On-site
--
Ernst & Young AE

Job Details

As part of our Cybersecurity Consulting team, you will lead and execute penetration testing and offensive security engagements for enterprise and government clients. The role involves identifying vulnerabilities, simulating real-world attacks, and providing actionable recommendations to strengthen clients security posture. You will collaborate with cross-functional teams and contribute to pre-sales activities and client workshops.

Key Responsibilities

  • Perform penetration testing across web, mobile, APIs, cloud, and network environments (internal and external).
  • Conduct red team and purple team exercises, including social engineering and OSINT.
  • Execute adversary simulation using commercial and open-source C2 frameworks.
  • Deliver detailed technical reports and present findings to technical and executive stakeholders.
  • Stay updated on emerging threats and offensive security techniques.
  • Support scoping, proposal development, and client presentations.

Skills & Attributes

  • Strong technical expertise in offensive security methodologies.
  • Ability to interpret complex technical results and communicate effectively to business stakeholders.
  • Excellent analytical and problem-solving skills.
  • Strong collaboration and communication skills.

Qualifications

  • Hands-on experience in penetration testing and offensive security engagements.
  • Proficiency in at least two areas:
    • Web/mobile application testing
    • Network penetration testing
    • Secure code review
    • Wireless assessments
    • Social engineering
  • Familiarity with tools such as Burp Suite, Metasploit, BloodHound, Cobalt Strike, Sliver, Havoc.
  • Knowledge of frameworks like MITRE ATT&CK, OWASP Top 10, and NIST SP.
  • Relevant certifications (OSCP, OSWE, OSEP, GXPN, CRTO, etc.) are a plus.

What We Offer

  • Competitive compensation and benefits.
  • Continuous learning and development opportunities.
  • A diverse and inclusive work environment.

Desired Candidate Profile

  • Bachelor s degree in Computer Science, Cybersecurity, or related field.
  • Hands-on experience in penetration testing and offensive security engagements.
  • Proficiency in at least two areas:
    • Web/mobile application testing
    • Network penetration testing
    • Secure code review
    • Wireless assessments
    • Social engineering
  • Familiarity with tools such as Burp Suite, Metasploit, BloodHound, Cobalt Strike, Sliver, Havoc.
  • Knowledge of frameworks like MITRE ATT&CK, OWASP Top 10, and NIST SP.
  • Relevant certifications (OSCP, OSWE, OSEP, GXPN, CRTO, etc.) are a plus.

Similar Jobs

About Ernst & Young AE
Saudi, Riyadh