
Security Analyst
Full Job Description
At EY, you will have the chance to build a career as unique as you are, with global scale, inclusive culture, and technology to become the best version of you. Join a global team of over 950 Information Security professionals who collaborate to protect EY and client information assets. You will work in the Technology Assurance, Risk, and Policy (TARP) function to develop and promote a holistic Governance, Risk, and Compliance (GRC) program aligned with global objectives and emerging cybersecurity threats.
The opportunity: A Senior Information Security Analyst will assist with one or more of the following areas:
- Develop comprehensive Information Security technical audit plans and schedules based on client demands, regulatory requirements, industry best practices, and organizational objectives.
- Maintain the firm's Information Security Management System (ISMS) and execute ISO 27001 activities, including risk assessments, monitoring frameworks, and remediation tracking.
- Train audit stakeholders on audit processes and advise on effective evidence collection.
- Support the firm's technology SQM program.
- Schedule and facilitate Information Security audits or penetration tests of varying complexity.
- Coordinate internal pre-assessments for external audits and certifications.
- Collaborate with internal stakeholders (IT, compliance, ET, CT) to align audit activities with organizational goals.
- Facilitate communication between internal stakeholders and third-party vendors regarding audit results, remediation efforts, and ongoing security requirements.
- Maintain accurate documentation of vulnerabilities, remediation plans, and risk mitigation strategies.
- Stay informed about emerging threats, attack vectors, and security vulnerabilities.
- Work collaboratively with other Information Security groups and external stakeholders across EY.
Skills and attributes for success:
- Network and/or application pen testing experience (a plus).
- In-depth knowledge of SOC2 Trust principles and ISO 27001 frameworks.
- Experience in participating complex information security audits and assessments.
- Good time management, interpersonal, communication, organizational, and decision-making skills.
- Experience responding to audits in a global environment.
- Excellent organizational and coordination abilities.
- Strong analytical skills with the ability to collect, organize, and analyze information.
- Ability to learn quickly and adapt to a fast-moving environment.
- Critical thinking skills.
- Strong time management skills.
To qualify for the role, you must have:
- 5 or more years of experience in an information security or technology audit field.
- Detailed understanding of assurance audits, certifications, and frameworks, including ISAE 3402, SOC1, SOC2, ISO 42001, and ISO 27001.
- Working knowledge of Network and Application Penetration testing and experience in communicating vulnerabilities to technical and non-technical audiences.
- Maintain awareness of the current security threat landscape.
- Ability to work collaboratively with various teams to understand processes and documentation requirements.
- Ability to deliver high-quality documentation with attention to detail.
- Ability to quickly grasp complex technical concepts and make them understandable in text and pictures.
- Strong communication and interpersonal skills.
- Must be a strong multi-tasker and prioritize duties.
- A Bachelor's or above in Information Technology or Cyber Security-related degrees.
- Experience performing security audits, penetration testing of networks or applications, or managing ISO 27001 and ISO 42001 implementations in a large firm.
- One of the following certifications or equivalent: CISSP, Certified Information Security Manager (CISM), Certified Information Security Auditor (CISA), Certified Internal Auditor (CIA), or Global Information Assurance Certification (GIAC) in a related area.
Ideally, you will also have:
Company
EY
EY is a global professional services firm helping to create a better working world. With over 150 countries represented, EY combines assurance, consulting, law, strategy, tax, and transactions to prov...