About this role
<div style="font-family:Arial;font-size:1.0em"> <p>At EY, we’re all in to shape your future with confidence. </p> <p>We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. </p> <p>Join EY and help to build a better working world. </p> </div> <div style="font-family:Arial;font-size:1.0em"> </div><p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Job description - </strong><strong>Senior – Cybersecurity (Risk Consulting – Digital Risk)</strong></span></p> <p> </p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities. At EY GDS, you’ll have the chance to build a career as unique as you are, with global scale, support, inclusive culture, and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY GDS become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong> </strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>The opportunity</strong></span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">The objective of our risk consulting services is to provide clients with a candid and reliable overview of their risk landscape. Our solutions can be used by our clients to build confidence and trust with their customers, the overall market and when required by regulation or contract.</span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">For our Cyber Risk services, the ideal candidate will support engagements focused on testing and validating cybersecurity controls across organizations. This role involves working closely with IT, security teams, and business units to ensure that organizations’ cyber risk posture is aligned with their business objectives and regulatory requirements.</span></p> <p> </p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Your key responsibilities</strong></span></p> <p> </p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Work closely with client personnel to analyze risk landscapes and information systems, leveraging technical expertise to identify strategic and tactical improvement opportunities.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Collaborate with engagement teams to plan engagements, develop work programs, timelines, risk assessments, and testing procedures.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Serve as a fieldwork leader by directing daily testing activities, informing supervisors of engagement status, and managing staff performance.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support cyber monitoring and response activities using tools such as CrowdStrike, Splunk, and Microsoft Sentinel.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Apply a strong understanding of NIST CSF 2.0 in testing execution and reporting.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Prepare detailed reports and recommendations aligned with US work product quality standards.</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong> </strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Skills and attributes for success</strong></span></p> <p> </p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong fundamentals across the cybersecurity domain, including cyber risk management, cyber resilience, and security policies and procedures.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven experience performing engagements across strategy and governance, audits, risk assessments, and maturity assessments.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong audit mindset with the ability to design, execute, and evidence control testing across cyber and IT domains; OT exposure is a plus.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven ability to lead multi-location teams, manage risks, and deliver high-quality outcomes within agreed timelines and budgets.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong written and verbal communication skills in English (non-negotiable).</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Ability to manage time effectively and work in US time zones.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Ability to inspire teamwork, accountability, and responsibility within engagement teams.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Ability to align cyber and cloud security controls with frameworks and standards such as ISO 27001, NIST CSF, SOC 2, PCI DSS, and privacy expectations.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong written and verbal communication skills in English (non-negotiable).</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Ability to follow defined methodologies, instructions, and testing procedures.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Ability to complete assigned tasks within agreed timelines and quality expectations.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Good understanding of network security (firewalls, SD-WAN, familiarity with Vectra AI) is a plus.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Good understanding of cloud security across Azure, AWS, and GCP is a plus.</span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong> </strong></span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>To qualify for the role, you must have.</strong></span></p> <p> </p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">A bachelor’s degree in Information Technology, Cybersecurity, Risk Management, or a related field</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Proven 3–6 years of experience in cybersecurity testing or risk assessment.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Certifications: ISO 27001:2022, CISM, CISA, CCNA are a plus.</span></li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Familiarity with regulatory frameworks and compliance standards including ISO 27001, ISO 27017, ISO 42001, NIST CSF</span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong> </strong></span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Ideally, you’ll also have</strong></span></p> <p> </p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Certifications such as CISA, CISSP, or AWS/Azure/GCP security certifications are preferred.</span></li> </ul> <p> </p><div style="font-family:Arial;font-size:1.0em"> <p><b>EY | Building a better working world </b></p> <p>EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.</p> <p>Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.</p> <p>EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.</p> </div>