Full-Time

Penetration Testing Manager

Cyber Security

Posted on 10/17/2025

Ernst & Young

Ernst & Young

5,001-10,000 employees

Global professional services: consulting, assurance, tax

No salary listed

Bengaluru, Karnataka, India

In Person

US Top Secret Clearance Required

Category
IT & Security (1)
Required Skills
TCP/IP
PowerShell
Python
Java
Perl
Linux/Unix
Requirements
  • Graduates /BE / M Sc (Stats, Maths, Computer Science) / MBA with background in computer science and programming /MCA with minimum 8 years of work experience in penetration testing which includes internet, intranet, web application penetration tests, wireless, social engineering, and Red Team assessments.
  • Any two of the following certifications: CISSP, OSCP, OSWP, GPEN, GWAPT, OSCE, OSEE, GXPN Network Security certifications (C|EH, Security+, SANS, ISACA, product certifications).
  • Quality Management training/certification (e.g. ITIL, Six Sigma, TQM)
  • Knowledge of Windows, Linux, UNIX, any other major operating systems.
  • Deep understanding of TCP/IP network protocols.
  • Deep understanding and experience with various Active Directory attack techniques.
  • Understanding of network security and popular attacks vectors.
  • In-depth understanding of OWASP Top 10 vulnerabilities and their mitigation strategies. Experience with manual attack and penetration testing.
  • Experience with scripting / programming skills (e.g., Python, PowerShell, Java, Perl etc.).Updated and familiarized with the latest exploits and security trends.
  • Experience to lead a technical team to conduct remote and on-site penetration testing within defined rules of engagement.
  • Familiarity to perform network penetration testing in stealth manner.
  • Understanding of software security, network security, and information technology management technologies and principles
  • Knowledge of vulnerability management, patch management, and configuration management best practices.
Responsibilities
  • Lead engagements from kickoff with clients through scoping engagements, penetration testing and reporting while adhering to the agreed scope and deadlines.
  • Perform technical QAs for the penetration testing engagements which includes Network, web application, Mobile app (both Android & iOS), APIs Cloud Security, wireless, social engineering, physical penetration testing.
  • Lead penetration testing projects using the established methodology, tools and rules of engagements.
  • Execute red team assessments to highlight gaps impacting organizations security postures.
  • Identify and exploit security vulnerabilities in a wide array of systems in a variety of situations.
  • Drive in client conversations strategically.
  • Engage in handling escalations.
  • Be uptodate with all the latest Pentest techniques including emerging tech such as AI.
  • Perform in-depth analysis of penetration testing results and create report that describes findings, exploitation procedures, risks and recommendations.
  • Convey complex technical security concepts to technical and non-technical audiences including executives.
  • Confident with OWASP Top 10 and SANS Top 25 vulnerabilities and ability to effectively communicate methodologies and techniques with development teams.
  • Understanding and experience with Active Directory attacks.
  • Keeping up to date with Industry trends for Application security testing.
  • Knowledge of TCP/IP, OSI Layer, IPv4 & IPv6, Network Protocols and Wireless Communication skills preferred. Develop automated solutions that mitigate risks throughout the organization.
  • Ability to automate DAST/SAST solutions and reporting.
  • Support SDLC and agile environments with application security testing and source code reviews.
  • Serve as a mentor and guide to junior pen testers, sharing your knowledge, skills, and best practices to nurture their growth and development.
  • Provide technical expertise and guidance to clients on remediation strategies and security best practices.
  • Build strong internal relationships within EY Advisory Services and with other service lines across the organization.
Desired Qualifications
  • Project management skills
  • Certifications: CREST
  • Demonstrable flair for technical writing, including engagement reports, presentations and operating procedures

EY (Ernst & Young) provides professional services at a global scale, offering consulting, assurance, tax, and transaction advisory services. It serves clients across industries such as technology, media, real estate, hospitality, and construction. Instead of selling a single product, EY works with clients through tailored engagements where cross-disciplinary teams analyze challenges, design strategies, perform audits, help with tax planning, and assist with mergers or divestitures. What sets EY apart is its worldwide reach and integrated service model, industry-specific expertise, and focus on responsible business practices like sustainability, cybersecurity, and workforce flexibility. EY’s goal is to help organizations improve performance, manage risk, and achieve sustainable growth while building a better working world.

Company Size

5,001-10,000

Company Stage

N/A

Total Funding

N/A

Headquarters

Boston, Massachusetts

Founded

1991

Simplify Jobs

Simplify's Take

What believers are saying

  • ESG and sustainability services capture growing enterprise carbon tracking demand.
  • AI-driven consulting from whyaye acquisition expands high-margin advisory revenue.
  • Diverse entrepreneur network expansion opens mid-market consulting growth opportunities.

