At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
Security Consultant
As an Information Security Consultant, the individual will be responsible for providing security guidance to projects and operations teams responsible for delivering, respectively maintaining, IT cloud-based solutions. The Consultant will support the entire system development lifecycle (SDLC) of business IT solutions with information security expertise and guidance. This includes performing a risk assessment of the solution and the underpinning cloud infrastructure in order to derive adequate risk treatment options, driving the security assurance activities with cloud vendors, specifying and prioritizing security requirements, directing the design of security controls, supervising the security attestation activities and effectively articulating all related findings, issues, recommendations to team members and management, assessing the security impact of change requests and providing the operations teams with related recommendations and decisions.
The successful candidate should have solid background in web services architecture and design, networking principles supporting hybrid cloud models, experience in applications development processes and methodologies (experience in agile application development and DevOps operations mode is strongly preferred), as well as oversight knowledge of infrastructure and hosting technologies leveraging virtualization and containerization. The successful candidate should have broad consulting or security assurance experience across all Information Security knowledge areas relevant to modern cloud-based architectures.
EY Technology:
Technology has always been at the heart of what we do and deliver at EY. We need technology to keep an organization the size of ours working efficiently. We have 250,000 people in more than 140 countries, all of whom rely on secure technology to be able to do their job every single day. Everything from the laptops we use, to the ability to work remotely on our mobile devices and connecting our people and our clients, to enabling hundreds of internal tools and external solutions delivered to our clients. Technology solutions are integrated in the client services we deliver and is key to us being more innovative as an organization.
EY Technology supports our technology needs through three business units:
Client Technology (CT) - focuses on developing new technology services for our clients. It enables EY to identify new technology-based opportunities faster, and pursue those opportunities more rapidly.
Enterprise Workplace Technology (EWT) – EWT supports our Core Business Services functions and will deliver fit-for-purpose technology infrastructure at the cheapest possible cost for quality services. EWT will also support our internal technology needs by focusing on a better user experience.
Information Security (Info Sec) - Info Sec prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and our information management systems.
The opportunity:
The Security Consultant reports to Deputy CISO of Enterprise Workplace Technology in a hands-on role, focused on the secure design, architecture and development for applications, which processes sensitive data and constitutes core as well as critical business services. The Security Consultant works directly with Architects, Developers, IAM engineers, Project Managers and other resources; through collaboration and mentoring, they help teams to deliver secure business solutions.
The Security Consultant’s role is a technical position which will support the global strategies and architecture vision as it relates to the development of secure design, build, deployment and operation of business applications and related infrastructure.
Your key responsibilities:
This position is an individual contributor capable of supporting multiple project teams in the design, implementation and validation of security controls across applications and services (incl. underpinning infrastructure and cloud hosting platform), as well as providing the operations teams with consultancy, reviews and decisions upon deployment of changes to existent operational services. The core responsibilities are as listed in the following.
Skills and attributes for success:
The position requires knowledge of various IT system architectures and technologies like cloud, virtualization, containerization, mobile, as well as expertise and experience in security subject matter areas such as IAM, network and perimeter security, web applications security, user account management, privileged access, auditing & logging, and others as outlined in ISO 27001, OWASP, NIST and related guidelines and standards. The consultant filling the position should also have experience in conduction of 3rd party security assessments, in particular within the scope of SOC1, SOC2 reports, and in vendor risk management.
A successful candidate should have significant security working experience and knowledge in the design, implementation and operation of security controls in any two or more of the following areas:
To qualify for the role you must have:
A BSc or MSc degree in Computer Science, Information Technology or a related discipline, or equivalent work experience, with preference towards advanced degrees.
Seven or more years of experience in Information Technology disciplines. Five or more years of experience in Information Security subject matter area with demonstrated experience in the following:
Ideally, you’ll also have:
What we look for:
What working at EY offers:
We offer a competitive remuneration package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well-being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer:
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.

EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams in more than 150 countries work across a full spectrum of services in assurance, consulting, tax, strategy and transactions, strengthened by sector experience and diverse ecosystem partners.
Find out more about the EY global network: http://ey.com/en_gl/legal-statement