Cyber Attack & Penetration Testing Manager – Consulting
RegionUSA
Job description
Job Description: - Identify potential threats and vulnerabilities in enterprise environments
- Lead technical teams conducting penetration testing, red team, and purple team exercises
- Apply offensive security analysis to enhance other cybersecurity areas
- Oversee delivery of offensive security engagements
- Collaborate with security and business teams
- Deliver clear, concise, and actionable reports and support to technical and executive audiences
- Mentor senior and junior analysts
- Build a collaborative and trust-based team culture
- Enhance team skillsets and capabilities
- Monitor emerging cyber threat trends and technologies
- Represent EY in industry groups, conferences, and events
- Plan and execute internet, intranet, wireless, web application, cloud, social engineering, and physical penetration testing
- Develop and execute red team scenarios
- Analyze penetration testing results and report findings, exploitation procedures, risks, and recommendations
- Manage testing projects using established methodologies, tools, and rules of engagement
Requirements: - Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, Information Technology, Engineering or a related major with 6+ years of related work experience, or a Master’s degree with approximately 3–4+ years of related work experience
- Experience in managing and executing penetration testing projects
- Experience with manual attack and penetration testing
- Experience establishing and managing Red Team or application penetration testing programs
- Scripting/programming skills, such as Python, PowerShell, Java, or Perl
- Familiarity with the latest exploits and security trends
- Experience leading technical teams in remote and on-site penetration testing within defined rules of engagement
- Ability to oversee multiple attack and penetration testing projects simultaneously while navigating strict deadlines
- Familiarity with stealth network penetration testing
- Any two certifications: OSCP, OSWP, GPEN, GWAPT, OSCE, OSEE, GXPN, CISSP, CISM, PMP, or CREST Certified Simulated Attack Manager
- A driver’s license valid in the U.S.
- Willingness and ability to travel domestically and internationally
- Estimated travel required up to 50%
- Knowledge of Windows, Linux, Unix, or other major operating systems
- Familiarity with cloud vulnerability remediation, TTPs, exploits, and security trends
- Deep understanding of MITRE ATT&CK framework
- Deep understanding of TCP/IP network protocols
- Deep understanding and experience with Active Directory attack techniques
- Understanding of network security and popular attack vectors
- Understanding of web application vulnerabilities, including OWASP Top 10
- Experience developing harnesses and agentic workflows for offensive security
Benefits: - Medical and dental coverage
- Pension plan
- 401(k) plan
- Wide range of paid time off options
- Professional growth
- Personal fulfillment
- Inclusive culture
- Reasonable accommodation for qualified individuals with disabilities
first seen 2026-09-11 09:30:01 · last verified 2026-09-11 17:30:01
pentestcareers.com // breach the job market