Offensive Security Analyst
Ernst & Young Oman
The opportunity As an Offensive Security Analyst on the Attack Surface Management team, you will play a key role in evaluating and reducing EY’s digital exposure through hands‑on penetration testing and adversarial simulation. Working under the guidance of the Exposure Management Lead, you will identify, assess and help mitigate vulnerabilities across EY’s global attack surface. This role goes beyond traditional scanning by actively emulating threat actors, performing penetration testing and assessing the true impact of security weaknesses. Your responsibilities will include supporting the validation of third‑party risk assessments, identifying misconfigurations and exposed assets, and ensuring security standards are applied across EY’s digital ecosystem. You will also contribute to strengthening Continuous Threat Exposure Management and Attack Surface Management efforts by providing actionable insights that improve proactive defense and reduce overall business risk. Your key responsibilities The Analyst will apply offensive security techniques to assess EY’s external and internal attack surface, identifying vulnerabilities across web applications, APIs, cloud environments, networks, and infrastructure. This includes testing proof‑of‑concepts to validate exploitability and determine real‑world impact. The role involves emulating adversary tactics to test detection and response capabilities, as well as conducting reconnaissance and asset discovery to uncover unmanaged or exposed assets. The candidate will support third‑party and supply chain risk validation efforts by reviewing assessments or conducting targeted testing where required. Collaborating closely with security engineering, blue teams and business stakeholders, the analyst will help prioritize remediation efforts based on risk severity and exploitability. Additionally, the role will contribute to enhancing processes, playbooks and reporting standards within the Vulnerability Discovery and offensive security functions. Skills and attributes for success Capability to identify and exploit vulnerabilities beyond automated scanning tools like Qualys, Nessus etc. Strong attention to detail with a methodical approach to identifying complex attack paths Critical thinking and analytical skills to evaluate vulnerabilities in a business risk context Ability to manage high volumes of testing requests without compromising depth or quality Flexibility to work across diverse technologies, including cloud, applications and infrastructure Effective communication skills to convey technical findings to both technical and non‑technical audiences Familiarity with research techniques and threat intelligence to support proactive risk identification To qualify for the role you must have A minimum of 4 years of experience in penetration testing, red teaming, purple teaming or offensive security Hands‑on experience testing applications, APIs, cloud environments and network infrastructure Strong understanding of common vulnerability classes such as OWASP Top 10 and exploitation techniques Familiarity with offensive security methodologies and frameworks Experience supporting or performing third‑party risk assessments Strong analytical and problem‑solving skills with the ability to prioritize risks effectively Strong communication and stakeholder management skills Ideally, you’ll also have OWASP training Incident response experience What we look for We are looking for a developing Offensive Security Analyst that can operate with supervision and bring new approaches to discovering and evaluating the business’s externally‑exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization. What we offer you We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is 76,400 to 138,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team‑led and leader‑enabled hybrid model. Our expectation is for most people in external, client‑serving roles to work together in person 40‑60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial and emotional well‑being. EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io. #J-18808-Ljbffr
- ...Job Title: Security Analyst Location: Lansing, MI 48909 Duration: 12 Months Job Desription: Top Skills & Years of Experience: - 2+ years overall experience - Experience with NIST and CJIS (1-2+ years) - Keylight experience...Suggested
- ...Responsibilities The IT Security Analyst is responsible for completing and maintaining system security plans (SSP) for new and existing systems. This requires close coordination with IT project teams, business and enterprise security representatives, and product owners...SuggestedWork at officeShift work
- ...Compliance Specialist Top Skills & Years of Experience Required 3-5 years' experience for skills below: Knowledge of Cyber Security NIST 800-53 Follow the IT security technical architecture design methodology and best practices. External Vendor contact/...Suggested
- ...IT Security Analyst 3 The State of Michigan is looking for an IT Security Analyst 3. Top skills and years of experience include: ~6+ years experience with IT security and auditing. ~ Expert knowledge around NIST Controls and ability to perform risk assessments...SuggestedLocal areaRemote workRelocation
- ...IT Security Analyst Monitor and advise on information security issues related to the systems and workflow at an agency to ensure the internal IT security controls for an agency are appropriate and operating as intended. Coordinate and execute IT security related projects...SuggestedWork at officeWork from homeFlexible hours2 days per week
- ...IT Security Analyst 3 Location Lansing MI Top Skills & Years of Experience: - 5+ years of experience with cybersecurity related job functions. - Strong knowledge and understanding of compliance regulations and their related frameworks, such as: - NIST SP80...
