Cyber - Attack & Penetration Testing - Senior - Consulting

EY

Tulsa (OK)

On-site

USD 150,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

EY is seeking a Senior Attack & Penetration Tester to contribute to client resilience through sophisticated offensive security operations. You will plan, lead, and execute complex testing across diverse environments, applying intelligence-led approaches to emulate adversaries and identify exploitable paths.

This role spans external/internal networks, AD, cloud, APIs, and more. You will mentor junior testers, guide methodology development, and communicate risk insights to technical and executive

Qualifications

  • Demonstrated ability to plan and execute complex penetration tests and red team engagements.
  • Ability to identify and exploit vulnerabilities across networks, AD, cloud, and APIs.
  • Experience applying threat-informed testing techniques aligned with MITRE ATT&CK.

Responsibilities

  • Plan, lead, and execute penetration tests and red team engagements.
  • Identify vulnerabilities across external and internal networks, AD, cloud, APIs, web, and mobile apps.
  • Translate testing results into actionable remediation and security controls.
  • Mentor junior team members and coordinate testing workstreams.
  • Produce client reports and executive-level risk insights.

Skills

Advanced problem-solving
Penetration testing
Red team engagements
Threat-informed testing
Lead technical testers
Team mentorship
Executive communication
Travel up to 80%

Tools

MITRE ATT&CK

Job description

Location: Anywhere in Country

At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

The Opportunity

Cyber threats, social media, artificial intelligence, privacy requirements, and continuity of the business as usual require heavy information security measures. As a Senior Attack & Penetration Tester, you will contribute to our client’s resilience through the execution of sophisticated offensive security operations.

Your Key Responsibilities

As a Senior on the Attack & Penetration Testing team, you will plan, lead, and execute complex penetration testing and advanced red team engagements across diverse client environments. You will apply an intelligence-led, threat-informed approach to emulate realistic adversary behaviors, identify exploitable attack paths, and evaluate preventive, detective, and responsive security controls. Your work will span external and internal networks, Active Directory, Microsoft Entra ID, web and mobile applications, application programming interfaces (APIs), cloud environments, wireless networks, social engineering, and physical security scenarios, as permitted by the rules of engagement. You will translate technical testing results into clear, actionable insights for technical and executive audiences. You will work collaboratively with client technical teams to validate identified weaknesses and develop practical remediation or mitigation strategies, including Active Directory security improvements, system-hardening measures, and compensating controls aligned with the client environment and operational constraints. You will also lead technical workstreams, coordinate testing activities, mentor junior team members, contribute to methodology and capability development, and remain current on emerging vulnerabilities, adversary tactics, offensive security tooling, and industry research.

Skills And Attributes For Success

To thrive in this role, you'll need a blend of technical and business skills, along with the ability to navigate complex problems and make informed decisions. Your professional knowledge and experience will guide you in adhering to broad policies and tackling issues with in-depth evaluations.

  • Demonstrate advanced problem-solving and critical-thinking skills when developing and executing attack paths.
  • Plan and conduct penetration tests and advanced red team engagements within defined scopes, rules of engagement, and safety constraints.
  • Identify, validate, and exploit vulnerabilities across external and internal networks, Active Directory, Microsoft Entra ID, cloud, wireless, web, mobile, and API environments.
  • Apply threat-informed testing techniques aligned with the MITRE ATT&CK framework and relevant adversary tactics, techniques, and procedures.
  • Lead technical testers, coordinate distributed workstreams, and provide hands‑on coaching and quality review for junior team members.
  • Recognize when to escal
  • Produce high‑quality technical work products, evidence, client reports, and executive‑ready presentations that clearly explain risk and remediation priorities.
  • Communicate complex offensive security concepts clearly to technical stakeholders, business leaders, and executives.
  • Work collaboratively in cross‑functional, culturally diverse, and geographically dispersed teams while adhering to service quality and engagement management requirements.

A valid U.S. driver’s license and the willingness and flexibility to travel up to 80 percent, domestically and internationally, to meet client needs.

Ideally, you’ll also have
  • Hands‑on cloud
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber - Attack & Penetration Testing - Senior - Consulting
Cyber - Attack & Penetration Testing - Senior - Consulting

EY • Seattle (WA)

On-site
USD 120,000 - 170,000
Cyber - Attack & Penetration Testing - Senior - Consulting
Cyber - Attack & Penetration Testing - Senior - Consulting

EY • Birmingham (AL)

On-site
USD 120,000 - 180,000
Cyber - Attack & Penetration Testing - Senior - Consulting
Cyber - Attack & Penetration Testing - Senior - Consulting

EY • Charleston (WV)

On-site
USD 140,000 - 190,000
Cyber - Attack & Penetration Testing - Senior - Consulting
Cyber - Attack & Penetration Testing - Senior - Consulting

EY • Greenville (SC)

On-site
USD 120,000 - 190,000
Cyber - Attack & Penetration Testing - Senior - Consulting
Cyber - Attack & Penetration Testing - Senior - Consulting

EY • Chicago (IL)

On-site
USD 120,000 - 180,000
Cyber - Attack & Penetration Testing - Senior - Consulting
Cyber - Attack & Penetration Testing - Senior - Consulting

Ernst & Young Oman • Salem (OR)

On-site
USD 140,000 - 180,000
Cyber - Attack & Penetration Testing - Senior - Consulting
Cyber - Attack & Penetration Testing - Senior - Consulting

Ernst & Young Advisory Services Sdn Bhd • Houston (TX)

On-site
USD 125,000 - 210,000
Cyber - Attack & Penetration Testing - Manager - Consulting
Cyber - Attack & Penetration Testing - Manager - Consulting

EY • Indianapolis (IN)

On-site
USD 145,000 - 290,000
Medical insurance
Pension plan
401(k) plan
+1
Cyber - Attack & Penetration Testing - Manager - Consulting
Cyber - Attack & Penetration Testing - Manager - Consulting

EY • Providence (RI)

On-site
USD 145,000 - 302,000
Medical and dental coverage
Pension and 401(k) plans
Paid time off
Cyber - Attack & Penetration Testing - Manager - Consulting
Cyber - Attack & Penetration Testing - Manager - Consulting

EY • Nashville (TN)

On-site
USD 145,000 - 290,000
Medical and dental coverage
Pension and 401(k)
Paid time off