Full-Time

Attack and Penetration Testing Manager

Consulting

Posted on 9/11/2026

Ernst & Young

Ernst & Young

5,001-10,000 employees

Global professional services: consulting, assurance, tax

Compensation Overview

$144.9k - $302.1k/yr

Houston, TX, USA

Remote

Remote within the United States; travel up to 50% domestically and internationally.

Bachelor's, Master's

Category
Cybersecurity (1)
Required Skills
TCP/IP
PowerShell
Python
LDAP
Microsoft Windows
Java
Cybersecurity
Vulnerability Analysis
Perl
Penetration Testing
Linux/Unix

Get referred to Ernst & Young

See people who can refer or advise you

Requirements
  • A bachelor's degree in Computer Science, Cybersecurity, Information Systems, Information Technology, Engineering or a related major with at least 6 years of related work experience, or a master's degree with approximately 3–4 years of related work experience in penetration testing.
  • Experience managing and executing penetration testing projects.
  • Experience with manual attack and penetration testing.
  • Experience establishing and managing red team or application penetration testing programs.
  • Scripting or programming skills, such as Python, PowerShell, Java, or Perl.
  • Current familiarity with the latest exploits and security trends.
  • Experience leading a technical team conducting remote and on-site penetration testing within defined rules of engagement.
  • Proficiency overseeing multiple attack and penetration testing projects simultaneously while meeting strict deadlines.
  • Familiarity with performing network penetration testing in a stealth manner.
  • Any two of the following certifications: OSCP, OSWP, GPEN, GWAPT, OSCE, OSEE, GXPN, CISSP, CISM, PMP, or CREST Certified Simulated Attack Manager.
  • A valid U.S. driver's license.
  • Willingness and ability to travel domestically and internationally to meet client needs.
Responsibilities
  • Identify potential threats and vulnerabilities in enterprise environments.
  • Lead technical teams conducting penetration testing, red team, and purple team exercises using industry frameworks and techniques.
  • Apply penetration testing analysis to inform and enhance other areas of cybersecurity.
  • Oversee delivery of offensive security engagements and ensure productive collaboration with security and business teams.
  • Ensure delivery of clear, concise, and actionable reports and support for technical and executive audiences.
  • Mentor senior and junior analysts and advance a collaborative, trust-based culture.
  • Develop ideas to enhance the team's skill sets and capabilities.
  • Stay current with emerging cyber threat trends and technologies and represent EY and the team in industry groups, conferences, and events.
  • Plan and execute internet, intranet, wireless, web application, cloud, social engineering, and physical penetration testing projects.
  • Develop and execute red team scenarios to identify gaps affecting organizational security postures.
  • Lead and mentor penetration testers by providing technical leadership and support for professional growth.
  • Perform in-depth analysis of penetration testing results and create reports describing findings, exploitation procedures, associated risks, and actionable recommendations.
  • Manage and execute penetration testing projects using the established methodology, tools, and agreed-upon rules of engagement.
Desired Qualifications
  • Knowledge of Windows, Linux, Unix, and other major operating systems.
  • Familiarity with the latest exploits, tactics, techniques and procedures, vulnerability remediation, and security trends in cloud implementations.
  • Ability to manage multiple projects and meet tight deadlines.
  • Deep understanding of the MITRE ATT&CK framework.
  • Engagement with the security community through research, CVE disclosures, bug bounty recognition, open-source contributions, blogging, publishing, and presenting research at cybersecurity conferences.
  • Deep understanding of TCP/IP network protocols.
  • Deep understanding and experience with Active Directory attack techniques.
  • Understanding of network security and common attack vectors.
  • Understanding of web application vulnerabilities, including the OWASP Top 10.
  • Experience developing harnesses and agentic workflows for offensive security.

EY (Ernst & Young) provides professional services at a global scale, offering consulting, assurance, tax, and transaction advisory services. It serves clients across industries such as technology, media, real estate, hospitality, and construction. Instead of selling a single product, EY works with clients through tailored engagements where cross-disciplinary teams analyze challenges, design strategies, perform audits, help with tax planning, and assist with mergers or divestitures. What sets EY apart is its worldwide reach and integrated service model, industry-specific expertise, and focus on responsible business practices like sustainability, cybersecurity, and workforce flexibility. EY’s goal is to help organizations improve performance, manage risk, and achieve sustainable growth while building a better working world.

Company Size

5,001-10,000

Company Stage

N/A

Total Funding

N/A

Headquarters

Boston, Massachusetts

Founded

1991

Get referred to Ernst & Young

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • EY's January 2026 acquisitions of couniq and Qiado expand public-sector and FAAS consulting.
  • EY's April 2026 agentic AI rollout strengthens audit quality and client delivery speed.
  • EY's Microsoft alliance and AI assurance services attract transformation work from regulated enterprises.

