Specialist, SCA Penetration Tester Job at KPMG US in Charlotte
KPMG US, Charlotte, NC, United States, 28245
Overview
Join to apply for the Specialist, SCA Penetration Tester role at KPMG US.
KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand, and we expect this to continue. Our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority, with opportunities for learning and career development, a world-class training facility, and leading market tools. If you are looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have flexibility and access to new areas of inspiration, consider a career in Advisory.
KPMG is currently seeking a Specialist, SCA Penetration Tester to join our Managed Services practice.
Responsibilities
- Conduct in-depth source code analysis and manual penetration testing of web applications to identify vulnerabilities and security flaws
- Collaborate with development and engineering teams to remediate findings and provide secure coding guidance
- Utilize industry-standard tools (for example: Burp Suite, OWASP ZAP, Fortify, Checkmarx) to perform dynamic and static application security testing
- Document and communicate findings in detailed reports, including risk ratings, remediation recommendations, and technical evidence
- Stay current with emerging threats, attack vectors, and security trends relevant to web applications and source code vulnerabilities
- Support internal security initiatives and contribute to the development of secure coding standards and best practices
- Act with integrity, professionalism, and personal responsibility to uphold KPMG\'s respectful and courteous work environment
Qualifications
- Minimum one year of recent experience in web application penetration testing and source code analysis
- Bachelor\'s degree from an accredited college or university in computer science, cybersecurity, or a related field
- Familiarity with secure coding practices and common vulnerabilities (for example: OWASP Top 10)
- Hands-on experience with SAST and DAST tools, and scripting languages such as Python, JavaScript, or Java
- Strong analytical, problem-solving, and communication skills
- Relevant certifications (for example: OSCP, GWAPT, CEH, CSSLP) are a plus but not required
- Ability to travel as required
- Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity
KPMG LLP and its affiliates and subsidiaries (“KPMG”) complies with all local/state regulations regarding displaying salary ranges. If required, ranges are provided for hires in listed locations. Our Total Rewards package includes medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a suite of personal well-being benefits. Depending on classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. We also publish a calendar of holidays and provide two breaks per year where PTO is not required. Additional details about benefits are available on the KPMG US Careers site at Benefits & How We Work.
California Salary Range: $72,600 - $112,200 (see salary ranges by city outside of CA at the link above).
KPMG is an equal opportunity employer. All qualified applicants are considered for employment without regard to race, color, religion, sex, national origin, citizenship status, disability, or any other category protected by applicable laws. No phone calls or agencies please.
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Los Angeles County applicants: material job duties and applicable fair chance laws apply as described in the posting.