Risk Consulting - Digital Risk - Senior - Cyber
About this role
The opportunity
The objective of our risk consulting services is to provide clients with a candid and reliable overview of their risk landscape. Our solutions can be used by our clients to build confidence and trust with their customers, the overall market and when required by regulation or contract.
For our Cyber Risk services, the ideal candidate will support engagements focused on testing and validating cybersecurity controls across organizations. This role involves working closely with IT, security teams, and business units to ensure that organizations’ cyber risk posture is aligned with their business objectives and regulatory requirements.
Your key responsibilities
- Work closely with client personnel to analyze risk landscapes and information systems, leveraging technical expertise to identify strategic and tactical improvement opportunities.
- Collaborate with engagement teams to plan engagements, develop work programs, timelines, risk assessments, and testing procedures.
- Serve as a fieldwork leader by directing daily testing activities, informing supervisors of engagement status, and managing staff performance.
- Support cyber monitoring and response activities using tools such as CrowdStrike, Splunk, and Microsoft Sentinel.
- Apply a strong understanding of NIST CSF 2.0 in testing execution and reporting.
- Prepare detailed reports and recommendations aligned with US work product quality standards.
Skills and attributes for success
- Strong fundamentals across the cybersecurity domain, including cyber risk management, cyber resilience, and security policies and procedures.
- Proven experience performing engagements across strategy and governance, audits, risk assessments, and maturity assessments.
- Strong audit mindset with the ability to design, execute, and evidence control testing across cyber and IT domains; OT exposure is a plus.
- Proven ability to lead multi-location teams, manage risks, and deliver high-quality outcomes within agreed timelines and budgets.
- Strong written and verbal communication skills in English (non-negotiable).
- Ability to manage time effectively and work in US time zones.
- Ability to inspire teamwork, accountability, and responsibility within engagement teams.
- Ability to align cyber and cloud security controls with frameworks and standards such as ISO 27001, NIST CSF, SOC 2, PCI DSS, and privacy expectations.
- Strong written and verbal communication skills in English (non-negotiable).
- Ability to follow defined methodologies, instructions, and testing procedures.
- Ability to complete assigned tasks within agreed timelines and quality expectations.
- Good understanding of network security (firewalls, SD-WAN, familiarity with Vectra AI) is a plus.
- Good understanding of cloud security across Azure, AWS, and GCP is a plus.
To qualify for the role, you must have.
- A bachelor’s degree in Information Technology, Cybersecurity, Risk Management, or a related field
- Proven 3–6 years of experience in cybersecurity testing or risk assessment.
- Certifications: ISO 27001:2022, CISM, CISA, CCNA are a plus.
- Familiarity with regulatory frameworks and compliance standards including ISO 27001, ISO 27017, ISO 42001, NIST CSF
Ideally, you’ll also have
- Certifications such as CISA, CISSP, or AWS/Azure/GCP security certifications are preferred.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
Apply now » Apply now- Start applying with LinkedIn
- Apply Now Start
-
Please wait...
- Connect with us
- Our locations
- My EY
- Site map
- Legal and privacy
- Labor condition applications
- Cookie Consent Manager
-
Opens in a new tab.
-
Opens in a new tab.
-
Opens in a new tab.
-
Opens in a new tab.
-
Opens in a new tab.
EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
×Cookie Consent Manager
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. Because we respect your right to privacy, you can choose not to allow some types of cookies. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
Required Cookies
These cookies are required to use this website and can't be turned off.
Required Cookies Show More Details Required Cookies Provider Description Enabled SAP as service provider We use the following session cookies, which are all required to enable the website to function:- "route" is used for session stickiness
- "careerSiteCom