Offensive Security Analyst
$76.4k - $138.6kErnst & Young
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and
take your career wherever you want it to go. Join EY and help to build a better
working world. Today’s world is fueled by vast amounts of information. Data is more valuable
than ever before. Protecting data and information systems is central to doing
business, and everyone in EY Information Security has a critical role to play.
Join a global team of almost 950 people who collaborate to support the business
of EY by protecting EY and client information assets! Our Information Security
professionals enable EY to work securely and deliver secure products and
services, as well as detect and quickly respond to security events as they
happen. Together, the efforts of our dedicated team helps protect the EY brand
and build client trust. Within Information Security we blend risk strategy, digital identity, cyber
defense, application security and technology solutions as we consider the entire
security lifecycle. You will join a team of hardworking, security-focused
individuals dedicated to supporting, protecting and enabling the business
through innovative, secure solutions that provide speed to market and business
value. The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will
play a key role in evaluating and reducing EY’s digital exposure through
hands-on penetration testing and adversarial simulation. Working under the
guidance of the Exposure Management Lead, you will identify, assess and help
mitigate vulnerabilities across EY’s global attack surface. This role goes
beyond traditional scanning by actively emulating threat actors, performing
penetration testing and assessing the true impact of security weaknesses.Your
responsibilities will include supporting the validation of third-party risk
assessments, identifying misconfigurations and exposed assets, and ensuring
security standards applied across EY’s digital ecosystem. You will also
contribute to strengthening Continuous Threat Exposure Management and Attack
Surface Management efforts by providing actionable insights that improve
proactive defense and reduce overall business risk. Your key responsibilities The Analyst will apply offensive security techniques to assess EY’s external and
internal attack surface, identifying vulnerabilities across web applications,
APIs, cloud environments, networks, and infrastructure. This includes testing
proof-of-concepts to validate exploitability and determine real-world impact.
The role involves emulating adversary tactics to test detection and response
capabilities, as well as conducting reconnaissance and asset discovery to
uncover unmanaged or exposed assets.The candidate will support third-party and
supply chain risk validation efforts by reviewing assessments or conducting
targeted testing where required. Collaborating closely with security
engineering, blue teams, and business stakeholders, the analyst will help
prioritize remediation efforts based on risk severity and exploitability.
Additionally, the role will contribute to enhancing processes, playbooks, and
reporting standards within the Vulnerability Discovery and offensive security
functions. Skills and attributes for success * Capability to identify and exploit vulnerabilities beyond automated scanning
tools like Qualys, Nessus etc.
* Strong attention to detail with a methodical approach to identifying complex
attack paths
* Critical thinking and analytical skills to evaluate vulnerabilities in a
business risk context
* Ability to manage high volumes of testing requests without compromising depth
or quality
* Flexibility to work across diverse technologies, including cloud,
applications, and infrastructure
* Effective communication skills to convey technical findings to both technical
and non-technical audiences
* Familiarity with research techniques and threat intelligence to support
proactive risk identification To qualify for the role you must have * A minimum of 4 years of experience in penetration testing, red teaming,
purple teaming or offensive security
* Hands-on experience testing applications, APIs, cloud environments, and
network infrastructure
* Strong understanding of common vulnerability classes such as OWASP Top 10 and
exploitation techniques
* Familiarity with offensive security methodologies and frameworks
* Experience supporting or performing third-party risk assessments
* Strong analytical and problem-solving skills with the ability to prioritize
risks effectively
* Strong communication and stakeholder management skills Ideally, you’ll also have * Certifications such as OSCP, GPEN, GWAPT, or equivalent offensive security
credentials What we look for We are looking for a developing Offensive Security Analyst that can operate with
supervision and bring new approaches to discovering and evaluating the
business’s externally-exposed vulnerabilities. We are seeking a seasoned analyst
to improve the organization’s ability to reduce the attack surface while
enabling the business. The ideal candidate will seek to improve others while
continuously learning and identifying ways to strengthen the organization. What we offer you
The compensation ranges below are provided in order to comply with United States
pay transparency laws. Other geographies will follow their local salary
guidelines, which may not be a direct conversion of published US salary ranges.
At EY, we’ll develop you with future-focused skills and equip you with
world-class experiences. We’ll empower you in a flexible environment, and fuel
you and your extraordinary talents in a diverse and inclusive culture of
globally connected teams. Learn more
[* We offer a comprehensive compensation and benefits package where you’ll be
rewarded based on your performance and recognized for the value you bring to
the business. The base salary range for this job in all geographic locations
in the US is $76,400 to $138,600. The base salary range for New York City
Metro Area, Washington State and California (excluding Sacramento) is $91,700
to $157,500. Individual salaries within those ranges are determined through
a wide variety of factors including but not limited to education, experience,
knowledge, skills and geography. In addition, our Total Rewards package
includes medical and dental coverage, pension and 401(k) plans, and a wide
range of paid time off options.
