Cyber - KPMG International - Consultant-SAST , DAST
Bangalore, Karnataka, India
- *Description for Internal Candidates
Roles and Responsibilities: SAST, DAST-Consultant - Analyze False positives on the Fortify Scans to identify potential security risks and vulnerabilities.
- Perform manual application penetration tests on one or more of the following to discover and exploit vulnerabilities: web applications, internal applications, APIs, internal and external networks, and mobile applications
- Experience in one or more of the following a plus: mobile application testing, Web application pen testing, application architecture and business logic analysis.
- Need to work on application tools to perform security tests: AppScan, NetsSparker, Acunetix, Checkmarx, Veracode, BurpSuite, OWASP ZAP, Kali Linux.
- Implement advanced cryptographic techniques, authentication, and authorization protocols to secure sensitive data.
- Establish and maintain Access Control Lists (ACL) to manage and regulate network access.
Develop and execute Disaster Recovery (DR) plans to ensure business continuity in case of security incidents. - Collaborate effectively with cross-functional teams, including developers, IT operations, and business stakeholders to integrate security best practices seamlessly into project workflows.
- Provide mentorship and guidance to junior security staff and foster a culture of proactive security awareness within the organization.
- One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA
- *Description for Internal Candidates
Roles and Responsibilities: SAST, DAST-Consultant - Analyze False positives on the Fortify Scans to identify potential security risks and vulnerabilities.
- Perform manual application penetration tests on one or more of the following to discover and exploit vulnerabilities: web applications, internal applications, APIs, internal and external networks, and mobile applications
- Experience in one or more of the following a plus: mobile application testing, Web application pen testing, application architecture and business logic analysis.
- Need to work on application tools to perform security tests: AppScan, NetsSparker, Acunetix, Checkmarx, Veracode, BurpSuite, OWASP ZAP, Kali Linux.
- Implement advanced cryptographic techniques, authentication, and authorization protocols to secure sensitive data.
- Establish and maintain Access Control Lists (ACL) to manage and regulate network access.
Develop and execute Disaster Recovery (DR) plans to ensure business continuity in case of security incidents. - Collaborate effectively with cross-functional teams, including developers, IT operations, and business stakeholders to integrate security best practices seamlessly into project workflows.
- Provide mentorship and guidance to junior security staff and foster a culture of proactive security awareness within the organization.
- One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA
Prior Experience:
The candidate must have 4 to 6 years of relevant experience in a similar role, preferably in a professional services organization.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
10
0
1
Category:
Consulting Jobs
Tags: APIs Burp Suite Checkmarx CREST DAST Ethical hacking Exploit GWAPT Kali Linux OSWE OWASP Pentesting SAST Veracode Vulnerabilities
Region:
Asia/Pacific
Country:
India
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Specialist jobsSecurity Operations Engineer jobsSenior Security Analyst jobsSystems Administrator jobsSenior Cybersecurity Engineer jobsCybersecurity Editor jobsSenior Information Security Analyst jobsCybersecurity Content Editor jobsInformation Security Manager jobsCyber Security Specialist jobsSenior Network Security Engineer jobsIT Security Analyst jobsSenior Information Security Engineer jobsChief Information Security Officer jobsInformation System Security Officer (ISSO) jobsSecurity Consultant jobsSenior Product Security Engineer jobsIT Security Engineer jobsSecurity Specialist jobsInformation Systems Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Cyber Security Engineer jobsSenior Software Engineer jobsSecurity Operations Analyst jobsSenior IT Auditor jobs
EDR jobsSaaS jobsCEH jobsEncryption jobsJava jobsSplunk jobsTop Secret jobsThreat detection jobsSDLC jobsTerraform jobsIDS jobsMalware jobsRMF jobsIPS jobsFinance jobsSQL jobsDocker jobsSOC 2 jobsForensics jobsCompTIA jobsIntrusion detection jobsActive Directory jobsOWASP jobsClearance Required jobsAnsible jobs
VPN jobsGIAC jobsHIPAA jobsITIL jobsTCP/IP jobsIT infrastructure jobsDoDD 8570 jobsCRISC jobsBanking jobsMITRE ATT&CK jobsOSCP jobsSOAR jobsJira jobsDNS jobsSOX jobsIndustrial jobsData Analytics jobsZero Trust jobsCCSP jobsUNIX jobsGCIH jobsJavaScript jobsCISO jobsArtificial Intelligence jobsNIST 800-53 jobs