LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
or continue with e-mail and password
Forgot password?
Don't have an account?
Create an account
or continue with e-mail and password
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Consulting_Cyber Threat Management - Pen Testing Staff

ExperiencedNo visa sponsorship
Ernst & Young logo

at Ernst & Young

Big Four

Posted 13 days ago

No clicks

**EY Penetration Testing Staff: Cyber Threat Management** - **Key Responsibilities**: Perform internet, intranet, wireless, web app, social & physical penetration testing. Analyze results, report findings, and recommend security improvements. Collaborate with development teams and convey complex security concepts. Lead junior team members and develop risk mitigation solutions. - **Skills & Experience**: - 1+ years in penetration testing, including 3+ types (e.g., web app, network, social engineering) - Relevant certifications (e.g., OSCP, OSWP, GPEN, GWAPT) - Experience with scripting/programming (Python, PowerShell, etc.) - Familiarity with DAST/SAST tools & methodologies (e.g., BurpSuite, OWASP Top 10) - Strong knowledge of Active Directory, TCP/IP, and network security - Experience with automation tools (e.g., Chef, Puppet) and CI/CD pipelines - **Education**: BE/B.Tech/MCA with 1-4 years of relevant experience in strategy & operations projects.

Compensation
Not specified

Currency: Not specified

City
Colombo
Country
Not specified

Full Job Description

At EY, youll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And were counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

EY GDS Cybersecurity Attack & Penetration Testing - Staff 

As part of our EY-cyber security team, you shall perform penetration testing which includes internet, intranet, wireless, web application, social engineering and physical penetration testing. You shall also perform in-depth analysis of penetration testing results and create report that describes findings, exploitation procedures, risks and recommendations. 

 

The opportunity 
Were looking for Security Analyst with expertise in penetration testing. This is a fantastic opportunity to be part of a leading firm whilst being instrumental in the growth of a new service offering. 

 

Your key responsibilities 

  • Perform penetration testing which includes internet, intranet, web application, wireless, social engineering, physical penetration testing. 
  • Execute red team assessments to highlight gaps impacting organizations security postures. 
  • Identify and exploit security vulnerabilities in a wide array of systems in a variety of situations. 
  • Perform in-depth analysis of penetration testing results and create report that describes findings, exploitation procedures, risks and recommendations. 
  • Execute penetration testing projects using the established methodology, tools and rules of 
    engagements. 
  • Convey complex technical security concepts to technical and non-technical audiences including executives. 
  • Strong knowledge of OWASP Top 10 web and the ability to effectively communicate methodologies and techniques with development teams.
  • Ability to automate DAST/SAST solutions and reporting 
  • Support SDLC and agile environments with application security testing and source code reviews. 
  • Provide technical leadership and advise to junior team members on attack and penetration test engagements. 
  • Develop automated solutions that mitigate risks throughout the organization. 
  • Understanding and experience with Active Directory attacks. 
  • Understanding of TCP/IP network protocols. 

 

Skills and attributes for success 

  • Experience with automation through solutions such as Chef, Puppet, Jenkins, and Ansible. 
  • Experience with scripting / programming skills (e.g., Python, PowerShell, Java, Perl etc.) updated and familiarized with the latest exploits and security trends. 
  • Familiarity with dynamic web application vulnerability scanning tools and services (Acunetix, HP WebInspect, IBM AppScan, BurpSuite, IBM AppScan). 
  • Familiarity with static code analysis tools and services (CheckMarx, Fortify Static Code Analysis tool, Veracode, Coverity, IBM AppScan Source). 
  • Familiarity with Secure DevOps Integration. 
  • Understanding and experience with Active Directory attacks. 
  • Understanding of TCP/IP network protocols. 
  • Understanding of network security and popular attacks vectors. 
  • Understanding of web-based application vulnerabilities (OWASP Top 10). 
  • Experience with scripting / programming skills (e.g., Python or PowerShell or Java or Perl etc.). 

 

To qualify for the role, you must have 

  • BE/ B.Tech/ MCA. 
  • Minimum of 1 year of work experience in penetration testing which may include at least three of the following: internet, intranet, web application penetration tests, wireless, social engineering, physical and Red Team assessments. 
  • One of the following certifications: OSCP, OSWP, GPEN, GWAPT. 
  • Knowledge of Windows, Linux, UNIX, any other major operating systems. 
  • 2-4 years of work experience in Strategy and Operations projects 
  • Strong Excel and PowerPoint skills. 

 

Ideally, youll also have 

  • Project management skills 
  • Certifications: OSCP, OSWP, GPEN, GWAPT. 

 

What we look for 
Who can perform penetration testing which includes internet, intranet, wireless, web application, social engineering and physical penetration testing and provide analysis for the testing results. 

 

What working at EY offers 

At EY, were dedicated to helping our clients, from startups to Fortune 500 companies and the work we do 
with them is as varied as they are. You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange.

Plus, we offer: 
Support, coaching and feedback from some of the most engaging colleagues around 
Opportunities to develop new skills and progress your career 
The freedom and flexibility to handle your role in a way thats right for you 

 

EY | Building a better working world 


 
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  


 
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  


 
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.  

