Senior Consultant - Cyber Defense (Cybersecurity)

KPMG Middle East

Dubai

On-site

AED 350,000 - 650,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

KPMG Middle East is seeking a Senior Consultant for the Cyber Defense and Response team to deliver red team operations, penetration testing, adversarial emulations, and SOC maturity assessments across sectors in the UAE. You will simulate real-world attacks including web, mobile, API, and network VAPT with C2 infrastructure setup and social engineering engagements.

The role requires hands-on offensive security experience, including frameworks like MITRE ATT&CK, strong reporting skills, and

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or related field.
  • OSCP certification mandatory; candidates must hold at least one of: OSEP, OSWE, CCT INF, CCT APP.
  • Proficiency with Burp Suite, Nmap, Metasploit, BloodHound.
  • Proficient in scripting with Python, PowerShell, or Bash.
  • Proficient in programming with Java, C#, or JavaScript.
  • Excellent presentation and communication skills; able to interact with senior stakeholders.
  • Commitment to continuous learning and professional development in offensive and defensive security.

Responsibilities

  • Execute penetration tests of web apps, mobile apps, APIs, and network infrastructure.
  • Participate in red team and social engineering engagements, including phishing and physical intrusion scenarios.
  • Set up, maintain, and operate C2 infrastructure using tools such as Cobalt Strike or Sliver.
  • Assist adversary emulation exercises based on MITRE ATT&CK.
  • Prepare detailed, risk-based reports and present findings to internal and client teams.
  • Develop internal tools, scripts, and documentation for offensive testing.
  • Collaborate with blue/purple teams to improve client defenses.
  • Stay up-to-date with offensive security techniques, vulnerabilities, and tools.
  • Develop understanding of KPMG’s broader offerings to identify business opportunities.
  • Support business development activities including proposal development and budgeting.
  • Develop constructive client relationships and network.
  • Build a professional network and be a trusted advisor.

Skills

Offensive security
Penetration testing
Social engineering
C2 infrastructure
MITRE ATT&CK
Web testing
Team collaboration

Education

Bachelor’s degree in Computer Science or Information Security

Tools

Burp Suite
Nmap
Metasploit
BloodHound
Cobalt Strike
Sliver
Mythic

Job description

The Role

You will be a Senior Consultant within the Cyber Defense and Response team, supporting the delivery of red team operations, penetration testing, adversarial emulations, and SOC maturity assessment projects for our clients across various sectors.

The ideal candidate will have hands-on experience simulating real-world attacks across enterprise environments and executing various types of assessments including web, mobile, API, and network VAPT. The candidate should be technically proficient in using offensive security tools, command-and-control (C2) infrastructure, and conducting social engineering engagements as part of red team operations.

In addition to technical responsibilities, you will assist with business development activities such as proposal preparation, effort estimation, and staffing inputs for offensive security projects.

If you are passionate about cyber security, enjoy solving complex technical challenges, and want to grow your career in offensive and defensive security, then this role is for you.

Responsibilities
  • Executing penetration tests of web applications, mobile applications, APIs, and network infrastructure.
  • Participating in red team and social engineering engagements, including phishing and physical intrusion scenarios under supervision or defined playbooks.
  • Setting up, maintaining, and operating C2 infrastructure using tools such as Cobalt Strike, Sliver, or similar frameworks.
  • Assisting in adversary emulation exercises based on frameworks like MITRE ATT&CK.
  • Preparing detailed, risk-based reports and presenting technical findings to internal and client teams.
  • Developing and maintaining internal tools, scripts, and documentation for offensive testing.
  • Collaborating with other teams including blue/purple teams to improve client defenses.
  • Staying up-to-date with the latest offensive security techniques, vulnerabilities, and tools.
  • Developing an understanding of KPMG’s broader offerings to enable identification of business opportunities.
  • Supporting with business development activities including proposal development, budgeting, etc.
  • Developing constructive client relationships, both inside and outside of KPMG.
  • Building out and maintaining a professional network.
  • Being a trusted advisor and a role model for quality and risk management practices.
  • Upholding KPMG’s values by acting with integrity.
The Person

