Ernst & Young

Cybersecurity - Financial Services (FSO) - Senior Consultant

Ernst & Young$90K — $136K *
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of hands-on experience in cybersecurity assessments and advisory roles.
  • Proven ability to lead workstreams independently from data gathering to reporting.
  • Strong knowledge of cybersecurity frameworks and their application to reality.
  • Broad cybersecurity understanding with deep expertise in at least two domains, alongside familiarity across multiple others.
  • Experience in conducting interviews and presentations for both technical and executive audiences.
  • Excellent analytical skills for deriving conclusions from complex and varied data.
  • Strong written communication abilities for creating executive-level reports and presentations.

Responsibilities

  • Own cybersecurity assessment domains through planning and reviewing documentation.
  • Translate cybersecurity frameworks into client-specific assessment criteria.
  • Evaluate existing cybersecurity policies and practices to understand current states.
  • Lead workshops and interviews with cybersecurity stakeholders.
  • Challenge unsupported assertions and validate findings through targeted questioning.
  • Synthesize information to produce coherent maturity assessments and improvement recommendations.
  • Prepare and present high-quality, executive-ready materials to client leadership.

Benefits

  • Comprehensive medical, dental, and drug coverage.
  • Robust mental health and Employee Assistance Program.
  • Generous paid time off including vacation and personal days.
  • Access to exclusive learning and career development programs.
  • Opportunities for community engagement through volunteering initiatives.
Full Job Description
We are seeking a Senior Consultant to support the delivery of enterprise cybersecurity assessments. This role combines cybersecurity advisory, structured assessment, stakeholder engagement, analytical judgment, and executive reporting. The successful candidate will independently own assigned cybersecurity domains, assess the maturity of relevant capabilities, and translate complex technical and operational information into clear findings and practical improvement recommendations.

The opportunity

The Senior Consultant will work with large, complex organizations to evaluate how effectively cybersecurity capabilities are designed, implemented, governed, measured, automated, and sustained. The role is broader than compliance mapping or control testing. It requires the ability to understand how people, process, technology, governance, and risk considerations work together across an enterprise cybersecurity program.

This job posting relates to an existing vacancy within our organization.

Key responsibilities
  • Own assigned cybersecurity domains through assessment planning, artifact requests, document review, stakeholder workshops, maturity analysis, quality review, and reporting.
  • Translate framework outcomes and other industry guidance into practical, capability-based assessment criteria appropriate to the client environment.
  • Review policies, standards, procedures, operating models, architectures, inventories, metrics, reports, and technical documentation to understand the current state.
  • Plan and facilitate interviews and workshops with cybersecurity leaders, architects, engineers, risk teams, and control or capability owners.
  • Ask targeted follow-up questions, appropriately challenge unsupported statements, and identify where further validation is required.
  • Synthesize stakeholder input, artifacts, metrics, and technical context into consistent and defensible maturity conclusions.
  • Draft concise current-state observations, maturity rationales, opportunities for improvement, risk implications, and practical recommendations.
  • Connect detailed domain findings to broader themes, business impacts, target-state considerations, and prioritized improvement actions.
  • Prepare clear, executive-ready materials and support presentations to client leadership.
  • Guide Consultants, review draft analyses and workpapers, maintain consistency across domains, and escalate issues early.
  • Contribute to the refinement of assessment methodologies, capability libraries, reporting approaches, and reusable intellectual property.


To qualify for the role you must have
  • Hands-on experience delivering cybersecurity maturity, capability, risk, controls, assurance, or transformation assessments.
  • Demonstrated ability to independently lead a workstream or assessment domain from information gathering through final reporting.
  • Working knowledge of common cyber and IT frameworks, with the ability to explain how framework outcomes apply to real cybersecurity capabilities and operating environments.
  • Broad understanding across multiple cybersecurity domains, with meaningful depth in at least two or three areas.
  • Experience facilitating stakeholder interviews or workshops and communicating with both technical practitioners and senior leaders.
  • Strong analytical judgment, including the ability to form supportable conclusions from incomplete, varied, or conflicting information.
  • Excellent written communication skills, including findings, recommendations, presentations, and executive summaries.
  • Ability to manage multiple domains, stakeholders, and deliverables while maintaining quality and consistency.
  • Experience coaching junior team members and reviewing their work.


Ideally, you'll also have
  • Experience applying NIST CSF 2.0, including Functions, Categories, Subcategories, Current Profiles, and Target Profiles.
  • Familiarity with NIST SP 800-53, CIS Controls, ISO/IEC 27001 and 27002, COBIT, CRI Profile, CSA CCM, or related cyber-risk frameworks.
  • Experience in banking, insurance, payments, or another highly regulated and federated enterprise environment.
  • Familiarity with Canadian financial-services expectations such as OSFI B-13 or other relevant regulatory guidance.
  • Experience developing maturity models, target states, cyber roadmaps, benchmarking insights, or transformation recommendations.
  • Relevant cybersecurity or risk certification such as CISSP, CISM, CRISC, CISA, ISO 27001, CCSP, or equivalent credential. Certifications are considered supporting qualifications rather than a substitute for practical delivery experience.


Cybersecurity domain coverage

Candidates are not expected to be specialists in every domain. The strongest profiles will demonstrate depth in selected areas and working fluency across several others.

Domain grouping

Illustrative areas

Governance and risk

Cyber governance, policy and standards, security metrics, second-line cyber risk, third-party risk, privacy

Identity and data

IAM, PAM, customer identity, data protection, data security, cryptography

Applications and engineering

Application security, API security, DevSecOps, secure software development, cloud security, AI security

Infrastructure and operations

Network security, endpoint security, vulnerability management, configuration management, asset management

Detection and resilience

Security operations, threat management, incident response, insider risk, forensics, disaster recovery, business continuity

What we look for

We're interested in intellectually curious people with a genuine passion for cybersecurity. If you have the confidence in both your presentation and technical abilities to grow into a leading expert here, this is the role for you.

What we offer you

The EY benefits package is designed to support your physical, emotional, financial, and social wellbeing. Our extensive benefits include comprehensive medical, dental, and prescription drug coverage, as well as mental health benefits, a robust Employee Assistance Program and group savings plans to promote your overall wellbeing. We offer generous time off, including personal days, vacation days, and additional firm-wide holidays, along with the option to purchase extra vacation days. Employees can take advantage of EY's exclusive learning programs tailored just for them. We also provide internal opportunities for career development and advancement, enabling you to grow within the firm. Get involved in meaningful volunteering through EY Ripples and make a positive impact in the community.

EY reports salary ranges in accordance with applicable provincial pay transparency legislation. Individual salaries within the anticipated salary ranges noted below are determined through a wide variety of factors including but not limited to internal equity, education, relevant experience, knowledge, and applicable skill sets.
  • Toronto/Calgary/Vancouver/Edmonton/Montreal: $90,000 to 136,000 per year


Are you ready to shape your future with confidence? Apply today.

To help create the best experience during the recruitment process, please describe any accommodations you may need.

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Finance & Insurance Jobs

Find similar Cybersecurity - Financial Services (FSO) - Senior Consultant jobs: