As part of our Cyber Technology Consulting team, you will execute advanced penetration testing, red team engagements, and adversary simulation exercises for enterprise and government clients. You will be responsible for identifying vulnerabilities, exploiting them in controlled scenarios, and providing actionable recommendations to improve clients security posture. The client base spans various sectors and includes collaboration with other teams within Advisory services. This role requires a balance of strong technical expertise, client communication, and mentoring junior team members.
We re looking for a senior consultant with hands-on expertise and experience in driving offensive security engagements to join our Cyber Technology Consulting team. This is a fantastic opportunity to be part of a leading firm
Conduct penetration testing across web, mobile, APIs, cloud, and network environments (internal and external). Execute red team and purple team operations, including social engineering, OSINT, and physical security assessments. Perform secure code reviews, wireless security assessments, and application security consulting when required. Develop and execute adversarial attack simulations, leveraging C2 frameworks (commercial: Cobalt Strike, Brute Ratel, NightHawk; open source: Havoc, Mythic, Sliver, Merlin). Stay updated with emerging cyber threats, vulnerabilities, and offensive security techniques, and incorporate these insights into client engagements. Develop detailed reports, articulate technical findings, and deliver actionable recommendations to both technical teams and executive stakeholders. Support pre-sales activities such as scoping, proposal writing, and client workshops.
Collaborating with other members of the engagement team to plan the engagement and develop work program timelines, risk assessments and other documents/templates. Ability to interpret complex technical results and present insights to business stakeholders. Strong analytical, problem-solving, and critical-thinking skills. Excellent communication and collaboration skills. Deep technical understanding of offensive security methodologies, including network penetration testing, web application testing, and adversary simulation.
Bachelor s degree in computer science, Cybersecurity, or related field. 4 6 years of hands-on experience in penetration testing, red teaming, or exploit development. Demonstrable proficiency in at least two of the following methodologies:
- Web, web services, mobile, or thick client penetration testing.
- Internal/external network penetration testing.
- Secure code review & application security consulting.
- Wireless assessments.
- Social engineering and red team assessments.
Strong technical understanding in at least two of the following domains:
- Common web technologies and frameworks.
- Application architecture.
- Cloud platforms (AWS, Azure, GCP).
- Networking and network protocols.
- DevOps pipelines and CI/CD security.
Hands-on expertise with offensive tools and frameworks (e.g., Burp Suite, Metasploit, BloodHound, Cobalt Strike, Sliver, Havoc). Strong knowledge of MITRE ATT&CK, OWASP Top 10, NIST SP 800-115, and red team methodologies. A valid passport for travel. Excellent communication skills with a consulting mindset.
Relevant Cyber and offensive security certifications
Relevant certifications such as OSCP, OSCE, OSWE, OSEP, OSEE, GXPN, CRTO, SANS GWAPT, GPEN.
Strong understanding of security frameworks and methodologies (e.g., MITRE ATT&CK, OWASP, NIST). Experience in offensive security engagements
We offer a competitive compensation package where you ll be rewarded based on performance and recognized for the value you bring to our business. Plus, we offer:
- Continuous learning: You ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You ll be embraced for who you are and empowered to use your voice to help others find theirs.
If you can demonstrate that you meet the criteria above, please contact us as soon as possible. The exceptional EY experience. It s yours to build. EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform, and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
Desired Candidate Profile
Bachelor s degree in computer science, Cybersecurity, or related field. 4 6 years of hands-on experience in penetration testing, red teaming, or exploit development. Demonstrable proficiency in at least two of the following methodologies:
- Web, web services, mobile, or thick client penetration testing.
- Internal/external network penetration testing.
- Secure code review & application security consulting.
- Wireless assessments.
- Social engineering and red team assessments.
Strong technical understanding in at least two of the following domains:
- Common web technologies and frameworks.
- Application architecture.
- Cloud platforms (AWS, Azure, GCP).
- Networking and network protocols.
- DevOps pipelines and CI/CD security.
Hands-on expertise with offensive tools and frameworks (e.g., Burp Suite, Metasploit, BloodHound, Cobalt Strike, Sliver, Havoc). Strong knowledge of MITRE ATT&CK, OWASP Top 10, NIST SP 800-115, and red team methodologies. A valid passport for travel. Excellent communication skills with a consulting mindset.
