Ernst & Young

Cyber Strategy - Senior - Consulting

Ernst & Young$125K — $218K *
Business Services
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business, or related field; or a graduate degree with 2-4 years relevant experience.
  • 3-5 years of relevant experience in cybersecurity assessments, governance, and compliance.
  • Knowledge of cybersecurity frameworks such as NIST CSF and ISO 27001.
  • Strong analytical skills related to cybersecurity risks and controls.
  • Proficiency in Microsoft PowerPoint, Excel, and Word.

Responsibilities

  • Deliver cybersecurity strategy and transformation engagements for clients.
  • Conduct cybersecurity assessments and facilitate stakeholder interviews.
  • Analyze findings and translate insights into actionable recommendations.
  • Evaluate cybersecurity programs against industry standards and best practices.
  • Develop client deliverables, including presentations and reports.
  • Identify strategic improvement opportunities in clients' cybersecurity initiatives.
  • Collaborate with teams, support project management, and mentor junior staff.

Benefits

  • Comprehensive compensation and benefits package based on performance.
  • Flexible hybrid work model with in-person collaboration 40-60% of the time.
  • Flexible vacation policy to accommodate personal needs and circumstances.
  • Medical and dental coverage, pension, and 401(k) plans.
  • Time off for designated EY Paid Holidays, personal or family care, and other leaves when needed.
Full Job Description
Location: Anywhere in Country

The Opportunity

Organizations today face increasingly complex cybersecurity challenges driven by evolving threats, heightened regulatory expectations, cloud adoption, digital transformation, and emerging technologies. As a Senior Consultant within EY's Cyber Strategy practice, you will work with clients to evaluate cybersecurity programs, identify opportunities to strengthen risk management and governance, and develop practical strategies that support business objectives. This role offers the opportunity to work on complex engagements across multiple industries while developing deep expertise in cybersecurity strategy, governance, operating models, and transformation.

Your Key Responsibilities

As a Senior Consultant, you will play an active role in delivering cybersecurity strategy and transformation engagements while working closely with clients and EY engagement teams. You will support cybersecurity assessments, facilitate stakeholder interviews and workshops, analyze findings, and help translate insights into actionable recommendations. You will evaluate cybersecurity programs, governance structures, policies, operating models, and risk management capabilities against industry frameworks and leading practices. You will assist clients in identifying capability gaps, emerging risks, and strategic improvement opportunities, helping them prioritize initiatives that strengthen security while supporting business objectives.

In addition, as a Senior Consultant, you will contribute to the development of cybersecurity strategies, target operating models, governance frameworks, maturity assessments, and transformation roadmaps. You will prepare client deliverables, executive presentations, and reports, communicating complex concepts to both technical and non-technical audiences. You will collaborate with multidisciplinary teams to deliver high-quality work products, support project planning and management activities, mentor junior team members, and contribute to business development initiatives, thought leadership, and practice-building efforts.

Skills and Attributes for Success
  • Strong understanding of cybersecurity concepts, risk management principles, and industry trends.
  • Ability to analyze complex problems and develop practical, business-oriented recommendations.
  • Strong critical thinking, analytical, and problem-solving skills.
  • Ability to communicate effectively with both technical and business stakeholders.
  • Experience developing executive-level presentations, reports, and client-facing deliverables.
  • Strong verbal and written communication skills.
  • Ability to manage competing priorities in a fast-paced consulting environment.
  • Strong attention to detail and commitment to high-quality client service.
  • Ability to build relationships and collaborate effectively across teams and client organizations.
  • Demonstrated initiative, adaptability, and a commitment to continuous learning.


To Qualify for the Role, You Must Have
  • A bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, Business, Risk Management, or a related field, and approximately 3-5 years of relevant experience; or a graduate degree and 2-4 years of relevant experience.
  • Experience in one or more of the following areas:
    • Cybersecurity assessments and maturity evaluations
    • Cybersecurity governance, risk management, and compliance
    • Security strategy and roadmap development
    • Cybersecurity operating models and organizational design
    • Security policies, standards, procedures, and controls
    • Cybersecurity metrics, reporting, and program management
    • Regulatory and compliance assessments
    • Cybersecurity awareness and training programs
  • Knowledge of cybersecurity frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001/27002, CIS Controls, and PCI DSS.
  • Experience conducting research, assessments, and analysis related to cybersecurity risks and controls.
  • Strong Microsoft PowerPoint, Excel, and Word skills.
  • Willingness to travel based on client and business needs; travel estimated at 25-50%.


Ideally, You'll Also Have
  • Professional certifications such as CISSP, CISM, CRISC, CISA, Security+, or other relevant cybersecurity certifications.
  • Experience supporting NIST Cybersecurity Framework assessments, strategic transformation initiatives, or cybersecurity program modernization efforts.
  • Exposure to cybersecurity domains including Identity and Access Management, Security Operations, Vulnerability Management, Data Protection, Cloud Security, Third-Party Risk Management, or Zero Trust.
  • Experience facilitating client workshops, interviews, and collaborative working sessions.
  • Experience within a consulting, professional services, or advisory environment.
  • Knowledge of regulated industries such as healthcare, financial services, life sciences, government, or critical infrastructure.


What We Look For

We are seeking professionals who are curious, collaborative, and passionate about helping organizations strengthen cybersecurity and manage risk. Successful candidates combine strong analytical abilities with sound business judgment and can effectively engage with clients to solve complex challenges. The ideal candidate is motivated to learn, focused on delivering exceptional client service, and eager to contribute to the growth and success of both client organizations and EY's Cyber Strategy practice.

What we offer you
At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
  • We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $104,800 to $192,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Business Services Jobs

Find similar Cyber Strategy - Senior - Consulting jobs: