2,061 Security Consultant jobs in the United States
Security Consultant

Posted 1 day ago
Job Viewed
Job Description
Together, we are enhancing the quality of life globally through design.
Join us and design your place with Stantec.
Your Opportunity
The Security Designer performs basic technical and project management duties under the supervision of a Senior Security Consultant or Project Manager. Understands and identifies project requirements and performs independent technical work on basic tasks within one's own discipline. Provides guidance to Production Coordinator on completion of duties.
Your Key Responsibilities
- Develops basic system designs for Access Control, Video Surveillance, Intrusion Detection, and Intercom systems under minimal supervision; this includes the ability to offer solutions to general technical problems.
- Works in conjunction with senior project engineer to prepare project deliverables per the client's intent and scope of work outlined in Stantec's proposal.
- Follows Stantec's quality management process; reviews project deliverables prior to submission to QA/AC reviewer.
- Actively participates in the engineering/Professional community to build personal knowledge and professional growth (e.g. attend meetings / seminars / conferences.)
- Performs duties to assist the project manager as follows:
- Gives input or creates plans to complete tasks within the project timeline and budget, identifies required precursors from other disciplines in a timely fashion.
- Meets or exceeds utilization goals and adheres to project budget.
- Identifies and reports potential roadblocks and competing client and co-worker priorities that may inhibit the ability to maintain the project scope, schedule, and budget.
Your Capabilities and Credentials
- Possess basic knowledge of engineering practices within the physical security discipline.
- Knowledge of commonly used and accepted design and construction concepts, practices, procedures.
- Able to read, analyze, and interpret technical documents and specifications, technical procedures, and government regulations.
- Proficient in applicable software (i.e. CAD and REVIT).
- Exhibits strong communication skills to confidently interact and communicate scope and coordinate tasks with vendors and inter-discipline co-workers.
- Displays effective organization and time management skills with projects, reports and other duties; effectively manages multiple priorities and is punctual and dependable.
Education and Experience
- Experience with transportation distribution facilities a plus
- Accredited engineering degree or equivalent experience required.
- Minimum 2 years related industry experience.
- ASIS Associate Protection Professional (APP) / Physical Security Professional (PSP) / or other professional certification based on area of expertise preferred.
This description is not a comprehensive listing of activities, duties or responsibilities that may be required of the employee and other duties, responsibilities and activities may be assigned or may be changed at any time with or without notice.
About Stantec
Stantec is a global leader in sustainable engineering, architecture, and environmental consulting. The diverse perspectives of our partners and interested parties drive us to think beyond what's previously been done on critical issues like climate change, digital transformation, and future-proofing our cities and infrastructure. We innovate at the intersection of community, creativity, and client relationships to advance communities everywhere, so that together we can redefine what's possible.
**Pay Range:**
- Locations in CO, HI, IL, MD & Various CA, NJ Areas - Min Salary $ 76,600.00 - Max Salary $ 111,000.00
**Pay Transparency:** In compliance with pay transparency laws, pay ranges are provided for positions in locations where required. Please note, the final agreed upon compensation is based on individual education, qualifications, experience, and work location. At Stantec certain roles are bonus eligible.
**Benefits Summary:** Regular full-time and part-time employees (working at least 20 hours per week) have access to medical, dental, and vision plans, a wellness program, health saving accounts, flexible spending accounts, 401(k) plan, employee stock purchase program, life and accidental death & dismemberment (AD&D) insurance, short-term/long-term disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage and paid family leave. Regular full-time and part-time employees will receive ten paid holidays in each calendar year. In addition, employees will be eligible to accrue vacation between 10 and 20 days per year and eligible for paid sick leave (and if more generous, in accordance with state and local law).
Temporary/casual employees have access to 401(k) plans, employee stock purchase program, and paid leave, in accordance with state and local law.
The benefits information listed above may not apply to union positions because benefits for such positions are governed by applicable collective bargaining agreements
**Primary Location:** United States | IL | Chicago
**Organization:** 2805 Buildings-US Central & South BSS-Chicago IL
**Employee Status:** Regular
**Travel:** No
**Schedule:** Full time
**Job Posting:** 09/07/2025 10:07:12
**Req ID:** 1001423
Stantec provides equal employment opportunities to all qualified employees and applicants for future and current employment and prohibit discrimination on the grounds of race, colour, religion, sex, national origin, age, marital status, genetic information, disability, sexual orientation, gender identity or gender expression. We prohibit discrimination in decisions concerning recruitment, hiring, referral, promotion, compensation, fringe benefits, job training, terminations or any other condition of employment. Stantec is in compliance with laws and regulations and ensures equitable opportunities in all aspects of employment. At Stantec we are committed to ensuring our recruitment process is accessible to all. If you require reasonable adjustments to be made during the recruitment process then please inform a member of our Talent Acquisition team.
Security Consultant

