About this role
<p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px">At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. </span></span></p> <p> </p> <p> </p> <p> </p> <p> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Information Security Analyst – Associate/Senior Associate</strong></span></p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of over 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.</span></p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.</span></p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>The opportunity</strong></span></p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">The Technology Assurance, Risk, and Policy (TARP) function within Information Security strives to create and promote a holistic Governance, Risk, and Compliance (GRC) program by creating a robust, resilient, and proactive governance framework, supported by a strategic risk management approach and stringent compliance structures. It aims to integrate and align its GRC initiatives in line with the global firm's objectives and emerging threats within the cybersecurity landscape.</span></p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">The Technology Assurance team develops provides security assurance on EY’s deployed technology to internal and external stakeholders. The team members act as subject matter experts across a number of information and cyber security disciplines that include, among others, application and network penetrating testing and vulnerabilities identification, information security audits, compliance to cyber security and regulatory frameworks, and conducting or coordinating security audits and assessments. All applications must pass through security review prior to EY production usage. Security Certification checks the compliance of the application against EY security standards. The team develops the overall strategy and for implementing various technical attack and penetration assessment, information security audits like HITRUST, SOC 1 and SOC 2 to provide third-party assurance to EY’s Clients in EY’s senior leadership. The team is responsible of overseeing and leading the technical audit process that includes third-party external assessments of client-facing critical business applications, M365 Teams Apps, Network, cloud configuration reviews, infrastructure reviews, UK Cyber Essentials Plus Certification and UK IT Health Check Certification. The team manages Attack and Penetration testing controls based on Industry Standards and obtain third-party security attestations/certifications to enable EY Business to win in the market. The team also manages and maintains the firm’s ISO 27001 certifications is responsible for the end-end delivery of attestation audits like SOC 1 and SOC2. Technical compliance to regulatory framework like Internation Standard on Quality Management (ISQM) is also a responsibility of the team.</span></p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">An Information Security Analyst will work closely with team leads to assist with one of the security functional areas described above.</span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Your key responsibilities</strong></span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Preparing detailed security review reports and remediation guidance</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Researching new application security vulnerabilities and attack vectors</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support the team in updating their skill and knowledge</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Leading strategic initiatives and mentoring new team members</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Continuous improvement to improve quality of service</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Configure, manage, and update vulnerability assessment tools to ensure they are running optimally and providing accurate results</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Skills and attributes for success</strong></span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Hands on experience of Web, thick client, Mobile, VOIP, Wireless application security testing</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proficient in automated and manual application testing methodologies</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Expert in using manual testing tools such as Burp Professional, Nmap, Wireshark, Nessus, echomirage</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Expert in using automated application scan tool Webinspect / Qualys WAS, CheckMarx, WhiteSource etc..</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Basic Knowledge of programming language like C/C++, C#, JAVA, ASP.NET and familiar with PERL/Python Scripting</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Basic understanding of secure coding principles and common coding vulnerabilities (e.g., OWASP Top Ten). This helps in identifying vulnerabilities during code reviews and collaborating with development team</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Knowledge of common security requirements within ASP.NET & Java application</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Good knowledge of TCP/IP, Network Security</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Hands-on experience in testing AI integrated projects</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Capable of testing both Android & iOS based applications</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Knowledge to perform manual code review</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Good Technical aptitude, problem solving and ability to quickly learn and master new topics and domains</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Excellent communication skills; written and verbal</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>To qualify for the role you must have</strong></span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">1 to 6 years of experience in application security assessment</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Hands on experience of Web, thick client, Mobile Application security reviews</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Exposure and good understanding of the various manual testing methodologies</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Knowledge of how vulnerabilities can lead to incidents and the role of vulnerability assessments in incident detection and response</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A grasp of how applications, networks, and systems are architected from a security perspective. This includes understanding security controls like firewalls, IDS/IPS, and encryption</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Must be a strong multi-tasker and be able to prioritize duties</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Ideally, you’ll also have</strong></span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Bachelors or above in Information Technology or Cyber Security related Degrees</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Keen interest in pursuing relevant Information Security Certifications like CEH, OSCP CISSP, CISM, CISA, etc.</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>What we offer</strong></span></p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial and social well-being. Your recruiter can talk to you about the benefits available in your country. Here’s a snapshot of what we offer:</span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Continuous learning:</strong> You will develop the mindset and skills to navigate whatever comes next.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Success as defined by you:</strong> We will provide the tools and flexibility, so you can make a significant impact, your way.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Transformative leadership: </strong>We will give you the insights, coaching and confidence to be the leader the world needs.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Diverse and inclusive culture: </strong>You will be accepted for who you are and empowered to use your voice to help others find theirs.</span></li> </ul><p> </p> <p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"><b>EY | Building a better working world </b></span></span></p> <p><br> <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br> EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. </span></span></p> <p><br> <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br> Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. </span></span></p> <p><br> <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br> Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. </span></span></p>