18 Aug
|
KPMG Assurance and Consulting Services
|
Mumbai
18 Aug
KPMG Assurance and Consulting Services
Mumbai
Key Responsibilities
Penetration Testing & Security Assessment
- Conduct Web Application, Mobile Application, API, Network, and Cloud Penetration Testing.
- Perform Vulnerability Assessments and identify security risks across enterprise systems.
- Execute black-box, grey-box, and white-box security testing.
- Simulate real-world cyberattacks to evaluate security controls.
- Validate vulnerabilities and work with development teams for remediation.
- Prepare detailed technical and executive-level security assessment reports.
AI Security & Emerging Technologies
- Assess security risks associated with AI/ML applications and Large Language Models (LLMs).
- Perform security testing on AI-powered applications, chatbots, and GenAI solutions.
- Identify vulnerabilities such as prompt injection, model poisoning, jailbreaks, insecure output handling, and data leakage.
- Support secure AI development practices and AI governance initiatives.
- Evaluate third-party AI tools and integrations from a security perspective.
Security Operations Support
- Collaborate with SOC, DevSecOps, and Development teams to enhance security posture.
- Support threat modeling exercises and secure architecture reviews.
- Participate in red team activities and adversary simulations.
- Provide security awareness and technical guidance to internal stakeholders.
Required Skills
Technical Skills
- Solid understanding of OWASP Top 10, SANS Top 25, MITRE ATT&CK; Framework.
- Hands-on experience with:
- Burp Suite Pro
- Nmap
- Metasploit
- Nessus / Qualys
- Wireshark
- OWASP ZAP
- Kali Linux
- Experience in Web, API, Network, Cloud, and Wireless Security Testing.
- Knowledge of authentication mechanisms, OAuth, JWT, SAML, and IAM concepts.
- Familiarity with secure coding practices and SDLC.
AI Security Skills
- Understanding of AI/ML concepts and Generative AI applications.
- Knowledge of OWASP Top 10 for LLM Applications.
- Awareness of prompt injection, adversarial attacks, model poisoning, and data privacy risks.
- Experience with AI frameworks such as OpenAI, Azure AI, LangChain, or similar platforms is preferred.
Programming/Scripting
- Python
- PowerShell
- Bash
- JavaScript (preferred)
📌 Penetration Tester (F Interviews - Mumbai )
🏢 KPMG Assurance and Consulting Services
📍 Mumbai