KPMG India Logo

KPMG India

Consultant - Application Security Testing/ Red Teaming

Posted Yesterday
Be an Early Applicant
In-Office
Mumbai, Maharashtra, IND
Mid level
In-Office
Mumbai, Maharashtra, IND
Mid level
Perform manual and automated penetration testing and red team engagements across networks, applications, mobile, cloud, and Active Directory. Use offensive tools (Cobalt Strike, Metasploit, Burp Suite, etc.), map techniques to MITRE ATT&CK, develop custom exploits/scripts, conduct SAST/SCA code analysis, produce technical reports, and work with stakeholders and SOC/Blue teams to remediate vulnerabilities and run purple-team exercises.
The summary above was generated by AI

About KPMG in India

KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada. 

KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.

Responsibilities
  • Strong understanding of security risks in networks and application platforms 
  • Strong understanding of network security, infrastructure security and application security,
  • Strong understanding of OSI, TCP/IP model and network basics 
  • Demonstrate technical penetration testing skills on IT infrastructure, web applications, mobile platforms and Red teaming 
  • Strong technical skills: Information security, network security, Windows security, UNIX/Linux security, web and mobile application security, Cloud platforms.
  • Good knowledge on web,Thick client,API, Mobile (Android,iOS) VAPT and Penetration testing assessments.
  • Broad knowledge of security technologies for applications, databases, networks, servers, and desktops. 
  • Ability to perform manual penetration testing.
  • Experience in Application Security Testing, or related functions Vulnerability Assessment, Penetration testing.
  • Perform penetration testing of various thick client software, web applications, and communications infrastructure to assist in hardening the cybersecurity posture against malicious actors 
  • Perform technical writing to communicate the preparation, testing, and recommendation phases for various security tests. Work with stakeholders to remediate system vulnerabilities.  
  • Expertise in the phases of penetration testing. Familiarity with Kali Linux distribution and the associated penetration testing tools suite. Experience in penetration testing simulations like Hack the Box or Capture the Flag exercises considered a plus.
  • Good Understanding of OWASP top 10 and mitigation techniques
  • Experience in performing web application security assessments using hands on techniques for identifying SQL injections, XSS, Security Misconfiguration, CSRF, authentication/ authorization issues
  • Experience on both commercial, open source tools and frameworks but not limited: Burpsuite, Checkmarx, Metasploit, Core-Impact, Kali-Linux, AppScan, WebInspect, SSLScan, Soap UI Pro, SonarQube, Qualys, Nikto, Nessus, nmap, sqlmap, OWASP ZAP .
  • Conduct Source code(SAST/SCA) Analysis manually.
  • Knowledge on scripting language like Python, Shell is an add-on.
Qualifications
  • Strong expertise in network, OS (Windows/Linux), and Active Directory security. 
  • Hands-on experience with tools such as Cobalt Strike, Metasploit, Empire, BloodHound, Nmap, Impacket. 
  • Proficiency in scripting and programming (Python, PowerShell, Bash, C/C++). 
  • Experience with cloud attacks (Azure AD, AWS IAM abuse is a strong plus). 
  • Understanding of EDR/XDR bypass techniques.
  • Plan and execute red team engagements simulating real‑world threat actors. Perform advanced attack simulations including phishing, social engineering, privilege escalation, lateral movement, and persistence. Conduct network, application, cloud, and Active Directory exploitation. 
  • Use MITRE ATT&CK framework to design and map adversary techniques. Develop custom scripts, payloads, and exploits to bypass detection controls. 
  • Collaborate with Blue Team and SOC for purple team exercises.

Equal employment opportunity information 

KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.


 

Similar Jobs

Mid level
Financial Services
Manage end-to-end broking operations for equity and currency derivatives (F&O), including trade contracting, confirmations, clearing, settlement, reconciliations, reporting, and exception management. Monitor margins and positions, coordinate with clients, exchanges, custodians and banks, investigate breaks, prepare operational and regulatory reports, respond to queries, and drive root-cause fixes and process improvements to enhance straight-through processing.
Top Skills: AlteryxBseExcelMicrosoft WordNseTableauUipath
2 Hours Ago
Remote or Hybrid
India
Entry level
Entry level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
As an ML Engineer, you will design, experiment, and deploy AI/ML models, evaluate their performance, and leverage Python and SQL.
Top Skills: PythonPyTorchScikit-LearnSQL
3 Hours Ago
Easy Apply
Hybrid
Easy Apply
Mid level
Mid level
Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software
Own full-cycle recruiting for assigned roles: source passive candidates, screen, interview coordination, coach hiring managers, negotiate offers, ensure compliance, and deliver a positive candidate experience while meeting performance metrics.

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account