Cyber - KPMG International - Consultant-SAST , DAST
Bangalore, Karnataka, India
- *Description for Internal Candidates
Roles and Responsibilities: SAST, DAST-Consultant - Analyze False positives on the Fortify Scans to identify potential security risks and vulnerabilities.
- Perform manual application penetration tests on one or more of the following to discover and exploit vulnerabilities: web applications, internal applications, APIs, internal and external networks, and mobile applications
- Experience in one or more of the following a plus: mobile application testing, Web application pen testing, application architecture and business logic analysis.
- Need to work on application tools to perform security tests: AppScan, NetsSparker, Acunetix, Checkmarx, Veracode, BurpSuite, OWASP ZAP, Kali Linux.
- Implement advanced cryptographic techniques, authentication, and authorization protocols to secure sensitive data.
- Establish and maintain Access Control Lists (ACL) to manage and regulate network access.
Develop and execute Disaster Recovery (DR) plans to ensure business continuity in case of security incidents. - Collaborate effectively with cross-functional teams, including developers, IT operations, and business stakeholders to integrate security best practices seamlessly into project workflows.
- Provide mentorship and guidance to junior security staff and foster a culture of proactive security awareness within the organization.
- One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA
- *Description for Internal Candidates
Roles and Responsibilities: SAST, DAST-Consultant - Analyze False positives on the Fortify Scans to identify potential security risks and vulnerabilities.
- Perform manual application penetration tests on one or more of the following to discover and exploit vulnerabilities: web applications, internal applications, APIs, internal and external networks, and mobile applications
- Experience in one or more of the following a plus: mobile application testing, Web application pen testing, application architecture and business logic analysis.
- Need to work on application tools to perform security tests: AppScan, NetsSparker, Acunetix, Checkmarx, Veracode, BurpSuite, OWASP ZAP, Kali Linux.
- Implement advanced cryptographic techniques, authentication, and authorization protocols to secure sensitive data.
- Establish and maintain Access Control Lists (ACL) to manage and regulate network access.
Develop and execute Disaster Recovery (DR) plans to ensure business continuity in case of security incidents. - Collaborate effectively with cross-functional teams, including developers, IT operations, and business stakeholders to integrate security best practices seamlessly into project workflows.
- Provide mentorship and guidance to junior security staff and foster a culture of proactive security awareness within the organization.
- One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA
Prior Experience:
The candidate must have 4 to 6 years of relevant experience in a similar role, preferably in a professional services organization.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
9
0
1
Category:
Consulting Jobs
Tags: APIs Burp Suite Checkmarx CREST DAST Ethical hacking Exploit GWAPT Kali Linux OSWE OWASP Pentesting SAST Veracode Vulnerabilities
Region:
Asia/Pacific
Country:
India
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Specialist jobsInformation System Security Officer jobsSenior Security Analyst jobsSenior Cloud Security Engineer jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsSystems Engineer jobsSenior Information Security Analyst jobsCyber Security Specialist jobsSenior Network Security Engineer jobsInformation Security Manager jobsIT Security Analyst jobsChief Information Security Officer jobsIT Security Engineer jobsSecurity Consultant jobsSenior Information Security Engineer jobsSecurity Specialist jobsInformation System Security Officer (ISSO) jobsSenior Product Security Engineer jobsInformation Systems Security Engineer jobsSenior Cyber Security Engineer jobsCyber Threat Intelligence Analyst jobsCyber Security Architect jobsSenior Software Engineer jobsCybersecurity Specialist jobs
EDR jobsSaaS jobsEncryption jobsJava jobsBash jobsTop Secret jobsThreat detection jobsTerraform jobsSplunk jobsRMF jobsIDS jobsSDLC jobsSOC 2 jobsIPS jobsMalware jobsSQL jobsActive Directory jobsCompTIA jobsDocker jobsFinance jobsForensics jobsGIAC jobsIntrusion detection jobsDoDD 8570 jobsITIL jobs
OWASP jobsVPN jobsHIPAA jobsIT infrastructure jobsCRISC jobsAnsible jobsClearance Required jobsTCP/IP jobsCCSP jobsOSCP jobsMITRE ATT&CK jobsData Analytics jobsBanking jobsZero Trust jobsNIST 800-53 jobsJira jobsCISO jobsUNIX jobsEndpoint security jobsSOAR jobsDNS jobsIndustrial jobsPolygraph jobsSOX jobsGCIH jobs