Now hiring

EY-Cyber Security-Offensive Security-Manager (Kochi, KL, IN, 682313) @ EY Global Services

Kochi, KL, IN, 682313OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<div style="font-family:Arial;font-size:1.0em"> <p>At EY, we’re all in to shape your future with confidence. </p> <p>We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. </p> <p>Join EY and help to build a better working world. </p> </div> <div style="font-family:Arial;font-size:1.0em"> </div><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>EY – Cyber Security – Manager – Offensive Security </strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Job Listing Detail</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture, and technology to become the best version of you. We’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>The Opportunity</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">We’re looking for a <strong>Manager in our Cyber Security team</strong> with a strong focus on <strong>Offensive Security, Red Teaming, Cloud‑native VAPT, and DevSecOps security assurance</strong>. Exposure to <strong>AI, ML, and GenAI security assessments is considered a desirable and good‑to‑have capability</strong>, as organizations increasingly adopt AI‑enabled technologies.</span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">As part of our Cyber Technology Consulting practice, you will play a key role in leading and delivering offensive security services to clients across the MENA region. You will work with leading organizations across sectors including Financial Services, Government &amp; Public Sector, Energy, Telecom, Healthcare, and Digital-native enterprises, helping them proactively identify vulnerabilities, simulate advanced adversaries, and strengthen their cyber resilience.</span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">This role offers a unique opportunity to operate at the intersection of deep technical expertise, strategic advisory, and large-scale transformation, while contributing to the growth of our Offensive Security competency.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Your Key Responsibilities</strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Client Delivery And Engagement Management</strong></span></p> <ul type="disc"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Lead and deliver end-to-end offensive security engagements, including:</span></li> <ul type="circle"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Network and infrastructure penetration testing</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Web and mobile application security testing</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">API security assessments (REST, SOAP, GraphQL, microservices)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Cloud security testing across AWS, Azure, and GCP</span></li> </ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Plan and execute red team / adversary simulation / assumed breach exercises, emulating real-world threat actors to test organizational detection and response capabilities.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Execute and oversee purple teaming engagements, enabling alignment between offensive findings and defensive improvements (SOC, detection engineering, incident response).</span></li> </ul> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Conduct and lead cloud offensive security assessments and validate effectiveness of controls across all layers and workloads within AWS, Azure, and GCP, including IAM, network, storage, container, serverless, and DevSecOps pipeline components.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Assess cloud misconfigurations, identity abuse paths, privilege escalation scenarios, insecure pipeline configurations, exposed secrets, and lateral movement techniques across hybrid and cloud native environments.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Perform penetration testing and security assessments of cloud native architectures, APIs, microservices, Kubernetes, infrastructure as code, container images, and CI/CD pipelines to identify weaknesses across the secure software delivery lifecycle.</span></li> </ul> <ul type="disc"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Assess and validate CSPM / CNAPP controls, identifying configuration gaps, privilege escalation paths, and exposure risks in cloud-native environments.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Deliver AI/GenAI security assessments, including <strong>(Desirable / Good‑to‑Have)</strong>:</span></li> <ul type="circle"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Prompt injection and adversarial input risks</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Model misuse and abuse scenarios</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Data leakage and insecure integration risks</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">AI governance and secure deployment considerations</span></li> </ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Translate technical vulnerabilities into business risk insights, including attack paths, impact analysis, and prioritized remediation strategies.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Stakeholder Engagement And Advisory</strong></span></p> <ul type="disc"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Serve as a trusted advisor to CISOs, CIOs, security leaders, and engineering teams, articulating security risks in a business-relevant and outcome-driven manner.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Present complex offensive security findings to both technical and executive audiences, tailoring messaging appropriately.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support clients in developing offensive security roadmaps, maturity models, and remediation programs aligned to leading practices.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Practice And Capability Development</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Contribute to building the Offensive Security practice, including:</span> <ul style="list-style-type:circle"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Development of methodologies, testing playbooks, and accelerators</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Creation of reusable assets and frameworks</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Standardization of delivery approaches and quality benchmarks</span></li> </ul> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support go-to-market initiatives, thought leadership, and client pursuits:</span> <ul style="list-style-type:circle"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">RFP/RFI responses</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Solution positioning and capability presentations</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Market-facing content development (whitepapers, POVs)</span></li> </ul> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Stay ahead of evolving threat landscape, including:</span> <ul style="list-style-type:circle"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Advanced attacker techniques and exploit trends</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">API and cloud-native attack vectors</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">AI/ML security risks and emerging vulnerabilities</span></li> </ul> </li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>People Leadership And Team Development</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Manage and mentor a team of consultants and senior consultants, fostering:</span> <ul style="list-style-type:circle"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Deep technical capability in offensive security domains</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">High-quality delivery and reporting standards</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Continuous learning and certification progression</span></li> </ul> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Provide performance feedback, coaching, and career guidance aligned with firm values.