What critics are saying

  • EY paid £105.5 million over NMC Health in 2026, signaling recurring audit liability exposure.
  • KPMG, Deloitte, and PwC relentlessly poach EY partners after the failed 2021 split.
  • Agentic AI standardizes audit workflows by 2028, compressing billable hours and weakening junior leverage.

What makes Ernst & Young unique

  • EY Canvas embeds agentic AI across 160,000 audits with Microsoft Azure, Foundry, and Fabric.
  • EY-Parthenon ties consulting, assurance, tax, and transactions into one global client platform.
  • EY's sector teams, especially banking and capital markets, deepen specialization across regulated industries.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Flexible Work Hours

Remote Work Options

Company News

Yahoo Finance
Aug 31st, 2026
EY commits $100M to bonuses rewarding human skills alongside AI adoption

Ernst & Young's US division is allocating $100 million this fiscal year to bonus payments rewarding employees who demonstrate adaptability, innovation, and judgement. Individual spot awards reach $500, whilst employees or teams making significant contributions can receive between $10,000 and $25,000, five times the previous programme's ceiling. The initiative also covers AI experimentation. "What we recognise signals what we value," said Ginnie Carlier, chief talent and culture officer for EY Americas. The bonuses form part of a broader strategy to reshape employee development across all career levels. Other professional services firms are pursuing similar approaches. KPMG restructured its audit internship this summer to emphasise critical thinking, whilst PwC US introduced training combining AI proficiency with human qualities like empathy. EY reported AI-related revenue grew 30% year-over-year in 2025.

Consultancy.eu
Aug 28th, 2026
EY-Parthenon acquires Dutch digital strategy consultancy SparkOptimus

EY-Parthenon has acquired SparkOptimus, a Dutch digital strategy consultancy founded in 2010. The Amsterdam-based firm employs around 50 consultants and specialises in AI transformation, digital business model redesign and technology-driven transformation. SparkOptimus founders Alexandra Jankovich and Tom Voskes, both former McKinsey consultants, said joining EY-Parthenon will create significant value for clients and staff whilst providing access to broader capabilities. The acquisition marks EY-Parthenon's first European deal since 2021. EY-Parthenon, established in 2014, is EY's strategy consulting and transactions advisory business with around 25,000 professionals globally. Mark Reich, Partner at EY-Parthenon Netherlands, said SparkOptimus' expertise will complement existing capabilities in the Dutch market. The deal closes on 1 September 2026. Financial terms were not disclosed.

Yahoo Finance
Aug 18th, 2026
KPMG and EY win $579M UK civil servants training contract despite consultancy spending pledge

The UK Government has awarded a contract worth up to £456 million to KPMG and EY to train civil servants, the Financial Times reported, citing government procurement tracker Tussell. Under the arrangement, the firms will train officials across various skills areas, including AI, between 2026 and 2028. KPMG's share is capped at £319 million, representing almost a quarter of its total UK advisory net sales from last year. EY's portion is worth £137 million, equivalent to around 13% of its UK consulting revenue. The deal is the largest single contract awarded to Big Four companies since Tussell started tracking records in 2012. The previous record was a £322 million deal between the Foreign Office and PricewaterhouseCoopers in 2012.

Business Insider
Jul 30th, 2026
EY's 'invisible' AI router cuts token costs by 60% by directing queries to cheaper models

EY has introduced an "invisible" AI router to manage internal AI spending, helping cut token consumption by up to 60% since its April rollout. The router sits behind specialised AI tools and directs employee queries to the most appropriate model for each task, rather than defaulting to the most powerful option. Token costs have become a growing concern as AI providers increasingly charge based on usage. EY's AI Pulse survey found that 82% of senior leaders at companies investing in AI were worried about token usage. The router has been deployed on department-specific platforms, including tax and risk functions, though not on the general Microsoft Copilot chatbot available to all staff. EY has also implemented token budgets based on employees' roles and departments. The firm's global consulting AI leader Dan Diasio said companies should focus AI investment on areas with the deepest impact rather than spreading resources thinly.

Yahoo Finance
Jul 29th, 2026
FRC fines EY $1.5M over Made.com audit failures before 2022 collapse

The UK's Financial Reporting Council has fined EY nearly £1.2m and audit partner Julie Carlyle £49,000 for failings in their 2021 audit of Made.com. Both received severe reprimands for breaching international auditing standards regarding going concern and deferred tax assets. The FRC said the auditors relied on management forecasts without sufficient challenge or adequate testing. Made.com, an online furniture retailer that listed on the London Stock Exchange in June 2021, entered administration in November 2022 after reporting a £35.3m loss. EY later disclaimed its opinion on Made.com's 2022 interim statements due to material uncertainty about the company's ability to continue operating.