Cyber - KPMG International - Consultant-SAST , DAST
Bangalore, Karnataka, India
- *Description for Internal Candidates
Roles and Responsibilities: SAST, DAST-Consultant - Analyze False positives on the Fortify Scans to identify potential security risks and vulnerabilities.
- Perform manual application penetration tests on one or more of the following to discover and exploit vulnerabilities: web applications, internal applications, APIs, internal and external networks, and mobile applications
- Experience in one or more of the following a plus: mobile application testing, Web application pen testing, application architecture and business logic analysis.
- Need to work on application tools to perform security tests: AppScan, NetsSparker, Acunetix, Checkmarx, Veracode, BurpSuite, OWASP ZAP, Kali Linux.
- Implement advanced cryptographic techniques, authentication, and authorization protocols to secure sensitive data.
- Establish and maintain Access Control Lists (ACL) to manage and regulate network access.
Develop and execute Disaster Recovery (DR) plans to ensure business continuity in case of security incidents. - Collaborate effectively with cross-functional teams, including developers, IT operations, and business stakeholders to integrate security best practices seamlessly into project workflows.
- Provide mentorship and guidance to junior security staff and foster a culture of proactive security awareness within the organization.
- One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA
- *Description for Internal Candidates
Roles and Responsibilities: SAST, DAST-Consultant - Analyze False positives on the Fortify Scans to identify potential security risks and vulnerabilities.
- Perform manual application penetration tests on one or more of the following to discover and exploit vulnerabilities: web applications, internal applications, APIs, internal and external networks, and mobile applications
- Experience in one or more of the following a plus: mobile application testing, Web application pen testing, application architecture and business logic analysis.
- Need to work on application tools to perform security tests: AppScan, NetsSparker, Acunetix, Checkmarx, Veracode, BurpSuite, OWASP ZAP, Kali Linux.
- Implement advanced cryptographic techniques, authentication, and authorization protocols to secure sensitive data.
- Establish and maintain Access Control Lists (ACL) to manage and regulate network access.
Develop and execute Disaster Recovery (DR) plans to ensure business continuity in case of security incidents. - Collaborate effectively with cross-functional teams, including developers, IT operations, and business stakeholders to integrate security best practices seamlessly into project workflows.
- Provide mentorship and guidance to junior security staff and foster a culture of proactive security awareness within the organization.
- One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA
Prior Experience:
The candidate must have 4 to 6 years of relevant experience in a similar role, preferably in a professional services organization.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
5
0
0
Category:
Consulting Jobs
Tags: APIs Burp Suite Checkmarx CREST DAST Ethical hacking Exploit GWAPT Kali Linux OSWE OWASP Pentesting SAST Veracode Vulnerabilities
Region:
Asia/Pacific
Country:
India
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Specialist jobsInformation System Security Officer jobsSenior Security Analyst jobsSenior Cloud Security Engineer jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsSystems Engineer jobsInformation Security Manager jobsSenior Information Security Analyst jobsSenior Network Security Engineer jobsIT Security Engineer jobsCyber Security Specialist jobsIT Security Analyst jobsChief Information Security Officer jobsSecurity Specialist jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Cyber Security Engineer jobsSenior Product Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Information Security Engineer jobsCyber Security Architect jobsThreat Intelligence Analyst jobsSenior Software Engineer jobs
Java jobsEncryption jobsBash jobsTS/SCI jobsEDR jobsIDS jobsThreat detection jobsSQL jobsIPS jobsSplunk jobsSDLC jobsMalware jobsTerraform jobsFinance jobsTop Secret jobsSOC 2 jobsDocker jobsRMF jobsForensics jobsActive Directory jobsIntrusion detection jobsCompTIA jobsGIAC jobsOWASP jobsITIL jobs
VPN jobsHIPAA jobsDoDD 8570 jobsData Analytics jobsOSCP jobsIT infrastructure jobsAnsible jobsTCP/IP jobsSAP jobsCRISC jobsUNIX jobsCCSP jobsBanking jobsSANS jobsJavaScript jobsClearance Required jobsMITRE ATT&CK jobsSOAR jobsSOX jobsMachine Learning jobsSecurity strategy jobsZero Trust jobsDNS jobsNIST 800-53 jobsJira jobs