Project Objectives:
- Our practice works with clients across a variety of industries to assess and improve their cybersecurity programs through technical security testing, cybersecurity assessments, and recognized frameworks and standards, including NIST, PCI DSS, CIS Controls, and other leading practices.
- Hands-on penetration testing and technical assessment experience
Experience performing network, web application, wireless, cloud, and/or internal security assessments. Candidates should have direct experience conducting security testing activities, identifying vulnerabilities, validating findings, and developing remediation recommendations.
- Strong cybersecurity and technical foundation
Understanding of networking, operating systems, Active Directory, authentication protocols, cloud technologies, and common attack techniques. Comfortable discussing both technical findings and associated business risks.
- Knowledge of key frameworks
Experience with NIST CSF, NIST 800-53, NIST 800-171, CMMC, PCI DSS, CIS Controls, OWASP, MITRE ATT&CK, or similar standards and methodologies.
- Consulting and client communication skills
Able to communicate with clients, gather information, explain technical findings clearly, and present recommendations to both technical and executive audiences.
- Strong documentation and attention to detail
Ability to create thorough testing workpapers, technical reports, executive summaries, spreadsheets, and recommendations that are accurate, well-supported, and client-ready. - Ability to manage multiple priorities
Comfortable working across different client engagements, deadlines, meetings, testing activities, reporting requirements, and follow-up tasks in a fast-paced environment.
Engagement Tasks:
- Performs network, web application, wireless, cloud, and other cybersecurity assessments and penetration testing engagements.
- Assists with vulnerability validation, exploitation testing, attack path analysis, and security control evaluations in support of client engagements.
- Gathers and documents business requirements, testing plans, testing results, configuration reviews, technical observations, and any other deliverables required by the project as determined by management.
- Develops technical reports, executive summaries, remediation recommendations, and client deliverables consistent with leading practices.
- Adheres to established testing methodologies, firm standards, and leading industry practices in all deliverables.
- Establishes strong relationships with clients and serves as a trusted advisor throughout engagements.
- Manages segments of projects independently while being involved in multiple projects simultaneously.
- Keeps project teams informed regarding the status of assigned responsibilities, identified risks, findings, and project milestones.
- Responds to all clients with a sense of urgency, escalating matters or managing up as necessary.
- Achieves firm, team, and organizational metrics (e.g., utilization and realization).
Required education and experience
- Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Computer Science, Accounting Information Systems, or a related field.
- Minimum of 2 years of relevant professional experience in cybersecurity, penetration testing, security consulting, offensive security, vulnerability assessment, or a related field.
- Demonstrated experience performing penetration testing or technical security assessments, including one or more of the following:
- Network Penetration Testing
- Web Application Penetration Testing
- Internal Security Assessments
- Wireless Security Assessments
- Active Directory Security Assessments
- Cloud Security Assessments
- Working knowledge of penetration testing methodologies, security assessment techniques, and common testing tools.
- Working knowledge of cybersecurity frameworks and standards such as NIST CSF, NIST SP 800-53, NIST SP 800-171, CMMC, CIS Controls, PCI DSS, OWASP, and/or MITRE ATT&CK.
- Proficient in using office software and tools, including Microsoft Office Suite (Word, Excel, Outlook, PowerPoint).
Preferred education and experience
- Industry certifications such as OSCP, PNPT, GPEN, GWAPT, Security+, CySA+, CISSP, CISA, CRISC, PCI ISA, or similar certifications.
- Experience using penetration testing and security assessment tools such as Burp Suite, Nmap, Nessus, Metasploit, BloodHound, Kali Linux, Wireshark, or similar platforms.
- Experience developing technical penetration testing reports and presenting findings to clients.
- Experience with scripting or automation using PowerShell, Python, Bash, or similar languages.
