FSO Consulting – Technology Risk – Penetration Testing & Purple Team – Senior Consultant/Consultant – Hong Kong
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
The Opportunity
Technology compliance, licensing, governance setup, massive data storage and related privacy security, virtual asset management, and resilience of the business require rigorous technology risk measures to safeguard the crown jewels and comply with regulatory requirements. support businesses to identify and manage risks while enhancing their agility.
Join EY's Technology Risk and Cyber Team and become a key player in defending against cyber threats. As a Senior Consultant, you will work with top-tier talent in a collaborative environment, tackling complex cybersecurity challenges and simulating real-world cyber-attacks. At EY, you will also guide clients to manage technology risks, comply with regulatory requirements, and strengthen their cybersecurity posture. You will apply your technical skills to help businesses identify and manage risks while enhancing their agility.
Your key responsibilities
Under the leadership of the project manager, you will:
- Conduct Technology Compliance Reviews: Assess institutions in banking, wealth and asset management, and insurance across Hong Kong, the Greater Bay Area, and other regions.
- IT Risk Assurance: Deliver quality, independent audits of financial systems to ensure integrity and compliance.
- Risk Analysis & Controls Evaluation: Analyze IT environments, identify risks, and evaluate controls (including cloud security) according to regulatory requirements and industry best practices.
- Vulnerability Assessment & Penetration Testing: Perform in-depth vulnerability scans and penetration tests to uncover security risks.
- Cyber-Attack Simulation: Simulate real-world attacks to identify vulnerabilities and recommend cybersecurity improvements.
- IT System Architecture Review: Evaluate IT system architectures and configurations.
- Incident Response: Respond promptly to security incidents and support clients in managing and recovering from breaches.
What we look for
- A Bachelor’s degree or Master’s degree preferably in one of the following areas: Information Security, Information Systems, Computer Science, Engineering, and other related majors.
- 1-4 years of relevant experience in penetration testing, offensive security assessments, or Purple Team engagements (consulting experience preferred).
- Industry-recognized certifications such as OSCP, OSWE, OSEP, OSEE, GPEN, CRTO, GXPN, CRTP, CRTE, or equivalent. Candidates who are actively pursuing these certifications are also encouraged to apply.
- Strong knowledge of security frameworks, protocols, and attack vectors (e.g., OWASP, MITRE ATT&CK, NIST, ISO).
- Experience with vulnerability assessment and penetration testing tools (e.g., Burp Suite, Nmap, Metasploit, Nessus, Cobalt Strike, BloodHound, PowerShell).
- Understanding of TCP/IP, DNS, VPNs, firewalls, and network protocols.
- Strong knowledge of cloud security, secure development practices, and crafting/red teaming offensive infrastructure.
- Familiarity with Windows and Linux environments, including Active Directory attacks, lateral movement, and persistence techniques.
- Experience in incident response, threat hunting, and malware analysis.
- Familiarity with security event analysis, incident response, and computer forensics tools.
- Experience in bypassing modern defensive controls (e.g., EDRs, network defenses, email filters).
- Experience in performing digital forensics and incident response analysis (e.g., network, application/log analysis, disk forensics, memory forensics, malware analysis, cloud forensics, endpoint forensics). Expert knowledge of common security tools (including EDR, DLP, UEBA, SIEM, SOAR, and other related forensics platforms) is a plus.
- Knowledge of SQL, Python or other programming languages would be considered as an advantage
- Candidates with less experience may be considered for the Consultant role
What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
Are you ready to shape your future with confidence? Apply today.
To help create an equitable and inclusive experience during the recruitment process, please inform us as soon as possible about any disability-related adjustments or accommodations you may need.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.