KPMG US
Senior Specialist, SCA Penetration Tester
KPMG Advisory is our fastest growing practice, with client demand and a collaborative, team-driven culture. We prioritize our people with learning, career development, world-class training, and leading market tools.
Responsibilities
Conduct in-depth source code analysis and manual penetration testing of web applications to identify vulnerabilities and security flaws
Collaborate with development and engineering teams to remediate findings and provide secure coding guidance
Utilize industry-standard tools (for example: Burp Suite, OWASP ZAP, Fortify, Checkmarx) to perform dynamic and static application security testing
Document and communicate findings in detailed reports, including risk ratings, remediation recommendations, and technical evidence
Stay current with emerging threats, attack vectors, and security trends relevant to web applications and source code vulnerabilities
Support internal security initiatives and contribute to the development of secure coding standards and best practices
Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications
Minimum three years of recent experience in web application penetration testing and source code analysis
Bachelor's degree from an accredited college or university in computer science, cybersecurity, or a related field
Familiarity with secure coding practices and common vulnerabilities (for example, OWASP Top 10)
Hands‑on experience with SAST and DAST tools, and scripting languages such as Python, JavaScript, or Java
Strong analytical, problem‑solving, and communication skills
Relevant certifications (for example: OSCP, GWAPT, CEH, CSSLP) are a plus but not required
Ability to travel as required
Applicants must be authorized to work in the U.S. without the need for employment‑based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H‑1B, L‑1, TN, O‑1, E‑3, H‑1B1, F‑1, J‑1, OPT, CPT or any other employment‑based visa)
KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin or any other category protected by applicable federal, state or local laws.
#J-18808-Ljbffr
Responsibilities
Conduct in-depth source code analysis and manual penetration testing of web applications to identify vulnerabilities and security flaws
Collaborate with development and engineering teams to remediate findings and provide secure coding guidance
Utilize industry-standard tools (for example: Burp Suite, OWASP ZAP, Fortify, Checkmarx) to perform dynamic and static application security testing
Document and communicate findings in detailed reports, including risk ratings, remediation recommendations, and technical evidence
Stay current with emerging threats, attack vectors, and security trends relevant to web applications and source code vulnerabilities
Support internal security initiatives and contribute to the development of secure coding standards and best practices
Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications
Minimum three years of recent experience in web application penetration testing and source code analysis
Bachelor's degree from an accredited college or university in computer science, cybersecurity, or a related field
Familiarity with secure coding practices and common vulnerabilities (for example, OWASP Top 10)
Hands‑on experience with SAST and DAST tools, and scripting languages such as Python, JavaScript, or Java
Strong analytical, problem‑solving, and communication skills
Relevant certifications (for example: OSCP, GWAPT, CEH, CSSLP) are a plus but not required
Ability to travel as required
Applicants must be authorized to work in the U.S. without the need for employment‑based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H‑1B, L‑1, TN, O‑1, E‑3, H‑1B1, F‑1, J‑1, OPT, CPT or any other employment‑based visa)
KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin or any other category protected by applicable federal, state or local laws.
#J-18808-Ljbffr