Posted 1 day ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
You are seeking a position that allows you to demonstrate your information security skills, experience and ability to solve complex problems. This position is an opportunity to embed information security in a strategic investment by the EY Tax practice that is intended to enable innovation and disruptive new services:
**Your key responsibilities**
This position is a leading and consulting role in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires detailed participation in the design, implementation and certification of security controls across the multiple projects/applications. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. Also, should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
The position requires being able to work remotely and will leverage EY's collaboration tools such as Teams, SharePoint, and AzureDevOps.
**Skills and attributes for success**
Significant working security experience and knowledge in the design, implementation and operation of security controls in one of the following areas:
+ Agile & DevOps Methodologies - Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
+ Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture.
+ Security scanning tools - Experience in SAST & DAST scanning tools, network sniffers, Burpsuite etc. Work closely with our internal PEN testing team to identify the vulnerabilities and analyze these findings with our security controls.
+ Cloud Security -Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud-based solutions in Microsoft Azure Google GCP, Amazon AWS and other vendors.
+ Infrastructure Security - Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
+ Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
**To qualify for the role, you must have 5 years of experience in:**
+ Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions.
+ In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards.
+ Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements.
+ Knowledge of GRC tool to work closely with Compliance team on handling remediation plans of security related issues.
+ A degree in Computer Science or a related field.
+ Security certifications
+ Excellent communication skills, English speaking and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
**Ideally, you'll also have**
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
+ Operational Security - Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls.
+ Information Security Standards - Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA and CIS Controls.
+ Cloud security certifications such as AZ-300 Azure Architect Technologies, CISSP or security related certifications.
+ Product Management - working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support.
**What we look for**
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $38,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
Security Consultant

Posted 1 day ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
You are seeking a position that allows you to demonstrate your information security skills, experience and ability to solve complex problems. This position is an opportunity to embed information security in a strategic investment by the EY Tax practice that is intended to enable innovation and disruptive new services:
**Your key responsibilities**
This position is a leading and consulting role in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires detailed participation in the design, implementation and certification of security controls across the multiple projects/applications. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. Also, should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
The position requires being able to work remotely and will leverage EY's collaboration tools such as Teams, SharePoint, and AzureDevOps.
**Skills and attributes for success**
Significant working security experience and knowledge in the design, implementation and operation of security controls in one of the following areas:
+ Agile & DevOps Methodologies - Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
+ Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture.
+ Security scanning tools - Experience in SAST & DAST scanning tools, network sniffers, Burpsuite etc. Work closely with our internal PEN testing team to identify the vulnerabilities and analyze these findings with our security controls.
+ Cloud Security -Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud-based solutions in Microsoft Azure Google GCP, Amazon AWS and other vendors.
+ Infrastructure Security - Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
+ Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
**To qualify for the role, you must have 5 years of experience in:**
+ Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions.
+ In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards.
+ Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements.
+ Knowledge of GRC tool to work closely with Compliance team on handling remediation plans of security related issues.
+ A degree in Computer Science or a related field.
+ Security certifications
+ Excellent communication skills, English speaking and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
**Ideally, you'll also have**
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
+ Operational Security - Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls.
+ Information Security Standards - Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA and CIS Controls.
+ Cloud security certifications such as AZ-300 Azure Architect Technologies, CISSP or security related certifications.
+ Product Management - working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support.
**What we look for**
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $38,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
Security Consultant

