone penetration testing (CPT), pressure meter testing,...  ...percent employee-owned multidiscipline consulting firm comprised of more than 8,000 curious... 

    Terracon

    Charleston, WV
    18 hours ago
  •  ...and requires U.S. work authorization Job Summary / Introduction Senior IT Internal Auditor *** This role does not offer sponsorship...  ...Advisory focus, providing the opportunity to combine hands‑on testing with more strategic advisory work. The successful candidate will... 
    Senior

    Oliver James Group

    Charleston, WV
    3 days ago
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates...  ...governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and continual... 
    Cyber
    Senior
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Charleston, WV
    4 days ago
  •  ...Larson Design Group, an employee-owned Architecture, Engineering, and Consulting firm, is seeking a Project Manager to oversee client and project management, budgets, schedules, and business development within the Transportation Group. The role emphasizes leadership,... 
    Senior

    Larson Design Group

    Charleston, WV
    2 days ago
  • Senior Tax Manager High Net Worth & Family WealthIf you are a seasoned tax professional ready to lead complex estate and family wealth...  ...you will doDeliver high-level tax compliance and strategic consulting for high-net-worth individuals, families, trusts, and estates,... 
    Senior
    Work at office
    Flexible hours

    CyberCoders

    Charleston, WV
    3 days ago
  • $121.4k - $218.6k

     ...Job Title: Senior Software Development Engineer in Test Work Location: 145 Broadway, Cambridge, MA 02142 Job Description: Akamai Technologies, Inc. is hiring for the following role in Cambridge, MA (multiple openings): Senior Software Development Engineer in... 
    Senior
    Work experience placement
    Work at office
    Remote work

    Akamai

    Charleston, WV
    3 days ago
  •  ...investigations into financial crimes, including counterfeiting, cyber fraud, and other threats to the financial infrastructure of the...  ...essential to the performance of this position. Submit to a drug test prior to your appointment and random drug testing while you... 
    Cyber
    Immediate start
    Overseas
    Trial period

    The United States Secret Service

    Charleston, WV
    8 days ago
  •  ...Job Summary The Senior Clinical Applications Analyst is responsible for the analysis, building, testing and implementing of information systems and solutions. The Senior Application Analyst is accountable for providing knowledge and skills in assigned software applications... 
    Senior
    Full time
    Flexible hours
    Shift work

    CAMC Health System

    Charleston, WV
    2 days ago
  • $71.2k - $158.2k

    **Job Description** An experienced consulting professional who has an understanding of solutions, industry best practices, multiple business...  ...as immunization/occupational health mandates, and/or drug testing requirements.** **Range and benefit information provided in... 
    Temporary work
    Flexible hours

    Oracle

    Charleston, WV
    3 days ago
  • $211.72k

     ...bring experience identifying and selling consulting, engineering, design-build and EPC (...  ...Growing market share by partnering with senior project managers and key technical specialists...  ...law. Background Check and Drug Testing Information CDM Smith Inc. and its divisions... 
    Temporary work
    Work experience placement
    H1b

    CDM Smith

    Charleston, WV
    4 days ago
  • $18 - $25 per hour

     ...helps clients and partners conceptualize, test and validate innovative technology...  ...6. If you’re interested in Solutions, Consulting and Engineering this is the place for you...  ...Business Administration Computer Science Cyber Security Data Science/Analytics Economics... 
    Cyber
    Remote job
    Hourly pay
    Summer work
    Internship
    Work at office
    Immediate start
    Shift work

    World Wide Technology

    Charleston, WV
    2 days ago
  •  ...Job Description Perform field and/or laboratory testing, observation, and inspection of construction materials (e.g. soils, aggregates...  ...Terracon is a 100 percent employee-owned multidiscipline consulting firm comprised of more than 8,000 curious minds focused on... 
    For contractors

    Terracon

    Charleston, WV
    1 day ago
  •  ...Owens & Minor is seeking an experienced SAP PP/QM/PM Functional Consultant with 10+ years of hands-on delivery in Production Planning,...  ...lead end-to-end SAP activities, including design, configuration, testing, and production support in highly customized environments... 
    Senior

    Jobleads-US

    Charleston, WV
    8 hours ago
  • $71.2k - $166.1k

     ...ve come to the right place. We are looking for an experienced Consultant to help design, configure, activate, and support the implementation...  ...as immunization/occupational health mandates, and/or drug testing requirements.** **Range and benefit information provided in... 
    Temporary work
    Flexible hours

    Oracle

    Charleston, WV
    3 days ago
  • $140k - $180k

     ...ready to design your future? Be our next Senior Mechanical Engineer Your work...  ...provides engineering, architecture, design and consulting services to the world’s built and...  ...Status, Disability, Genetic Information or Testing, Family and Medical Leave, Sexual Orientation... 
    Senior
    Full time

    EXP

    Charleston, WV
    18 hours ago
  • $110k - $150k

     ...Together, we are EXP. Project Manager/Senior Structural Engineer, Mining Your...  ...provides engineering, architecture, design and consulting services to the world’s built and...  ...Status, Disability, Genetic Information or Testing, Family and Medical Leave, Sexual... 
    Senior
    Full time

    EXP

    Charleston, WV
    2 days ago
  • $27 - $30 per hour

     ...communities we serve. Responsibilities Serve as a Maintenance Director at a Genesis center and occasionally provide maintenance consulting services to other Genesis centers. Maintain building free of hazards and perform repairs on electrical, plumbing, heating, and cooling... 
    Senior
    Temporary work
    Immediate start

    Genesis Healthcare, Inc.

    South Charleston, WV
    1 day ago
  • $169.8k - $355.4k

     ...facing roles may be required to comply with applicable requirements, such as immunization/occupational health mandates, and/or drug testing requirements. Range and benefit information provided in this posting are specific to the stated locations only US: Hiring... 
    Senior
    Temporary work
    Flexible hours

    Oracle

    Charleston, WV
    3 days ago
  • $94k - $110k

     ...Senior Internal Communications Specialist FBT Gibbons LLP is a national law firm focused on serving companies operating and investing in the middle market. With nearly 1,500 employees across 26 offices, we support clients ranging from large multinationals to mid-sized... 
    Senior
    Temporary work
    Work at office
    Local area

    FBT Gibbons LLP

    Charleston, WV
    2 days ago
  •  ...business continues to expand, we are looking for an experienced Senior Performance Engineer to join our growing Service team. This...  ...software, controls, and configuration layers. Develop electrical test plans, evaluate test results, and provide technical... 
    Senior

    HyperStrong

    Charleston, WV
    1 hour ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber - Attack & Penetration Testing - Senior - Consulting. Be the first to apply!