KPMG India Logo

KPMG India

Senior - AppSec / Red Teaming

Posted Yesterday
Be an Early Applicant
In-Office
Kolkata, West Bengal, IND
Senior level
In-Office
Kolkata, West Bengal, IND
Senior level
Lead and perform VAPT and red team engagements across web, mobile, API, network, cloud, and thick-client systems. Manually identify and exploit vulnerabilities, develop PoC exploits, conduct SAST/SCA reviews, prepare technical reports with remediation recommendations, automate testing tasks, and collaborate with development and infrastructure teams to improve security posture and support compliance audits.
The summary above was generated by AI

About KPMG in India

KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada. 

KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.

  • Strong understanding of security risks in networks and application platforms 

  • Strong understanding of network security, infrastructure security and application security,

  • Strong understanding of OSI, TCP/IP model and network basics 

  • Demonstrate technical penetration testing skills on IT infrastructure, web applications, mobile platforms and Red teaming 

  • Strong technical skills: Information security, network security, Windows security, UNIX/Linux security, web and mobile application security, Cloud platforms.

  • Good knowledge on web,Thick client,API, Mobile (Android,iOS) VAPT and Penetration testing assessments.

  • Broad knowledge of security technologies for applications, databases, networks, servers, and desktops. 

  • Ability to perform manual penetration testing.

  • Experience in Application Security Testing, or related functions Vulnerability Assessment, Penetration testing.

  • Perform penetration testing of various thick client software, web applications, and communications infrastructure to assist in hardening the cybersecurity posture against malicious actors 

  • Perform technical writing to communicate the preparation, testing, and recommendation phases for various security tests. Work with stakeholders to remediate system vulnerabilities.  

  • Expertise in the phases of penetration testing. Familiarity with Kali Linux distribution and the associated penetration testing tools suite. Experience in penetration testing simulations like Hack the Box or Capture the Flag exercises considered a plus.

  • Good Understanding of OWASP top 10 and mitigation techniques

  • Experience in performing web application security assessments using hands on techniques for identifying SQL injections, XSS, Security Misconfiguration, CSRF, authentication/ authorization issues

  • Experience on both commercial, open source tools and frameworks but not limited: Burpsuite, Checkmarx, Metasploit, Core-Impact, Kali-Linux, AppScan, WebInspect, SSLScan, Soap UI Pro, SonarQube, Qualys, Nikto, Nessus, nmap, sqlmap, OWASP ZAP .

  • Conduct Source code(SAST/SCA) Analysis manually.

  • Knowledge on scripting language like Python, Shell is an add-on.

  • Perform Vulnerability Assessment and Penetration Testing (VAPT) for web, mobile, API, network, cloud, and infrastructure components.

  • Identify, exploit, and document security vulnerabilities using manual and automated techniques.

  • Conduct source code reviews to detect security flaws.

  • Develop proof-of-concept (PoC) exploits for validated vulnerabilities.

  • Prepare detailed technical reports, including findings, severity ratings, and remediation recommendations.

  • Work closely with product, development, and infrastructure teams to help fix security gaps.

  • Research the latest vulnerabilities, exploits, attack trends, and security tools.

  • Participate in red team / blue team exercises when required.

  • Ensure VAPT activities are aligned with security standards (OWASP, SANS, NIST, ISO 27001, etc.).

  • Automate repetitive security testing tasks using scripts or tools.

  • Support compliance audits and security certifications.

Qualifications
  • 4+ years of hands-on experience in VAPT or Security Research.

  • Strong understanding of:

    • OWASP Top 10

    • MITRE ATT&CK

    • Web and mobile security concepts

    • Network security protocols

  • Hands-on experience with tools such as:
    Burp Suite, Metasploit, Nmap, Nessus, Wireshark, Kali Linux, Nikto, Fortify, ZAP, MobSF, etc.

  • Ability to perform manual testing and identify vulnerabilities beyond automated scanner capabilities.

  • Strong analytical and problem-solving skills.

  • Experience in writing exploit scripts (Python, Bash, PowerShell, or similar).

  • Understanding of cloud platforms (AWS, Azure, GCP) is a plus.

  • Knowledge of secure coding practices.

 

Equal employment opportunity information 


KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you

Responsibilities
  • Strong understanding of security risks in networks and application platforms 

  • Strong understanding of network security, infrastructure security and application security,

  • Strong understanding of OSI, TCP/IP model and network basics 

  • Demonstrate technical penetration testing skills on IT infrastructure, web applications, mobile platforms and Red teaming 

  • Strong technical skills: Information security, network security, Windows security, UNIX/Linux security, web and mobile application security, Cloud platforms.

  • Good knowledge on web,Thick client,API, Mobile (Android,iOS) VAPT and Penetration testing assessments.

  • Broad knowledge of security technologies for applications, databases, networks, servers, and desktops. 

