Executive - Cyber Defense

Reposted Yesterday
Be an Early Applicant
Mumbai, Maharashtra, IND
In-Office
Senior level
Fintech • Professional Services • Software • Financial Services
The Role
Lead and perform manual and automated penetration tests, red team engagements and attack simulations across networks, applications, mobile and cloud. Identify vulnerabilities, develop exploits and remediation guidance, use industry tools and frameworks (Kali, MITRE ATT&CK), collaborate with SOC/blue teams, and produce technical reports documenting findings and recommendations.
Summary Generated by Built In

About KPMG in India

KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada. 

KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.

Responsibilities
  • Strong understanding of security risks in networks and application platforms 

  • Strong understanding of network security, infrastructure security and application security,

  • Strong understanding of OSI, TCP/IP model and network basics 

  • Demonstrate technical penetration testing skills on IT infrastructure, web applications, mobile platforms and Red teaming 

  • Strong technical skills: Information security, network security, Windows security, UNIX/Linux security, web and mobile application security, Cloud platforms.

  • Good knowledge on web,Thick client,API, Mobile (Android,iOS) VAPT and Penetration testing assessments.

  • Broad knowledge of security technologies for applications, databases, networks, servers, and desktops. 

  • Ability to perform manual penetration testing.

  • Experience in Application Security Testing, or related functions Vulnerability Assessment, Penetration testing.

  • Perform penetration testing of various thick client software, web applications, and communications infrastructure to assist in hardening the cybersecurity posture against malicious actors 

  • Perform technical writing to communicate the preparation, testing, and recommendation phases for various security tests. Work with stakeholders to remediate system vulnerabilities.  

  • Expertise in the phases of penetration testing. Familiarity with Kali Linux distribution and the associated penetration testing tools suite. Experience in penetration testing simulations like Hack the Box or Capture the Flag exercises considered a plus.

  • Good Understanding of OWASP top 10 and mitigation techniques

  • Experience in performing web application security assessments using hands on techniques for identifying SQL injections, XSS, Security Misconfiguration, CSRF, authentication/ authorization issues

  • Experience on both commercial, open source tools and frameworks but not limited: Burpsuite, Checkmarx, Metasploit, Core-Impact, Kali-Linux, AppScan, WebInspect, SSLScan, Soap UI Pro, SonarQube, Qualys, Nikto, Nessus, nmap, sqlmap, OWASP ZAP .

  • Conduct Source code(SAST/SCA) Analysis manually.

  • Knowledge on scripting language like Python, Shell is an add-on.

Qualifications
  • Strong expertise in network, OS (Windows/Linux), and Active Directory security. 

  • Hands-on experience with tools such as Cobalt Strike, Metasploit, Empire, BloodHound, Nmap, Impacket. 

  • Proficiency in scripting and programming (Python, PowerShell, Bash, C/C++). 

  • Experience with cloud attacks (Azure AD, AWS IAM abuse is a strong plus). 

  • Understanding of EDR/XDR bypass techniques.

  • Plan and execute red team engagements simulating real‑world threat actors. Perform advanced attack simulations including phishing, social engineering, privilege escalation, lateral movement, and persistence. Conduct network, application, cloud, and Active Directory exploitation. 

  • Use MITRE ATT&CK framework to design and map adversary techniques. Develop custom scripts, payloads, and exploits to bypass detection controls. 

  • Collaborate with Blue Team and SOC for purple team exercises.

Equal employment opportunity information 

KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.

Skills Required

  • Strong understanding of network, infrastructure, and application security
  • Hands-on penetration testing experience (infrastructure, web, mobile, thick client) and red teaming
  • Ability to perform manual penetration testing and VAPT assessments
  • Experience with SAST/SCA and source code security analysis
  • Proficiency in scripting and programming (Python, PowerShell, Bash, C/C++)
  • Hands-on experience with tools such as Cobalt Strike, Metasploit, Empire, BloodHound, Nmap, Impacket
  • Good knowledge of web, API, mobile (Android/iOS) VAPT techniques and OWASP Top 10 mitigations
  • Familiarity with Kali Linux and common penetration testing tool suites
  • Experience mapping and designing attacks using MITRE ATT&CK and conducting purple team exercises
  • Ability to produce technical reports and work with stakeholders to remediate vulnerabilities
  • Experience with cloud attacks and Azure AD/AWS IAM exploitation
  • Familiarity with penetration testing platforms/simulations (e.g., Hack The Box, CTF) is a plus
  • Understanding of EDR/XDR bypass techniques
  • Knowledge of commercial and open-source security tools (Burp Suite, Checkmarx, AppScan, WebInspect, Nessus, Qualys, sqlmap, OWASP ZAP, etc.)
  • Knowledge on scripting languages like Python and Shell
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
30,867 Employees

What We Do

KPMG entities in India are established under the laws of India and are owned and managed (as the case may be) by established Indian professionals. Established in September 1993, the KPMG entities have rapidly built a significant competitive presence in the country. Today we operate from offices across 14 cities including in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada. KPMG entities have a domestic client base of over 2700 companies. Our global approach to service delivery helps provide value-added services to clients. Our differentiation is derived from a rapid performance-based, industry-tailored and technology-enabled business advisory services delivered by some of the leading talented professionals in the country. KPMG professionals are grouped by industry focus and our clients are able to deal with industry professionals who speak their language. Our internal information technology and knowledge management systems enable the delivery of informed and timely business advice to clients.

Similar Jobs

Bose Logo Bose

Account Manager

Automotive • eCommerce • Hardware • Music • Retail • Software • Wearables
Hybrid
Mumbai, Maharashtra, IND
2900 Employees

Bose Logo Bose

Account Manager

Automotive • eCommerce • Hardware • Music • Retail • Software • Wearables
Remote or Hybrid
India
2900 Employees

Capco Logo Capco

Project Manager

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Mondelēz International Logo Mondelēz International

Senior Internal Auditor

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Hybrid
Mumbai, Maharashtra, IND
90000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account