Job Description
Summary
Ernst & Young (EY), one of the world’s leading professional services firms, is hiring Senior Penetration Testing Consultants in Trivandrum (with remote flexibility across India). This role offers cybersecurity professionals an opportunity to work on advanced penetration testing, red team assessments, and application security testing projects for global clients. If you have strong technical expertise, recognized certifications like OSCP, OSCE, OSEP, or CREST, and a passion for ethical hacking and cyber defense, this is your chance to accelerate your career with EY.
Job Details at a Glance
| Job Title | Senior Consultant – Penetration Testing |
|---|---|
| Company | EY (Ernst & Young Global Limited) |
| Location | Trivandrum, Kerala, India (Remote/Anywhere in Country) |
| Experience | 5+ years in penetration testing & cybersecurity |
| Shift | Full-time, flexibility with travel to MENA region |
| Tools/Tech | OWASP Top 10, TCP/IP, Active Directory, Linux, Windows, Cloud (AWS/Azure/GCP), Red Team tools |
| Certifications | OSCP, OSCE, OSEP, OSWE, CREST, CRTE, eCPTX, eWPTX (Mandatory); CISSP/GPEN/GWAPT (Preferred) |
Key Responsibilities
As a Senior Penetration Tester at EY, you will:
- Conduct penetration testing across internet, intranet, wireless, web applications, social engineering, and physical environments.
- Perform red team assessments to identify vulnerabilities and test real-world attack scenarios.
- Analyze penetration test results, prepare detailed reports, and present risks/recommendations.
- Collaborate with development teams to address OWASP Top 10 vulnerabilities.
- Apply expertise in Active Directory attacks, TCP/IP protocols, and enterprise security controls.
- Automate security testing and integrate DAST/SAST solutions.
- Support SDLC and Agile environments through application security testing and secure code reviews.
- Communicate findings effectively with both technical and executive stakeholders.
Skills & Attributes for Success
- Strong knowledge of OWASP Top 10 and common web application vulnerabilities.
- Expertise in Active Directory, Windows/Linux/UNIX environments, TCP/IP.
- Hands-on penetration testing for cloud platforms (AWS, Azure, GCP) and IoT/OT systems.
- Strong communication and technical writing skills for executive-level reporting.
- Ability to manage high-pressure consulting projects and client relationships.
Required Qualifications
- BE/B.Tech/MCA or equivalent degree.
- 5+ years of penetration testing experience (internet, intranet, wireless, web, social engineering, red team).
- At least one advanced certification: OSCP, OSCE, OSEP, OSWE, CREST, CRTE, eCPTX, eWPTX.
- Knowledge of Windows, Linux, UNIX OS and experience with PowerPoint/Excel for reporting.
Preferred Qualifications
- Advanced certifications such as CISSP, GPEN, GWAPT.
- Experience with DevSecOps, automation, and cloud security testing.
- Consulting experience in client-facing security roles.
What EY Offers
- Global exposure with Fortune 500 clients and innovative cybersecurity projects.
- Continuous learning, coaching, and career development.
- Flexible work culture with opportunities for remote and hybrid working.
- A diverse and inclusive environment encouraging leadership and innovation.
Apply Now
Ready to take your cybersecurity career to the next level with EY?
👉 Apply directly on the official EY careers page and join a global leader shaping the future of cybersecurity and consulting.