Executive - Cyber Defense

BSR & Co

Mumbai

On-site

INR 1,400,000 - 2,300,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KPMG India in Mumbai is seeking an experienced security professional to lead offensive security engagements, including penetration testing of networks, applications, mobile and cloud platforms.

You will perform red team simulations, write detailed findings, and collaborate with blue teams to improve defenses. Strong hands-on skills with tools like Metasploit, Burp Suite and Kali are valued, as are knowledge of OWASP top 10 and ethical hacking methodologies.

Qualifications

  • Strong expertise in network, OS and AD security.
  • Hands-on experience with offensive security tools such as Metasploit, Empire, Cobalt Strike.
  • Proficiency in scripting (Python, PowerShell, Bash).

Responsibilities

  • Perform penetration testing of networks, web apps, and mobile platforms.
  • Conduct red team engagements and simulate real-world threat actor activities.
  • Prepare technical write-ups detailing prep, testing, and remediation steps.
  • Collaborate with Blue Team and SOC to improve detection and response.

Skills

Network security
Application security
Penetration testing
Red teaming
Cloud security
Threat modeling

Tools

Burp Suite
Metasploit
Kali Linux
Nessus
Nmap
OWASP ZAP
Sqlmap
Nikto

Job description

Responsibilities
  • Strong understanding of security risks in networks and application platforms
  • Strong understanding of network security, infrastructure security and application security,
  • Strong understanding of OSI, TCP/IP model and network basics
  • Demonstrate technical penetration testing skills on IT infrastructure, web applications, mobile platforms and Red teaming
  • Strong technical skills: Information security, network security, Windows security, UNIX/Linux security, web and mobile application security, Cloud platforms.
  • Good knowledge on web,Thick client,API, Mobile (Android,iOS) VAPT and Penetration testing assessments.
  • Broad knowledge of security technologies for applications, databases, networks, servers, and desktops.
  • Ability to perform manual penetration testing.
  • Experience in Application Security Testing, or related functions Vulnerability Assessment, Penetration testing.
  • Perform penetration testing of various thick client software, web applications, and communications infrastructure to assist in hardening the cybersecurity posture against malicious actors
  • Perform technical writing to communicate the preparation, testing, and recommendation phases for various security tests. Work with stakeholders to remediate system vulnerabilities.
  • Expertise in the phases of penetration testing. Familiarity with Kali Linux distribution and the associated penetration testing tools suite. Experience in penetration testing simulations like Hack the Box or Capture the Flag exercises considered a plus.
  • Good Understanding of OWASP top 10 and mitigation techniques
  • Experience in performing web application security assessments using hands on techniques for identifying SQL injections, XSS, Security Misconfiguration, CSRF, authentication/ authorization issues
  • Experience on both commercial, open source tools and frameworks but not limited: Burpsuite, Checkmarx, Metasploit, Core-Impact, Kali-Linux, AppScan, WebInspect, SSLScan, Soap UI Pro, SonarQube, Qualys, Nikto, Nessus, nmap, sqlmap, OWASP ZAP .
  • Conduct Source code(SAST/SCA) Analysis manually.
  • Knowledge on scripting language like Python, Shell is an add-on.
Qualifications
  • Strong expertise in network, OS (Windows/Linux), and Active Directory security.
  • Hands‑on experience with tools such as Cobalt Strike, Metasploit, Empire, BloodHound, Nmap, Impacket.
  • Proficiency in scripting and programming (Python, PowerShell, Bash, C/C++).
  • Experience with cloud attacks (Azure AD, AWS IAM abuse is a strong plus).
  • Understanding of EDR/XDR bypass techniques.
  • Plan and execute red team engagements simulating real‑world threat actors. Perform advanced attack simulations including phishing, social engineering, privilege escalation, lateral movement, and persistence. Conduct network, application, cloud, and Active Directory exploitation.
  • Use MITRE ATT&CK framework to design and map adversary techniques. Develop custom scripts, payloads, and exploits to bypass detection controls.
  • Collaborate with Blue Team and SOC for purple team exercises.

KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Associate - Cyber Security - VAPT
Senior Associate - Cyber Security - VAPT

BDO India • Pune District

On-site
INR 900,000 - 1,500,000
Senior Penetration Tester
Senior Penetration Tester

Basebiz • Dadri

On-site
INR 1,200,000 - 2,400,000
Associate - VAPT (Ahmedabad)
Associate - VAPT (Ahmedabad)

BDO India • Ahmedabad District

On-site
INR 1,200,000 - 2,200,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,200,000 - 2,000,000
SISA Information Security - Network Security Engineer
SISA Information Security - Network Security Engineer

SISA • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Penetration Tester Architect ( VAPT, Android , IOS ) - Naukri.com
Penetration Tester Architect ( VAPT, Android , IOS ) - Naukri.com

Info Edge • Greater Noida, Dadri

On-site
INR 900,000 - 1,200,000
Cyber Assessment (Diversity + Shifts)- Manager-BLR/GGN/Noida
Cyber Assessment (Diversity + Shifts)- Manager-BLR/GGN/Noida

Sampoorna Consultants • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Hiring For Penetration Tester - Mumbai
Hiring For Penetration Tester - Mumbai

Saint Gobain • Mumbai, Navi Mumbai

On-site
INR 4,000,000 - 8,000,000
Cyber Penetration Tester Senior
Cyber Penetration Tester Senior

Baker Tilly US • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Principal Consultant, Offensive Security
Principal Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,800,000 - 3,000,000