Specialist, Security Tester
22 hours ago
Raleigh
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Specialist, Security Tester to join our ___ practice. Responsibilities: • Perform automated application / network penetration tests on one or more of the following to discover and exploit vulnerabilities: web applications, internal applications, APIs, internal and external networks, and mobile applications, • Execute dynamic application security tests on web applications and static application security tests on source code, including identifying false positives and reprioritizing findings severity, • Conduct vulnerability analysis against internal and external networks leveraging automation techniques and solutions, • Elevate to executing independently in either the application or network domain within one year of service, • Minimum one year of recent experience performing application and/or network penetration tests using tools such as AppScan, NetsSparker, Acunetix, BurpSuite, OWASP ZAP, Tenable Nessus, Qualys, Kali Linux, Metasploit, or equivalent; minimum one year of recent experience working with technical and non-technical audiences in reporting results and leading remediation conversations, • Bachelor's degree from an accredited college or university is preferred. Minimum of a high school diploma or GED required., • Experience in one or more of the following a plus: mobile application testing, manual code analysis, and/or static analysis using Veracode, Fortify, SonarQube, Checkmarx, Contrast or equivalent, • Experience in one of the following a plus: Python, JavaScript, PHP, C/C++, SQL, and more, • One or more ethical hacking certifications preferred (for example: CEH, GWAPT, GPEN, OSCP, OSWA), • Ability to travel as necessary