Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Analyst

$76.4k - $138.6k

Ernst & Young

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.

Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

The opportunity

As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands-on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses.Your responsibilities will include supporting the validation of third-party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk.

Your key responsibilities

The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof-of-concepts to validate exploitability and determine real-world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets.The candidate will support third-party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams, and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks, and reporting standards within the Vulnerability Discovery and offensive security functions.

Skills and attributes for success

  • Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc.

  • Strong attention to detail with a methodical approach to identifying complex attack paths

  • Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context

  • Ability to manage high volumes of testing requests without compromising depth or quality

  • Flexibility to work across diverse technologies, including cloud, applications, and infrastructure

  • Effective communication skills to convey technical findings to both technical and non-technical audiences

  • Familiarity with research techniques and threat intelligence to support proactive risk identification

To qualify for the role you must have

  • A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security

  • Hands-on experience testing applications, APIs, cloud environments, and network infrastructure

  • Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques

  • Familiarity with offensive security methodologies and frameworks

  • Experience supporting or performing third-party risk assessments

  • Strong analytical and problem-solving skills with the ability to prioritize risks effectively

  • Strong communication and stakeholder management skills

Ideally, you’ll also have

  • Certifications such as OSCP, GPEN, GWAPT, or equivalent offensive security credentials

What we look for

We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally-exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.

What we offer you

The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $91,700 to $157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.

  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.

  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.

Are you ready to shape your future with confidence? Apply today.

EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. 

EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .

Vacancy posted 6 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Analyst in Chicago, IL vacancy
  •  ...The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure... 
    Suggested
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    Chicago, IL
    2 days ago
  • Ernst & Young Oman is looking for an Offensive Security Analyst to assess and reduce digital exposure through penetration testing. You will identify vulnerabilities across web applications, APIs, and networks while collaborating with various teams to improve security standards... 
    Suggested

    Ernst & Young Oman

    Chicago, IL
    3 days ago
  •  ...Offensive Security Analyst (Structured / Non-Exploit) - AI Training About the Role What if your ability to trace an attacker's footsteps - mapping kill chains, spotting defensive gaps, and modeling adversary behavior - could directly shape how the world's most... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Chicago, IL
    1 day ago
  •  ...Security Analyst (XIN001_JB7T) Xinnovit is a global leader in technology consulting, outsourcing, and workforce management solutions. Our mission is to enable our clients to become more agile and competitive with the help of innovative technologies. We empower our... 
    Suggested

    Xinnovit

    Chicago, IL
    25 days ago
  •  ...Security Analyst Client is a leader in the healthcare industry. Client is dedicated to providing excellence in healthcare and compassionate care to the community. The organization serves residents of 15 counties in Illinois and Wisconsin. Job Description Reports... 
    Suggested
    Weekend work

    Bluestone Solutions Group

    Chicago, IL
    2 days ago
  •  ...As part of the Security and Network Operations Command Center staff you will be instrumental in supporting customers as part of our managed services and support offerings. All staff will be placed in our on‑the‑job career development program that will allow you to increase... 
    Work experience placement
    Currently hiring
    Work at office
    Night shift
    Day shift
    Afternoon shift

    Nexum Inc

    Chicago, IL
    4 days ago
  • Evolve Security is looking for an OSOC Security Analyst to join our growing team. This position will assist with the overall successful delivery of various application vulnerability assessments, continuous internal / external penetration assessments, incident response... 
    Work experience placement
    Flexible hours

    Evolve Security

    Chicago, IL
    1 day ago
  • $77.4k - $135.4k

    Vizient, Inc is looking for an IT Security Demand Analyst. This role involves serving as a central coordinator for security demand intake and management. The Analyst will work closely with various security teams to enhance operational effectiveness, manage request tracking... 

    Vizient, Inc

    Chicago, IL
    3 days ago
  • $120.14k

     ...SENIOR SECURITY ANALYST Job Number: 419477 Description JOB ANNOUNCEMENT Senior Security Analyst Department of Technology & Innovation Security Division Number of Positions: 1 (Additional vacancies possible pending budget approval) Starting... 
    Local area
    Immediate start
    Monday to Friday
    Flexible hours

    City of Chicago

    Chicago, IL
    2 days ago
  •  ...other scanning tools. Web application scanning and web application firewalls. Containers. CIS benchmarks, STIGs, or other security hardening standards. Additional Desirable Skills Or Experience SAML, Kerberos, OAuth, OIDC, LDAP. Powershell and... 

    The Dignify Solutions, LLC

    Chicago, IL
    5 days ago
  • $80k - $100k

     ...IT Security Analyst The IT Security Analyst supports the organization's cybersecurity operations by monitoring security alerts, analyzing potential threats, and assisting with the identification, investigation, and remediation of security incidents. This role requires... 
    Full time
    Work at office

    Jet Support, Inc.

    Chicago, IL
    5 days ago
  • $136k - $187k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted...  ...can effectively manage their risk. As a senior level analyst of Customer Assurance, you will support prioritizing and... 
    Work experience placement
    Local area
    Worldwide
    Flexible hours

    Okta, Inc.

    Chicago, IL
    5 days ago
  •  ...AI / Emerging Tech Security Analyst (AI Training) About The Role What if your security expertise could directly shape how the world’s most powerful AI systems defend themselves against attack? We’re looking for AI Security Analysts to probe frontier AI models for vulnerabilities... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Chicago, IL
    2 days ago
  •  ...Security Analyst The Security Analyst is responsible for managing third-party vulnerability data, executing scans using Sompo’s proprietary tools, and partnering with IT teams to prioritize remediation efforts. The role requires strong technical expertise in vulnerability... 

