Cyber Attack & Penetration Testing Manager – Consulting

atEYRemoteUS flagUnited StatesFull-timeCybersecurity / Security EngineerMid-levelSenior$144.9k – $265.8k/year

Posted Sep 11

This is a fully remote position, open to applicants in United States.

📋 Description

• Identify potential threats and vulnerabilities within enterprise environments.

• Lead technical teams in conducting penetration testing, red team, and purple team exercises.

• Utilize offensive security analysis to bolster other areas of cybersecurity.

• Manage the delivery of offensive security engagements.

• Collaborate effectively with security and business teams.

• Produce clear, concise, and actionable reports for both technical and executive audiences.

• Mentor both senior and junior analysts.

• Foster a collaborative and trust-based team culture.

• Enhance the skillsets and capabilities of the team.

• Monitor emerging trends and technologies in cyber threats.

• Represent EY at industry groups, conferences, and events.

• Plan and execute penetration testing across various domains including internet, intranet, wireless, web applications, cloud, social engineering, and physical environments.

• Develop and implement red team scenarios.

• Analyze results from penetration testing and report findings, exploitation procedures, associated risks, and recommendations.

• Manage testing projects using established methodologies, tools, and rules of engagement.


⛳️ Requirements

• Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Information Technology, Engineering, or a related field with over 6 years of relevant work experience, or a Master’s degree with approximately 3-4 years of related experience.

• Proven experience in managing and executing penetration testing projects.

• Hands-on experience with manual attack and penetration testing.

• Experience in establishing and managing Red Team or application penetration testing programs.

• Proficiency in scripting/programming languages such as Python, PowerShell, Java, or Perl.

• Up-to-date knowledge of the latest exploits and security trends.

• Experience in leading technical teams for remote and on-site penetration testing while adhering to defined rules of engagement.

• Capability to oversee multiple attack and penetration testing projects concurrently while meeting strict deadlines.

• Familiarity with stealth network penetration testing techniques.

• Hold at least two certifications from the following: OSCP, OSWP, GPEN, GWAPT, OSCE, OSEE, GXPN, CISSP, CISM, PMP, or CREST Certified Simulated Attack Manager.

• A valid driver’s license in the U.S.

• Willingness and ability to travel domestically and internationally.

• Estimated travel requirement is up to 50%.

• Knowledge of major operating systems including Windows, Linux, and Unix.

• Familiarity with cloud vulnerability remediation, TTPs, exploits, and security trends.

• Profound understanding of the MITRE ATT&CK framework.

• Extensive knowledge of TCP/IP network protocols.

• In-depth understanding and experience with Active Directory attack techniques.

• Solid grasp of network security and common attack vectors.

• Knowledge of web application vulnerabilities, including OWASP Top 10.

• Experience in developing harnesses and agentic workflows for offensive security.


🏝️ Benefits

• Medical and dental coverage.

• Pension plan.

• 401(k) plan.

• A wide variety of paid time off options.

• Opportunities for professional growth.

• Personal fulfillment.

• An inclusive culture.

• Reasonable accommodations for qualified individuals with disabilities.

People also viewed

VMD Corp21 hours ago

Senior Cybersecurity Assessment Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
GR8 Tech21 hours ago

Information Security Access Specialist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Modern Health22 hours ago

Product Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$101.4k – $140.4k/year
ApplyView job
Accumulus Technologies23 hours ago

Head of Information Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$200k – $260k/year
ApplyView job
ShorePoint Inc23 hours ago

Lead Security Architect

US flagVirginia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Smile Digital Health1 day ago

Cloud Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security EngineerC$120k – C$140k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers