via Indeed · 18 September 2026 ·1 day ago

UKI Technology Consulting - Application Penetration Tester, Senior Consultant / Assistant Manager

EY
DUBLIN 2 Full-time
This listing is from Indeed
View original listing ↗

Location: Dublin 2
Other locations: Primary Location Only
Salary: Competitive
Date: Sep 14, 2026
Job description
-------------------

Requisition ID: 1744530
At EY, we’re all in to shape your future with confidence.

We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.

General Information

Location: Dublin

Available for Work Visa Sponsorship: NO

Business Area: Cyber Security

Contract Type: Full\-Time – Permanent

EY’s Cyber Security practice is one of the fastest growing areas of the business with an immediate requirement for security consultants with a diverse range of skills and experience. As a leader on our Cyber team you will be providing advisory and technical leadership to help our clients improve their cyber security posture to respond to the dynamic Cyber Security threats. You will provide security domain expertise and utilise your business insight to work closely with our clients to advise, design, build, deploy and test pragmatic security solutions that will give real and tangible benefits and security enhancement.

The opportunity

You will be a lead member of a highly skilled and rapidly growing team of Technical Security specialists. Your role will consist of leading and supporting global penetration testing and offensive security teams and carrying out offsite and onsite penetration tests and vulnerability assessments against a wide range of systems and environments, in addition to advancing red teaming and DevSecOps capabilities. As a member of the team, you will have the opportunity to grow your career in leading the delivery of penetration testing and offensive security, with a significant opportunity for leadership experience and career progression.

Skills and Knowledge for this role include:

Strong hands\-on experience performing structured web application penetration tests across large and complex applications, including estates with hundreds of URLs, routes or functional components.

Strong hands\-on API security testing experience across REST and SOAP services; GraphQL experience is an advantage

Ability to assess authentication, authorisation, access control, session management, input validation, business logic and data exposure weaknesses

Experience testing modern identity and API security mechanisms, including OAuth 2\.0, OpenID Connect, SAML, JSON Web Tokens and API keys

Experience performing grey\-box and code\-assisted penetration testing, using source code, architecture information, credentials and developer input to improve test depth and coverage

Ability to review application code for security weaknesses and trace findings from source to runtime behaviour; experience with common languages and frameworks such as Java, .NET/C\#, JavaScript/TypeScript or Python is desirable

Working knowledge of OWASP Web Security Testing Guide, OWASP Top 10, OWASP API Security Top 10, CWE and CVSS, with the ability to apply them appropriately during testing and reporting

Proficiency with application and API testing tools such as Burp Suite Professional, Postman or equivalent API clients, browser developer tools, intercepting proxies and appropriate supporting scripts

Ability to define and challenge test scope, identify coverage gaps, obtain missing technical information and maintain traceability between the agreed scope, test activity, evidence and final report

Experience producing clear, reproducible findings with requests and responses, proof\-of\-concept evidence, affected components, risk rationale and practical remediation guidance

Strong understanding of secure software development and DevSecOps practices, including application architecture, CI/CD pipelines, SAST, DAST, software composition analysis, secrets management and secure code review

Ability to work closely with developers, product owners and security stakeholders, explain technical issues clearly, challenge assumptions constructively and drive remediation and retesting discussions

Experience operating effectively in highly restricted client environments, including client\-managed virtual machines, controlled tooling, limited internet access and prohibitions on moving client data or evidence outside the environment

Strong evidence\-handling discipline, including secure storage, naming, version control, review, quality assurance, sign\-off and disposal in line with client requirements

Ability to work independently, manage multiple assessments and deliver consistently high\-quality outputs to agreed deadlines

Ability to peer review test plans, evidence and reports, and to mentor less experienced penetration testers

Strong written and verbal communication skills, including the ability to translate technical vulnerabilities into credible business risk for technical and non\-technical stakeholders

Current knowledge of web and API attack techniques, emerging application security threats, bypass methods and defensive controls

Experience and attributes for success

Experience:

Minimum 5 years’ hands\-on penetration testing experience, with substantial recent delivery across web applications and APIs

Demonstrable experience testing large and complex applications with extensive URL, route or endpoint coverage

Demonstrable grey\-box or code\-assisted testing experience, including secure code review and collaboration with development teams

Experience assessing REST and SOAP APIs; GraphQL, microservices and cloud\-native application testing experience is desirable