* Join us in our team-led and leader-enabled hybrid model. Our expectation is
for most people in external, client serving roles to work together in person
40-60% of the time over the course of an engagement, project or year.
* Under our flexible vacation policy, you’ll decide how much vacation time you
need based on your own personal circumstances. You’ll also be granted time
off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family
Care, and other leaves of absence when needed to support your physical,
financial, and emotional well-being. Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis. For those living in California, please click here
[
for additional information. EY focuses on high-ethical standards and integrity among its employees and
expects all candidates to demonstrate these qualities. EY | Building a better working world EY is building a better working world by creating new value for clients, people,
society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the
future with confidence and develop answers for the most pressing issues of today
and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax,
strategy and transactions. Fueled by sector insights, a globally connected,
multi-disciplinary network and diverse ecosystem partners, EY teams can provide
services in more than 150 countries and territories. EY provides equal employment opportunities to applicants and employees without
regard to race, color, religion, age, sex, sexual orientation, gender
identity/expression, pregnancy, genetic information, national origin, protected
veteran status, disability status, or any other legally protected basis,
including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals
with disabilities including veterans with disabilities. If you have a disability
and either need assistance applying online or need to request an accommodation
during any part of the application process, please call 1-800-EY-HELP3, select
Option 2 for candidate related inquiries, then select Option 1 for candidate
queries and finally select Option 2 for candidates with an inquiry which will
route you to EY’s Talent Shared Services Team (TSS) or email the TSS at
View email address on click.appcast.io [View email address on click.appcast.io].
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Offensive Security Analyst in Austin, TX vacancy
$76.4k - $138.6k
...central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost... ...protect the EY brand and build client trust. Opportunity As an Offensive Security Analyst on the Vulnerability Management team, you will play a...SuggestedSummer holidayFlexible hours$124.2k - $186.2k
...About the team: The Information Security organization advances the overall state of security at Rubrik through purposeful initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams...SuggestedLocal areaRemote work$30 - $35 per hour
...A customer of Insight Global is looking to hire a Security Analyst to come onboard! This individual will support enterprise vulnerability management efforts by coordinating remediation activities across multiple engineering teams, validating vulnerability findings,...Suggested- ...Position: Security Analyst 1 Location: Austin, TX 78701 Duration: 7+ years All work products resulting from the project shall be considered "works made for hire" and are the property of the TEA. TEA may include pre-selection requirements that potential...Suggested
- ...CAPPS Program. Responsible for the IAM (TDIS) and ERP (CAPPS) security framework, which includes but is not limited to: Provides oversight... ...and processes. 5 Required Experience serving in a security analyst role with responsibility overseeing a Managed Services provider...SuggestedContract workWork at officeLocal area
- ...Neos Consulting Group is seeking a Sr. Systems Analyst for a contract role in the Austin, TX area. The position focuses on advanced security, access control, and service-desk support for CPA's CAPPS HR/Payroll environment. Responsibilities include enforcing RBAC, validating...Contract work
- ...Brivo invites a junior GRC professional to join our Austin security team, offering high visibility and broad exposure across Engineering, Legal, HR, and leadership. You’ll gain dedicated time to learn enterprise security frameworks while supporting policy, training, and...
- ...Insight Global is seeking a Security Analyst to support enterprise vulnerability management by coordinating remediation across engineering teams, validating findings, and ensuring SLA compliance. You will review data in Ivanti, track risk in Archer GRC, create Jira tickets...
- ...safety. Please be aware that all official communication will only be sent from @Rippling.com addresses.About the RoleJoin Rippling's Security Assurance team and help demonstrate the trust our customers place in us every day. You'll play a key role in delivering...Work at office3 days per week
- ...and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.Job Title: Network Security Analyst 1Location(s): Austin, TX Summary: A public-sector transportation agency is seeking a Network Security Analyst I to...
