TC-CS-CTM-PenTesting-Senior
at EY
Location:
Employment Type: full_time
Job Description
<div style="font-family:Arial;font-size:1.0em"><p>At EY, we’re all in to shape your future with confidence. </p><p>We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. </p><p>Join EY and help to build a better working world. </p></div><div style="font-family:Arial;font-size:1.0em"> </div><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Attack & Penetration Testing - Senior</span></strong></p><p> </p><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">As part of our Cyber Security team, you shall perform penetration testing which includes internet, intranet, wireless, web application, social engineering and physical penetration testing. You shall also perform in-depth analysis of penetration testing results and create report that describes findings, exploitation procedures, risks and recommendations.</span></p><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">The opportunity</span></strong></p><p> </p><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">We’re looking for Security Consultant / Senior Security Consultant with expertise in penetration testing. This is a fantastic opportunity to be part of a leading firm whilst being instrumental in the growth of a new service offering.</span></p><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Your key responsibilities</span></strong></p><p> </p><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Lead engagements from kickoff with clients through scoping engagements, penetration testing and reporting while adhering to the agreed scope and deadlines.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Perform penetration testing which includes Network, web application, Mobile app (both Android & iOS), APIs Cloud Security, Thick Client application, wireless, social engineering, physical penetration testing.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Execute penetration testing projects using the established methodology, tools and rules of engagements.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Execute red team assessments to highlight gaps impacting organizations security postures.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Identify and exploit security vulnerabilities in a wide array of systems in a variety of situations.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Perform in-depth analysis of penetration testing results and create report that describes findings, exploitation procedures, risks and recommendations.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Convey complex technical security concepts to technical and non-technical audiences including executives.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Perform technical quality reviews and conduct technical conversations directly with clients.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Keep uptodate with the latest techniques and concepts.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Confident with OWASP Top 10 and SANS Top 25 vulnerabilities and ability to effectively communicate methodologies and techniques with development teams</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Utilize tools such as BurpSuite, Nessus, Nmap, Kali Linux, and Nessus for effective vulnerability assessment and penetration testing.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Understanding and experience with Active Directory attacks.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Stay up-to-date with the latest security threats, vulnerabilities, and best practices in vulnerability management. Knowledge of AI in Pentest, TCP/IP, OSI Layer, IPv4 & IPv6, Network Protocols and Wireless Communication skills preferred.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Working knowledge with any scripting languages (e.g. Python, Perl, PHP, Ruby) to develop automated solutions that mitigate risks throughout the organization.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support SDLC and agile environments with application security testing and source code reviews.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Serve as a mentor and guide to junior pen testers, sharing your knowledge, skills, and best practices to nurture their growth and development.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Provide technical expertise and guidance to clients on remediation strategies and security best practices.</span></li></ul><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Skills and attributes for success</span></strong></p><p> </p><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">In-depth understanding of OWASP Top 10 vulnerabilities and their mitigation strategies. Good understanding of enterprise security controls in Active Directory / Windows environments</span></p><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Good to have knowledge in AI in pentest</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Understanding of TCP/IP network protocols.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Understanding of network security and popular attacks vectors.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience with Operation Technology / Internet of Things, Cloud technologies (AWS, Azure, GCP), Active Directory and 802.1x penetration testing</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong understanding of security principles, policies, and industry best practices</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven ability to lead client engagements, build strong client relationships, and deliver exceptional results.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Excellent communication and presentation skills, both written and verbal.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Demonstrated thought leadership in the cybersecurity field through publications, speaking engagements, or contributions to industry forums.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Exceptional problem-solving skills, strategic thinking, and the ability to influence and lead.</span></li></ul><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">To qualify for the role, you must have</span></strong></p><p> </p><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">BE/ B.Tech/ MCA or equivalent</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Minimum of 3 years of work experience in penetration testing which may include at least three of the following: Network, web application Mobile app (Android & iOS), Thick client, APIs, wireless, social engineering, physical and Red Team assessments.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">One of the following certifications: OSCP, OSCE, OSEP, OSWE, CREST, CRTE, eCPTX, or eWPTX</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Knowledge of Windows, Linux, UNIX, any other major operating systems.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">3-9 years of work experience in Strategy and Operations projects</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Team management skills are preferred.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Conduct technical discussions and perform technical Quality reviews.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Familiarity with OWASP methodologies and application security vulnerabilities.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Exceptional ability to educate and guide application developers in security best practices.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Excellent communication, presentation, and interpersonal skills.</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong Word, Excel and PowerPoint skills.</span></li></ul><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Ideally, you’ll also have</span></strong></p><p> </p><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Project management skills</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Certifications: OSCP, OSCE, CRTP, CRTO, CISSP, GPEN, GWAPT.</span></li></ul><p> </p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">What we look for</span></strong></p><p> </p><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Who can perform penetration testing which includes internet, intranet, wireless, web application, social engineering and physical penetration testing and provide analysis for the testing results.</span></p><p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">What working at EY offers</span></strong></p><p> </p><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">At EY, we’re dedicated to helping our clients, from start–ups to Fortune 500 companies — and the work we do with them is as varied as they are.</span></p><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange. Plus, we offer:</span></p><p> </p><ul><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support, coaching and feedback from some of the most engaging colleagues around</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Opportunities to develop new skills and progress your career</span></li><li><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">The freedom and flexibility to handle your role in a way that’s right for you</span></li></ul><div style="font-family:Arial;font-size:1.0em"><p><b>EY | Building a better working world </b></p><p>EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.</p><p>Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.</p><p>EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.</p></div>