Relevant Cyber and offensive security certifications
Relevant certifications such as OSCP, OSCE, OSWE, OSEP, OSEE, GXPN, CRTO, SANS GWAPT, GPEN.
Strong understanding of security frameworks and methodologies (e.g., MITRE ATT&CK, OWASP, NIST). Experience in offensive security engagements
كجزء من فريق استشارات تكنولوجيا Cyber الخاصة بنا، ستنفذ اختبارات اختراق متقدمة ومشاركات فريق أحمر وتدريبات محاكاة للمهاجمين للعملاء من المؤسسات والحكومات. ستكون مسؤولاً عن تحديد الثغرات واستغلالها في سيناريوهات محكومة وتقديم توصيات قابلة للتنفيذ لتحسين وضع الأمان لدى العملاء. تغطي قاعدة العملاء قطاعات مختلفة وتتضمن التعاون مع فرق أخرى ضمن خدمات الاستشارة. يتطلب هذا الدور توازناً بين الخبرة التقنية القوية، والتواصل مع العملاء، وتوجيه أعضاء الفريق junior.
نحن نبحث عن استشاري كبير يمتلك خبرة عملية ومهارات في قيادة مشاركات الأمن الهجومي للانضمام إلى فريق استشارات تكنولوجيا Cyber الخاص بنا. هذه فرصة رائعة لأن تكون جزءاً من شركة رائدة
إجراء اختبارات الاختراق عبر بيئات الويب، والهواتف المحمولة، وواجهات البرمجة التطبيقية، والسحابة، والشبكات (الداخلية والخارجية). تنفيذ عمليات فريق أحمر وفريق أرجواني، بما في ذلك الهندسة الاجتماعية، وOSINT، وتقييمات الأمن المادي. إجراء مراجعات آمنة للكود، وتقييمات أمان لاسلكي، واستشارات أمان التطبيقات عند الحاجة. تطوير وتنفيذ محاكاة هجمات عدائية، بالاعتماد على أطر C2 (تجاري: Cobalt Strike، Brute Ratel، NightHawk؛ مفتوح المصدر: Havoc، Mythic، Sliver، Merlin). متابعة التهديدات السيبرانية الناشئة، والثغرات، وتقنيات الأمن الهجومي، ودمج هذه الرؤى في تعاملات العملاء. إعداد تقارير تفصيلية، توضيح النتائج التقنية، وتقديم توصيات قابلة للتنفيذ للفرق الفنية وأصحاب القرار التنفيذيين. دعم أنشطة ما قبل البيع مثل النطاق، وكتابة المقترحات، وورش العمل مع العملاء.
التعاون مع أعضاء آخرين من فريق المشاركة لتخطيط المشاركة وتطوير جداول عمل وخطط مخاطر ووثائق/نماذج أخرى. القدرة على تفسير نتائج تقنية معقدة وتقديم الرؤى لأصحاب العمل. مهارات تحليلية قوية وحل المشكلات والتفكير النقدي. مهارات تواصل وتعاون ممتازة. فهم تقني عميق لأساليب الأمن الهجومي، بما في ذلك اختبارات اختراق الشبكات، اختبار أمان تطبيقات الويب، ومحاكاة المهاجم.
درجة البكالوريوس في علوم الكمبيوتر، الأمن السيبراني، أو مجال ذي صلة. 4–6 سنوات خبرة عملية في اختبارات الاختراق، الفرق الحمراء، أو تطوير الاستغلال. إتقان واضح على الأقل في اثنين من المنهجيات التالية:
- اختبار اختراق الويب، وخدمات الويب، والهاتف المحمول، أو عميل قوي.
- اختبار اختراق الشبكات الداخلية/الخارجية.
- مراجعة كود آمنة وتقديم استشارات أمان التطبيقات.
- تقييمات لاسلكية.
- الهندسة الاجتماعية وتقييمات الفريق الأحمر.
فهم تقني قوي في ما لا يقل عن مجالين من المجالات التالية:
- تكنولوجيات الويب الشائعة والأطر.
- هندسة التطبيقات.
- منصات السحابة (AWS، Azure، GCP).
- شبكات وبروتوكولاتها.
- خطوط أنابيب DevOps وأمن CI/CD.