Work Quality:
- Consistently produces work of the utmost quality
Supervisory responsibilities
- None
Work environment
- There is an expectation to spend time with the client in accordance with the client’s needs. Time may be spent in both the Firm’s office environment and/or the client premises where conditions may vary
- The volume and predictability of work may vary with client demands; may be subject to on-call requests with short notice and work hours exceeding 40 per week
Physical demands
- Physical demands include the ability to transport necessary equipment between client sites; this requires the ability to lift issued equipment such as laptops, backpacks, keyboards, note-taking materials, bending or standing as necessary
Travel required
- Travel may be required.
Other duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the colleague for this job. Duties, responsibilities and activities may change at any time with or without notice.
WHO WE AREUHY is one of the nation’s largest professional services firms providing audit, tax, consulting and advisory services to clients primarily in the dynamic middle market. We are trailblazers who bring our experience from working within numerous industries to our clients so that we can provide them with a 360-degree view of their businesses. Together with our clients, UHY works collaboratively to develop flexible, innovative solutions that meet our clients’ business challenges. As an independent member of UHY International, we are proud to be a part of a top 20 international network of independent accounting and consulting firms.
WHAT WE OFFERPOSITIVE WORK ENVIRONMENT
Enjoy a collaborative and supportive work environment where teamwork is valued.
ATTRACTIVE COMPENSATION PACKAGES
Our compensation is competitive and tailored to reflect the role, qualifications, and expertise of each individual.
COMPREHENSIVE BENEFIT PACKAGE
Access comprehensive benefits including group health insurance, dental and vision coverage, 401(k) retirement plans, and generous paid time off (PTO) allowances.
Skills Required
- Bachelor's degree in related field or equivalent experience
- 2-4 years of experience since undergraduate degree (or 0-3 years since MBA)
- Proficient in MS Office Suite (Word, Excel, Outlook, PowerPoint)
- Ability to travel frequently and unpredictably to client sites
- Ability to lift and transport equipment (laptops, backpacks, keyboards)
- CISSP, CISA, CISM, CEH, or other relevant certifications
UHY-US Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about UHY-US and has not been reviewed or approved by UHY-US.
-
Healthcare Strength — Health coverage includes medical, dental, vision, life and disability, with some locations citing strong employer contributions. Consultant materials also outline multiple plan choices and HSA access.
-
Leave & Time Off Breadth — Time off includes paid holidays and accrued PTO, and consultant roles are eligible for time-and-a-half overtime. Local write-ups also reference full maternity and paternity leaves in at least one market.
-
Retirement Support — Savings options include a 401(k) with pre-tax, after-tax, and Roth features. Feedback suggests retirement benefits are viewed favorably in some cases.
UHY-US Insights
What We Do
UHY is one of the nation’s largest professional services firms providing audit, tax, consulting and advisory services to clients primarily in the dynamic middle market. We are trailblazers who bring our experience from working within numerous industries to our clients so that we can provide them a 360-degree view of their businesses. Together with our clients, UHY works collaboratively to develop flexible, innovative solutions that meet our clients’ business challenges. As an independent member of UHY International, we are proud to be a part of a top 20 international network of independent accounting and consulting firms. Firm Disclaimer ©2025 UHY LLP. ALL RIGHTS RESERVED. “UHY” is the brand name under which UHY LLP and UHY Advisors, Inc. provide professional services. The two firms operate as separate legal entities in an alternative practice structure. UHY LLP is a licensed independent CPA firm that performs attest services. UHY Advisors, Inc. provides tax and business consulting services through subsidiary entities. UHY Advisors, Inc. and UHY LLP are U.S. members of Urbach Hacker Young International Limited (UHY International), a UK company, and form part of the international UHY network of legally independent accounting and consulting firms. Any services described herein are provided by UHY Advisors, Inc. and/or UHY LLP (as the case may be) and not by UHY International or any other member firm of UHY International. Neither UHY International nor any member of UHY International has any liability for services provided by other members. On this website, (i) the term "our firm", "we" and terms of similar import, denote the alternative practice structure conducted by UHY LLP and UHY Advisors, Inc. and its subsidiary entities, and (ii) the term "UHYI" denotes the UHY international network, in each case as more fully described in the preceding paragraph.









