JOBSEARCHER

Attack Surface and Exposure Validation Assistant Engineer

EYWashington, DCL6 LeadAugust 25th, 2026
At EY, we’re all in to shape your future with confidence.We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.The opportunityAs an Attack Surface Validation & Exposure Engineer in the Attack Surface Management function, you will serve as a strategic contributor within EY’s Vulnerability Management and Exposure Assessment capability, with a deep focus on attack path discovery, scalable vulnerability detection, and exposure validation through self-engineered solutions. Operating with a high degree of autonomy, you will play a senior role in developing EY’s strategy to discovering and managing vulnerabilities to keep pace with the evolving threat landscape. This role is designed for an experienced practitioner who understands that vulnerabilities on EY digital assets represent the firm’s greatest source of exposure as their rate of exploitation increases exponentially. The candidate will develop solutions to discover and exploit vulnerabilities at scale within the EY environment.You will partner closely with partners in the Red Team, Exposure Assessment, Vulnerability Intelligence, Cyber Threat Intelligence and Cyber Threat Detection to identify the greatest areas of susceptibility and emerging threats and build solutions to them.Your Key ResponsibilitiesDesign and engineer automated attack‑path discovery and validation capabilitiesBuild scalable vulnerability detection and verification pipelines that combine enterprise scanning sources with custom validation logicDevelop controlled exploitation and exploit‑chaining workflows to safely demonstrate real attacker outcomesOperationalize continuous offensive validation by engineering testing routines that can run with minimal human promptingFuse Vulnerability Intelligence and Cyber Threat Intelligence into detection and prioritization—tracking exploit maturity/availability, active exploitation signals, and technique trends, etcProduce high‑fidelity deliverables that enable remediation and decisioning: reproducible evidence, attack‑path narratives, severity/exploitability rationale, compensating control notes, and clear remediation/mitigation recommendationsPartner across Red Team, Exposure Assessment, Threat Detection, and VM stakeholdersSkills And Attributes For SuccessExpert attention to detailDemonstrated ability to thinking criticallyInterest in engineering creative solutions to complex issuesFlexibility and comfortability pivoting between diverse environmentsExceptional communication and rapport building skillsExtensive experience augmenting offensive securityTo qualify for the role you must haveMinimum combined 8 years of experience in vulnerability management, exposure management, offensive security, and security engineeringDemonstrated experience analyzing vulnerability and security posture dataDeep understanding of attack paths, misconfigurations, and control failures that lead to material riskProven ability to build scalable solutions to vulnerability and exposure challengesExperience operating at a strategic level, balancing technical depth with organizational risk contextStrong analytical skills with the ability to evaluate large volumes of data to influence solution developmentExcellent communication skills, with comfort engaging senior stakeholders and security leadershipAbility to manage competing priorities and operate independently in a complex, global environmentIdeally, you’ll also haveExperience leveraging AI to conduct exposure assessmentsWhat We Look ForWe are looking for a senior analyst that can operate autonomously and bring new, strategic approaches to discovering and evaluating the firm’s exposure to vulnerabilities to improve the overall security posture. We are seeking a seasoned analyst to improve the organization’s ability to reduce the attack surface while enabling the business. The ideal candidate will seek to improve others while continuously learning and identifying ways to strengthen the organization.