Padmi

EY-Cyber Security-Offensive Security-Manager

IndiaPosted 3 months ago
CybersecuritySeniorFull Time, Permanent
Apply at EY

Opens the source posting on naukri.com

Source description

About the role

View original

EY Cyber Security Manager Offensive Security Job Listing Detail The Opportunity We re looking for a Manager in our Cyber Security team with a strong focus on Offensive Security, Red Teaming, Cloud native VAPT, and DevSecOps security assurance . Exposure to AI, ML, and GenAI security assessments is considered a desirable and good to have capability , as organizations increasingly adopt AI enabled technologies. As part of our Cyber Technology Consulting practice, you will play a key role in leading and delivering offensive security services to clients across the MENA region. You will work with leading organizations across sectors including Financial Services, Government Public Sector, Energy, Telecom, Healthcare, and Digital-native enterprises, helping them proactively identify vulnerabilities, simulate advanced adversaries, and strengthen their cyber resilience. This role offers a unique opportunity to operate at the intersection of deep technical expertise, strategic advisory, and large-scale transformation, while contributing to the growth of our Offensive Security competency. Your Key Responsibilities Client Delivery And Engagement Management Lead and deliver end-to-end offensive security engagements, including: Network and infrastructure penetration testing Web and mobile application security testing API security assessments (REST, SOAP, GraphQL, microservices) Cloud security testing across AWS, Azure, and GCP Plan and execute red team / adversary simulation / assumed breach exercises, emulating real-world threat actors to test organizational detection and response capabilities. Execute and oversee purple teaming engagements, enabling alignment between offensive findings and defensive improvements (SOC, detection engineering, incident response). Conduct and lead cloud offensive security assessments and validate effectiveness of controls across all layers and workloads within AWS, Azure, and GCP, including IAM, network, storage, container, serverless, and DevSecOps pipeline components. Assess cloud misconfigurations, identity abuse paths, privilege escalation scenarios, insecure pipeline configurations, exposed secrets, and lateral movement techniques across hybrid and cloud native environments. Perform penetration testing and security assessments of cloud native architectures, APIs, microservices, Kubernetes, infrastructure as code, container images, and CI/CD pipelines to identify weaknesses across the secure software delivery lifecycle. Assess and validate CSPM / CNAPP controls, identifying configuration gaps, privilege escalation paths, and exposure risks in cloud-native environments. Deliver AI/GenAI security assessments, including (Desirable / Good to Have) : Prompt injection and adversarial input risks Model misuse and abuse scenarios Data leakage and insecure integration risks AI governance and secure deployment considerations Translate technical vulnerabilities into business risk insights, including attack paths, impact analysis, and prioritized remediation strategies. Stakeholder Engagement And Advisory Serve as a trusted advisor to CISOs, CIOs, security leaders, and engineering teams, articulating security risks in a business-relevant and outcome-driven manner. Present complex offensive security findings to both technical and executive audiences, tailoring messaging appropriately. Support clients in developing offensive security roadmaps, maturity models, and remediation programs aligned to leading practices. Practice And Capability Development Contribute to building the Offensive Security practice, including: Development of methodologies, testing playbooks, and accelerators Creation of reusable assets and frameworks Standardization of delivery approaches and quality benchmarks Support go-to-market initiatives, thought leadership, and client pursuits: RFP/RFI responses Solution positioning and capability presentations Market-facing content development (whitepapers, POVs) Stay ahead of evolving threat landscape, including: Advanced attacker techniques and exploit trends API and cloud-native attack vectors AI/ML security risks and emerging vulnerabilities People Leadership And Team Development Manage and mentor a team of consultants and senior consultants, fostering: Deep technical capability in offensive security domains High-quality delivery and reporting standards Continuous learning and certification progression Provide performance feedback, coaching, and career guidance aligned with firm values. Build a collaborative, high-performance culture within the Offensive Security team. Skills and Attributes for Success Strong hands-on expertise in offensive security methodologies, including penetration testing, exploit development, adversary simulation, and attack path analysis. Deep understanding of: OWASP Top 10 and API Security Top 10 Authentication and authorization mechanisms (OAuth, JWT, SSO, etc.) Business logic vulnerabilities and modern application architectures Proven experience in API security testing and microservices environments. Strong working knowledge of cloud security risks, including: AWS Azure GCP Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

One address, no account. We’ll tell you when matching roles go live.

More at EY

Related open roles

View all roles