What critics are saying

  • NMC Health £2bn lawsuit alleges negligent audits from 2012-2018 period.[2]
  • SEC $100 million penalty for CPA exam cheating and evidence withholding.[1]
  • Super Micro Computer auditor resignation cites governance and transparency concerns.[4]

What makes Ernst & Young unique

  • Blockchain carbon tracking platform on Ethereum differentiates ESG advisory services.
  • whyaye acquisition strengthens AI and data analytics consulting capabilities.
  • Tony Jordan appointed Chief Ethics Officer signals governance and compliance focus.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Flexible Work Hours

Remote Work Options

Company News

Yahoo Finance
Apr 7th, 2026
EY deploys agentic AI across global audit practice with 2028 full rollout target

EY has deployed enterprise-scale agentic AI across its global assurance practice, integrating a multi-agent AI framework into EY Canvas, its audit technology platform. The system, built on Microsoft Azure, Microsoft Foundry and Microsoft Fabric, aims to help audit teams coordinate complex tasks and respond to risks more adaptively. The rollout follows extensive piloting and testing, with AI now embedded across all audit stages for engagements worldwide. EY expects the technology to underpin all end-to-end audit activities by 2028. The company says the platform will reduce administrative burdens on clients whilst enhancing risk evaluation and maintaining professional judgement. EY Global chair Janet Truncale described it as a "human-led, AI-powered audit of the future" designed to deliver greater value and insight for clients and stakeholders.

PR Newswire
Mar 26th, 2026
EY launches blockchain privacy sandbox to test zero-knowledge proof smart contracts

EY has launched the EY Blockchain Privacy Sandbox, a web-based development environment enabling organisations to experiment with privacy-preserving smart contracts on public Ethereum Virtual Machine-compatible blockchains. The sandbox uses Starlight, an open-source zero-knowledge proof compiler originally developed by EY and now in the public domain. The platform allows developers to transform standard Solidity smart contracts into privacy-preserving applications without requiring local setup, lowering technical barriers to zero-knowledge technology adoption. It includes sample projects that can be explored and modified to accelerate proof-of-concept development. Grand View Research projects the global zero-knowledge proof market will reach approximately $7.6 billion by 2033. The sandbox is designed for experimentation and validation, helping businesses assess feasibility before broader enterprise integration. The platform is now available via request.

The Associated Press
Mar 24th, 2026
Unilever and UK government back Kenya-India waste tech partnership to automate recycling

Kenyan waste management enterprise TakaTaka Ni Mali and India-based TrashCon have partnered to modernise Kenya's circular economy infrastructure through decentralised waste segregation technology. The collaboration was facilitated by TRANSFORM, an impact accelerator led by Unilever, the UK Government's FCDO, and EY. The partnership addresses implementation challenges of Kenya's Sustainable Waste Management Act (2022), which requires household waste separation. TrashCon's TrashBot technology automatically separates wet organic material from dry recyclables, creating safer conditions for waste workers whilst improving recovery rates. Urban waste collection in Kenya currently reaches only 20-30%. TakaTaka Ni Mali will serve as local reseller for TrashBot, supporting installation and maintenance whilst deploying its Ecomali digital traceability platform. The first TrashBot model will be showcased at Kenya International Investment Conference from 25-27 March, with two additional machines planned.

PR Newswire
Mar 18th, 2026
EY and 8090 launch AI-native software development platform claiming 70% productivity boost and 80x faster delivery

Ernst & Young LLP has launched EY.ai Product Development Lifecycle in partnership with 8090, introducing an AI-native approach to software development. The system, powered by 8090's Software Factory platform, uses AI agents with human oversight to deliver production-ready software in days or weeks rather than months. The framework addresses traditional development challenges including project failures and budget overruns. An EY US use case demonstrates a 70% increase in productivity and cost efficiency, with delivery speeds 80 times faster and over 95% automated test coverage. EY.ai PDLC will be deployed to tens of thousands of EY US consultants. The platform targets two key areas: legacy system modernisation and new product development. EY plans to expand the programme with additional technology partners over time.

Business Wire
Mar 17th, 2026
EY selects CrowdStrike and NVIDIA AI to power agentic SOC services

Ernst & Young LLP has selected CrowdStrike's Falcon platform to power its Agentic Security Operations Centre services, accelerated by NVIDIA AI infrastructure. The collaboration aims to help enterprises transform security operations using AI agents capable of responding to threats at machine speed. The partnership comes as average eCrime breakout time has dropped to 29 minutes, with the fastest observed attack occurring in just 27 seconds. CrowdStrike's agentic platform leverages NVIDIA's AI tools, including Nemotron models and NeMo microservices, to enable more accurate threat analysis and faster response times. The system includes AI-ready data layers, mission-ready agents trained on real response expertise, and Charlotte AI AgentWorks, which allows organisations to build custom agents without coding. The platform aims to address the challenge of analysts manually investigating the growing volume of security alerts.

INACTIVE