Associate - Cybersecurity Consultant
EY Luxembourg, Luxembourg, Luxembourg
Professional Services · 10,001+ employees
About the role
The consultant will provide Governance, Risk and Compliance (GRC) services, including cybersecurity maturity assessments and policy development. They will also perform technical security reviews, vulnerability assessments, and support cybersecurity transformation initiatives for clients.
What they look for
Requirements
Candidates must hold a Master's degree in Cybersecurity, Information Security, Computer Science, or a related field. Additionally, 1 to 3 years of experience in cybersecurity or risk management and fluency in English and French are required.
Benefits
Full description
Associate - Cybersecurity Consultant
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.
Join EY and help to build a better working world.
Are you ready to shape the future with confidence?
Here at EY, you’ll have the chance to build a truly exceptional experience. We’ll empower you with the latest technology, surround you with high-performing teams, and provide the global scale and diverse and inclusive culture you need to discover your full potential. Through our coaching and training programs, you’ll develop the skills you need to stay relevant today and, in the future, – all while building a network of colleagues, mentors, and leaders who will be on the journey with you at EY and beyond.
The opportunity: your next adventure awaits
Provide Governance, Risk and Compliance (GRC) services to clients:
- Perform cybersecurity maturity assessments and gap analyses against recognised frameworks such as ISO 27001, NIST Cybersecurity Framework, CIS Controls and industry best practices.
- Conduct enterprise and operational risk assessments and facilitate risk treatment planning.
- Develop and review security policies, standards, procedures and governance frameworks.
- Support compliance programmes related to NIS2, DORA, AI Act, GDPR and relevant Luxembourg regulatory requirements (CSSF, CAA and other sector-specific obligations).
- Assist organisations in strengthening third-party risk management and supply chain security programmes.
- Contribute to cyber strategy, security roadmaps and transformation initiatives.
- Contribute to programmes related to operational resilience, third-party risk management and business continuity.
Assist clients in performing Cybersecurity Technical Security Reviews:
- Assess the effectiveness of security controls across infrastructure, cloud, applications and endpoint environments.
- Perform security reviews, vulnerability assessments and technical risk analyses.
- Carry out penetration testing activities and remediation validation exercises.
- Evaluate cloud security postures across Microsoft Azure, AWS and Google Cloud environments.
- Contribute to security architecture reviews and secure-by-design initiatives.
- Assess identity and access management, privileged access management, endpoint security, network security and security monitoring capabilities.
- Support security operations, detection and response improvement initiatives.
Support clients in driving Cybersecurity Transformation:
- Support clients in defining cybersecurity target operating models and governance structures.
- Facilitate workshops with business stakeholders, technical teams and executives.
- Translate technical findings into business risks and actionable recommendations.
- Contribute to complex cyber transformation programmes covering people, process and technology dimensions.
- Assist clients in prioritising remediation activities and security investment decisions.
Project Delivery & Business Development
- Prepare assessment reports, presentations and client deliverables.
- Participate in client meetings, workshops and project activities.
- Contribute to the development of methodologies, accelerators and internal assets.
- Maintain awareness of emerging threats, technologies and regulations.
Consultant
- Prepare assessment reports, presentations and client deliverables.
- Participate in client meetings, workshops and project activities.
- Contribute to the development of methodologies, accelerators and internal assets.
- Maintain awareness of emerging threats, technologies and regulations.
What we look for:
- You have an agile, growth-oriented mindset. What you know matters. But the right mindset is just as important in determining success. We’re looking for people who are innovative, can work in an agile way and keep pace with a rapidly changing world.
- You are curious and purpose driven. We’re looking for people who see opportunities instead of challenges, who ask better questions to seek better answers.
- You are inclusive. We’re looking for people who seek out and embrace diverse perspectives, who value differences, and team inclusively to build safety and trust.
Qualifications:
- Master's degree in Cybersecurity, Information Security, Computer Science or related field
- 1 to 3 years of experience in cybersecurity, risk management, IT security or related domains.
- Fluent in English and French
What’s in it for you:
- Accelerate your technical capabilities and transformative leadership skills with future-focused courses and development programs.
- Broaden your horizons by working on highly integrated teams across the globe and collaborate with people of diverse backgrounds — both professionally and culturally.
- Bring out the best in yourself with continuous investment in your personal well-being and career development.
- Develop your own personal purpose and help us create a positive ripple effect on our teams, our business, clients and society.
What you can expect:
HR Call
Technical Interview
Are you ready to shape your future with confidence? Apply today.
To help create the best experience during the recruitment process, please describe any disability-related adjustments or accommodations you may need.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
Our offer of employment is contingent upon the successful completion of a background check and pre-screening requirements. The candidate acknowledges that all information provided must be accurate.
Similar roles
-
Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
-
CyberSecurity Engineer H/F
Consort Group Liège, Wallonia, Belgium · €50K–€80K/yr
-
Cloud Security Engineer
Malomatia Doha, Qatar
-
Senior Product Security Engineer
Collibra Raleigh, North Carolina, United States · $168K–$210K/yr
-
Identity Security Engineer - Customer Delivery
Way Security Tel-Aviv, Tel-Aviv District, Israel
-
Application Security Engineer - Senior
Plata Card Osnabrück, Lower Saxony, Germany