    Argyle Infotech

    Chicago, IL
    1 day ago
  • $10 - $15 per hour

     ...About the job SAP Security Analyst Applicants outside US are encouraged to apply Position: SAP Security Analyst Rate: $10-15 (Depending on your experience) Work Authorization: Any Location: 100% Remote Job Summary SAP security troubleshooting... 
    Remote work

    Knack Solutions

    Chicago, IL
    3 days ago
  •  ...We’re Hiring – Securities Operations Professionals – all levels! Location: Chicago, IL (Hybrid) Phillip Capital Inc., located in Chicago, is dually registered with the SEC/FINRA as a self-clearing broker dealer and the Commodity Futures Trading Commission (CFTC) as... 
    Work experience placement
    Work at office

    Phillip Capital Inc.

    Chicago, IL
    1 day ago
  •  ...Security Operations Analyst The Security Operations Analyst function is responsible for providing continuous threat monitoring and incident response services. This individual is responsible for monitoring, developing, and maintaining the tools, technologies, and processes... 

    1872 Consulting

    Chicago, IL
    2 days ago
  •  ...IT Security Operations Analyst The Security Analyst will support security operations and analysis of security related incidents, vulnerabilities, DLP and other security events. This role will enhance existing security tools and automations, with a focus on protecting... 

    1872 Consulting

    Chicago, IL
    5 days ago
  •  ...Security Operations Analyst (AI Training) About the Role We're looking for experienced Security Operations Analysts to help evaluate and improve AI systems designed for modern SOC environments. Your real-world expertise in threat detection, alert triage, and incident... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Chicago, IL
    1 day ago
  • $96.7k - $148.1k

     ...Sr. Information Security Analyst page is loaded## Sr. Information Security Analystlocations: Rochester, New York: Chicago, Illinois: San Antonio, Texastime type: Full timeposted on: Posted Todayjob requisition id: R-40050**Job Description****Role Summary**The Senior Information... 
    Minimum wage
    Full time
    Remote work
    Shift work

    Constellation Brands

    Chicago, IL
    2 days ago
  •  ...Senior Security Analyst – GRC The Senior Security Analyst – GRC (Governance, Risk and Compliance) is a member of the IT Security team and works closely with other IT teams and business stakeholders in the development and automation of core functions supporting the... 

    1872 Consulting

    Chicago, IL
    5 days ago
  •  ...We are looking for a detail-oriented and analytical Junior Security Operations Analyst to join our cybersecurity team. In this role, you will monitor our security tools and systems, investigate alerts, escalate issues, and document security incidents. Responsibilities... 

    Benda Infotech

    Chicago, IL
    2 days ago
  •  ...Network & Infrastructure Security Analyst (AI Training) About the Role We're partnering with the world's leading AI research teams to build next-generation security intelligence - and we need experienced practitioners to help get it right. As a Network & Infrastructure... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Chicago, IL
    1 day ago
  • $75k - $88k

    The Jackson National Life Insurance Company seeks a Portfolio Analyst to support investment accounting and cash management among client portfolios. This role involves reconciling holdings, ensuring trade settlement accuracy, and developing new operational processes for... 

    The Jackson National Life Insurance Company

    Chicago, IL
    1 day ago
  • $22 - $23 per hour

    Job Title High Signal To Noise Ratio, Make The Content Beautiful. Job Description Location 5800 Edgewod Rd SW, Cedar Rapids, IA, 52404, United States Base Pay $22.00 - $23.00 / Hour Job Category Free Snacks, 2 Weeks PTO, Full-Time Industry Secruity, Tech...
    Full time

    Metro One Security

    Chicago, IL
    2 days ago
  • $77.4k - $135.4k

    Vizient, Inc. is looking for a Security Demand Analyst in Chicago, IL. The role involves coordinating Security demand intake and management across the enterprise. You will liaise with business stakeholders and facilitate collaboration among teams to ensure requests are... 

    Vizient, Inc.

    Chicago, IL
    5 days ago
  • Evolve Security is seeking an OSOC Security Analyst in Chicago, IL, to support various security assessments and incident responses. This role involves monitoring eASM dashboards, conducting vulnerability validations, and engaging with clients to understand security objectives... 
    Flexible hours

    Evolve Security

    Chicago, IL
    1 day ago
  • $77.4k - $135.4k

    IT Security Demand Analyst page is loaded## IT Security Demand Analystlocations: Irving, TX 75062 Vizient Corporate HQ: Chicago, IL 60607time type: Full timeposted on: Posted Todayjob requisition id: 33198RWhen you’re the best, we’re the best. We instill an environment... 
    For contractors

    Vizient, Inc

    Chicago, IL
    5 days ago
  • A technology solutions company is seeking a remote SAP Security Analyst. The role involves troubleshooting SAP security, supporting projects at various stages, and designing new authorization concepts. Candidates should have experience with SAP security, GRC access control... 
    Remote job

    Knack Solutions

    Chicago, IL
    3 days ago
  • $72k - $90k

     ...stack technical know-how to develop innovative solutions for our clients' most complex challenges. Position Overview: The Security Analyst supports customer engagements by helping to deliver business and technology solutions, interacting with clients to understand... 
    Full time
    Remote work
    Shift work

    World Wide Technology

    Chicago, IL
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!