Jobiglo

No results.

Senior Consultant – Penetration Testing & Purple Team (Hong Kong)

EY · Île de Hong Kong

New
Senior 🇬🇧 English
OSCP OSWE OSEP OSEE GPEN CRTO GXPN CRTP CRTE OWASP MITRE ATT&CK NIST ISO Burp Suite Nmap Metasploit Nessus Cobalt Strike BloodHound PowerShell TCP/IP DNS VPN firewalls cloud security Windows Linux Active Directory EDR DLP UEBA SIEM SOAR SQL Python

Job description

About the role

Join EY's Technology Risk and Cyber Team and become a key player in defending against cyber threats. As a Senior Consultant, you will work with top‑tier talent in a collaborative environment, tackling complex cybersecurity challenges and simulating real‑world cyber‑attacks. You will guide clients to manage technology risks, comply with regulatory requirements, and strengthen their cybersecurity posture.

Key responsibilities

  • Conduct Technology Compliance Reviews for banking, wealth, asset management and insurance institutions across Hong Kong and the Greater Bay Area.
  • Deliver independent IT Risk Assurance audits of financial systems to ensure integrity and compliance.
  • Analyze IT environments, identify risks and evaluate controls (including cloud security) against regulatory requirements and best practices.
  • Perform vulnerability assessments and penetration testing to uncover security weaknesses.
  • Simulate real‑world cyber‑attacks to identify vulnerabilities and recommend improvements.
  • Review IT system architectures and configurations for security gaps.
  • Respond promptly to security incidents and support clients in breach recovery.

Required profile

  • Bachelor’s or Master’s degree in Information Security, Computer Science, Engineering or related fields.
  • 1‑4 years of experience in penetration testing, offensive security assessments or Purple Team engagements (consulting experience preferred).
  • Industry‑recognized certifications such as OSCP, OSWE, OSEP, OSEE, GPEN, CRTO, GXPN, CRTP or CRTE (or actively pursuing).
  • Strong knowledge of security frameworks and attack models (e.g., OWASP, MITRE ATT&CK, NIST, ISO).
  • Hands‑on experience with tools like Burp Suite, Nmap, Metasploit, Nessus, Cobalt Strike, BloodHound and PowerShell.
  • Understanding of TCP/IP, DNS, VPNs, firewalls and network protocols, as well as cloud security and secure development practices.
  • Familiarity with Windows and Linux environments, Active Directory attacks, lateral movement and persistence techniques.
  • Experience in incident response, threat hunting, malware analysis and digital forensics.

Required skills

  • OSCP, OSWE, OSEP, OSEE, GPEN, CRTO, GXPN, CRTP, CRTE certifications.
  • OWASP, MITRE ATT&CK, NIST, ISO frameworks.
  • Burp Suite, Nmap, Metasploit, Nessus, Cobalt Strike, BloodHound, PowerShell.
  • TCP/IP, DNS, VPN, firewalls, network protocols.
  • Cloud security, secure development practices.
  • Windows, Linux, Active Directory.
  • EDR, DLP, UEBA, SIEM, SOAR platforms.
  • SQL, Python (or other programming languages).

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec EY.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Hong Kong.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 4 days ago

Expires 1 month from now

16 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

EY

Île de Hong Kong