
Attack Surface and Exposure Validation Assistant Engineer
Ernst and Young20 days ago
Responsibilities
- Design and engineer automated attack-path discovery and validation capabilities.
- Build scalable vulnerability detection and verification pipelines using enterprise scanning sources and custom validation logic.
- Develop controlled exploitation and exploit-chaining workflows to demonstrate attacker outcomes safely.
- Engineer continuous offensive validation routines that require minimal human prompting.
- Combine Vulnerability Intelligence and Cyber Threat Intelligence to support detection and prioritization.
- Produce reproducible evidence, attack-path narratives, severity and exploitability rationale, compensating-control notes, and remediation recommendations.
- Partner with Red Team, Exposure Assessment, Threat Detection, and vulnerability-management stakeholders.
- Operate autonomously and contribute strategic approaches to reducing the organization’s attack surface.
Requirements
- At least 8 years of combined experience in vulnerability management, exposure management, offensive security, and security engineering.
- Experience analyzing vulnerability and security posture data.
- Deep understanding of attack paths, misconfigurations, and control failures that create material risk.
- Demonstrated ability to build scalable solutions for vulnerability and exposure challenges.
- Experience operating strategically while balancing technical depth with organizational risk context.
- Strong analytical skills for evaluating large volumes of data and influencing solution development.
- Excellent communication skills and comfort engaging senior stakeholders and security leadership.
- Ability to manage competing priorities and work independently in a complex, global environment.
- Preferred: experience leveraging AI to conduct exposure assessments.
- Expert attention to detail, critical thinking, creative problem-solving, flexibility, and experience augmenting offensive security.