חברות הייטק בישראלEYOffensive Security Consultant

Offensive Security Consultant

EY logo
EY· Professional Services
Tel Aviv, IL, 6706703פורסמה החודש

כישורים מהמשרה

Hands-on penetration testing (white/grey/black box)Red Team and Purple Team engagementsWeb, mobile, and thick-client application security testingInfrastructure and internal/external network penetration testingVulnerability identification and exploitation (e.g., SQL injection, XSS, auth issues)Client-facing security communication and technical report writingEnd-to-end pentest lifecycle (prepare, execute, document, recommend)Penetration testing tool proficiency (Burp Suite, Kali Linux, Nmap, Metasploit, Nessus, Wireshark)Active Directory / Windows domain security testing (advantage)Security methodologies and frameworks (OWASP, PTES, MITRE ATT&CK)

תיאור המשרה

Offensive Security Consultant, responsible for performing hands-on penetration tests and offensive security assessments for local and global clients. The role includes a broad range of assessments, including white, grey, and black box testing across infrastructure, applications, and other relevant technology environments. Educating clients on inherent security risks, providing meaningful hardening and mitigation strategies, and supporting engagements with local and global clients through clear communication, technical leadership, and high-quality deliverables. Responsibilities: Perform hands-on offensive security assessments across a wide range of technologies and engagement types, including Red Team, Purple Team, external and internal network testing, web and mobile applications, thick client applications, web3 environments, and additional offensive security domains. Deliver end-to-end penetration testing engagements, including preparation, execution, documentation of findings, risk-based recommendations, and professional client-facing reporting. Collaborate with client technical teams to validate security gaps, explain findings clearly, support remediation discussions, and ensure practical, business-relevant security improvements. Participate in client meetings throughout the engagement lifecycle, including kickoff, scoping, technical walkthroughs, and final report presentation. Requirements: At least 3 years hands-on experience in infrastructure, networking, systems administration, IT operations, or related technical infrastructure domains – Must. At least 1 year hands-on experience in Offensive Security, including application and/or infrastructure penetration testing – Must. Hands-on experience identifying and exploiting common security vulnerabilities across applications and infrastructure, such as SQL Injection, Cross-Site Scripting, authentication and authorization weaknesses, misconfigurations, insecure services, and other relevant attack vectors – Must. Experience with common penetration testing tools, including Burp Suite, Kali Linux, Nmap, Metasploit, Nessus, and Wireshark, and similar offensive security tools – Must. Good written and verbal communication skills, with the ability to document technical findings clearly, write professional assessment reports, and present risks and recommendations to technical and non-technical stakeholders – Must. Self-motivated, responsible, and able to manage assigned testing activities independently while working effectively as part of a consulting team – Must. Familiarity with offensive security methodologies and frameworks such as OWASP, PTES, MITRE ATT&CK, or similar references – Significant Advantage. Strong understanding of TCP/IP, networking concepts, common ports and protocols, and how they are assessed during infrastructure and network penetration tests – Significant Advantage. Hands-on familiarity with Active Directory environments, Windows domains, authentication flows, privilege escalation paths, and common enterprise misconfigurations – Significant Advantage. Proven experience in infrastructure penetration testing, including internal and external network assessments – Significant Advantage. Relevant professional certifications from a recognized offensive security institute – Significant Advantage. Familiarity with public cloud environments such as Microsoft Azure, AWS, or Google Cloud Platform, including identity, permissions, exposed services, and common cloud misconfigurations – Significant Advantage. Ability to conduct source code reviews, database security assessments, or additional specialized security testing activities – Advantage.
EY logo

על EY

EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams in more than 150 countries work across a full spectrum of services in assurance, consulting, tax, strategy and transactions, strengthened by sector experience and diverse ecosystem partners. Find out more about the EY global network: http://ey.com/en_gl/legal-statement

לעמוד החברה

מה זו משרה סודית?

רוב המשרות בישראל מתפרסמות באתרי הקריירה של החברות הרבה לפני שהן מגיעות ללינקדאין — ולפעמים לא מגיעות לשם בכלל. SecretJobs סורקת מדי יום את דפי הדרושים של יותר מ-5,000 חברות הייטק בישראל ומאתרת בדיוק את המשרות האלה.

עוד משרות ב-EY