EY

Senior Cybersecurity Consultant – Penetration Tester

EY

full-time

Posted on:

Origin:  • 🇵🇱 Poland

Visit company website
AI Apply
Manual Apply

Job Level

Senior

Tech Stack

CloudCyber SecurityJavaPython

About the role

  • As a Cyber Security Senior Consultant, you’ll contribute technically to Cyber Security client projects and internal projects.
  • You will work in multinational environment together with other top security experts and your responsibility will be to deliver Attack & Penetration Testing projects and various other security projects including application code review, social engineering, Red Team Assessments, Purple Team Assessments, Threat Modeling, Security Architecture reviews.
  • To qualify for the role, you must have 3+ years of experience in Dev / ITSec conducting penetration tests projects
  • Knowledge of security issues at the technical level, Knowledge of solutions and recommendations to prevent or mitigate security vulnerabilities, Knowledge of the application security verification standards
  • Deep understanding of how information’s technology systems work: networking architecture, networking protocols operating systems
  • Deep understanding of how web applications work, starting from backend, ending with frontend
  • Familiarity of Red Team methodologies (MITRE, Social engineering, OSINT etc.)
  • Experience with cloud-hosted applications and services
  • Autonomy and maturity in what you do as security professional, Consulting and communication skills to provide technical security expertise understandable by non-technical audience
  • Strong investigative mindset with attention to detail
  • OSCP, OSWE, GPEN certificate or similar
  • Excellent command of English language and additional language as a plus
  • Ideally, you’ll also have Documented participation in Bug Bounty programs or acknowledgement of Responsible Disclosures outside those programs, Granted CVEs, Programming language skills (Python, C++, C# or Java)

Requirements

  • 3+ years of experience in Dev / ITSec conducting penetration tests projects
  • Knowledge of security issues at the technical level, Knowledge of solutions and recommendations to prevent or mitigate security vulnerabilities, Knowledge of the application security verification standards
  • Deep understanding of how information’s technology systems work: networking architecture, networking protocols operating systems
  • Deep understanding of how web applications work, starting from backend, ending with frontend
  • Familiarity of Red Team methodologies (MITRE, Social engineering, OSINT etc.)
  • Experience with cloud-hosted applications and services
  • Autonomy and maturity in what you do as security professional, Consulting and communication skills to provide technical security expertise understandable by non-technical audience
  • Strong investigative mindset with attention to detail
  • OSCP, OSWE, GPEN certificate or similar
  • Excellent command of English language and additional language as a plus
  • Documented participation in Bug Bounty programs or acknowledgement of Responsible Disclosures outside those programs, Granted CVEs, Programming language skills (Python, C++, C# or Java)