Lead Specialist, MAST Application Penetration Testing Manager
KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be an impact, advance your skills, deepen your experiences, and have the flexibility to find new areas of inspiration, consider a career in Advisory.
About the role
KPMG is seeking a Lead Specialist, MAST Application Penetration Testing Manager to join our Managed Services practice. In this role, you will provide strategic direction for application penetration testing teams, manage client engagements, and foster growth and learning among team members.
Responsibilities
- Provide strategic direction for application penetration testing teams to develop growth of the services solution and manage client engagements
- Demonstrate exceptional technical capability in application penetration testing from a manual perspective
- Lead client engagements and provide technical leadership as well as advice to team members on application penetration testing engagements
- Promote and enable thought leadership, growth, and learning amongst team members
- Engage with non-technical audiences around testing processes and techniques, as well as report read-outs; guide technical audiences on remediation options and assist them in weighing those options
- Partner with the Cyber teams to develop new testing techniques, automation for testing, and marketing collateral to support the practice
- Mentor onshore and offshore team members on tools and techniques in performing testing; operate as a mentor and people leader to foster career growth amongst team members
- Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Requirements
- Minimum five years of recent experience using application penetration tools to perform security tests such as AppScan, Netsparker, Acunetix, ZAP, Veracode, BurpSuite, or equivalent
- Minimum five years of recent experience working with technical and non-technical audiences in reporting results and leading remediation conversations
- Minimum five years of recent experience leading application security testing teams in a consulting environment
- Bachelor's degree from an accredited college/university or equivalent industry experience
- One or more major ethical hacking certifications preferred: Certified Information Systems Security Professional (CISSP), GIAC Web Application Penetration Tester (GWAPT), Council of Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)
- Experience in one or more areas such as mobile application testing, code development, manual code analysis, and/or static analysis using Veracode, Fortify, SonarQube, Checkmarx, Contrast, or equivalent
- Ability to travel as required
- Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future
Benefits
- Comprehensive medical and dental plans, vision coverage, disability and life insurance
- 401(k) plans
- Robust suite of personal well-being benefits to support mental health
- Personal Time Off per fiscal year, based on job classification, standard work hours, and years of service
- Two annual breaks where employees are not required to use Personal Time Off: one at year-end and one around the July 4th holiday
Salary ranges are displayed for locations where required by local/state regulations. Offered salary is determined based on applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications, and market considerations. For more details, visit KPMG Pay Transparency.