Now hiring

FS-RISK CONSULTING-TPRM-Senior-Application and Offensive Security (Bengaluru, KA, IN, 560016) @ EY Global Services

Bengaluru, KA, IN, 560016OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<div style="font-family:Arial;font-size:1.0em"> <p>At EY, we’re all in to shape your future with confidence. </p> <p>We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. </p> <p>Join EY and help to build a better working world. </p> </div> <div style="font-family:Arial;font-size:1.0em"> </div><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Digital Risk- Application &amp; Offensive Security – Senior</strong></span></p> <p> </p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Job purpose:</strong></span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Senior in the Risk Advisory team to work on Application Security and Offensive Security engagements for our customers across the globe.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">You will be responsible for delivering secure application and adversarial testing engagements in accordance with EY quality guidelines &amp; methodologies. You will be expected to execute and coordinate engagement activities on a day-to-day basis and proactively support the identification of new opportunities in application and offensive security domains.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">You will work closely with development, DevOps, and security teams to embed secure-by-design practices and validate application security through real-world attack simulations using a Glasswing-aligned adversarial approach. You will assist in developing new methodologies, strengthen secure engineering practices, and contribute to creating a strong learning culture by mentoring junior team members.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">In line with EY’s commitment to quality, you will confirm that work is of the highest quality by reviewing outputs from junior members.</span></p> <p> </p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Your client responsibilities:</strong></span></p> <p> </p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Perform Secure SDLC reviews and provide actionable recommendations across application environments</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Conduct and support bug bounty programs and vulnerability validation activities</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Execute adversarial testing and attack simulation exercises using real-world attack scenarios (Glasswing-aligned approach)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Identify exploitable vulnerabilities and validate them from an attacker’s perspective</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support threat modeling and secure architecture reviews for applications</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Maintain relationships with client stakeholders across development, DevOps, and security teams</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Demonstrate understanding of modern application architectures (APIs, microservices, cloud-native systems)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support secure design and DevSecOps integration across the application lifecycle</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Assist Managers in business development, proposal creation, and solutioning</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Contribute to development of methodologies, frameworks, and thought leadership</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Facilitate knowledge sharing sessions and discussions with client teams</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Provide regular status updates on engagements and deliverables</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Stay updated on emerging application security threats, vulnerabilities, and attack techniques</span></li> </ul> <p> </p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Your people responsibilities:</strong></span></p> <p> </p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Work collaboratively with team members to deliver high-quality outputs within timelines</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Mentor and train junior resources on secure coding, testing, and adversarial thinking</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Drive adherence to quality standards and methodologies</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Participate in internal capability development and knowledge sharing initiatives</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support performance management of team members</span></li> </ul> <p> </p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Mandatory skills:</strong></span></p> <p> </p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong understanding of Secure SDLC and DevSecOps practices</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience in application security testing (SAST, DAST, API testing, manual testing)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong knowledge of OWASP Top 10 and web application vulnerabilities</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience in bug bounty programs and vulnerability validation</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Understanding of adversarial testing and attack simulation approaches (Glasswing-aligned)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Knowledge of API security (OAuth2, OIDC, mTLS)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience in threat modeling techniques</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Familiarity with modern application architectures (cloud, microservices, containers)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong understanding of web protocols and technologies</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Knowledge of CI/CD pipelines and secure engineering practices</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Certifications such as CEH, OSCP, GWAPT or equivalent preferred</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">BE/BTech/MCA with 4–8 years of relevant experience</span></li> </ul> <p> </p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Preferred skills:</strong></span></p> <p> </p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Exposure to cloud security (AWS/Azure/GCP)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience working in Agile/DevOps environments</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Prior client-facing or consulting experience</span></li> </ul> <p> </p><div style="font-family:Arial;font-size:1.0em"> <p><b>EY | Building a better working world </b></p> <p>EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.</p> <p>Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.</p> <p>EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.</p> </div>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores