-
KPMG India

VAPT - PenTesting / Red Teaming

KPMG India
India · Full-time · Not Applicable

Job Description

About KPMG in India

KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada.

KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.

Responsibilities

  • Perform Vulnerability Assessment and Penetration Testing (VAPT) for web, mobile, API, network, cloud, and infrastructure components.
  • Identify, exploit, and document security vulnerabilities using manual and automated techniques.
  • Conduct source code reviews to detect security flaws.
  • Develop proof-of-concept (PoC) exploits for validated vulnerabilities.
  • Prepare detailed technical reports, including findings, severity ratings, and remediation recommendations.
  • Work closely with product, development, and infrastructure teams to help fix security gaps.
  • Research the latest vulnerabilities, exploits, attack trends, and security tools.
  • Participate in red team / blue team exercises when required.
  • Ensure VAPT activities are aligned with security standards (OWASP, SANS, NIST, ISO 27001, etc.).
  • Automate repetitive security testing tasks using scripts or tools.
  • Support compliance audits and security certifications.


Qualifications

  • 6+ years of hands-on experience in VAPT or Security Research.
  • Strong understanding of:
    • OWASP Top 10
    • MITRE ATT&CK
    • Web and mobile security concepts
    • Network security protocols
  • Hands-on experience with tools such as: Burp Suite, Metasploit, Nmap, Nessus, Wireshark, Kali Linux, Nikto, Fortify, ZAP, MobSF, etc.
  • Ability to perform manual testing and identify vulnerabilities beyond automated scanner capabilities.
  • Strong analytical and problem-solving skills.
  • Experience in writing exploit scripts (Python, Bash, PowerShell, or similar).
  • Understanding of cloud platforms (AWS, Azure, GCP) is a plus.
  • Knowledge of secure coding practices.

Equal employment opportunity information

KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.

Key Skills

Ranked by relevance

owasp cloud vulnerability assessment security certifications penetration testing network security powershell metasploit burp suite kali linux wireshark python nessus linux bash nist nmap aws gcp
Login to Apply
Posted
Apr 24, 2026
Type
Full-time
Level
Not Applicable
Location
Noida
Company
KPMG India

Industries

Business Consulting Services

Categories

Other

Related Jobs

3 roles aligned with this opportunity

View all jobs
View Job Details
KPMG India
Related

Manager - AI/ML

2026-05-20

Full-time
Not Applicable
India
Business Consulting
Engineering
View Job Details
PwC India
Related

Associate

2026-05-27

Full-time
Associate
India
Business Consulting
Other
View Job Details
Môre
Related

UX Designer - Pleno | Môre (Híbrido - SP)

2026-05-28

Full-time
Not Applicable
Brazil
Business Consulting
Other