Posted 1 day ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
You are seeking a position that allows you to demonstrate your information security skills, experience and ability to solve complex problems. This position is an opportunity to embed information security in a strategic investment by the EY Tax practice that is intended to enable innovation and disruptive new services:
**Your key responsibilities**
This position is a leading and consulting role in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires detailed participation in the design, implementation and certification of security controls across the multiple projects/applications. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. Also, should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
The position requires being able to work remotely and will leverage EY's collaboration tools such as Teams, SharePoint, and AzureDevOps.
**Skills and attributes for success**
Significant working security experience and knowledge in the design, implementation and operation of security controls in one of the following areas:
+ Agile & DevOps Methodologies - Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
+ Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture.
+ Security scanning tools - Experience in SAST & DAST scanning tools, network sniffers, Burpsuite etc. Work closely with our internal PEN testing team to identify the vulnerabilities and analyze these findings with our security controls.
+ Cloud Security -Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud-based solutions in Microsoft Azure Google GCP, Amazon AWS and other vendors.
+ Infrastructure Security - Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
+ Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
**To qualify for the role, you must have 5 years of experience in:**
+ Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions.
+ In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards.
+ Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements.
+ Knowledge of GRC tool to work closely with Compliance team on handling remediation plans of security related issues.
+ A degree in Computer Science or a related field.
+ Security certifications
+ Excellent communication skills, English speaking and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
**Ideally, you'll also have**
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
+ Operational Security - Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls.
+ Information Security Standards - Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA and CIS Controls.
+ Cloud security certifications such as AZ-300 Azure Architect Technologies, CISSP or security related certifications.
+ Product Management - working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support.
**What we look for**
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $38,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
Security Consultant

Posted 1 day ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
You are seeking a position that allows you to demonstrate your information security skills, experience and ability to solve complex problems. This position is an opportunity to embed information security in a strategic investment by the EY Tax practice that is intended to enable innovation and disruptive new services:
**Your key responsibilities**
This position is a leading and consulting role in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires detailed participation in the design, implementation and certification of security controls across the multiple projects/applications. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. Also, should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
The position requires being able to work remotely and will leverage EY's collaboration tools such as Teams, SharePoint, and AzureDevOps.
**Skills and attributes for success**
Significant working security experience and knowledge in the design, implementation and operation of security controls in one of the following areas:
+ Agile & DevOps Methodologies - Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
+ Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture.
+ Security scanning tools - Experience in SAST & DAST scanning tools, network sniffers, Burpsuite etc. Work closely with our internal PEN testing team to identify the vulnerabilities and analyze these findings with our security controls.
+ Cloud Security -Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud-based solutions in Microsoft Azure Google GCP, Amazon AWS and other vendors.
+ Infrastructure Security - Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
+ Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
**To qualify for the role, you must have 5 years of experience in:**
+ Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions.
+ In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards.
+ Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements.
+ Knowledge of GRC tool to work closely with Compliance team on handling remediation plans of security related issues.
+ A degree in Computer Science or a related field.
+ Security certifications
+ Excellent communication skills, English speaking and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
**Ideally, you'll also have**
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
+ Operational Security - Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls.
+ Information Security Standards - Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA and CIS Controls.
+ Cloud security certifications such as AZ-300 Azure Architect Technologies, CISSP or security related certifications.
+ Product Management - working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support.
**What we look for**
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $38,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
Security Consultant

Posted 2 days ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
You are seeking a position that allows you to demonstrate your information security skills, experience and ability to solve complex problems. This position is an opportunity to embed information security in a strategic investment by the EY Tax practice that is intended to enable innovation and disruptive new services:
**Your key responsibilities**
This position is a leading and consulting role in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires detailed participation in the design, implementation and certification of security controls across the multiple projects/applications. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. Also, should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
The position requires being able to work remotely and will leverage EY's collaboration tools such as Teams, SharePoint, and AzureDevOps.
**Skills and attributes for success**
Significant working security experience and knowledge in the design, implementation and operation of security controls in one of the following areas:
+ Agile & DevOps Methodologies - Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
+ Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture.
+ Security scanning tools - Experience in SAST & DAST scanning tools, network sniffers, Burpsuite etc. Work closely with our internal PEN testing team to identify the vulnerabilities and analyze these findings with our security controls.
+ Cloud Security -Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud-based solutions in Microsoft Azure Google GCP, Amazon AWS and other vendors.
+ Infrastructure Security - Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
+ Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
**To qualify for the role, you must have 5 years of experience in:**
+ Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions.
+ In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards.
+ Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements.
+ Knowledge of GRC tool to work closely with Compliance team on handling remediation plans of security related issues.
+ A degree in Computer Science or a related field.
+ Security certifications
+ Excellent communication skills, English speaking and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
**Ideally, you'll also have**
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
+ Operational Security - Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls.
+ Information Security Standards - Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA and CIS Controls.
+ Cloud security certifications such as AZ-300 Azure Architect Technologies, CISSP or security related certifications.
+ Product Management - working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support.
**What we look for**
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $38,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
Security Consultant

