EY GDS
EY GDS
New

Senior Pentester / Red Team Operator

Brak informacji o wynagrodzeniu
SeniorFull-time
#433228·Dodano wczoraj·0
Źródło: nofluffjobs.com
Aplikuj teraz

Tech Stack / Keywords

SecurityAzurePythonPowerShellGCPAWS

Firma i stanowisko

EY GDS Poland is a member of the global integrated service delivery center network by EY. The Information Security team at EY supports and protects both EY and client information assets, enabling secure business operations and rapid response to security events. The team covers the entire security lifecycle including risk strategy, digital identity, cyber defense, application security, and technology solutions.

Wymagania

  • 6-8 years of hands-on experience in penetration testing, red teaming, or offensive security.
  • Demonstrated experience executing red team or advanced penetration testing engagements.
  • Relevant certifications including OSCP, CPTS, or equivalents such as GPEN, CRTO, OSEP, OSCE.
  • Ability to work effectively in a fully remote environment.
  • Deep expertise in offensive security tools and frameworks (e.g., Metasploit, Cobalt Strike/custom C2, Empire, BloodHound, Nmap, Burp Suite).
  • Strong knowledge of networking, operating systems (Windows/Linux), Active Directory, cloud platforms (AWS/Azure/GCP), web app security, and common protocols.
  • Proficiency in scripting/programming (Python, PowerShell, Bash, etc.) for automation and custom tooling.
  • Ability to translate complex technical findings into clear business risk language for executives and non-technical stakeholders.
  • Ability to build attack paths and threat models relevant to current infrastructure and threat intelligence.
  • Excellent analytical, problem-solving, technical writing, teamwork, independence, and communication skills.

Nice to have:

  • Experience with threat intelligence-driven adversary emulation (e.g., MITRE ATT&CK framework, TIBER-EU).
  • Prior consulting or client-facing experience.
  • Knowledge of purple teaming, security operations (SOC), incident response, and detection engineering.
  • Contributions to open-source tools or projects, CTF participation, or public research/blogging.

Obowiązki

  • Plan, execute, and lead red team operations and adversary emulation including reconnaissance, initial access, execution, persistence, lateral movement, exfiltration, and impact.
  • Conduct advanced penetration testing across external/internal networks, web/cloud applications, APIs, Active Directory, identity systems, and hybrid/cloud infrastructures.
  • Perform social engineering such as phishing as part of integrated engagements.
  • Identify, validate, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business risks.
  • Collaborate in Purple Team exercises with defensive teams to improve detection, response, and resilience.
  • Produce detailed technical reports, executive summaries, risk assessments, and remediation recommendations.
  • Mentor junior team members, provide technical oversight, and contribute to methodology improvements and tooling including custom exploits and automation scripts.
  • Stay current with emerging threats, TTPs, exploits, and defensive countermeasures through research, conferences, and self-development.

Benefity

  • Private healthcare
  • Sport subscription
  • Training budget
  • International projects
Opieka zdrowotna
Karta sportowa
Dofinansowanie szkoleń
EY GDS

EY GDS

4 aktywne oferty

Zobacz wszystkie oferty
Aplikuj teraz