Senior Consultant – Penetration Testing & Purple Team (Hong Kong)
EY · Île de Hong Kong
Job description
About the role
Join EY's Technology Risk and Cyber Team and become a key player in defending against cyber threats. As a Senior Consultant, you will work with top‑tier talent in a collaborative environment, tackling complex cybersecurity challenges and simulating real‑world cyber‑attacks. You will guide clients to manage technology risks, comply with regulatory requirements, and strengthen their cybersecurity posture.
Key responsibilities
- Conduct Technology Compliance Reviews for banking, wealth, asset management and insurance institutions across Hong Kong and the Greater Bay Area.
- Deliver independent IT Risk Assurance audits of financial systems to ensure integrity and compliance.
- Analyze IT environments, identify risks and evaluate controls (including cloud security) against regulatory requirements and best practices.
- Perform vulnerability assessments and penetration testing to uncover security weaknesses.
- Simulate real‑world cyber‑attacks to identify vulnerabilities and recommend improvements.
- Review IT system architectures and configurations for security gaps.
- Respond promptly to security incidents and support clients in breach recovery.
Required profile
- Bachelor’s or Master’s degree in Information Security, Computer Science, Engineering or related fields.
- 1‑4 years of experience in penetration testing, offensive security assessments or Purple Team engagements (consulting experience preferred).
- Industry‑recognized certifications such as OSCP, OSWE, OSEP, OSEE, GPEN, CRTO, GXPN, CRTP or CRTE (or actively pursuing).
- Strong knowledge of security frameworks and attack models (e.g., OWASP, MITRE ATT&CK, NIST, ISO).
- Hands‑on experience with tools like Burp Suite, Nmap, Metasploit, Nessus, Cobalt Strike, BloodHound and PowerShell.
- Understanding of TCP/IP, DNS, VPNs, firewalls and network protocols, as well as cloud security and secure development practices.
- Familiarity with Windows and Linux environments, Active Directory attacks, lateral movement and persistence techniques.
- Experience in incident response, threat hunting, malware analysis and digital forensics.
Required skills
- OSCP, OSWE, OSEP, OSEE, GPEN, CRTO, GXPN, CRTP, CRTE certifications.
- OWASP, MITRE ATT&CK, NIST, ISO frameworks.
- Burp Suite, Nmap, Metasploit, Nessus, Cobalt Strike, BloodHound, PowerShell.
- TCP/IP, DNS, VPN, firewalls, network protocols.
- Cloud security, secure development practices.
- Windows, Linux, Active Directory.
- EDR, DLP, UEBA, SIEM, SOAR platforms.
- SQL, Python (or other programming languages).
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Hong Kong.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 4 days ago
Expires 1 month from now
17 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
EY
Île de Hong Kong
Related job offers
-
Implementation Consultant
TS Imagine Île de Hong Kong -
Production Engineer – End User Computing & Automation (Hong Kong)
BAH Partners Île de Hong Kong -
Senior Data Centre Operator – 24/7 Shift
The Hongkong Electric Co., Ltd. (HK Electric) Île de Hong Kong -
Analyste Support Production – Applications Front‑Office (H/F)
Shanthi Hong Kong -
Senior Engineer – Infrastructure Operations
EcoCeres Kowloon