
EY•1h ago
Naukri
Security Analyst
Bengaluru
Full Time
Mid Level
Full Job Description
At EY, you’ll join the Information Security team as an **Information Security Analyst** (Associate/Senior Associate) in Bengaluru, India. This role is ideal for professionals passionate about safeguarding data, systems, and applications in a dynamic, globally diverse environment. You’ll collaborate with a team of 950+ cybersecurity experts to implement robust security frameworks, conduct penetration testing, and ensure compliance with global standards like ISO 27001, SOC 1/2, and HITRUST. Your responsibilities will include:
- Performing detailed security reviews, vulnerability assessments, and remediation guidance for applications and networks.
- Researching and identifying new security threats, attack vectors, and application vulnerabilities (e.g., web, mobile, thick client, AI-integrated projects).
- Using manual and automated tools (e.g., Burp Suite, Nessus, Qualys WAS) to test security controls and ensure compliance with EY’s security standards.
- Supporting strategic initiatives, mentoring junior team members, and driving continuous improvement in security practices.
- Assisting in third-party audits (e.g., SOC 1/2, UK Cyber Essentials Plus) and regulatory compliance (e.g., ISQM) to protect EY’s brand and client trust.
- Collaborating with development teams to integrate secure coding principles (e.g., OWASP Top Ten) and conduct manual code reviews.
To succeed in this role, you should have:
- 1–6 years of experience in application security assessment, with hands-on experience in web, mobile, and network security testing.
- Proficient knowledge of manual and automated testing methodologies (e.g., Burp Suite, Wireshark, CheckMarx).
- Basic understanding of programming languages (C/C++, C#, Java, Python) and secure coding practices.
- Strong problem-solving skills, adaptability, and a passion for emerging cybersecurity trends.
- Excellent communication skills to collaborate with cross-functional teams.
Ideal candidates will also have:
- A degree in Information Technology, Cybersecurity, or a related field.
- Certifications like CEH, OSCP, CISSP, or CISA to enhance expertise.
- Experience with regulatory frameworks (e.g., SOC 2, HITRUST) and cloud security (e.g., M365 Teams apps).
Why EY?
EY offers a dynamic, flexible work environment with global opportunities, continuous learning, and a focus on well-being. You’ll work alongside leaders in cybersecurity, driving innovation while contributing to EY’s mission of building a better working world through trust, technology, and diversity.
Company
EY
EY (Ernst & Young) is a global professional services firm leading in assurance, consulting, tax, and advisory services. With over 150,000 employees across 150+ countries, EY empowers organizations to ...
Bengaluru
Posted on Naukri