At KPMG, you'll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world.
Are you a talented individual with a proven track record on executing project deliverables.
This is a key role within the Cyber Defense - Offensive Security Team at KPMG, where the candidate will serve as a subject matter expert primarily in web application security, and also perform infrastructure vulnerability assessment and penetration testing, red/purple team assessment and social engineering exercises. The selected candidate will work on client projects to understand requirements, conduct manual and automated penetration tests, draft reports and provide detailed walkthroughs of the reports to relevant client stakeholders.
Perform manual and automated application security assessments on web applications, mobile applications and network infrastructure using industry standards. This includes controlled exploitation of identified vulnerabilities, simulating real-world attacks through manual penetration testing.
Define and execute test cases to identify and exploit vulnerabilities and weaknesses.
Analyze the impact and severity of exploits, determining the associated risks and potential consequences.
Stay updated with the latest security vulnerabilities, techniques, and industry best practices.
Bachelor's or relevant degree in Computer Science, Information Security, or a related field.
Minimum of 1 year of experience in application security testing.
Knowledge of performing infrastructure vulnerability assessment and penetration testing, red team assessment and social engineering.
Expertise in security testing frameworks, including:
Open Web Application Security Project (OWASP)
Open-Source Security Testing Methodology Manual (OSSTMM)
Penetration Testing Execution Standard (PTES)
Programming knowledge (python, java)
HTB Certified Penetration Testing Specialist (HTB CPTS)
Excellent communication skills to present findings and recommendations to technical and non-technical stakeholders.
We prioritize candidates that demonstrate a strong passion for cybersecurity and have hands-on experience showcasing their skills in a local lab environment , such as through capture-the-flag (CTF) competitions, personal lab projects, or open-source contributions.
Integrity , we do what is right | Excellence , we never stop learning and improving | Courage , we think and act boldly | Together , we respect each other and draw strength from our differences | For Better , we do what matters
At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. If you require support, please contact KPMG's Employee Relations Service team by calling View phone number on onjobcentre.ca.