$111k - $144k
...who are remote in the United States, but can travel to our headquarters 1-2 times per quarter*We are looking for a passionate Security Data Analyst/Python Developer to help us parse, transform, and analyze dirty data. The ideal candidate has a thorough understanding of...Full timeTemporary workLocal areaRemote workWorldwideVisa sponsorshipFlexible hours2 days per week- ...The Security Operations Center (SOC) Analyst I is a frontline cyber defender responsible for monitoring security tools and dashboards to identify indicators of compromise across networks, endpoints, and cloud‑hosted systems in mission‑critical environments. The role focuses...Contract workWork at officeShift work
- ...The Security Operations Center (SOC) Analyst II serves as a mid‑level cyber defender responsible for continuous monitoring, investigation, and response to security events across enterprise networks, endpoints, and cloud environments in a highly regulated government setting...Contract workWork at office
$30 - $35 per hour
...pay range $30.00/hr - $35.00/hr Skills & Experience 3-5 years of Security Incident Response, Security Operations Center, and/or threat... ...either an enterprise and/or cloud Security SIEM technologies as an analyst Ability to support and work across multiple customer and...Contract workShift workNight shiftWeekend work$30 per hour
...the Oracle Government, Defense & Intelligence team supporting Federal Compliance and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management team to ensure documentation, processes and policies up to date...Hourly payTemporary workInternshipFlexible hours- ...Must Have Skills Skill 1 - Any recognized security certifications, e.g., CISSP, CISA, CISM Skill 2 - Monitor internal and external threat landscape to update strategy and intellectual protection program roadmap Skill 3 - Provide periodic reports to management team...
$100k - $120k
...companies. Learn more at bonterratech.com. About the Role The Bonterra Information Security Risk and Compliance department is looking to hire a Senior Information Security Risk Analyst to our team. If you enjoy problem solving, are enthusiastic working in a team format...Full timeLocal area$72k - $90k
...stack technical know-how to develop innovative solutions for our clients' most complex challenges. Position Overview: The Security Analyst supports customer engagements by helping to deliver business and technology solutions, interacting with clients to understand...Full timeRemote workShift work- Job Overview As a SecOps Analyst at Saronic, you'll be on the front line of our detection and response operations, triaging and investigating security alerts across endpoint, cloud, identity, network, and SaaS telemetry using our SIEM and XDR platforms. You'll run root...Permanent employmentTemporary workWork at office
- ...Job Description Job Description Description: The Senior IT & Security Governance Analyst is responsible for advancing technology governance, security, and operational maturity initiatives across corporate IT, cloud and product environments, and operational systems...
- ...Preferred 10+ Years (Enterprise/Government GRC Environments) Job Description: Seeking an experienced RSA Archer GRC Security Analyst to support enterprise governance, risk, and compliance initiatives through the administration, configuration, integration, and...
- Job DescriptionAt General Motors, we are building secure software and connected experiences at scale. The Offensive Security function helps strengthen that mission by continuously validating defenses through real-world attack simulation, penetration testing, responsible...Full timeLocal areaWork from homeRelocation package
- ...diverse backgrounds, experiences, and perspectives to join our network of industry subject matter experts. The Logistics Security Analyst, assigned to one of Pinkerton’s largest global clients, will be a part of a diverse team within the centralized hub of prototype...Work at officeLocal areaWeekend work
- ...and improving efficiency with real-time guidance.The Compliance Analyst is responsible for the execution of processes relating to... ...violence, status as a victim of stalking, status as a victim of sex offenses, genetic information, political activities or recreational activities...Full timeWork at office
- ...alienage, sexual orientation, status as a victim of domestic violence, status as a victim of stalking, status as a victim of sex offenses, genetic information, political activities or recreational activities, arrest or conviction record, salary history, natural hairstyle...Full time
- ...constraints, and manage formal risk exceptions. By providing Information Security leadership with a transparent, data-driven view of the global... ...marital status, status as a victim of domestic violence or sex offenses, reproductive health decision, or any other characteristics...Casual workFlexible hoursShift work
- ...Armed Services Vocational Aptitude Battery for enlisted roles or officer qualification tests for officer programs Eligibility for a security clearance when required for your rating or designator Additional qualifications can include specific skills, education, licensure,...ApprenticeshipNight shift
$120k - $170k
Position Title:Senior Manager, Hyperscale Investment Strategy (Sr Analyst)Locations:New York, NY | Boston, MA | Dallas, TX | Austin, TX |... ...’s global data center platform, provides customers with a secure data meeting place and a proven Pervasive Datacenter Architecture...Full timeShift work$77.3k - $135.3k
...be the right fit for you.The AWS Global Data Center Supply Solutions Team is looking for a talented, experienced Colocation Lease Analyst based in our Seattle, Austin or DC corporate office campuses. In this role, you will be a key member of the Colocation Portfolio &...Contract workWork at officeFlexible hours- ...industry, join our team as we help shape a brighter way forward. Analyst, Capital Markets - Investment Sales Advisory (ISA) - JLLWhat... ...recruitment process. We endeavour to keep your personal information secure with appropriate level of security and keep for as long as we...Full timeWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!
Related searches
- rate analyst Austin, TX
- security analyst Austin, TX
- bond analyst Austin, TX
- junior security analyst Austin, TX
- senior security analyst Austin, TX
- network security analyst Austin, TX
- information security analyst Austin, TX
- security operations analyst Austin, TX
- application security analyst Austin, TX
- information security compliance analyst Austin, TX