  • Ability to perform manual penetration testing.

  • Experience in Application Security Testing, or related functions Vulnerability Assessment, Penetration testing.

  • Perform penetration testing of various thick client software, web applications, and communications infrastructure to assist in hardening the cybersecurity posture against malicious actors 

  • Perform technical writing to communicate the preparation, testing, and recommendation phases for various security tests. Work with stakeholders to remediate system vulnerabilities.  

  • Expertise in the phases of penetration testing. Familiarity with Kali Linux distribution and the associated penetration testing tools suite. Experience in penetration testing simulations like Hack the Box or Capture the Flag exercises considered a plus.

  • Good Understanding of OWASP top 10 and mitigation techniques

  • Experience in performing web application security assessments using hands on techniques for identifying SQL injections, XSS, Security Misconfiguration, CSRF, authentication/ authorization issues

  • Experience on both commercial, open source tools and frameworks but not limited: Burpsuite, Checkmarx, Metasploit, Core-Impact, Kali-Linux, AppScan, WebInspect, SSLScan, Soap UI Pro, SonarQube, Qualys, Nikto, Nessus, nmap, sqlmap, OWASP ZAP .

  • Conduct Source code(SAST/SCA) Analysis manually.

  • Knowledge on scripting language like Python, Shell is an add-on.

  • Perform Vulnerability Assessment and Penetration Testing (VAPT) for web, mobile, API, network, cloud, and infrastructure components.

  • Identify, exploit, and document security vulnerabilities using manual and automated techniques.

  • Conduct source code reviews to detect security flaws.

  • Develop proof-of-concept (PoC) exploits for validated vulnerabilities.

  • Prepare detailed technical reports, including findings, severity ratings, and remediation recommendations.

  • Work closely with product, development, and infrastructure teams to help fix security gaps.

  • Research the latest vulnerabilities, exploits, attack trends, and security tools.

  • Participate in red team / blue team exercises when required.

  • Ensure VAPT activities are aligned with security standards (OWASP, SANS, NIST, ISO 27001, etc.).

  • Automate repetitive security testing tasks using scripts or tools.

  • Support compliance audits and security certifications.

Qualifications
  • 3+ years of hands-on experience in VAPT or Security Research.

  • Strong understanding of:

    • OWASP Top 10

    • MITRE ATT&CK

    • Web and mobile security concepts

    • Network security protocols

  • Hands-on experience with tools such as:
    Burp Suite, Metasploit, Nmap, Nessus, Wireshark, Kali Linux, Nikto, Fortify, ZAP, MobSF, etc.

  • Ability to perform manual testing and identify vulnerabilities beyond automated scanner capabilities.

  • Strong analytical and problem-solving skills.

  • Experience in writing exploit scripts (Python, Bash, PowerShell, or similar).

  • Understanding of cloud platforms (AWS, Azure, GCP) is a plus.

  • Knowledge of secure coding practices.

 

Equal employment opportunity information 


KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.

Similar Jobs

6 Minutes Ago
Remote or Hybrid
India
Mid level
Mid level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Business Analyst for FINREP regulatory reporting: assess FINREP EUCs, validate data sourcing, transformations and mapping to GRCA codes before Saracen upload. Perform detailed report production assessments, manage documentation, engage stakeholders across Financial Accounting and Group Regulatory Financial Reporting, and deliver analyses and outputs under tight deadlines.
Top Skills: ExcelMicrosoft PowerpointSaracen
6 Minutes Ago
Remote or Hybrid
India
Entry level
Entry level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Prepare and manage Bank of England statistical reporting by understanding end-to-end product lifecycles (mortgages, ISAs, equities), analysing data, testing, and designing processes. Develop specialist knowledge of systems and data flows, apply accounting concepts, and collaborate with stakeholders. BoE reporting experience is desirable; expect ~2 years to become fully self-sufficient.
Top Skills: Boe Statistical ReportingData AnalysisSQLTesting
21 Minutes Ago
Remote or Hybrid
India
Senior level
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead design and delivery of agentic LLM-powered workflows and autonomous agents across GTM systems (Salesforce, Slack). Build RAG/semantic search, orchestration, vector retrieval, evaluation frameworks, CI/CD, and secure AI integrations. Mentor engineers, replace legacy integrations, enforce AI engineering standards, and implement observability, governance, and automation for production-grade enterprise AI.
Top Skills: AgentcoreAgentforceApexAutogenAws BedrockCopadoCrewaiGithub ActionsJavaScriptJenkinsLangchainLanggraphLightning Web ComponentsLlamaindexMcpPythonRestSalesforce EinsteinSalesforce Platform EventsSemantic KernelSlackSlack Workflow BuilderSoapTypescriptVector DatabasesVertex Ai

What you need to know about the Kolkata Tech Scene

When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account