- ...IT Security Analyst Monitor and advise on information security issues related to the systems and workflow at an agency to ensure the internal IT security controls for an agency are appropriate and operating as intended. Years of Experience: 4-7 years of experience...Shift work
- ...Michigan IT Security Analyst #1057680 Job Description: Who we are looking for: This role is instrumental in defending us against sophisticated cyber threats, with a main focus on mitigating malware/virus and software vulnerability‑related incidents, specifically leveraging...Permanent employmentImmediate start
$30 per hour
...the Oracle Government, Defense & Intelligence team supporting Federal Compliance and Federal Sales Teams. The Information Security Compliance Analyst is expected to work with the GDI Performance Management team to ensure documentation, processes and policies up to date...Hourly payTemporary workInternshipFlexible hours- ...Seeking a C2C candidate located in the specified area. The Senior Security Analyst position works as a member of the Incident Response Team. This position reviews and remediates cyber incidents, alerts and vulnerabilities in the State of Michigan (SOM) environment...
- ...Job Title Seeking a C2C candidate located in the specified area. Monitor and advise on information security issues related to the systems and workflow at an agency to ensure the internal IT security controls for an agency are appropriate and operating as intended...
- ...Job Title : IT Security Analyst 3 - Vulnerability Management Team Location: Dimondale, MI, Hybrid Rate : Best competitive rate Top Skills & Years of Experience: ~5+ Years' IT Security Experience ~ Experience with vulnerability management scanning and reporting...Work at officeLocal areaRemote workRelocation2 days per week
- ...Job Title: IT Security Analyst 3 Job Location: Dimondale, MI (Hybrid) Job Type: Contract Job Description: Plans, schedules, implements and maintains scalable vulnerability scans using modern vulnerability management scanning tools for high-complexity...Contract work
- ...Cyber Security Analyst Location: Dimondale, MI Duration: 12+ Months Remote or On-site: Candidates must be currently local within a commutable distance, no more than 1-1.5 hours. Position will be hybrid, in office 2 days a week upon start. Job Description The...Work at officeLocal areaRemote work2 days per week
$143k - $243k
A leading pharmacy benefits manager is seeking a Senior Principal Actuary to provide actuarial direction and thought leadership. The role involves creating innovative modeling concepts, strategic consulting, and mentoring actuarial staff. Applicants should have a minimum...Remote work$143k - $243k
...business solutions to clients’ complex pharmacy benefit challenges. Every employee must understand, comply with and attest to the security responsibilities and security controls unique to their job, and comply with all applicable legal, regulatory, and contractual...Work experience placementLocal areaRemote workVisa sponsorshipWork visa- Job Purpose Responsible for complex actuarial projects in product development, financial modeling, financial reporting, risk analysis, or data analysis assignments, as applicable. Independently performs activities related to the application of advanced actuarial principles...
