Vulnerability Management Exposure Management senior associate - EY Global Delivery Services
CABA, B, AR, 1001
EY
Mit unseren vier integrierten Geschäftsbereichen — Wirtschaftsprüfung und prüfungsnahe Dienstleistungen, Steuerberatung, Unternehmensberatung und Strategy and Transactions — sowie unserem Branchenwissen unterstützen wir unsere Mandanten dabei,...Vulnerability Analyst, Exposure Assessment
Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
As Vulnerability Analyst on the Exposure Assessment team, you will play a supporting role in the meticulous evaluation and management of EY's digital exposure, working under the guidance of the Exposure Assessment Lead to identify and mitigate vulnerabilities in the EY digital attack surface. Your responsibilities will include aiding in the assessment and validation of third-party risk assessments and ensuring that EY's security standards are upheld across all digital assets. Additionally, the analyst will assist in monitoring the evolving digital threat landscape, helping to implement proactive defense strategies to maintain the integrity and security of the firm's digital footprint.
Your key responsibilities
The Analyst will evaluate the firm's digital exposure, identifying and mitigating risks stemming from misconfigurations, vulnerabilities, and mismanaged assets. The candidate will play a crucial role in managing third-party risk assessments and identifying assets failing to meet stringent EY security standards. Collaborating closely with multiple functions, the analyst will work to execute the Attack Surface Management strategy to protect EY's digital assets. Additionally, the analyst will assess emerging threats in the digital landscape as directed, evaluating and advising proactive measures to safeguard the firm.
Skills and attributes for success
-
Expert attention to detail
-
Aptitude for thinking critically
-
Ability to handle high volume requests
-
Flexibility and comfortability pivoting between diverse environments
-
Developing communication Skills
-
Familiarity with research methodologies
To qualify for the role you must have
-
A minimum of 3 years of experience in vulnerability management, red team, or purple team
-
Familiarity with cloud services, network security, and data protection principles
-
Well-developed knowledge of offensive security principles
-
Professional-level analytical and problem-solving skills
-
Developing ability to translate vulnerability information to business impact
-
Demonstrated experience with third-party risk assessments
-
Strong communication and interpersonal skills
-
Experience providing prioritization recommendations to stakeholders
Ideally, you’ll also have
-
OWASP training
-
Incident response experience
What we look for
We are looking for a developing Vulnerability Analyst that can operate with supervision and bring new approaches to discovering and evaluating the firm’s externally-exposed vulnerabilities. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.
What working at EY offers
As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial and social well-being. Your recruiter can talk to you about the benefits available in your country. Here’s a snapshot of what we offer:
-
Continuous learning: You will develop the mindset and skills to navigate whatever comes next.
-
Success as defined by you: We will provide the tools and flexibility, so you can make a significant impact, your way.
-
Transformative leadership: We will give you the insights, coaching and confidence to be the leader the world needs.
-
Diverse and inclusive culture: You will be accepted for who you are and empowered to use your voice to help others find theirs.
We ensure that individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions and to receive other benefits and privileges of employment. Please contact us to request accommodations.
EY is committed to being an inclusive employer, and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance.
If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible.
Make your mark
Apply now
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Cloud Cyber defense Incident response Monitoring Network security Offensive security OWASP Red team Risk assessment Strategy Vulnerabilities Vulnerability management
Perks/benefits: Career development Flex hours Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.