Ernst & Young LLP ( EY India )

Senior Application and Offensive Security Consultant

Ernst & Young LLP ( EY India )
Bengaluru/Bangalore
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 4 yearsMin. 4 years

Job Description

FS-RISK CONSULTING-TPRM-Senior-Application and Offensive Security

At EY, we’re all in to shape your future with confidence. 

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. 

Join EY and help to build a better working world. 

 

Digital Risk- Application & Offensive Security – Senior

 

 

Job purpose:

 

Senior in the Risk Advisory team to work on Application Security and Offensive Security engagements for our customers across the globe.

 

You will be responsible for delivering secure application and adversarial testing engagements in accordance with EY quality guidelines & methodologies. You will be expected to execute and coordinate engagement activities on a day-to-day basis and proactively support the identification of new opportunities in application and offensive security domains.

 

You will work closely with development, DevOps, and security teams to embed secure-by-design practices and validate application security through real-world attack simulations using a Glasswing-aligned adversarial approach. You will assist in developing new methodologies, strengthen secure engineering practices, and contribute to creating a strong learning culture by mentoring junior team members.

 

In line with EY’s commitment to quality, you will confirm that work is of the highest quality by reviewing outputs from junior members.

 

 

Your client responsibilities:

 

  • Perform Secure SDLC reviews and provide actionable recommendations across application environments
  • Conduct and support bug bounty programs and vulnerability validation activities
  • Execute adversarial testing and attack simulation exercises using real-world attack scenarios (Glasswing-aligned approach)
  • Identify exploitable vulnerabilities and validate them from an attacker’s perspective
  • Support threat modeling and secure architecture reviews for applications
  • Maintain relationships with client stakeholders across development, DevOps, and security teams
  • Demonstrate understanding of modern application architectures (APIs, microservices, cloud-native systems)
  • Support secure design and DevSecOps integration across the application lifecycle
  • Assist Managers in business development, proposal creation, and solutioning
  • Contribute to development of methodologies, frameworks, and thought leadership
  • Facilitate knowledge sharing sessions and discussions with client teams
  • Provide regular status updates on engagements and deliverables
  • Stay updated on emerging application security threats, vulnerabilities, and attack techniques

 

 

Your people responsibilities:

 

  • Work collaboratively with team members to deliver high-quality outputs within timelines
  • Mentor and train junior resources on secure coding, testing, and adversarial thinking
  • Drive adherence to quality standards and methodologies
  • Participate in internal capability development and knowledge sharing initiatives
  • Support performance management of team members

 

 

Mandatory skills:

 

  • Strong understanding of Secure SDLC and DevSecOps practices
  • Experience in application security testing (SAST, DAST, API testing, manual testing)
  • Strong knowledge of OWASP Top 10 and web application vulnerabilities
  • Experience in bug bounty programs and vulnerability validation
  • Understanding of adversarial testing and attack simulation approaches (Glasswing-aligned)
  • Knowledge of API security (OAuth2, OIDC, mTLS)
  • Experience in threat modeling techniques
  • Familiarity with modern application architectures (cloud, microservices, containers)
  • Strong understanding of web protocols and technologies
  • Knowledge of CI/CD pipelines and secure engineering practices
  • Certifications such as CEH, OSCP, GWAPT or equivalent preferred
  • BE/BTech/MCA with 4–8 years of relevant experience

 

 

Preferred skills:

 

  • Exposure to cloud security (AWS/Azure/GCP)
  • Experience working in Agile/DevOps environments
  • Prior client-facing or consulting experience

 

EY | Building a better working world

EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.

Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.

EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

Experience Level

Senior Level

Job role

Work location
Work locationBengaluru, KA, IN, 560016
Department
DepartmentRisk Management & Compliance
Role / Category
Role / CategoryRisk Compliance
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 4 years

About company

Name
NameErnst & Young LLP ( EY India )
Job posted by Ernst & Young LLP ( EY India )

Similar jobs you can apply for

Accounts / Finance
Airtel

Field Installation Engineer

Airtel
Bengaluru/Bangalore
₹18,000 - ₹27,000
Field Job
Full Time
Any experience
No English Required
Newjaisa Technologies Private Limited

Laptop Technician

Newjaisa Technologies Private Limited
Arakere, Bengaluru/Bangalore
₹18,000 - ₹20,000
Work from Office
Full Time
Any experience
No English Required
Vindhya E-Infomedia

Systems Server Engineer

Vindhya E-Infomedia
Rajaji Nagar, Bengaluru/Bangalore
₹25,000 - ₹35,000
Work from Office
Full Time
Min. 3 years
Good (Intermediate / Advanced) English
V5 Global

Field Installation Engineer

V5 Global
Bengaluru/Bangalore
₹17,800 - ₹26,500*
Field Job
Full Time
Any experience
No English Required
Aroleap Fitness

Installation Engineer

Aroleap Fitness
Binnipete, Bengaluru/Bangalore
₹20,000 - ₹25,000
Field Job
Full Time
Any experience
Basic English
V5 Global

Field Installation Engineer

V5 Global
Bengaluru/Bangalore
₹20,000 - ₹25,000
Field Job
Full Time
Any experience
No English Required

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 4 to 8 years are eligible to apply for this job. You can apply for more jobs in Bengaluru/Bangalore to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Bengaluru/Bangalore at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Bengaluru/Bangalore . Through apna, you can find jobs in 64 cities across India. Join NOW!