KPMG US
Senior Specialist, AI Penetration Tester
KPMG US, San Francisco, California, United States, 94199
Join to apply for the
Senior Specialist, AI Penetration Tester
role at
KPMG US
KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand, and looking forward we do not anticipate that slowing down. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility and leading market tools, we make sure our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory.
KPMG is currently seeking a Senior Specialist, AI Penetration Tester to join our Managed Services practice.
Responsibilities
Execute AI-focused penetration testing engagements, including manual testing of systems incorporating AI/ML, objective-based testing of AI-driven features, and coverage of both traditional and AI-centric attack surfaces
Perform threat modeling for AI-powered software systems, evaluate AI-related business logic, and conduct architecture reviews with emphasis on adversarial ML vectors, prompt-based vulnerabilities, and other AI-specific security risks
Develop and improve AI-driven tools and methodologies for offensive security tasks such as discovery, exploitation, fuzzing, and adversarial ML testing, focusing on web apps, APIs, and mobile clients
Demonstrate AI penetration testing findings to technical and non-technical audiences, including live demos, and collaborate with engineering, development, and security teams to lead remediation discussions and advise on secure AI model development and deployment best practices
Research emerging AI attack techniques, evaluate their potential impact, identify vulnerabilities, and provide actionable recommendations to strengthen AI defenses
Collaborate with internal Red Teams, SOC analysts, and AI security researchers to refine AI red teaming approaches by integrating new adversarial ML techniques and proven exploitation tactics
Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications
Minimum three years of recent penetration testing experience focused on APIs, web applications, and mobile applications; experience with AI model testing or AI security highly desirable
Bachelor's degree from an accredited college or university is required
Proven background in AI red teaming and adversarial attack development, including prompt engineering attacks, LLM-based vulnerability analysis, and model evasion techniques
Proficiency with penetration testing tools (for example: Burp Suite Pro, Netsparker, Checkmarx) and AI security frameworks (for example: TensorFlow, PyTorch, LLM APIs, LangChain)
Strong communication and presentation skills to explain AI-related vulnerabilities to technical and non-technical stakeholders and drive remediation
One or more major ethical hacking certifications (for example: GWAPT, CREST, OSWE, OSWA) and certifications or training in AI security techniques
Ability to travel as necessary
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity
KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state, and local laws.
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity.
#J-18808-Ljbffr
Senior Specialist, AI Penetration Tester
role at
KPMG US
KPMG Advisory practice is currently our fastest growing practice. We are seeing tremendous client demand, and looking forward we do not anticipate that slowing down. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility and leading market tools, we make sure our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory.
KPMG is currently seeking a Senior Specialist, AI Penetration Tester to join our Managed Services practice.
Responsibilities
Execute AI-focused penetration testing engagements, including manual testing of systems incorporating AI/ML, objective-based testing of AI-driven features, and coverage of both traditional and AI-centric attack surfaces
Perform threat modeling for AI-powered software systems, evaluate AI-related business logic, and conduct architecture reviews with emphasis on adversarial ML vectors, prompt-based vulnerabilities, and other AI-specific security risks
Develop and improve AI-driven tools and methodologies for offensive security tasks such as discovery, exploitation, fuzzing, and adversarial ML testing, focusing on web apps, APIs, and mobile clients
Demonstrate AI penetration testing findings to technical and non-technical audiences, including live demos, and collaborate with engineering, development, and security teams to lead remediation discussions and advise on secure AI model development and deployment best practices
Research emerging AI attack techniques, evaluate their potential impact, identify vulnerabilities, and provide actionable recommendations to strengthen AI defenses
Collaborate with internal Red Teams, SOC analysts, and AI security researchers to refine AI red teaming approaches by integrating new adversarial ML techniques and proven exploitation tactics
Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Qualifications
Minimum three years of recent penetration testing experience focused on APIs, web applications, and mobile applications; experience with AI model testing or AI security highly desirable
Bachelor's degree from an accredited college or university is required
Proven background in AI red teaming and adversarial attack development, including prompt engineering attacks, LLM-based vulnerability analysis, and model evasion techniques
Proficiency with penetration testing tools (for example: Burp Suite Pro, Netsparker, Checkmarx) and AI security frameworks (for example: TensorFlow, PyTorch, LLM APIs, LangChain)
Strong communication and presentation skills to explain AI-related vulnerabilities to technical and non-technical stakeholders and drive remediation
One or more major ethical hacking certifications (for example: GWAPT, CREST, OSWE, OSWA) and certifications or training in AI security techniques
Ability to travel as necessary
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity
KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state, and local laws.
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity.
#J-18808-Ljbffr