We are looking for a technically strong and client-focused professional with experience in delivering and managing offensive and defensive security assessments. The ideal candidate should demonstrate:

  • At least 5+ years of experience in cyber security, with a focus on offensive security and VAPT.
  • Strong understanding and experience with common penetration testing methodologies (e.g., OWASP, PTES, NIST).
  • Practical experience in performing Web, Mobile, API, LLM, cloud and network-based VAPT assessments.
  • Practical experience in conducting secure source code reviews in languages such as JavaScript (Node.js), C#, Python, Swift, Java, Dart, SQL, etc.
  • Practical experience with red teaming & purple teaming concepts, such as social engineering, initial access, lateral movement, data exfiltration, security tooling etc.
  • Experience in setting up, using and maintaining C2 platforms (e.g., Cobalt Strike, Mythic, etc.).
  • Practical experience in conducting secure configuration reviews of network and application infrastructure components in line with industry leading benchmarks such as CIS and STIG.
  • Experience delivering cyber security services in a consulting environment is required; prior experience with a Big Four firm is a plus.
  • Strong problem-solving skills and attention to detail in execution and reporting.
  • Team-oriented attitude with a willingness to learn and contribute to project success.
  • Ability to work in fast-paced environments and meet deadlines.
  • Proven ability to deliver work at sustained levels of high intensity, and inspire drive and resilience in others.
  • Proven ability to analyze problems, identify core issues and recommend appropriate solutions.
Qualifications and Skills
  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • OSCP certification is mandatory. In addition, candidates must hold at least one of the following: OSEP, OSWE, CCT INF and CCT APP.
  • Proficiency with industry-standard tools such as Burp Suite, Nmap, Metasploit, BloodHound, etc.
  • Proficient in at least one scripting language such as Python, PowerShell, or Bash.
  • Proficient in at least one programming language such as Java, C#, or JavaScript.
  • Excellent presentation and communication skills (both written and oral).
  • Ability to interact with senior stakeholders in client organizations.
  • Commitment to continuous learning and professional development in offensive and defensive security.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Senior Red Team & Offensive Security Consultant
Remote Senior Red Team & Offensive Security Consultant

KPMG Middle East • United Arab Emirates

On-site
AED 250,000 - 450,000
Penetration Tester
Penetration Tester

HWG • Dubai

On-site
AED 180,000 - 320,000
Principal / Senior Red Team Services Consultant (Remote/KSA)
Principal / Senior Red Team Services Consultant (Remote/KSA)

CrowdStrike Inc. • Abu Dhabi

Remote
AED 250,000 - 551,000
Market compensation and equity awards
Wellness programs (physical & mental)
Competitive vacation & holidays
+4
Lead Consultant - Incident Response (CPX)
Lead Consultant - Incident Response (CPX)

Cpx Affiliate • Abu Dhabi

On-site
AED 240,000 - 360,000
Consultant
Consultant

Protiviti Middle East Member Firm • Dubai

On-site
AED 180,000 - 320,000
Principal / Senior Red Team Services Consultant
Principal / Senior Red Team Services Consultant

Crowdstrike • United Arab Emirates

On-site
AED 240,000 - 480,000
Market-leading compensation and equity
Wellness programs
Generous vacation and holidays
+5
Principal / Senior Red Team Services Consultant (Remote, UAE/KSA)
Principal / Senior Red Team Services Consultant (Remote, UAE/KSA)

CrowdStrike • Khor Fakkan

On-site
AED 300,000 - 600,000
Equity incentives
Wellness programs
Paid leaves
+1
Security Tester
Security Tester

AGAPI • Dubai

On-site
AED 279,000 - 502,000
Competitive Compensation
Top-Tier Equipment
Growth & Oppotunity
+1
Red Teaming Specialist
Red Teaming Specialist

CyberGate Defense LLC • Abu Dhabi

On-site
AED 150,000 - 230,000
Senior Consultant - Incident Response (CPX)
Senior Consultant - Incident Response (CPX)

CPX • Abu Dhabi

On-site
AED 250,000 - 350,000