Posted 2 days ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
You are seeking a position that allows you to demonstrate your information security skills, experience and ability to solve complex problems. This position is an opportunity to embed information security in a strategic investment by the EY Tax practice that is intended to enable innovation and disruptive new services:
**Your key responsibilities**
This position is a leading and consulting role in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires detailed participation in the design, implementation and certification of security controls across the multiple projects/applications. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. Also, should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
The position requires being able to work remotely and will leverage EY's collaboration tools such as Teams, SharePoint, and AzureDevOps.
**Skills and attributes for success**
Significant working security experience and knowledge in the design, implementation and operation of security controls in one of the following areas:
+ Agile & DevOps Methodologies - Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
+ Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture.
+ Security scanning tools - Experience in SAST & DAST scanning tools, network sniffers, Burpsuite etc. Work closely with our internal PEN testing team to identify the vulnerabilities and analyze these findings with our security controls.
+ Cloud Security -Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud-based solutions in Microsoft Azure Google GCP, Amazon AWS and other vendors.
+ Infrastructure Security - Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
+ Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
**To qualify for the role, you must have 5 years of experience in:**
+ Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions.
+ In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards.
+ Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements.
+ Knowledge of GRC tool to work closely with Compliance team on handling remediation plans of security related issues.
+ A degree in Computer Science or a related field.
+ Security certifications
+ Excellent communication skills, English speaking and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
**Ideally, you'll also have**
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
+ Operational Security - Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls.
+ Information Security Standards - Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA and CIS Controls.
+ Cloud security certifications such as AZ-300 Azure Architect Technologies, CISSP or security related certifications.
+ Product Management - working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support.
**What we look for**
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $38,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
Be The First To Know
About the latest Security consultant Jobs in United States !
Security Consultant

Posted 3 days ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
You are seeking a position that allows you to demonstrate your information security skills, experience and ability to solve complex problems. This position is an opportunity to embed information security in a strategic investment by the EY Tax practice that is intended to enable innovation and disruptive new services:
**Your key responsibilities**
This position is a leading and consulting role in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires detailed participation in the design, implementation and certification of security controls across the multiple projects/applications. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. Also, should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
The position requires being able to work remotely and will leverage EY's collaboration tools such as Teams, SharePoint, and AzureDevOps.
**Skills and attributes for success**
Significant working security experience and knowledge in the design, implementation and operation of security controls in one of the following areas:
+ Agile & DevOps Methodologies - Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
+ Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture.
+ Security scanning tools - Experience in SAST & DAST scanning tools, network sniffers, Burpsuite etc. Work closely with our internal PEN testing team to identify the vulnerabilities and analyze these findings with our security controls.
+ Cloud Security -Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud-based solutions in Microsoft Azure Google GCP, Amazon AWS and other vendors.
+ Infrastructure Security - Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
+ Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
**To qualify for the role, you must have 5 years of experience in:**
+ Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions.
+ In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards.
+ Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements.
+ Knowledge of GRC tool to work closely with Compliance team on handling remediation plans of security related issues.
+ A degree in Computer Science or a related field.
+ Security certifications
+ Excellent communication skills, English speaking and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
**Ideally, you'll also have**
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
+ Operational Security - Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls.
+ Information Security Standards - Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA and CIS Controls.
+ Cloud security certifications such as AZ-300 Azure Architect Technologies, CISSP or security related certifications.
+ Product Management - working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support.
**What we look for**
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $38,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
Security Consultant

