An application made for this job — a tailored resume and cover letter that speak straight to the posting.
EY is seeking a Senior Attack & Penetration Tester to strengthen client resilience through sophisticated offensive security operations. You will plan, lead, and execute complex engagements across diverse environments, applying threat-informed techniques and MITRE ATT&CK-informed approaches.
The role requires coordinating testing activities, mentoring junior staff, and communicating risk and remediation strategies to technical and executive audiences. Travel up to 80% may be required.
Location: Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Cyber threats, social media, artificial intelligence, privacy requirements, and continuity of the business as usual require heavy information security measures. As a Senior Attack & Penetration Tester, you will contribute to our client’s resilience through the execution of sophisticated offensive security operations.
As a Senior on the Attack & Penetration Testing team, you will plan, lead, and execute complex penetration testing and advanced red team engagements across diverse client environments. You will apply an intelligence-led, threat-informed approach to emulate realistic adversary behaviors, identify exploitable attack paths, and evaluate preventive, detective, and responsive security controls. Your work will span external and internal networks, Active Directory, Microsoft Entra ID, web and mobile applications, application programming interfaces (APIs), cloud environments, wireless networks, social engineering, and physical security scenarios, as permitted by the rules of engagement. You will translate technical testing results into clear, actionable insights for technical and executive audiences. You will work collaboratively with client technical teams to validate identified weaknesses and develop practical remediation or mitigation strategies, including Active Directory security improvements, system-hardening measures, and compensating controls aligned with the client environment and operational constraints. You will also lead technical workstreams, coordinate testing activities, mentor junior team members, contribute to methodology and capability development, and remain current on emerging vulnerabilities, adversary tactics, offensive security tooling, and industry research.
To thrive in this role, you'll need a blend of technical and business skills, along with the ability to navigate complex problems and make informed decisions. Your professional knowledge and experience will guide you in adhering to broad policies and tackling issues with in-depth evaluations.
A valid U.S. driver’s license and the willingness and flexibility to travel up to 80 percent, domestically and internationally, to meet client needs.