Logo
KPMG US

KPMG US is hiring: Specialist, SCA Penetration Tester in Raleigh

KPMG US, Raleigh, NC, United States, 27601

Save Job

Overview

Join to apply for the Specialist, SCA Penetration Tester role at KPMG US.

KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand and expect that to continue. At KPMG, our people are our number one priority, with learning and career development opportunities, a world-class training facility, and leading market tools to help you grow professionally and personally. If you are looking for a firm with a strong team connection where you can be your whole self and make an impact, consider a career in Advisory.

KPMG is currently seeking a Specialist, SCA Penetration Tester to join our Managed Services practice.

Responsibilities

  • Conduct in-depth source code analysis and manual penetration testing of web applications to identify vulnerabilities and security flaws
  • Collaborate with development and engineering teams to remediate findings and provide secure coding guidance
  • Utilize industry-standard tools (for example: Burp Suite, OWASP ZAP, Fortify, Checkmarx) to perform dynamic and static application security testing
  • Document and communicate findings in detailed reports, including risk ratings, remediation recommendations, and technical evidence
  • Stay current with emerging threats, attack vectors, and security trends relevant to web applications and source code vulnerabilities
  • Support internal security initiatives and contribute to the development of secure coding standards and best practices
  • Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment

Qualifications

  • Minimum one year of recent experience in web application penetration testing and source code analysis
  • Bachelor's degree from an accredited college or university in computer science, cybersecurity, or a related field
  • Familiarity with secure coding practices and common vulnerabilities (e.g., OWASP Top 10)
  • Hands-on experience with SAST and DAST tools, and scripting languages such as Python, JavaScript, or Java
  • Strong analytical, problem-solving, and communication skills
  • Relevant certifications (e.g., OSCP, GWAPT, CEH, CSSLP) are a plus but not required
  • Ability to travel as required
  • Applicants must be authorized to work in the U.S. without visa sponsorship now or in the future

KPMG LLP and its affiliates comply with all local/state regulations regarding salary ranges. Salary details vary by location and are provided where applicable. KPMG is an equal opportunity employer and complies with all applicable laws. No phone calls or agencies please.

Follow this link to obtain salary ranges by city outside of CA: https://kpmg.com/us/en/how-we-work/pay-transparency.html/?id=M105_6_25

California Salary Range: $72,600 - $112,200

KPMG recruits on a rolling basis. Candidates are considered as they apply until the opportunity is filled.

#J-18808-Ljbffr