Senior Security Consultant
Job description
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
Senior Security Consultant
Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
As a Security Consultant, the individual will provide security guidance to internal IT project teams responsible for delivering business solutions, with a focus on end user technology and related solutions. They will identify and prioritize security-related requirements, promote secure-by-default designs and ensure information systems and infrastructure will be secured throughout the system development life cycle (SDLC) in an agile environment.
Your key responsibilities
The successful candidate is expected to perform risk assessments of mobile applications, mobile and desktop end user technology platforms, infrastructure systems and solutions; effectively articulate findings and recommendations to internal customers and management; and they will be expected to work on multiple projects and tasks concurrently.
Skills and attributes for success
- Solid understanding of key security and privacy issues, risks and threats, and ability to apply this expertise across business needs via internal consulting and security risk assessment types of activities.
- Strong written and verbal communication skills are essential
- Proven background in IT risk assessments, and knowledge of good security practices and controls used in applications and infrastructure.
- Translate technical vulnerabilities and security risks into business risk terminology for business units and recommend corrective actions to customers and project stakeholders.
- Ability to document and produce important artefacts on risk assessments, engagement Statements of Work, process, minimum security baselines and presentations on security risks.
- Manage customer expectations and deliver quality security consulting services while balancing business objectives with security requirements.
- Ability to partner with technical teams in a practical manner when conflicting interests arise while preserving EY core security principles and policies.
- Ability to proactively lead, own and research security related subject matters when required to take a position or resolve issues.
- Ability to collaborate to facilitate and enhance the understanding & compliance to security policies.
To qualify for the role, you must have
- A minimum of 8-10 years of experience in an Information Security or Information Technology subject area.
- Two or more years of experience with iOS and Android security such as mobile application security analysis, mobile application penetration testing, mobile threat modelling, mobile device forensics, and assessing mobile device security capabilities.
- Three or more years of experience with understanding and defining good security practices for end user technology platforms (e.g., iOS, Android, macOS, Windows 10), multi-tier information systems, applications (e.g., web, mobile, desktop), and End Point Security solutions.
- Working experience in performing security risk assessments for information systems and applications such as those for web, desktop, and mobile.
- Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or risk assessments.
- Good interpersonal, communication, organizational and project management skills.
- Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change.
Ideally,you will also have
- One or more years of experience with iOS and Android mobile application development, Agile Methodology, Continuous Integration / Continuous Delivery, and IoT security.
- Knowledge or experience with Microsoft Azure cloud technology stack (e.g., M365, SharePoint, OneDrive for Business, Intune, Conditional Access) and Azure cloud applications.
- Knowledge of common information security standards and risk analysis methodologies, such as: ISO 27001/27002, NIST, PCI, COBIT, ISF IRAM2, and OWASP.
What we look for
We look for people who are customer-centric with good interpersonal, communication and organizational skills. The ideal candidate will have flexibility in adjusting to multiple demands, shifting priorities, ambiguity, rapid change, and an ardent desire to learn.
What we offer
As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial, and social well-being. Your recruiter can talk to you about the benefits available in your country. Here is a snapshot of what we offer:
- Continuous learning: You will develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We will provide the tools and flexibility, so you can make a significant impact, your way.
- Transformative leadership: We will give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You will be accepted for who you are and empowered to use your voice to help others find theirs.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.