Skip to content
mimi

Senior Specialist, MAST Application Penetration Tester

KPMG US

Washington · On-site Full-time Senior $96k – $208k/yr 1mo ago

About the role

About

The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory.

KPMG is currently seeking a Senior Specialist, MAST Application Penetration Tester to join our Managed Services practice.

Responsibilities

  • Conduct manual application penetration testing against API's (REST/SOAP), Web Applications, Mobile applications, and thick client applications
  • Perform objective based on abstract penetration testing engagements
  • Execute threat modeling, evaluate application business logic, and perform application architecture reviews
  • Demonstrate application testing experience in real time via demos to both internal and external audiences
  • Function independently in penetration testing engagements, with minimal oversight and guidance
  • Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment

Qualifications

  • Minimum three years of recent experience in application penetration testing of Application Programming Interface (API's), web applications, or mobile applications
  • Bachelor's degree from an accredited college/university or equivalent industry experience
  • Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
  • Experience with burp suite pro, and other app testing tools such as Netsparker and Checkmarx
  • One or more major ethical hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
  • Ability to travel as required
  • Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Disability insurance
  • Life insurance
  • 401(k) plans
  • Personal Time Off per fiscal year
  • Two breaks each year where employees will not be required to use Personal Time Off (year end and around July 4th holiday)

Skills

APIBurp SuiteCheckmarxNetsparkerRESTSOAP

Don't send a generic resume

Paste this job description into Mimi and get a resume tailored to exactly what the hiring team is looking for.

Get started free