Senior InfoSec Consultant jobs in United States
cer-icon
Apply on Employer Site
company-logo

EY · 3 hours ago

Senior InfoSec Consultant

EY is a global leader in professional services, and they are seeking a Senior InfoSec Consultant to join their Global Information Security team. This role involves managing security risks, embedding information security in new projects, and supporting client engagement teams with innovative security solutions using emerging technologies.

AccountingAdviceBusiness IntelligenceConsultingFinancial ServicesProfessional Services
check
Growth Opportunities
check
H1B Sponsor Likelynote

Responsibilities

This position is a leading role in designing, developing, and accessing all aspects of security for market leading regional and global systems based primarily on Cloud technologies
As a security consultant dedicated to the Innovation teams you will be an individual contributor capable of supporting multiple project teams operating in the latest technologies of Cloud-based, Agile developed systems, using automated deployment from CI/CD pipelines
In other words, it is not just an audit or oversight role, but one that requires detailed participation in the design, implementation, and certification of security controls across solutions
This requires knowledge of various IT system architecture and Cloud technology, as well as supporting technologies such as AI, Blockchain, Quantum Computing, Cloud Security, user account management, audit and logging, and other security concepts as outlined in ISO27001/2, OWASP and related regional security standards
Also, the successful candidate should have knowledge of 3rd party security assessments and applicability of SOC1 and SOC2 reports, and concepts of vendor risk management

Qualification

Cloud SecurityAI Security TechnologiesBlockchain SecurityAgile & DevOpsApplication SecurityInfrastructure SecurityOpen Source TechnologiesMicrosoft AzureIT System ArchitectureSecurity CertificationsVendor Risk ManagementOperational SecurityInformation Security StandardsProduct ManagementCommunication Skills

Required

Significant working security experience and knowledge in the design, implementation and operation of security controls in one or more of the following areas:
Hands-on experiences of developing and implementing AI security technologies, especially Gen AI and rapid growing LLMs
Experiences with designing and enforcing security protocols to safeguard blockchain technologies and applications
Agile & DevOps Methodologies – Experience as a contributing member of a balanced team within an Agile development or DevOps environment
Cloud Security –Technical understanding of virtualization, cloud infrastructure, and public cloud offerings and experience designing security configuration and controls within cloud based solutions in Microsoft Azure and Azure PAAS services (SQL, Service Bus, Service Fabric, Data Lake, PowerBI)
Application Security - Experience with the design of security controls for multi-tier business solutions including the design of application-level access and entitlement management, data tenancy and isolation, encryption, and logging. Working familiarity with REST API and microservices architecture
Infrastructure Security – Experience with the integration of common infrastructure security technologies and solutions into business solution architectures including the integration of identity & access management, intrusion detection and prevention, security monitoring, and data encryption solutions
Working experience with Open Source web technologies and programming languages, preferable with experiences in InfoSec Code Review
Significant experience in implementing security in a Microsoft Azure environment and practical knowledge of implementing global systems using a primarily PaaS and SaaS architecture, especially AI, Blockchain, Quantum Computing, Metaverse subjects
Direct knowledge of IT system architecture concepts and Cloud technology, as well as supporting technology such as IAM, network security, firewalls, user account management, audit and logging, and other security concepts as outlined in ISO27001/2, OWASP and related regional security standards
Advanced degree in Computer Science or a related discipline; or equivalent work experience. CISSP, CCSP, CISM, or similar security certifications preferred
Strong communication skills and ability to work with stakeholders ranging from developer to architects to business leaders to EY's clients

Preferred

Although not required, it is preferred that candidates possess additional working security experience and knowledge in one or more of the following areas:
Operational Security – Experience with defining operational models and procedures for business solutions including the operation and maintenance of infrastructure and application security controls
Information Security Standards – Knowledge of common information security standards such as: ISO 27001/27002, CSA and CIS Controls, etc
Cloud security certifications such as AZ-500 Azure Security Engineer
Product Management – working with a broader business team on aspects of security that affect all phases from concept to design to implementation and then operational support

Benefits

Medical and dental coverage
Pension and 401(k) plans
Paid time off options
Flexible vacation policy
Designated EY Paid Holidays
Winter/Summer breaks
Personal/Family Care
Other leaves of absence when needed to support your physical, financial, and emotional well-being

Company

EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets.

H1B Sponsorship

EY has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (10242)
2024 (9877)
2023 (10966)
2022 (9394)
2021 (5652)
2020 (8849)

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Jonathan Williamson
Chief Operating Officer
linkedin
leader-logo
Abhishek Sen
Partner
linkedin
Company data provided by crunchbase