Pubblicato il 20 maggio
Mansioni della posizione
Overview
Se le sue competenze, la sua esperienza e le sue qualifiche corrispondono a quelle descritte in questa panoramica, non ritardi l'invio della sua candidatura.
Junior Consultant Offensive Security – Milano or Bari. In EY, you will contribute to projects focused on Vulnerability Assessment and Penetration Testing (VA/PT) of IT infrastructures, applications, and cloud environments for clients across industries. You will work in structured teams, closely with senior professionals, to assess client security posture and support remediation initiatives.
Responsibilities
Execute Vulnerability Assessment and Penetration Testing on: web and mobile applications, APIs, on-premise and cloud infrastructures, Windows/Linux environments, and Active Directory.
Perform manual testing to validate identified vulnerabilities.
Identify misconfigurations, logical vulnerabilities, and exploitation techniques.
Assess real business risk impact of vulnerabilities.
Contribute to technical reports, including exploit evidence, risk assessment, and remediation recommendations.
Present results to clients and support remediation activities.
Collaborate with Red Team / Blue Team / Threat Intelligence on integrated initiatives (e.g., Purple Team, Adversary Simulation).
Contribute to continuous improvement of VA/PT methodologies, tools, and best practices.
What we look for
Academic background in computer science or a related field.
At least 1 year of professional experience in VA/PT, preferably in a consulting context.
Knowledge of key networking protocols (TCP/IP, DNS, HTTP, SMTP, SMB, etc.).
Familiarity with Windows, Linux, and Unix operating systems.
Strongly desirable experience with penetration testing techniques and tools (e.g., Metasploit, Cobalt Strike, Burp Suite, Nmap, BloodHound).
Ability to write scripts in Python, Bash, or PowerShell to support offensive activities is highly valued.
Certifications in offensive security (e.g., OSCP, eWPT, eCPPT, CRTP, CRTO or equi