Cyber Attack & Penetration Testing Manager – Consulting

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $144.9k - $265.8k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 4%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of EY

EY

10,000+ employees

Founded 1989

🏥 Healthcare

⚖️ Legal

📣 Marketing

Healthcare • Legal • Marketing

EY is a global professional services firm, widely recognized for providing audit, tax, consulting, and advisory services. It focuses on helping its clients solve complex problems and transform their businesses using data and technology. EY is committed to building a better working world by enhancing trust in financial markets and economies globally. Its services include corporate finance advisory, transaction strategy, technology consulting, and more, catering to sectors such as health, energy, finance, government, and more. EY also emphasizes sustainability and innovation in its solutions.

📋 Description

• Identify potential threats and vulnerabilities in enterprise environments • Lead technical teams conducting penetration testing, red team, and purple team exercises • Apply offensive security analysis to enhance other cybersecurity areas • Oversee delivery of offensive security engagements • Collaborate with security and business teams • Deliver clear, concise, and actionable reports and support to technical and executive audiences • Mentor senior and junior analysts • Build a collaborative and trust-based team culture • Enhance team skillsets and capabilities • Monitor emerging cyber threat trends and technologies • Represent EY in industry groups, conferences, and events • Plan and execute internet, intranet, wireless, web application, cloud, social engineering, and physical penetration testing • Develop and execute red team scenarios • Analyze penetration testing results and report findings, exploitation procedures, risks, and recommendations • Manage testing projects using established methodologies, tools, and rules of engagement

🎯 Requirements

• Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Information Technology, Engineering or a related major with 6+ years of related work experience, or a Master’s degree with approximately 3–4+ years of related work experience • Experience in managing and executing penetration testing projects • Experience with manual attack and penetration testing • Experience establishing and managing Red Team or application penetration testing programs • Scripting/programming skills, such as Python, PowerShell, Java, or Perl • Familiarity with the latest exploits and security trends • Experience leading technical teams in remote and on-site penetration testing within defined rules of engagement • Ability to oversee multiple attack and penetration testing projects simultaneously while navigating strict deadlines • Familiarity with stealth network penetration testing • Any two certifications: OSCP, OSWP, GPEN, GWAPT, OSCE, OSEE, GXPN, CISSP, CISM, PMP, or CREST Certified Simulated Attack Manager • A driver’s license valid in the U.S. • Willingness and ability to travel domestically and internationally • Estimated travel required up to 50% • Knowledge of Windows, Linux, Unix, or other major operating systems • Familiarity with cloud vulnerability remediation, TTPs, exploits, and security trends • Deep understanding of MITRE ATT&CK framework • Deep understanding of TCP/IP network protocols • Deep understanding and experience with Active Directory attack techniques • Understanding of network security and popular attack vectors • Understanding of web application vulnerabilities, including OWASP Top 10 • Experience developing harnesses and agentic workflows for offensive security

🏖️ Benefits

• Medical and dental coverage • Pension plan • 401(k) plan • Wide range of paid time off options • Professional growth • Personal fulfillment • Inclusive culture • Reasonable accommodation for qualified individuals with disabilities

Apply Now

Similar Jobs

🔥 1 hour ago

Danaher Corporation

10,000+ employees

🏥 Healthcare

💼 Consulting

📦 Logistics

Platform Information Security Officer leading global cybersecurity across Danaher Diagnostics operating companies. Securing regulated medical devices, clinical data, manufacturing environments, and enterprise systems.

🔥 2 hours ago

Business Wire

501 - 1000

📱 Media

📣 Marketing

Cybersecurity Engineer securing Business Wire’s applications, cloud, and IT systems. Integrating security testing, vulnerability management, incident response, and security awareness practices.

🔥 6 hours ago

Veeam Software

1001 - 5000

💼 Consulting

📦 Logistics

☁️ SaaS

Field Security Advisor helping Veeam, a data resilience and security company, prepare Global 2000 customers for cyber extortion. Designing tabletop exercises, advisory content, and executive workshops.

🔥 6 hours ago

U.S. Financial Technology

201 - 500

💳 Fintech

☁️ SaaS

🤝 B2B

Senior Director leading cybersecurity architecture, engineering, and identity governance for U.S. FinTech’s cloud mortgage securitization platform. Advising leaders and managing enterprise cyber risk.

🔥 6 hours ago

ZEISS Group

10,000+ employees

🏭 Manufacturing

🏥 Healthcare

🧬 Biotechnology

Regional Information Security Officer overseeing cybersecurity governance, risk, compliance, and incident response for ZEISS’s optics and optoelectronics operations. Remote role based in White Plains, New York.