Manager of Application Penetration Testing

New York 9 days agoFull-time External
Negotiable
KPMG's Advisory practice is experiencing rapid growth due to significant client demand. We prioritize a collaborative and adaptive team culture where our people are the focus. With ample opportunities for learning and career advancement, cutting-edge training facilities, and leading tools, we ensure our professionals thrive both personally and professionally. If you're searching for a workplace where you can be authentic, make a meaningful impact, enhance your skills, broaden your experiences, and enjoy flexibility, consider a career with us. KPMG is looking for a skilled Manager of Application Penetration Testing to join our Managed Services practice. Responsibilities: • Provide strategic leadership for application penetration testing teams, driving service growth and managing client engagements while demonstrating exceptional technical expertise in manual application penetration testing. • Lead client engagements, offering technical guidance and support to team members on application penetration testing projects. • Encourage thought leadership and promote continuous learning within the team. • Effectively communicate with both technical and non-technical audiences about testing processes and outcomes; advise technical teams on remediation strategies and assist them in evaluating these options. • Collaborate with Cyber teams to innovate testing techniques, automate testing processes, and create marketing materials that support practice growth; mentor both onshore and offshore personnel in testing tools and methodologies. • Uphold KPMG's values by maintaining integrity, professionalism, and responsibility to foster a respectful and courteous work environment. Qualifications: • A minimum of five years of recent experience using application penetration testing tools such as AppScan, Netsparker, Acunetix, ZAP, Veracode, BurpSuite, or equivalent; five years of experience leading application security testing teams in a consulting capacity; experience engaging with both technical and non-technical audiences in reporting and remediation discussions. • Bachelor's degree from an accredited college/university or equivalent industry experience. • Preferred: One or more major ethical hacking certifications (CISSP, GWAPT, CREST, OSWE, OSWA). • Experience in mobile application testing, code development, manual code analysis, or static analysis using tools like Veracode, Fortify, SonarQube, Checkmarx, Contrast, or equivalent is preferred. • Willingness to travel as needed. • Must be authorized to work in the U.S. without requiring employment-based visa sponsorship now or in the future. KPMG offers a comprehensive and competitive benefits package. We are an equal opportunity employer, compliant with all applicable recruitment and hiring laws. All qualified applicants will be considered, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other protected category. KPMG recruits on a rolling basis. Candidates are encouraged to apply promptly for roles they are qualified for and interested in. For applicants in Los Angeles County: Material job duties for this position are listed above. Criminal history may directly impact job duties and responsibilities. In line with various Fair Chance Acts, we consider qualified applicants with arrest and conviction records.