Experience delivering the full assessment lifecycle: scoping, test planning, access validation, execution, evidence capture, peer review, reporting, stakeholder readout, remediation support and retesting

Experience working within restricted or segregated client environments where testing, evidence and reporting must remain on client\-managed systems

Track record of producing high\-quality technical reports and explaining findings to developers, application owners, risk stakeholders and senior management

Consulting experience and experience coordinating multiple concurrent assessments are desirable

OSCP, OSWE, CREST, CHECK Team Member/Leader or an equivalent practical application security certification is desirable

A demonstrable commitment to continuing professional development in web, API and application security

Attributes:

  • Excellent communication and project management skills (verbal and written),

  • Excellent organisational and problem\-solving skills in addition to strong attention to detail,

  • Experience in drafting proposals, bids and tender responses,

  • Excellent working knowledge of Microsoft PowerPoint, Word, Excel and online research tools,

  • Strong collaboration skills, ideally working with global and multi\-functional teams.

  • Ability to prioritise and work to tight deadlines and manage own caseload.

  • The ability to learn quickly and to work well under pressure,

  • The ability to listen attentively and express complex issues concisely to clients

  • Show leadership and motivate teams, including project management of consultancy projects

  • Participate in implementation or deployment of new tools, processes and best\-practices in order to improve knowledge sharing and to raise security level while promoting security awareness among team members
*You will also have focused on some of these areas in the past:*
  • Web applications, APIs, mobile applications, cloud\-native services and supporting application infrastructure

  • Application development or secure code review experience, with knowledge of common frameworks and DevSecOps controls including SAST, DAST, SCA, secrets scanning and secure design review

  • Understanding of CI/CD, container concepts, agile project management, deployment, automation and orchestration

  • Programming or scripting experience in one or more relevant languages, such as Java, C\#/.NET, JavaScript/TypeScript, Python, PowerShell or Bash

  • OT Security (knowledge of or certification in ISA/IEC 62443 an advantage)

  • Cloud Security (Azure AZ900, AZ500 and AWS Security an advantage)

  • Security Engineering or Architecture (SABSA an advantage)
To qualify for the role you must have
  • A degree in information security, computer science, software engineering, computer engineering or a related discipline, or equivalent relevant professional experience

  • A relevant practical penetration testing certification e.g., OSCP, OSWE
Ideally, you’ll also have
  • CISSP or CISM (an advantage)

  • Additional application security qualifications such as GWAPT, CREST CCT APP, CHECK, Burp Suite Certified Practitioner or equivalent are desirable
What working at EY offers

We offer a competitive remuneration package. Our comprehensive Total Rewards package includes support for flexible working and career development, and with FlexEY you can select benefits that suit your needs, covering holidays, health and well\-being, insurance, savings and a wide range of discounts, offers and promotions. Plus, we offer:

  • Support and coaching from some of the most engaging colleagues around

  • Opportunities to develop new skills and progress your career

  • The freedom and flexibility to handle your role in a way that’s right for you
All our employees are given a benefits package which they can tailor to suit their individual preferences. Our range of benefits include:
  • Pension

  • Maternity \& Paternity leave

  • Discounted health insurance

  • Bike to work Scheme

  • Web Doctor \- Free unlimited online GP consultations for you and your family

  • Recognition Awards

  • The purchase of additional annual leave

  • Cash incentives for referrals

  • Hybrid Working

  • Work Mobile

  • Free Gym membership ·

  • TECH MBA paid by EY

  • Travel Pass

  • Wellness rooms Avai

The market for this type of role

Similar openings
52
Management roles in DUBLIN 2
Full-time
87%
of Management roles in Ireland
Remote possible
10%
of Management roles
EY

200 open positions · Amsterdam, Barcelona, Basel, Berchem, Birmingham +31

📊 Management · Ireland
1,035
active jobs
11.8%
Remote
Ø 3d
avg. online
Top skills in demand
ExcelERPISOBudgetKPICRMB2BLeanAgileSAP

Frequently asked questions

How many Management jobs are available in DUBLIN 2?
Currently 52 Management roles in DUBLIN 2 on AlmostHired, across 17 different companies. Our data is updated daily.
Do Management roles offer remote work?
10% of Management roles in Ireland allow remote work, either partial or full. To filter specifically for remote positions, use AlmostHired.
How do I know if I match this role?
Upload your CV — our AI compares your profile to the job requirements and gives you a precise match score, with matching and missing skills.