Cookies & analytics consent
We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.
Read how we use data in our Privacy Policy and Terms of Service.
🤖 15+ AI Agents working for you. Find jobs, score and update resumes, cover letter, interview questions, missing keywords, and lots more.
EY • Bucharest, Romania
Role & seniority: Senior Consultant, Offensive Security (EY)
Stack/tools: Penetration testing across web apps, networks, cloud, hardware/firmware; social engineering campaign development; automation tools; scripting (Python, Bash, PowerShell); major operating systems; client-facing reporting
Execute penetration testing projects across web apps, networks, cloud, and hardware/firmware; develop social engineering scenarios
Prepare detailed findings, exploitation procedures, risks, and mitigation recommendations; create client-facing reports
Present technical topics to client stakeholders; stay updated on threats and best practices; configure/testing infrastructure for optimal security
3+ years in penetration testing/offensive security
Proficiency in scripting (Python, Bash, PowerShell) and automation
Strong OS knowledge; ability to manage multiple security projects
Effective communication with clients/internal teams; actionable report writing
Bachelor’s degree in CS/IT/Cybersecurity or related field; relevant certifications
Certifications: OSCP, GPEN, GWAPT, GXPN, CSSLP
Experience with security testing tooling and client-facing engagements
Location & work type: Hybrid (EY); full-time role with global teams and flexible, inclusive culture
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
The opportunity
As a Senior Consultant in Offensive Security, you will play a pivotal role in enhancing our clients' security posture. You will collaborate with a team of cybersecurity professionals to execute penetration testing, red teaming, simulations of social engineering campaigns, and security assessments for our clients. You will work closely with cross-functional teams to identify vulnerabilities, develop mitigation strategies, and ensure that security practices align with industry standards.
Your key responsibilities
Execute penetration testing projects, having in scope web applications, networks, cloud environments, various hardware and their respective firmware Develop and operationalise scenarios for social engineering campaigns, including setup of supporting infrastructure Prepare detailed reports showcasing project results, such as findings, exploitation procedures, associated risks, and mitigation recommendations Contribute to the creation of supporting materials for client meetings and present technical topics to various client stakeholders from functions such as security, risk, IT or business Stay current with emerging security threats, vulnerabilities, and industry best practices, and promote continual learning within the team Configure and update penetration testing solutions and supporting infrastructure, to ensure optimal performance and security
Skills and attributes for success
Proven experience in penetration testing and offensive security practices, with a minimum of 3 years of related work experience Strong knowledge of automation tools and processes, particularly in the context of offensive security and application security Excellent problem-solving skills and the ability to manage multiple security projects simultaneously Effective communication skills to liaise with clients and internal stakeholders, translating complex technical concepts into understandable terms Proficiency in scripting languages (e.g., Python, Bash, PowerShell) Advanced knowledge of major operating systems Bachelor’s degree, ideally in computer science, information technology, cybersecurity, electrical engineering or a related field Certifications such as OSCP, GPEN, GWAPT, GXPN, CSSLP
What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
Get free certifications and enjoy national & international training. Get extra vacation days when public holidays fall on a weekend. Join an EY Community and practice your hobby with your colleagues off-work. Get plenty of discounts, perks and medical coverage. Free access to Udemy, EY Badges Bookster library Medical subscription for employees and family members (wife/husband/children) Life & accident insurance EAP – Employee Assistance Program - Short term confidential counselling services for you and those who live with you.
Are you ready to shape your future with confidence? Apply today.
To help create the best experience during the recruitment process, please describe any disability-related adjustments or accommodations you may need.
#LI-Hybrid
Code: C
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.