Consultant / Senior Consultant - VAPT - Technology Consulting - EY Mauritius
About this role
What if we didn’t focus on who you are now, but who you could become?
Here at EY, you will have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. Join us and build an exceptional experience for yourself, and a better working world for all.
The exceptional EY experience. It's yours to build.
The opportunity: your next adventure awaits
Our Technology Consulting team is a fast-growing sub-service line within EY’s Consulting service line. We work with clients to create value and deliver trusted, high-quality advice across digital, data, technology, cybersecurity and transformation programmes.
As part of our Cybersecurity offering, you will support clients in identifying, assessing and addressing security risks through vulnerability assessments, penetration testing, Red Teaming, secure architecture reviews and related advisory services.
We are looking for a Consultant / Senior Consultant with 3–5 years of experience in Vulnerability Assessment and Penetration Testing (VAPT), Red Teaming and Secure Architecture Reviews. The successful candidate will have a strong interest in offensive security, threat detection, cloud security and emerging AI security domains, with the ability to understand attack techniques, assess risks and provide practical recommendations to strengthen clients’ security posture.
Your key responsibilities
- Conduct vulnerability assessments and penetration testing across web applications, networks, APIs, cloud environments and infrastructure.
- Apply vulnerability assessment methodologies and support remediation validation to ensure identified risks are appropriately addressed.
- Use knowledge of OWASP Top 10, SANS Top 25 and common attack vectors to identify and assess security weaknesses.
- Use security testing tools such as Burp Suite, Nmap, Nessus, OpenVAS, Metasploit and Kali Linux to support assessments.
- Review penetration testing reports and map findings to relevant security monitoring, detection and response use cases.
- Support Red Team and adversary simulation activities, including threat emulation and attack lifecycle analysis.
- Apply awareness of the MITRE ATT&CK Framework and Cyber Kill Chain to identify attack paths, tactics, techniques and procedures.
- Identify indicators of compromise associated with phishing, credential attacks, privilege escalation, lateral movement, persistence and command-and-control activities.
- Review application, infrastructure and cloud architectures to identify security design weaknesses and control gaps.
- Provide practical recommendations aligned with industry standards, security frameworks and security-by-design principles.
- Contribute to continuous improvement initiatives and support the development of EY cybersecurity capabilities.
Skills and attributes for success
- Strong analytical, investigative and problem-solving skills, with the ability to understand technical risks and communicate them clearly.
- Good understanding of vulnerability assessment methodologies, penetration testing approaches and remediation validation.
- Knowledge of OWASP Top 10, SANS Top 25, common attack vectors, exploitation techniques and attack chains.
- Familiarity with web, network, API, cloud and infrastructure security assessments.
- Exposure to tools such as Burp Suite, Nmap, Nessus, OpenVAS, Metasploit, Kali Linux and related offensive security toolsets.
- Basic understanding of Red Team methodologies, adversary simulation, threat emulation, MITRE ATT&CK Framework and Cyber Kill Chain.
- Awareness of phishing, credential attacks, privilege escalation, lateral movement, persistence mechanisms and command-and-control activities.
- Ability to translate assessment findings into practical remediation, monitoring and detection opportunities.
- Strong interest in offensive security, threat detection, cloud security and emerging AI security domains.
- Excellent communication, collaboration and stakeholder management skills.
To qualify for the role, you must have
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity or a related field, or equivalent professional experience.
- 3–5 years of experience in VAPT, Red Teaming, Secure Architecture Reviews or related cybersecurity consulting roles.
- Practical exposure to security assessments across web applications, networks, APIs, cloud platforms and infrastructure environments.
- Experience in identifying security design weaknesses, control gaps and practical remediation recommendations.
- Relevant certifications such as eJPT, CEH or CPENT would be an advantage.
Ideally, you’ll also have
- Awareness of advanced threat actor techniques and indicators of compromise across the attack lifecycle.
- Experience supporting secure architecture reviews for applications, infrastructure and cloud environments.
- Exposure to cloud security concepts and security-by-design initiatives.
- Interest in emerging AI security risks and their impact on cybersecurity assessments and detection use cases.
- A proactive mindset and commitment to continuous learning in cybersecurity.
What we look for
We are interested in professionals who are passionate about cybersecurity, confident in solving complex client challenges and able to work collaboratively across teams. You will need to be curious, proactive and ready to challenge the status quo while delivering high-quality work for our clients.
If you have a genuine passion for helping businesses strengthen their security posture and build trust in technology, this role is for you.
If you are ready to develop your career in a global organisation and contribute to building a better working world, we would like to hear from you.
What working at EY offers
At EY, our Total Rewards package supports our commitment to creating a leading people culture - built on high-performance teaming - where everyone can achieve their potential and contribute to building a better working world for our people, our clients, and our communities. It's one of the many reasons we repeatedly win awards for being a great place to work.
We offer a competitive remuneration package where you’ll be rewarded for your individual and team performance. Our comprehensive Total Rewards package includes support for flexible working and career development. Plus, we offer:
- Support, coaching, and feedback from some of the most engaging colleagues around.
- Opportunities to develop new skills and progress your career.
- The freedom and flexibility to handle your role in a way that’s right for you.
EY is committed to being an inclusive employer and we are happy to consider flexible working arrangements. We strive to achieve the right balance for our people, enabling us to deliver excellent client service whilst allowing you to build your career without sacrificing your personal priorities. While our client-facing professionals can be required to travel regularly, and at times be based at client sites, our flexible working arrangements can help you to achieve a lifestyle balance.
About EY
As a global leader in Assurance, Consulting, Strategy and Transactions, Tax, we hire and develop the most passionate people in their field to help build a better working world. This starts with a culture that believes in giving you the training, opportunities, and creative freedom to make things better. So that whenever you join, however long you stay, the exceptional EY experience lasts a lifetime. And with a commitment to hiring and developing the most passionate people, we’ll make our ambition to be the best employer a reality.
If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible.
EY will recommend applicants to read our privacy statement prior to completing the pre application form above: https://www.ey.com/en_gl/privacy-statement
Join us in shaping the future with confidence. Apply now.
Only shortlisted candidates will be contacted.
Company at a glance
EY is building a better working world by creating new value for clients, people, society, the planet, while building trust in the capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams in more than 150 countries work across a full spectrum of services in assurance, consulting, tax, strategy and transactions, strengthened by sector experience and diverse ecosystem partners.
Find out more about the EY global network: http://ey.com/en_gl/legal-statement
Top Benefits
- Flexible working arrangements
- Career development support
- Coaching and feedback
- Competitive remuneration package
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?