Senior Cybersecurity Consultant, Email Security in Boston, Massachusetts
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Cyber threats, social media, massive data storage, privacy requirements and continuity of the business as usual require heavy information security measures. As an information security specialist, you will lead the implementation of security solutions for our clients and support the clients in their desire to protect the business. You will belong to an international connected team of specialists helping our clients with their most complex information security needs and contributing toward their business resilience. You will be working with our Advanced Security Centers to access the most sophisticated tools available to fight against cybercrime.
EY’s Cybersecurity Practice functions as a center of excellence to assist our consulting practices in planning, pursuing, delivering, and managing large, complex full lifecycle initiatives along with providing expertise in leading practices, methods, and resources in the space of Cybersecurity. The Data Security & Disposition capability within the Cybersecurity practice is a critical competency that supports our clients across all industry sectors.
We currently have a career opportunity for a Senior Consultant in our Cybersecurity practice for our Data Security & Disposition capability with demonstrated experience in developing data protection strategies and implementing solutions to provide data security, privacy, and integrity through e ncryption, secure data governance, and data disposition solutions.
The Data Security and Disposition Capability helps clients enable effective use of data security technologies including encryption tools (PKI, Data at Rest encryption), tokenization, masking, and disposition technologies. Additionally, we also assist to build secure data governance for enforcing appropriate controls throughout data's lifecycle (i.e. Data Stewardship, Data Quality). Key services include paper and technology-based assessments, technology selection and design, governance program design, technology build, and continued operation & maintenance of data security technologies across the following domains: PKI, Encryption, Data Masking & Test Data Management, Data Security Governance, and Data Disposition.
We will support you with career-long training and coaching to develop your skills. As EY is a global leading service provider in this space, you will be working with the best of the best in a collaborative environment. So, whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.
Your key responsibilities
As a Senior Consultant focused on Email Security in our Data Security team, you will help clients define technical and business requirements for data protection solutions as well as develop business processes and policies related to controlling access to data. This includes helping clients to identify, understand and protect their most critical data throughout the data lifecycle. Engagements range from identifying high value assets to developing data classification schemes, standards and guidelines and implementing processes and technologies to provide leading data protection capabilities.
You and your team will implement and advise clients on through
Participation in internal EY solution planning sessions with client account teams
Providing insights on client challenges and/or opportunities for EY in the market
Coaching EY client account leaders on effective engagement and relationship development strategies with client.
Skills and attributes for success
Consistently deliver quality client services. Monitor progress, manage risk, and ensure key stakeholders are kept informed about progress and expected outcomes. Stay abreast of current business and industry trends relevant to the client's business.
Establish relationships with client personnel at appropriate levels.
Demonstrate in-depth technical capabilities and professional knowledge. Demonstrate ability to assimilate to new knowledge.
Possess good business acumen.
Remain current on new developments in consulting services capabilities and industry knowledge
To qualify for the role, you must have
Bachelor's degree and approximately 2-3 years of related work experience; or a graduate degree and approximately 1-2 years of related work experience.
Approximately 2-3 years of technical architecture experience integrating data protection software into clients' infrastructure and applications.
Knowledge of general security concepts and methods such as vulnerability assessments, data classification, privacy assessments, incident response, security policy creation, enterprise security strategies, architectures, and governance.
Basic understanding of networking (TCP/IP, OSI model), operating system fundamentals (Windows, UNIX, mainframe), security technologies (firewalls, IDS/IPS, etc.) and application programming/scripting languages (C, Java, Perl, Shell).
Demonstrated experience in the following areas of secure messaging/email encryption:
Email Authentication Tools (DMARC Compliance)
Cisco Security Email Gateway
Microsoft Exchange Online Protection (EOP) and Microsoft Defender for Office (MDO)
Proofpoint Email Security (Phish Simulation, Report Phish, Analyzer)
Agari Phishing Response
Agari Brand Protect (DMARC)
Additional experience in at least one of the following:
Data leakage/content monitoring and filtering
Mobile device security
Disk, file, device, and database encryption
Key management/Public Key Infrastructure (PKI)
Data classification and privacy policies
Digital Rights Management (DRM)
Logging, monitoring, and security event management
Secure information storage
Ideally, you’ll also have
The successful candidate must hold or be willing to pursue related professional certifications such as the CISSP, CISM, and/or CISA.
What we look for
Basic understanding of regulatory requirements and compliance issues affecting clients related to privacy and data protection, such as PCI DSS, GLBA, Basel II, EU Data Protection Directive, International Cross Border, and U.S. State Data Privacy Laws.
Technical architecture experience integrating data protection software into clients' infrastructure; network architecture design, implementation, and administration.
Working knowledge of operating systems, virtual machine environments, mainframe security packages, and relational database management systems.
Willingness to travel to meet client needs; travel is estimated up to 40-60%.
Valid driver's license in the US and a valid passport required; willingness and ability to travel internationally.
What we offer
We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The salary range for this job in most geographic locations in the US is $100,800 to $184,800. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $121,000 to $210,000. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
If you can demonstrate that you meet the criteria above, please contact us as soon as possible.
The exceptional EY experience. It’s yours to build.
EY | Building a better working world
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
EY is an equal opportunity, affirmative action employer providing equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to individuals with disabilities. If you are a qualified individual with a disability and either need assistance applying online or need to request an accommodation during the interview process, please call 1-800-EY-HELP3, type Option 2 (HR-related inquiries) and then type Option 1 (HR Shared Services Center), which will route you to EY’s Talent Shared Services Team or email SSC Customer Support at firstname.lastname@example.org .