KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada.
KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.
We are seeking a skilled and proactive VAPT (Vulnerability Assessment and Penetration Testing) Cyber Defense Analyst with 2–4 years of experience in identifying, assessing, and mitigating security vulnerabilities across enterprise applications, networks, cloud environments, and infrastructure. The ideal candidate will have hands-on experience performing vulnerability assessments, penetration testing, security validations, and supporting cybersecurity incident response activities.
- Conduct Vulnerability Assessment and Penetration Testing (VAPT) on web applications, APIs, mobile applications, networks, and infrastructure.
- Perform internal and external security assessments to identify vulnerabilities and security gaps.
- Analyze security findings and provide remediation recommendations to stakeholders.
- Execute penetration testing using industry-standard tools and methodologies.
- Validate vulnerability fixes and conduct re-testing activities.
- Support secure configuration reviews and hardening assessments.
- Collaborate with development, infrastructure, and security teams to remediate vulnerabilities.
- Prepare detailed technical and executive-level VAPT reports.
- Participate in threat hunting, security monitoring, and incident response activities.
- Ensure compliance with security standards such as OWASP Top 10, NIST, ISO 27001, and CIS Benchmarks.
- Stay updated with emerging cyber threats, vulnerabilities, and attack techniques.
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related field.
- 2–4 years of hands-on experience in VAPT and Cyber Defense.
- Strong understanding of networking concepts, TCP/IP, DNS, HTTP/HTTPS, and network protocols.
- Experience with vulnerability scanning and penetration testing tools such as:
- Nessus
- Qualys
- Burp Suite
- Nmap
- OWASP ZAP
- Metasploit
- Wireshark
- Knowledge of web application security testing and OWASP Top 10 vulnerabilities.
- Experience in conducting infrastructure and network security assessments.
- Understanding of Windows, Linux, and Cloud security fundamentals (AWS/Azure/GCP).
- Familiarity with SIEM tools such as Splunk, QRadar, Sentinel, or ArcSight.
- Basic scripting knowledge in Python, PowerShell, or Bash is preferred.
- Strong analytical, troubleshooting, and report-writing skills.
- CEH (Certified Ethical Hacker)
- eJPT (eLearnSecurity Junior Penetration Tester)
- PNPT (Practical Network Penetration Tester)
- OSCP (Preferred)
- CompTIA Security+
- ISO 27001 Lead Implementer/Auditor (Added Advantage)
- Strong problem-solving and analytical skills.
- Excellent communication and stakeholder management abilities.
- Ability to work independently and in a team environment.
- Strong documentation and reporting skills.
- Passion for cybersecurity and continuous learning.
Equal employment opportunity information
KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.
Skills Required
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related field.
- 2-4 years of hands-on experience in VAPT and Cyber Defense.
- Experience conducting vulnerability assessments and penetration testing for web applications, APIs, mobile apps, networks, and infrastructure.
- Experience with vulnerability scanning and penetration testing tools: Nessus, Qualys, Burp Suite, Nmap, OWASP ZAP, Metasploit, Wireshark.
- Strong understanding of networking concepts (TCP/IP, DNS, HTTP/HTTPS) and network protocols.
- Knowledge of web application security testing and OWASP Top 10 vulnerabilities.
- Experience conducting infrastructure and network security assessments.
- Understanding of Windows, Linux, and Cloud security fundamentals (AWS, Azure, GCP).
- Familiarity with SIEM tools such as Splunk, QRadar, Microsoft Sentinel, or ArcSight.
- Basic scripting knowledge in Python, PowerShell, or Bash.
- Strong analytical, troubleshooting, and report-writing skills.
- Preferred certifications: OSCP, CEH, eJPT, PNPT, CompTIA Security+, ISO 27001 Lead Implementer/Auditor.
What We Do
KPMG entities in India are established under the laws of India and are owned and managed (as the case may be) by established Indian professionals. Established in September 1993, the KPMG entities have rapidly built a significant competitive presence in the country. Today we operate from offices across 14 cities including in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada. KPMG entities have a domestic client base of over 2700 companies. Our global approach to service delivery helps provide value-added services to clients. Our differentiation is derived from a rapid performance-based, industry-tailored and technology-enabled business advisory services delivered by some of the leading talented professionals in the country. KPMG professionals are grouped by industry focus and our clients are able to deal with industry professionals who speak their language. Our internal information technology and knowledge management systems enable the delivery of informed and timely business advice to clients.