$70.6k - $118.3k
SUMMARY This role sits at the intersection of core actuarial pricing work, analytical problem‐solving, and process enablement. You'll support rate indications, pricing tools, filings, and recurring reporting, while also investigating pricing results and business questions...Price workContract workWork at office- ...and rewarding. Our group of caring associates create financial security by helping individuals and businesses make a new start when a loss... ...individual to join our Actuarial Division as an Actuarial Analyst. The position is responsible for creating pricing plans to help...Currently hiringLocal areaHome office3 days per week
- OBJECTIVE Senior Life Actuary Objective To provide life actuarial programs, spreadsheets, reports, models, and supporting information for preparation of specific financial reporting, product development, and regulatory and analytical tasks. To incorporate new methodologies...Work at office
$75k - $90k
...Actuarial Analyst II – The Auto Club Group Job Type: Full time Exempt/Non Exempt: Salary What you will do Analyze data, develop material and prepare appropriate communications Compile and organize data for actuarial review Prepare reports, proposals, system documents,...Full timeWork at officeRemote work$129.3k - $177.8k
A leading healthcare organization based in Michigan is seeking an Actuary for Analytics/Forecasting. The role involves analyzing financial and economic data to support strategic decisions, collaborating with stakeholders, and analyzing medical claims trends. Candidates...Remote work$129.3k - $177.8k
Become a part of our caring community The Actuary, Analytics/Forecasting analyzes and forecasts financial, economic, and other data to provide accurate and timely information for strategic and operational decisions. Establishes metrics, provides data analyses, and works...Bi-weekly payFull timeTemporary workApprenticeshipWork experience placementRemote workWork from homeHome officeShift work$132.5k - $217k
...support of actuarial and underwriting leaders as well as be responsible for the pricing of Direct Markets accounts. The Senior Actuarial Analyst and team will partner with Direct Markets Underwriting teams, Line of Business Pricing, Reserving, and Data Analytics, among others...Full timeTemporary workApprenticeshipWork at officeLocal areaRemote workVisa sponsorship$17 - $19 per hour
...Overview DK Security is Michigan's fastest growing security company. Established in 1995, we began as an investigations firm and... ...substances (including for marijuana), or two or more alcohol related offenses, per MCL 338.1060 §10(1)(c). Must be able to sit, stand, and...Hourly payContract workPart timeTrial periodFlexible hoursShift workDay shiftAfternoon shift- ...sense of belonging. Join us on our One Perrigo journey as we evolve to win in self-care. Description Overview The Perrigo Corporate Security Specialist (CSS) will support the Corporate Security Department’s goal of providing best in practice enterprise security risk...For contractorsRemote workShift work2 days per week
$106.9k - $147k
Become a part of our caring community Reports To: Associate Director, Actuarial Analytics/Forecasting FLSA: Exempt/Salaried The Associate Actuary, Analytics/Forecasting analyzes and forecasts financial, economic, and other data to provide accurate and timely information...Full timeContract workTemporary workApprenticeshipRemote workWork from home$106.9k - $147k
...information. SSN Alert: Humana values personal identity protection. Please be aware that applicants may be asked to provide their Social Security Number, if it is not already on file. When required, an email will be sent from ****@*****.*** with instructions on how to...Bi-weekly payFull timeTemporary workApprenticeshipRemote workWork from homeHome office$1,891.2 - $2,836 per month
...State Properties Security Officer Print ( Apply State Properties Security Officer Salary $1,891.20 - $2,836.00 Biweekly... ...substance (drugs) None 07 PRSCOFR - Please provide date, offense, location, law enforcement agency and disposition of any criminal...Permanent employmentFull timePart timeImmediate startRemote workFlexible hours- ...vigilant and verify the authenticity of any job offers or communications. We will never request sensitive information such as Social Security numbers or bank details during the initial stages of the recruitment process. If you suspect fraudulent activity, contact us...Local areaWorldwideOverseasLong distance
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Analyst. Be the first to apply!
- security analyst remote Lansing, MI
- senior information security analyst Lansing, MI
- information security compliance analyst Lansing, MI
- security analyst intern Lansing, MI
- security analyst Lansing, MI
- application security analyst Lansing, MI
- IT security analyst Lansing, MI
- entry level information security analyst Lansing, MI
- cloud security analyst Lansing, MI
- network security analyst Lansing, MI