خبرة عملية مع أدوات وأطر هجوم مثل (Burp Suite، Metasploit، BloodHound، Cobalt Strike، Sliver، Havoc). معرفة قوية بMITRE ATT&CK، وOWASP Top 10، وNIST SP 800-115، ومنهجيات الفرق الحمراء. جواز سفر صالح للسفر. مهارات اتصال ممتازة مع عقلية استشارية.
شهادات الأمن السيبراني والهجومي ذات الصلة
شهادات ذات صلة مثل OSCP، OSCE، OSWE، OSEP، OSEE، GXPN، CRTO، SANS GWAPT، GPEN.
فهم قوي لأطر أمان ومناهجها (مثلاً MITRE ATT&CK، OWASP، NIST). خبرة في مشاركات الأمن الهجومي
نحن نقدم حزمة تعويضات منافسة حيث يتم مكافأتك بناءً على الأداء وتقدير قيمتك لأعمالنا. بالإضافة إلى ذلك، نقدم:
- التعلم المستمر: ستطور العقلية والمهارات لمواجهة ما يأتي من بعد.
- النجاح كما تحدده أنت: سنوفر لك الأدوات والمرونة، حتى تتمكن من إحداث تأثير معنوي بطريقتك.
- قيادة تحوّل: سنمنحك الرؤى والتوجيه والثقة لتكون القائد الذي يحتاجه العالم.
- ثقافة متنوعة وشاملة: ستُحتضن لما أنت عليه وستمكن من استخدام صوتك لمساعدة الآخرين في العثور على صوتهم.
إذا كنت تستطيع إثبات أنك تلبي المعايير المذكورة أعلاه، فيرجى التواصل معنا في أقرب وقت ممكن. تجربة EY الاستثنائية. إنها ملكك لتبني. EY | بناء عالم عمل أفضلEY موجودة لبناء عالم عمل أفضل، والمساعدة في خلق قيمة طويلة الأجل للعملاء والناس والمجتمع وبناء الثقة في أسواق رأس المال. بفضل البيانات والتكنولوجيا، توفر فرق EY المتنوعة في أكثر من 150 دولة الثقة من خلال الضمان وتساعد العملاء على النمو والتحول والتشغيل. تعمل فرق EY عبر الضمان والاستشارات والقانون والاستراتيجية والضرائب والمعاملات، وتطرح فرق EY أسئلة أفضل لإيجاد إجابات جديدة للقضايا المعقدة التي تواجه عالمنا اليوم.
الملف المرشح Desired Candidate Profile
درجة البكالوريوس في علوم الكمبيوتر، الأمن السيبراني، أو مجال ذو صلة. 4–6 سنوات خبرة عملية في اختبارات الاختراق، الفرق الحمراء، أو تطوير الاستغلال. إتقان واضح على الأقل في اثنين من المنهجيات التالية:
- اختبار اختراق الويب، وخدمات الويب، والهاتف المحمول، أو عميل قوي.
- اختبار اختراق الشبكات الداخلية/الخارجية.
- مراجعة كود آمن وتقديم استشارات أمان التطبيقات.
- تقييمات لاسلكية.
- الهندسة الاجتماعية وتقييمات الفريق الأحمر.
فهم تقني قوي في ما لا يقل عن مجالين من المجالات التالية:
- تكنولوجيات الويب الشائعة والأطر.
- هندسة التطبيقات.
- منصات السحابة (AWS، Azure، GCP).
- شبكات وبروتوكولات الشبكات.
- خطوط أنابيب DevOps وأمن CI/CD.
خبرة عملية مع أدوات وأطر هجوم مثل (Burp Suite، Metasploit، BloodHound، Cobalt Strike، Sliver، Havoc). معرفة قوية بMITRE ATT&CK، وOWASP Top 10، وNIST SP 800-115، ومنهجيات الفرق الحمراء. جواز سفر صالح للسفر. مهارات اتصال ممتازة مع عقلية استشارية.
شهادات الأمن السيبراني والهجومي ذات الصلة
شهادات مثل OSCP، OSCE، OSWE، OSEP، OSEE، GXPN، CRTO، SANS GWAPT، GPEN.
فهم قوي لأطر الأمان والمنهجيات (مثل MITRE ATT&CK، OWASP، NIST). خبرة في مشاركات الأمن الهجومي