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Build a collaborative, high-performance culture within the Offensive Security team.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Skills and Attributes for Success</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong hands-on expertise in offensive security methodologies, including penetration testing, exploit development, adversary simulation, and attack path analysis.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Deep understanding of:</span> <ul style="list-style-type:circle"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">OWASP Top 10 and API Security Top 10</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Authentication and authorization mechanisms (OAuth, JWT, SSO, etc.)</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Business logic vulnerabilities and modern application architectures</span></li> </ul> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven experience in API security testing and microservices environments.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong working knowledge of cloud security risks, including:</span> <ul style="list-style-type:circle"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Misconfigurations, IAM weaknesses, secrets exposure, lateral movement</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Cloud-native architectures and shared responsibility model</span></li> </ul> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Familiarity with CSPM, CNAPP, and CIEM concepts and their practical implementation.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Awareness of AI security risks, including adversarial attack techniques, prompt injection, and model governance concerns.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong analytical and problem-solving ability with attention to detail.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Ability to convert complex technical findings into clear, risk-based narratives.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Excellent communication, stakeholder management, and consulting skills.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven ability to manage multiple engagements in parallel with strong quality and delivery discipline.</span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong> </strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>To Qualify for the Role, You Must Have</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A bachelor’s or master’s degree in cyber security, Information Technology, Computer Science, or related discipline.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">10–14 years of experience in Cyber Security, with strong focus on Offensive Security and advanced VAPT.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong knowledge of OWASP Top 10, OWASP API Security, SANS Top 25, and MITRE ATT&amp;CK.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Hands-on experience delivering:</span> <ul style="list-style-type:circle"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">VAPT engagements across network, application, API, and cloud layers</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Red team / adversary simulation exercises</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Cloud security assessments</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven experience delivering Red Team, Cloud native penetration testing, and DevSecOps security validation engagements across modern engineering environments.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Hands on experience testing AWS, Azure, or GCP environments, modern application stacks, CI/CD platforms, containerized workloads, and infrastructure as code implementations.</span></li> </ul> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience working in a consulting or professional services environment, managing clients and engagements.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong reporting, documentation, and presentation skills.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven ability to work in global and cross-cultural environments.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Willingness and flexibility to travel across the MENA region, as required.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Relevant certifications such as OSCP, OSEP, OSCE, CRTO, GWAPT, GPEN, or equivalent.</span></li> </ul> <p> </p> <p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Experience in:</span></strong></p> <ul type="disc"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Advanced <strong>red teaming and purple teaming engagements</strong></span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>API security and cloud offensive security</strong></span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>AI/LLM application security testing</strong></span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">DevSecOps and CI/CD pipeline security</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Container and Kubernetes security</span></li> </ul> <p> </p> <p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Exposure to:</span></strong></p> <ul type="disc"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">BAS tools and attack simulation platforms</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">EDR/XDR validation and detection engineering</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Regulatory and industry frameworks relevant to MENA</span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong> </strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>What We Look For</strong></span></p> <p><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">We are looking for individuals who bring:</span></strong></p> <ul type="disc"> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A <strong>growth mindset</strong> and passion for offensive security</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">The ability to balance <strong>deep technical expertise with business acumen</strong></span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong <strong>client-centricity and relationship-building capability</strong></span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A collaborative approach to problem-solving and innovation</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A commitment to <strong>quality, integrity, and continuous improvement</strong></span></li> </ul><div style="font-family:Arial;font-size:1.0em"> <p><b>EY | Building a better working world </b></p> <p>EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.</p> <p>Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.</p> <p>EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.</p> </div>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores