Stand out for this role — generate a tailored resume and cover letter in about a minute.
EY is seeking security consultants for a Cyber Security role based in Dublin. You will lead and contribute to penetration testing engagements, assess web and API security, and work with clients to design, build and test pragmatic security solutions that improve posture.
We value hands-on testing, strong reporting, and the ability to mentor teammates as part of a rapidly growing practice. This permanent full-time role offers opportunities for leadership and career progression within a global
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Location: Dublin
Available for Work Visa Sponsorship: NO
Business Area: Cyber Security
Contract Type: Full-Time – Permanent
EY’s Cyber Security practice is one of the fastest growing areas of the business with an immediate requirement for security consultants with a diverse range of skills and experience. As a leader on our Cyber team you will be providing advisory and technical leadership to help our clients improve their cyber security posture to respond to the dynamic Cyber Security threats. You will provide security domain expertise and utilise your business insight to work closely with our clients to advise, design, build, deploy and test pragmatic security solutions that will give real and tangible benefits and security enhancement.
You will be a lead member of a highly skilled and rapidly growing team of Technical Security specialists. Your role will consist of leading and supporting global penetration testing and offensive security teams and carrying out offsite and onsite penetration tests and vulnerability assessments against a wide range of systems and environments, in addition to advancing red teaming and DevSecOps capabilities. As a member of the team, you will have the opportunity to grow your career in leading the delivery of penetration testing and offensive security, with a significant opportunity for leadership experience and career progression.
Strong hands-on experience performing structured web application penetration tests across large and complex applications, including estates with hundreds of URLs, routes or functional components.
Strong hands-on API security testing experience across REST and SOAP services; GraphQL experience is an advantage
Ability to assess authentication, authorisation, access control, session management, input validation, business logic and data exposure weaknesses
Experience testing modern identity and API security mechanisms, including OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens and API keys
Experience performing grey-box and code-assisted penetration testing, using source code, architecture information, credentials and developer input to improve test depth and coverage
Ability to review application code for security weaknesses and trace findings from source to runtime behaviour; experience with common languages and frameworks such as Java, .NET/C#, JavaScript/TypeScript or Python is desirable
Working knowledge of OWASP Web Security Testing Guide, OWASP Top 10, OWASP API Security Top 10, CWE and CVSS, with the ability to apply them appropriately during testing and reporting
Proficiency with application and API testing tools such as Burp Suite Professional, Postman or equivalent API clients, browser developer tools, intercepting proxies and appropriate supporting scripts
Ability to define and challenge test scope, identify coverage gaps, obtain missing technical information and maintain traceability between the agreed scope, test activity, evidence and final report
Experience producing clear, reproducible findings with requests and responses, proof-of-concept evidence, affected components, risk rationale and practical remediation guidance
Strong understanding of secure software development and DevSecOps practices, including application architecture, CI/CD pipelines, SAST, DAST, software composition analysis, secrets management and secure code review
Ability to work closely with developers, product owners and security stakeholders, explain technical issues clearly, challenge assumptions constructively and drive remediation and retesting discussions
Experience operating effectively in highly restricted client environments, including client-managed virtual machines, controlled tooling, limited internet access and prohibitions on moving client data or evidence outside the environment
Strong evidence-handling discipline, including secure storage, naming, version control, review, quality assurance, sign-off and disposal in line with client requirements
Ability to work independently, manage multiple assessments and deliver consistently high-quality outputs to agreed deadlines
Ability to peer review test plans, evidence and reports, and to mentor less experienced penetration testers
Strong written and verbal communication skills, including the ability to translate technical vulnerabilities into credible business risk for technical and non-technical stakeholders
Current knowledge of web and API attack techniques, emerging application security threats, bypass methods and defensive controls
Minimum 5 years’ hands-on penetration testing experience, with substantial recent delivery across web applications and APIs
Demonstrable experience testing large and complex applications with extensive URL, route or endpoint coverage
Demonstrable grey-box or code-assisted testing experience, including secure code review and collaboration with development teams
Experience assessing REST and SOAP APIs; GraphQL, microservices and cloud-native application testing experience is desirable
Experience delivering the full assessment lifecycle: scoping, test planning, access validation, execution, evidence capture, peer review, reporting, stakeholder readout, remediation support and retesting
Experience working within restricted or segregated client environments where testing, evidence and reporting must remain on client-managed systems
Track record of producing high-quality technical reports and explaining findings to developers, application owners, risk stakeholders and senior management
Consulting experience and experience coordinating multiple concurrent assessments are desirable
OSCP, OSWE, CREST, CHECK Team Member/Leader or an equivalent practical application security certification is desirable
A demonstrable commitment to continuing professional development in web, API and application security
We offer a competitive remuneration package. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer:
All our employees are given a benefits package which they can tailor to suit their individual preferences. Our range of benefits include:
As a global leader in assurance, tax, transaction and advisory services, we’re using the finance products, expertise and systems we’ve developed to build a better working world. That starts with a culture that believes in giving you the training, opportunities and creative freedom to make things better. Whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.
We hold a collective commitment to foster an environment where all differences are valued and respected, practices are equitable and everyone experiences a sense of belonging: Inclusion, diversity, and equity are part of who we are at EY. We believe that the highest-performing teams maximize the power of different perspectives and backgrounds. These teams are both diverse and inclusive and are willing to invite and learn from other perspectives. Our ability to include various viewpoints into our mindsets, behaviours and operations is fundamental to driving innovation, building strong relationships, and delivering the best solutions for our clients.
We recognise the strength that comes from having a diverse workforce and building a culture where we support all our people to achieve their potential. You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues for today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fuelled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.