Security Analyst, EY

September 7, 2026

Apply for this job

Email *
Executive Name *

Job Description

Security Analyst is a role within EY that aims to support information security assurance, application security assessment, vulnerability detection, and cybersecurity efforts. It requires writing security review reports, researching new vulnerabilities and methods of attacks, and facilitating remediation actions in different technology environments. The role also entails conducting application security testing of different types of applications such as web applications, mobile apps, thick-client applications, wireless applications, and others with the use of various tools for security testing.

Experience: 1–6 years in application security assessment 

Apply: Click Here

Responsibilities

  • Provide well-documented reports on security reviews and offer valuable advice on how to address the discovered security issues.
  • Conduct research regarding application vulnerabilities, attack vectors, and threats in order to conduct security assessments.
  • Make sure that the configuration, management, and updating of vulnerability assessment tools are properly done to achieve accurate and effective security testing results.
  • Conduct application security testing in different technological settings such as web, thick client, mobile, wireless, etc.
  • Take part in security audits, improvement, and mentoring activities of the team.

 Qualifications

  • A Bachelor’s Degree or an equivalent in disciplines such as Information Technology, Computer Science, Cybersecurity, or related disciplines.
  • One year to six years of work experience in the domain of performing application security testing and vulnerability testing, among others.
  • Experience in performing manual and automated testing of applications in different technological environments.
  • Knowledge of network security, TCP/IP, secure coding, and application vulnerabilities and controls.
  • Strong analytical skills, problem-solving abilities, and multitasking skills.

Preferred Qualifications

  • Hands-on experience working with software like Burp Professional, Nmap, Wireshark, Nessus, Qualys WAS, WebInspect, Checkmarx, and WhiteSource.
  • Hands-on experience testing applications for security on different platforms including mobile applications on the Android & iOS platforms.
  • Coding and/or scripting experience in any programming language like C/C++, C#, Java, ASP.NET, Perl, or Python.
  • Certifications in security domain like CEH, OSCP, CISSP, CISM, and CISA for professional skills and knowledge enhancement.
  • Hands-on experience with testing AI-integrated projects and manual code review.