Lead Application Security Penetration Testing Specialist

New York 6 days agoFull-time External
Negotiable
KPMG's Advisory practice is on a path of impressive growth driven by significant client demand. We celebrate adaptability and collaboration within our team-oriented culture. At KPMG, our employees are our priority, and we provide extensive opportunities for learning and career development. Our top-tier facilities and market-leading tools support ongoing professional and personal growth. If you're looking for a nurturing environment where you can be your true self, make a meaningful impact, enhance your skills, and discover fresh avenues of inspiration, consider taking your career to the next level with us. KPMG is excited to invite applications for the position of Lead Application Security Penetration Testing Specialist within our Managed Services practice. Responsibilities: • Conduct comprehensive manual penetration testing on APIs (REST/SOAP), web applications, mobile applications, and thick client applications. • Participate in objective-driven penetration testing projects. • Engage in threat modeling, business logic assessment, and application architecture review. • Present application testing findings and methodologies effectively to both technical and non-technical stakeholders. • Work autonomously on penetration testing assignments with minimal supervision. • Uphold values of integrity, professionalism, and personal accountability to create a respectful workplace at KPMG. Qualifications: • A minimum of three years of relevant experience in application penetration testing for APIs, web applications, or mobile applications. • A Bachelor's degree from an accredited institution or equivalent industry experience. • Excellent communication skills to convey results to a diverse audience and facilitate discussions on remediation. • Proficient in Burp Suite Pro and other application testing tools like Netsparker and Checkmarx. • Preferred certifications include GIAC Web Application Penetration Tester (GWAPT), CREST, Offensive Security Web Expert (OSWE), or Offensive Security Web Assessor (OSWA). • Willingness to travel as needed. • Eligible to work in the U.S. without the need for employment-based visa sponsorship at any time. KPMG offers a competitive compensation and benefits package. We are an equal opportunity employer and comply with all applicable laws regarding recruitment and hiring. All qualified candidates will be considered without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by law. KPMG conducts recruitment on a rolling basis. Interested candidates are encouraged to apply promptly for any positions of interest.