Posted 3 days ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
You are seeking a position that allows you to demonstrate your information security skills, experience and ability to solve complex problems. This position is an opportunity to embed information security in a strategic investment by the EY Tax practice that is intended to enable innovation and disruptive new services:
**Your key responsibilities**
This position is a leading and consulting role in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires detailed participation in the design, implementation and certification of security controls across the multiple projects/applications. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. Also, should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
The position requires being able to work remotely and will leverage EY's collaboration tools such as Teams, SharePoint, and AzureDevOps.
**Skills and attributes for success**
Significant working security experience and knowledge in the design, implementation and operation of security controls in one of the following areas:
+ Agile & DevOps Methodologies - Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
+ Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture.
+ Security scanning tools - Experience in SAST & DAST scanning tools, network sniffers, Burpsuite etc. Work closely with our internal PEN testing team to identify the vulnerabilities and analyze these findings with our security controls.
+ Cloud Security -Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud-based solutions in Microsoft Azure Google GCP, Amazon AWS and other vendors.
+ Infrastructure Security - Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
+ Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
**To qualify for the role, you must have 5 years of experience in:**
+ Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions.
+ In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards.
+ Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements.
+ Knowledge of GRC tool to work closely with Compliance team on handling remediation plans of security related issues.
+ A degree in Computer Science or a related field.
+ Security certifications
+ Excellent communication skills, English speaking and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
**Ideally, you'll also have**
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
+ Operational Security - Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls.
+ Information Security Standards - Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA and CIS Controls.
+ Cloud security certifications such as AZ-300 Azure Architect Technologies, CISSP or security related certifications.
+ Product Management - working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support.
**What we look for**
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $38,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
Security Consultant

Posted 3 days ago
Job Viewed
Job Description
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
You are seeking a position that allows you to demonstrate your information security skills, experience and ability to solve complex problems. This position is an opportunity to embed information security in a strategic investment by the EY Tax practice that is intended to enable innovation and disruptive new services:
**Your key responsibilities**
This position is a leading and consulting role in designing, developing and implementing all aspects of security for complex global applications based on Microsoft Azure technology and generally the Microsoft technology stack. The role is very much an individual contributor capable of supporting multiple project teams. In other words, it is not a program management or oversight role, but one that requires detailed participation in the design, implementation and certification of security controls across the multiple projects/applications. This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001, OWASP and related security standards. Also, should have knowledge of 3rd Party security assessments and applicability of SOC1 and SOC2 reports and concepts of vendor risk management.
The position requires being able to work remotely and will leverage EY's collaboration tools such as Teams, SharePoint, and AzureDevOps.
**Skills and attributes for success**
Significant working security experience and knowledge in the design, implementation and operation of security controls in one of the following areas:
+ Agile & DevOps Methodologies - Experience as a contributing member of a balanced team within an Agile development or DevOps environment.
+ Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture.
+ Security scanning tools - Experience in SAST & DAST scanning tools, network sniffers, Burpsuite etc. Work closely with our internal PEN testing team to identify the vulnerabilities and analyze these findings with our security controls.
+ Cloud Security -Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud-based solutions in Microsoft Azure Google GCP, Amazon AWS and other vendors.
+ Infrastructure Security - Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions.
+ Identity and Access Management - Active Directory based Identity and Access Management and Authorization design experience and integration with IDaaS and Federation technologies.
**To qualify for the role, you must have 5 years of experience in:**
+ Extensive experience in implementing, advising on, and consulting about security configurations across complex IT architectures, including cloud environments (primarily Microsoft's, but also including a range of IaaS, PaaS, and SaaS offerings from multiple vendors) and on-premises solutions.
+ In-depth knowledge of IT system architecture concepts and cloud technologies, along with associated technologies such as Identity and Access Management (IAM), network security, firewalls, software development best practices, systems auditing, system hardening, and other security principles as outlined in ISO27001, OWASP, and related security standards.
+ Proficiency in interpreting security reports (SAST and DAST) and testing outcomes for applications, providing advice on necessary corrections and security measures based on policies and non-functional requirements.
+ Knowledge of GRC tool to work closely with Compliance team on handling remediation plans of security related issues.
+ A degree in Computer Science or a related field.
+ Security certifications
+ Excellent communication skills, English speaking and the ability to collaborate with stakeholders ranging from developers and architects to business leaders and EY's clients.
**Ideally, you'll also have**
It is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
+ Operational Security - Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls.
+ Information Security Standards - Knowledge of common information security standards such as: ISO 27001/27002, NIST CSF, FEDRAMP, CSA and CIS Controls.
+ Cloud security certifications such as AZ-300 Azure Architect Technologies, CISSP or security related certifications.
+ Product Management - working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support.
**What we look for**
We are looking for individuals with a passion for information security and demonstrated ability to apply their knowledge to new and emerging technologies that are supporting the growth strategy of a global professional services firm.
**What we offer you**
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary ranges. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $76,400 to $38,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 91,700 to 157,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .