Logo
KPMG US

Senior Specialist, SCA Penetration Tester

KPMG US, Tallahassee, Florida, us, 32318

Save Job

Overview

Join to apply for the

Senior Specialist, SCA Penetration Tester

role at

KPMG US . KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand, and looking forward we do not anticipate that slowing down. In this environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility to find new areas of inspiration, consider a career in Advisory. KPMG is currently seeking a

Senior Specialist, SCA Penetration Tester

to join our Managed Services practice.

Responsibilities:

Conduct in-depth source code analysis and manual penetration testing of web applications to identify vulnerabilities and security flaws

Collaborate with development and engineering teams to remediate findings and provide secure coding guidance

Utilize industry-standard tools (for example: Burp Suite, OWASP ZAP, Fortify, Checkmarx) to perform dynamic and static application security testing

Document and communicate findings in detailed reports, including risk ratings, remediation recommendations, and technical evidence

Stay current with emerging threats, attack vectors, and security trends relevant to web applications and source code vulnerabilities

Support internal security initiatives and contribute to the development of secure coding standards and best practices

Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment

Qualifications:

Minimum three years of recent experience in web application penetration testing and source code analysis

Bachelor's degree from an accredited college or university in computer science, cybersecurity, or a related field

Familiarity with secure coding practices and common vulnerabilities (for example: OWASP Top 10)

Hands-on experience with SAST and DAST tools, and scripting languages such as Python, JavaScript, or Java

Strong analytical, problem-solving, and communication skills

Relevant certifications (for example: OSCP, GWAPT, CEH, CSSLP) are a plus but not required

Ability to travel as required

Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity

KPMG LLP and its affiliates and subsidiaries comply with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additional details about our benefits can be found on the KPMG US Careers site at Benefits & How We Work.

California Salary Range: $84,500 - $179,300

KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. No phone calls or agencies please.

KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr