Cyber Defense Analyst

EYRaleigh, DC

About The Position

At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust. Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.

Requirements

  • Minimum combined 8 years of experience in vulnerability management, exposure management, offensive security, and security engineering
  • Demonstrated experience analyzing vulnerability and security posture data
  • Deep understanding of attack paths, misconfigurations, and control failures that lead to material risk
  • Proven ability to build scalable solutions to vulnerability and exposure challenges
  • Experience operating at a strategic level, balancing technical depth with organizational risk context
  • Strong analytical skills with the ability to evaluate large volumes of data to influence solution development
  • Excellent communication skills, with comfort engaging senior stakeholders and security leadership
  • Ability to manage competing priorities and operate independently in a complex, global environment

Nice To Haves

  • Experience leveraging AI to conduct exposure assessments

Responsibilities

  • Design and engineer automated attack‑path discovery and validation capabilities
  • Build scalable vulnerability detection and verification pipelines that combine enterprise scanning sources with custom validation logic
  • Develop controlled exploitation and exploit‑chaining workflows to safely demonstrate real attacker outcomes
  • Operationalize continuous offensive validation by engineering testing routines that can run with minimal human prompting
  • Fuse Vulnerability Intelligence and Cyber Threat Intelligence into detection and prioritization—tracking exploit maturity/availability, active exploitation signals, and technique trends, etc
  • Produce high‑fidelity deliverables that enable remediation and decisioning: reproducible evidence, attack‑path narratives, severity/exploitability rationale, compensating control notes, and clear remediation/mitigation recommendations
  • Partner across Red Team, Exposure Assessment, Threat Detection, and VM stakeholders
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service