Senior Consultant - Digital Trust (Cyber Defense)

KPMG

HybridFull TimeInformation Technology
Posted Today

Job description

Responsibilities

  • Executing penetration tests of web applications, mobile applications, APIs, and network infrastructure
  • Participating in red team and social engineering engagements, including phishing and physical intrusion scenarios
  • Setting up, maintaining, and operating C2 infrastructure using tools such as Cobalt Strike or Sliver
  • Assisting in adversary emulation exercises based on frameworks like MITRE ATT&CK
  • Preparing detailed, risk-based reports and presenting technical findings to internal and client teams
  • Developing and maintaining internal tools, scripts, and documentation for offensive testing
  • Collaborating with blue/purple teams to improve client defenses
  • Supporting business development activities including proposal development and budgeting
  • Developing constructive client relationships and maintaining a professional network

Requirements

  • At least 5+ years of experience in cyber security with a focus on offensive security and VAPT
  • Strong understanding of penetration testing methodologies such as OWASP, PTES, or NIST
  • Practical experience in Web, Mobile, API, LLM, cloud, and network-based VAPT assessments
  • Experience conducting secure source code reviews in languages like JavaScript, C#, Python, Swift, Java, or SQL
  • Practical experience with red teaming and purple teaming concepts
  • Experience in a consulting environment (Big Four experience is a plus)
  • Bachelor's degree in Computer Science, Information Security, or a related field
  • Mandatory OSCP certification plus at least one of: OSEP, OSWE, CCT INF, or CCT APP
  • Proficiency with tools like Burp Suite, Nmap, Metasploit, and BloodHound
  • Proficiency in at least one scripting language (Python, PowerShell, or Bash) and one programming language (Java, C#, or JavaScript)

About the Company

KPMG is a global leader in professional services, providing expertise in digital trust, cyber defense, and risk management to clients across various sectors.

Skills & tools

Penetration TestingRed TeamingCybersecurity

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 015+ years cyber security experience
  2. 02OSCP certification mandatory
  3. 03Experience in VAPT
  4. 04Proficiency in scripting and programming
  5. 05Bachelor's degree in CS or Information Security
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches