KPMG Assurance and Consulting Services LLP

Penetration Tester

KPMG Assurance and Consulting Services LLP

Mumbai, Maharashtra, India · Full Time

Be the first to apply

Experience
Any
Salary
Openings
1
Posted
1 day ago
Work mode
In office
Education
Any Graduate
Eligibility
Applicants must hold a graduate degree in any discipline.
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About KPMG in India

KPMG is a leading professional services firm established in India since August 1993, providing services to various sectors across the country through its offices in major cities including Mumbai. Leveraging a global network and deep understanding of local laws and markets, KPMG delivers performance-oriented, industry-specific, and technology-enabled solutions to national and international clients.

Role Overview

The selected candidate will participate in diverse projects within a collaborative and fast-paced setting, focusing on software development tasks and adhering to KPMG’s best practices and policies. The role entails working closely with architects, analysts, designers, and developers to enhance current product offerings and create new ones, with a requirement to quickly adapt to new technologies when necessary.

Key Responsibilities

  • Conduct penetration testing across web, mobile, API, network, and cloud environments.
  • Perform vulnerability assessments to identify security threats in enterprise systems.
  • Execute black-box, grey-box, and white-box security evaluations simulating realistic cyberattacks.
  • Validate detected vulnerabilities and collaborate with development teams on fixes.
  • Prepare comprehensive technical and executive security assessment reports.
  • Evaluate security risks related to AI/ML applications and large language models.
  • Test AI-driven applications, including chatbots and generative AI solutions for vulnerabilities like prompt injection and model poisoning.
  • Support secure AI development best practices and governance efforts.
  • Review third-party AI tools and integrations for security concerns.
  • Collaborate with SOC, DevSecOps, and development teams to strengthen security frameworks.
  • Assist in threat modeling and secure architecture evaluations.
  • Engage in red team exercises and adversary simulations.
  • Provide security awareness training and technical advice to internal stakeholders.

Skill Requirements

  • Deep knowledge of OWASP Top 10, SANS Top 25, and MITRE ATT&CK frameworks.
  • Practical expertise in tools such as Burp Suite Pro, Nmap, Metasploit, Nessus/Qualys, Wireshark, OWASP ZAP, and Kali Linux.
  • Experience with security testing in web, API, network, cloud, and wireless domains.
  • Understanding of authentication concepts including OAuth, JWT, SAML, and IAM.
  • Familiarity with secure coding practices and software development lifecycle (SDLC) processes.
  • Knowledge of AI/ML fundamentals and generative AI applications.
  • Awareness of AI-specific security vulnerabilities like prompt injection, adversarial attacks, and data privacy risks.
  • Experience with AI platforms such as OpenAI, Azure AI, LangChain or equivalent preferred.
  • Proficiency in programming/scripting languages including Python, PowerShell, Bash, and preferably JavaScript.

Equal Opportunity Statement

KPMG India is committed to providing equal employment opportunities without discrimination based on attributes such as color, caste, religion, age, gender, national origin, disability, or other legally protected statuses. The firm encourages diversity and inclusivity in its workforce.

Minimum education

Bachelor's Degree

Tools & software

Python required Nmap required Metasploit required
🤖
Online · instant AI help
Broxer