The opportunityAs a Red Team Operator within the Attack Surface Management team, you will emulate advanced threat actors through offensive security testing and adversary emulation. You will identify vulnerabilities, demonstrate business and operational risks, and provide actionable recommendations to improve defenses.
Your key responsibilities- Plan, execute, and lead red team operations and adversary emulation, including reconnaissance, initial access, execution, persistence, lateral movement, exfiltration, and impact.
- Conduct advanced penetration testing across environments: external/internal networks, web/cloud applications, APIs, Active Directory, identity systems, and hybrid/cloud infrastructures.
- Perform social engineering (e.g., phishing) as part of integrated engagements.
- Identify, validate, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business risks.
- Collaborate in Purple Team exercises with defensive teams to improve detection, response, and resilience.
- Produce high-quality deliverables: detailed technical reports, executive summaries, risk assessments, and remediation recommendations.
- Mentor junior team members, provide technical oversight, and contribute to methodology improvements and tooling (e.g., custom exploits, automation scripts).
- Stay current with emerging threats, TTPs, exploits, and defensive countermeasures through research, conferences, and self-development.
Skills and attributes for success- Deep expertise in offensive security tools and frameworks (e.g., Metasploit, Cobalt Strike / custom C2, Empire, BloodHound, Nmap, Burp Suite, and others).Demonstrated ability to thinking critically
- Strong knowledge of networking, operating systems (Windows/Linux), Active Directory, cloud platforms (AWS/Azure/GCP), web app security, and common protocols.
- Proficiency in scripting/programming (Python, PowerShell, Bash, etc.) for automation and custom tooling.
- Ability to translate complex technical findings into clear business risk language for executives and non-technical stakeholders.
- Ability to accurately build out attack paths and threat models relevant to current infrastructure and threat intelligence.
- Independently research and stay knowledgeable of Threat Actor TTP's and how they may be leveraged.
- Excellent analytical, problem-solving, and technical writing skills.
- Strong teamwork, independence, and communication skills.
To qualify for the role you must have- 6-8 years of hands-on experience in penetration testing, red teaming, or offensive security.
- Demonstrated experience executing red team or advanced penetration testing engagements.
- Relevant certifications including OSCP, CPTS (or equivalents such as GPEN, CRTO, OSEP, OSCE).
- Ability to work effectively in a fully remote environment.
Ideally, you'll also have- Experience with threat intelligence-driven adversary emulation (e.g., MITRE ATT&CK framework, TIBER-EU).
- Prior consulting or client-facing experience (where applicable).
- Knowledge of purple teaming, security operations (SOC), incident response, and detection engineering.
- Creation of, or contributions to open-source tools or projects, CTF participation, or public research/blogging.
What we look forWe are looking for a senior operator that can operate autonomously and bring new, strategic approaches to discovering and evaluating the firm's attack surface to improve the overall security posture. We are seeking a seasoned operator to improve the organization's ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.
What we offer youThe compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
- We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $128,100 to $239,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $153,800 to $272,300. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
- Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today. EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.