Consulting_Cyber Threat Management - Pen Testing Staff

Compensation

Not specified

City: Colombo

Country: Not specified

Ernst & Young logo
Big Four

13 days ago

No clicks

at Ernst & Young

ExperiencedNo visa sponsorship

**EY Penetration Testing Staff: Cyber Threat Management** - **Key Responsibilities**: Perform internet, intranet, wireless, web app, social & physical penetration testing. Analyze results, report findings, and recommend security improvements. Collaborate with development teams and convey complex security concepts. Lead junior team members and develop risk mitigation solutions. - **Skills & Experience**: - 1+ years in penetration testing, including 3+ types (e.g., web app, network, social engineering) - Relevant certifications (e.g., OSCP, OSWP, GPEN, GWAPT) - Experience with scripting/programming (Python, PowerShell, etc.) - Familiarity with DAST/SAST tools & methodologies (e.g., BurpSuite, OWASP Top 10) - Strong knowledge of Active Directory, TCP/IP, and network security - Experience with automation tools (e.g., Chef, Puppet) and CI/CD pipelines - **Education**: BE/B.Tech/MCA with 1-4 years of relevant experience in strategy & operations projects.

Full Job Description

At EY, youll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And were counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. 

 

 

 

 

EY GDS Cybersecurity Attack & Penetration Testing - Staff 

As part of our EY-cyber security team, you shall perform penetration testing which includes internet, intranet, wireless, web application, social engineering and physical penetration testing. You shall also perform in-depth analysis of penetration testing results and create report that describes findings, exploitation procedures, risks and recommendations. 

 

The opportunity 
Were looking for Security Analyst with expertise in penetration testing. This is a fantastic opportunity to be part of a leading firm whilst being instrumental in the growth of a new service offering. 

 

Your key responsibilities 

  • Perform penetration testing which includes internet, intranet, web application, wireless, social engineering, physical penetration testing. 
  • Execute red team assessments to highlight gaps impacting organizations security postures. 
  • Identify and exploit security vulnerabilities in a wide array of systems in a variety of situations. 
  • Perform in-depth analysis of penetration testing results and create report that describes findings, exploitation procedures, risks and recommendations. 
  • Execute penetration testing projects using the established methodology, tools and rules of 
    engagements. 
  • Convey complex technical security concepts to technical and non-technical audiences including executives. 
  • Strong knowledge of OWASP Top 10 web and the ability to effectively communicate methodologies and techniques with development teams.
  • Ability to automate DAST/SAST solutions and reporting 
  • Support SDLC and agile environments with application security testing and source code reviews. 
  • Provide technical leadership and advise to junior team members on attack and penetration test engagements. 
  • Develop automated solutions that mitigate risks throughout the organization. 
  • Understanding and experience with Active Directory attacks. 
  • Understanding of TCP/IP network protocols. 

 

Skills and attributes for success 

  • Experience with automation through solutions such as Chef, Puppet, Jenkins, and Ansible. 
  • Experience with scripting / programming skills (e.g., Python, PowerShell, Java, Perl etc.) updated and familiarized with the latest exploits and security trends. 
  • Familiarity with dynamic web application vulnerability scanning tools and services (Acunetix, HP WebInspect, IBM AppScan, BurpSuite, IBM AppScan). 
  • Familiarity with static code analysis tools and services (CheckMarx, Fortify Static Code Analysis tool, Veracode, Coverity, IBM AppScan Source). 
  • Familiarity with Secure DevOps Integration. 
  • Understanding and experience with Active Directory attacks. 
  • Understanding of TCP/IP network protocols. 
  • Understanding of network security and popular attacks vectors. 
  • Understanding of web-based application vulnerabilities (OWASP Top 10). 
  • Experience with scripting / programming skills (e.g., Python or PowerShell or Java or Perl etc.). 

 

To qualify for the role, you must have 

  • BE/ B.Tech/ MCA. 
  • Minimum of 1 year of work experience in penetration testing which may include at least three of the following: internet, intranet, web application penetration tests, wireless, social engineering, physical and Red Team assessments. 
  • One of the following certifications: OSCP, OSWP, GPEN, GWAPT. 
  • Knowledge of Windows, Linux, UNIX, any other major operating systems. 
  • 2-4 years of work experience in Strategy and Operations projects 
  • Strong Excel and PowerPoint skills. 

 

Ideally, youll also have 

  • Project management skills 
  • Certifications: OSCP, OSWP, GPEN, GWAPT. 

 

What we look for 
Who can perform penetration testing which includes internet, intranet, wireless, web application, social engineering and physical penetration testing and provide analysis for the testing results. 

 

What working at EY offers 

At EY, were dedicated to helping our clients, from startups to Fortune 500 companies and the work we do 
with them is as varied as they are. You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange.

Plus, we offer: 
Support, coaching and feedback from some of the most engaging colleagues around 
Opportunities to develop new skills and progress your career 
The freedom and flexibility to handle your role in a way thats right for you 

 

EY | Building a better working world 


 
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.  


 
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.  


 
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.