EY

Risk Consulting - Digital Risk -Staff - Application Security

Stellenbeschreibung:

Risk Consulting – Digital Risk – Staff

The Opportunity

We are expanding our Digital Risk team and are looking for Staff with strong hands‑on expertise across at least two of the following domains:

  • IT Risk
  • Cloud Risk
  • Technology Controls Assurance
  • Third Party Digital Risk
  • Cyber and Operational Resilience

Your Key Responsibilities

Client Delivery

  • Participate in application security engagements, including Threat Modelling and SDL reviews
  • Perform architecture and design security assessments to identify potential risks and control gaps
  • Evaluate secure SDLC controls, including design reviews, code security practices, and release governance
  • Work closely with asset owners, developers, and stakeholders to explain findings and remediation actions
  • Document security findings and assist in preparing client reports and presentations
  • Track remediation efforts and follow up with stakeholders to ensure closure
  • Continuously strive to exceed client and team expectations while handling increasingly complex assignments
  • Manage day-to-day client relationships, leading client meetings, working sessions, and status reporting

People responsibilities

  • Maintain an ongoing learning plan to enhance application security and threat modelling skills
  • Adherent to organizational policies and security standards
  • Participate in training programs related to secure coding, cloud security, and AppSec tools
  • Exhibit initiative, teamwork, and contribute to knowledge sharing within the team
  • Support junior team members when required

Skills and attributes for success

  • Threat Modelling methodologies (STRIDE, PASTA, etc.)
  • Secure SDLC practices and security controls
  • OWASP Top 10 and common application vulnerabilities
  • Using SAST/DAST and security testing tools
  • Reviewing authentication, authorization, encryption, and API security controls
  • Strong understanding of Application architecture (web, APIs, Azure, Power automate)
  • Strong understanding of Azure OpenAI Service, Azure AI Foundry, Azure Machine Learning

To qualify for the role, you must have

  • Bachelor’s degree in B.E./B.Tech (Computer Science, IT, Electronics) or M.Sc./MCA
  • At least 1–2 years of experience in Application Security / Secure SDLC / Threat Modelling

Additionally, good to have

  • Ability to work in fast‑paced client environments with multiple priorities
  • Analytical mindset with attention to detail in identifying security gaps
  • Strong communication skills with ability to interact with asset owners and technical stakeholders
  • Proven experience in direct client facing roles, partnering with cross‑functional teams to deliver assessment and remediation activities

Ideally, you’ll also have

  • Experience with cloud platforms (AWS, Azure, GCP)
  • Exposure to cyber risk tooling and automation
  • Prior Big 4 or consulting leadership experience

What we offer you

At EY, we’ll develop you with future‑focused skills and equip you with world‑class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams.

Are you ready to shape your future with confidence? Apply today.

We are an equal opportunity employer and are committed to Diversity, Equity & Inclusion.

#J-18808-Ljbffr
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    15 Jul 2026
  • Standort:

    Remote

    Einsatzort:

    London, UK
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!