
UKI Technology Consulting- Penetration Tester, Manager
- Southside Dublin
- Permanent
- Full-time
- Ability to lead and support remote teams in performing complex penetration tests in a variety of environments, managing several teams across different client sites
- Ability to simulate real-world attacks on an organization's systems, networks, and applications to identify vulnerabilities and weaknesses.
- Ability to analyse potential threats and attack vectors to understand the risk landscape.
- Experience in delivering penetration test results to technical and non-technical colleagues and clients
- A deep understanding of technical security requirements, and conducting research projects to maintain and grow knowledge within technology
- Ability to independently perform technical responsibilities and deliver results to a high standard
- An in-depth awareness and understanding of advancements in the penetration testing domain
- Ability to collaborate with colleagues across other relevant teams to enhance service quality
- Experience in maintaining compliance with regulations and standards in relation to executing penetration tests, in addition to audit requirements and exacting reporting formats
- Ability to take on responsibility for penetration test projects and follow these through to completion including carrying out tests, issuing reports and providing recommendations
- Experience in mentoring junior members of teams, you will need to grow on-shore and off-shore capabilities and support overall service improvement
- Hands-on internal and external infrastructure and application penetration testing required
- Exposure to a variety of security testing tools and a wide range of exploit techniques
- Requirement to stay up-to-date on current security threats, trends and solutions
- Strong demonstrated ability to take vulnerabilities and articulate the actual business risk along with excellent reporting writing and client presentation skills
- Familiarity with Open Source Security Testing Methodology Manual (OSSTMM), Open Web Application Security Project (OWASP), National Institute of Standards and Technology (NIST) Special Publications, Tigerscheme SST, and CESG Check
- A consultative manner and customer facing skills with the ability to communicate with stakeholders at all levels and advise on best practices
- An enquiring mind, the tenacity to overcome technical challenges, and an ability to approach problems from different perspectives
- 7-10+ years' experience working in a penetration testing role across various sectors
- Experience in 'Big 4' or similar consultancy experience in the Irish market
- Track record in supporting the delivery of a broad range of cyber security projects
- Government, Utilities, Manufacturing, Financial Services and Pharma experience desirable
- Leadership experience with a strong focus on mentorship
- Onsite and Offsite Penetration Testing
- OSCP qualification and red team experience
- OT pen testing experience
- Driven cyber security professional with a passion for information security
- Strong analytical skills to solve technical issues and flexibility in handling multiple issues at once
- Excellent communication and project management skills (verbal and written),
- Excellent organisational and problem-solving skills in addition to strong attention to detail,
- Experience in drafting proposals, bids and tender responses,
- Excellent working knowledge of Microsoft PowerPoint, Word, Excel and online research tools,
- Strong collaboration skills, ideally working with global and multi-functional teams.
- Ability to prioritise and work to tight deadlines and manage own caseload.
- The ability to learn quickly and to work well under pressure,
- The ability to listen attentively and express complex issues concisely to clients
- Show leadership and motivate teams, including project management of consultancy projects
- Participate in implementation or deployment of new tools, processes and best-practices in order to improve knowledge sharing and to raise security level while promoting security awareness among team members
- Application, Mobile, IoT, Cloud, Infrastructure and Network Security
- Application developer background (common frameworks) and understand DevSecOps processes including VA, SAST, DAST, RASP, secure code design review
- Understanding of CI/CD, container concepts, agile project management, deployment, automation and orchestration
- Programming/scripting experience (Powershell, ASP, .NET, Python, Perl);
- OT Security (knowledge of or certification in ISA/IEC 62443 an advantage)
- Cloud Security (Azure AZ900, AZ500 and AWS Security an advantage)
- Security Engineering or Architecture (SABSA an advantage)
- MSc degree in information security, computer science, computer engineering, information systems, cloud computing or related field of study
- OSCP certified
- CISSP or CISM (an advantage)
- GPEN, GWAPT, GXPN, CEH, EC-Council LPT, CompTIA PenTest+ (desirable)
- Support and coaching from some of the most engaging colleagues around
- Opportunities to develop new skills and progress your career
- The freedom and flexibility to handle your role in a way that's right for you
- Pension
- Maternity & Paternity leave
- Discounted health insurance
- Bike to work Scheme
- Web Doctor - Free unlimited online GP consultations for you and your family
- Recognition Awards
- The purchase of additional annual leave
- Cash incentives for referrals
- Hybrid Working
- Work Mobile
- Free Gym membership ยท
- TECH MBA paid by EY
- Travel Pass
- Wellness rooms Available in some offices
- When you join EY, you will be supported to ensure that you are enhancing your skills from day one.
- Continuous learning, where you can develop the mindset and skills to navigate whatever comes next.
- As you grow and develop here, you'll discover opportunities to help customise your career journey, so that it's as unique as you are - success is defined by you, we will provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership, we will give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture, you will be embraced for who you are and empowered to use your voice to help others find theirs.
- We have embraced Hybrid working at EY adding greater flexibility and autonomy to the roles of our employees.