Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

OREGON EMPLOYMENT DEPARTMENT

Cyber Defense Analyst

Career Insights for Vulnerability Analyst / Penetration Tester

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Massachusetts data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.

$119,730 / year median in Massachusetts

+4% projected growth

Explore Career

Job Description

Job Listing ID:
4534912
Job Title:
Cyber Defense Analyst
Application Deadline:
Open Until Filled
Job Location:
Salem
Date Posted:
07/23/2026
Hours Worked Per Week:
Not Provided
Shift:
Not Provided
Duration of Job:
Either Full or Part Time, more than 6 months SR You may contact this employer directly. (Obtain the contact information to print or add to your jobs.) Obtain Contact Information Job Summary At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Today's world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust. Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value. The opportunity As a Red Team Operator within the Attack Surface Management team, you will emulate advanced threat actors through offensive security testing and adversary emulation. You will identify vulnerabilities, demonstrate business and operational risks, and provide actionable recommendations to improve defenses. Your key responsibilities Plan, execute, and lead red team operations and adversary emulation, including reconnaissance, initial access, execution, persistence, lateral movement, exfiltration, and impact. Conduct advanced penetration testing across environments: external/internal networks, web/cloud applications, APIs, Active Directory, identity systems, and hybrid/cloud infrastructures. Perform social engineering (e.g., phishing) as part of integrated engagements. Identify, validate, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business risks. Collaborate in Purple Team exercises with defensive teams to improve detection, response, and resilience.
Produce high-quality deliverables:
detailed technical reports, executive summaries, risk assessments, and remediation recommendations. Mentor junior team members, provide technical oversight, and contribute to methodology improvements and tooling (e.g., custom exploits, automation scripts). Stay current with emerging threats, TTPs, exploits, and defensive countermeasures through research, conferences, and self-development. Skills and attributes for success Deep expertise in offensive security tools and frameworks (e.g., Metasploit, Cobalt Strike / custom C2, Empire, BloodHound, Nmap, Burp Suite, and others).Demonstrated ability to thinking critically Strong knowledge of networking, operating systems (Windows/Linux), Active Directory, cloud platforms (AWS/Azure/GCP), web app security, and common protocols. Proficiency in scripting/programming (Python, PowerShell, Bash, etc.) for automation and custom tooling. Ability to translate complex technical findings into clear business risk language for executives and non-technical stakeholders. Ability to accurately build out attack paths and threat models relevant to current infrastructure and threat intelligence. Independently research and stay knowledgeable of Threat Actor TTP's and how they may be leveraged. Excellent analytical, problem-solving, and technical writing skills. Strong teamwork, independence,... Information Security Analysts Access our Statewide and Regional occupation report for more information about wages, employment outlooks, skills, training programs, related occupations, and more. Compensation Not Provided Job Requirements
Experience Required:
See Job Summary
Education Required:
None
Minimum Age:
N/A