Other locations: Primary Location Only
Requisition Id: 1739867
As a global leader in assurance, tax, transaction and advisory services, we hire and develop the most passionate people in their field to help build a better working world. This starts with a culture that believes in giving you the training, opportunities and creative freedom. At EY, we don't just focus on who you are now, but who you can become. We believe that it’s your career and ‘It’s yours to build’ which means potential here is limitless and we'll provide you with motivating and fulfilling experiences throughout your career to help you on the path to becoming your best professional self.
The opportunity : Consultant-National-Forensics-ASU - Forensics - Investigations & Compliance - Gurgaon
National :
National comprises of sector agnostic teams working across industries for a well rounded experience.
ASU - Forensics - Investigations & Compliance :
Successful organizations depend on their reputation for keeping promises, respecting laws and behaving ethically to maintain stakeholder trust. EY Forensic & Integrity Services professionals help organizations protect and restore enterprise and financial reputation. We assist companies and their legal counsel to investigate facts, resolve disputes and manage regulatory challenges. We put integrity at the heart of compliance programs to help better manage ethical and reputational risks.
Our integrated approach ranges from enhancements in areas of perceived weakness or issues — including governance, controls, culture and data insights — to full organizational design and structural implementation. We want to help companies safeguard and restore financial and brand reputations. The insights and quality services we deliver help build trust and confidence in the capital markets and in economies the world over.
Your key responsibilities
Technical Excellence
- Job Role Description: Offensive Security and Application Security Analyst A professional in this role will assist in identifying, exploiting, validating and helping remediate security weaknesses in applications, infrastructure, and cloud environments. The job blends ethical hacking, secure development practices, threat modelling, and vulnerability and penetration testing . The candidate should be able to:
- Identify vulnerabilities in application, network, mobile app and databases.
- Accurately assess real world exploitability and business impact.
- Deliver clear, concise, actionable remediation guidance.
- Build strong relationships with clients.
- Automate repetitive tasks (integrate scanners, scripts, tooling).
- Contribute to overall reduction of critical/high vulnerabilities for client. 1. Key Responsibilities
- Execute application security and DevSecOps engagements, supporting clients in identifying, assessing, and mitigating application security risks.
- Perform application security assessments across web, mobile, APIs, cloud-native applications, and supporting infrastructure.
- Conduct AppSec and DevSecOps maturity assessments using frameworks such as OWASP SAMM, NIST SSDF, and BSIMM, and document improvement opportunities.
- Identify security gaps within the SDLC and provide practical recommendations to enhance application security posture.
- Support the implementation and integration of security controls within CI/CD pipelines, including SAST, SCA, DAST, secrets scanning, IaC scanning, and container security.
- Perform secure code reviews, vulnerability validation, and remediation verification across multiple technology stacks.
- Assist clients in adopting secure development practices and embedding security requirements throughout the software development lifecycle.
- Communicate technical findings, risks, and remediation guidance to client stakeholders in clear and actionable terms.
- Support threat modeling activities, attack surface reviews, and security architecture assessments.
- Contribute to security automation initiatives, including tool integrations, reporting workflows, dashboards, and process improvements.
- Collaborate with development, DevOps, cloud, and security teams to address identified vulnerabilities and security gaps.
- Assist in the development of security standards, secure coding guidelines, and AppSec best practices.
- Prepare technical reports, presentations, and client deliverables while ensuring quality and consistency.
- Support proposal development, solution demonstrations, and other business development activities when required.
- Contribute to the development of reusable security tools, scripts, accelerators, and assessment methodologies.
- Support AI/GenAI security assessments, including LLM threat modeling, prompt security reviews, secure integration assessments, and AI risk evaluations. 2. Required Skills & Competencies: The candidate should have following technical skills:
- Strong understanding of: o Web technologies (HTTP, sessions, authentication) o API security (OAuth2, JWT, rate limiting) o OWASP Top 10 & OWASP API Top 10 o Authentication/Authorization patterns o Secure cloud architecture (AWS/Azure/GCP)
- Ability to exploit: o XSS, SQLi, IDOR, SSRF, RCE, CSRF o Deserialization, logic flaws o Permission & role escalation weaknesses 3. Experience & Qualifications
- 2–5 years of experience in security testing, penetration testing, or application security.
- Bachelor's degree in CS/IT/Cybersecurity (or equivalent experience).
- Preferred certifications (not mandatory, but highly valued): o OSCP (Offensive Security Certified Professional) o Burp Suite Certified Practitioner (BSCP) o GWAPT (GIAC Web Application Penetration Tester) o CPTS (Certified Penetration Testing Specialist)
- Hands-on penetration testing and Red Teaming experience is more important than certifications.
- Clear communication of vulnerabilities and business impact along with strong analytical and problem solving skills.
Skills and attributes
To qualify for the role you must have
Qualification
- Bachelor of Technology in Computer Science
Experience
- Frontend Development (2+ years)
What we look for
People with the ability to work in a collaborative manner to provide services across multiple client departments while following the commercial and legal requirements. You will need a practical approach to solving issues and complex problems with the ability to deliver insightful and practical solutions. We look for people who are agile, curious, mindful, and able to sustain positive energy, while being adaptable and creative in their approach.
What we offer
Fuelled by the brilliance of our people, EY has emerged as the strongest brand and the most attractive employer in our field, with market-leading growth over competitors. Our people work side-by-side with market-leading entrepreneurs, game-changers, disruptors, and visionaries. As an organization, we are investing more time, technology, and money than ever before in skills and learning for our people. At EY, you will have a personalized Career Journey and also the chance to tap into the resources of our career frameworks to better know about your roles, skills, and opportunities.
EY is equally committed to being an inclusive employer, and we strive to achieve the right balance for our people—enabling us to deliver excellent client service while allowing our people to build their careers as well as focus on their wellbeing.
If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible.
Join us in shaping the future with confidence. Apply Now