Manager, Penetration Testing

KTSA - KPMG Technology Services Americas

Región Centro

Presencial

MXN 550.000 - 950.000

Jornada completa

Hace 5 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

KTSAMÁS total rewards program
Learning opportunities & certification
Flexible working arrangements

Descripción de la vacante

KTSA - KPMG Technology Services Americas is seeking a seasoned Penetration Tester to conduct detailed security assessments and remediation guidance across web applications, APIs, networks, and cloud environments. You will document findings, engage with stakeholders, and stay current on evolving threats.

The role requires working with clients and internal teams to plan, execute, and communicate results, leveraging strong scripting skills and cloud security expertise.

Formación

  • Bachelor’s degree with 5+ years of practical cybersecurity experience.
  • Hands-on testing of web apps, APIs, networks, and cloud environments beyond automated scans.
  • Familiarity with MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, PTES.

Responsabilidades

  • Conduct detailed application and network penetration testing engagements to identify exploitable vulnerabilities and remediation paths.
  • Plan and execute testing across web apps, APIs, networks, cloud environments, and supporting infrastructure.
  • Assess common security weaknesses including authentication, authorization, injections, business logic flaws, insecure configurations, and data exposure.
  • Document findings with business impact, evidence, risk context, reproducible steps, and remediation guidance.

Conocimientos

Penetration testing
Manual testing
Cloud security
Scripting (Python/Bash/PowerShell)
Communication
Client collaboration

Educación

Bachelor’s degree in cybersecurity or related field

Herramientas

Python
Bash
PowerShell
Penetration testing tools

Descripción del empleo

We are KTSA - KPMG Technology Services Americas.

A Service Delivery Center of KPMG US, with offices in Mexico City, Guadalajara, and a growing network of remote talent across the country. We deliver high-value technology, consulting, and corporate support services to KPMG US and its clients.

At KTSA, our Employer Value Proposition is clear: Explore.

Explore isn't just a word - it’s how we grow, lead, and thrive. It's the mindset that drives our culture and shapes every opportunity:

  • Experience a collaborative, inclusive, and multicultural workplace where you belong.
  • Excel by creating impact and leaving your mark on global projects.
  • Expand your potential with real career paths, learning programs, and mentorship.
  • Express your individuality - come as you are, and thrive as your authentic self.
Key Responsibilities:
  • Conduct detailed application and network penetration testing engagements to identify exploitable vulnerabilities, control gaps, and practical paths to remediation.
  • Plan and execute penetration testing activities across web applications, APIs, external and internal networks, cloud-hosted environments, and supporting infrastructure, as applicable to the engagement scope.
  • Assess common application and API security weaknesses, including authentication flaws, authorization issues, injection vulnerabilities, business logic flaws, insecure configurations, and exposure of sensitive data.
  • Document findings clearly, including business impact, technical evidence, risk context, reproducible steps, and practical remediation guidance for member firm stakeholders.
  • Facilitate security assessments and support the resolution of identified vulnerabilities through clear communication, retesting, and coordination with application, infrastructure, and security teams.
  • Communicate assessment results to technical and non-technical stakeholders through written reports, walkthroughs, and remediation discussions.
  • Stay current with common and emerging security threats, penetration testing techniques, tooling, and assessment methodologies relevant to application and network security.
Qualifications:
  • Bachelor’s degree with 5+ years of practical experience in cybersecurity, focused on application penetration testing, network penetration testing, and related cloud security assessment activities.
  • Strong hands-on experience performing manual web application, API, network, and infrastructure penetration testing, including validation beyond automated scanning tools.
  • Strong familiarity with frameworks and methodologies such as MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, PTES.
  • Relevant certifications such as OSCP, GPEN, GWAPT, OSCE, GXPN, or similar are highly preferred. CISSP and Azure or other cloud platform certifications are a plus.
  • Solid foundation in network, application, and cloud security concepts, with hands-on experience identifying, validating, and explaining vulnerabilities in real-world environments.
  • Proficiency in scripting and automation with experience in Python, Bash, or PowerShell.
  • Experience with common and emerging security threats, scanning tools, exploitation techniques, assessment methodologies, and secure remediation practices.
  • Demonstrated understanding of security principles, IT security controls, and related technologies and products.
  • Strong verbal and written communication, problem solving, analytical, and independent judgment skills to support an environment driven by customer service, collaboration, and teamwork.
  • Experience working directly with clients, project stakeholders, or business units to clarify scope, communicate findings, and support remediation efforts.

And because we know that thriving at work also means thriving in life, we back this mindset with KTSAMÁS, our total rewards program, designed to support your well-being, goals, and personal milestones.

Expand your possibilities with KTSA through KTSAMÁS, where you can access:

  • Extended maternity, paternity, and adoption leaves
  • Learning opportunities, training, and certification programs
  • Extended marriage leave and daycare support
  • Wellness and Employee Assistance Programs (EAP)
  • Comprehensive medical plan, life insurance, car insurance, and funeral assistance

Visit www.ktsa.com.mx to learn more.

At KTSA, we celebrate and support everyone’s individuality. We do not discriminate against any race, religion, color, national origin, gender, sexual orientation, gender identity or expression, age, marital status, or disability. We are supportive of helping you to achieve a balance between your home and work demands. We are happy to discuss specific requirements and our range of flexible working arrangements could be of interest. Please ask to find out more. We strongly state that we DO NOT require a certificate of non-pregnancy or HIV in order to participate in any of our processes.

Explore KTSA, we dare to be different!

Home - KTSA

KTSA - KPMG Technology Services of Americas

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Manager, Pentesting
Manager, Pentesting

KTSA - KPMG Technology Services Americas • Ciudad de México

Presencial
MXN 900.000 - 1.500.000
Wellness programs
Learning and certification programs
Comprehensive medical plan
Manager, Cybersecurity Red Team Exercises - Advanced English
Manager, Cybersecurity Red Team Exercises - Advanced English

KTSA - KPMG Technology Services Americas • Región Centro

Presencial
MXN 900.000 - 1.200.000
Extended maternity/paternity leaves
Learning and certification programs
Wellness and EAP
Senior Associate, Cybersecurity Risk Assessment- Advanced English
Senior Associate, Cybersecurity Risk Assessment- Advanced English

KTSA - KPMG Technology Services Americas • Región Centro

Híbrido
MXN 600.000 - 900.000
Extended maternity leave
Learning programs & certification
Daycare support
+4
Manager, Information Security & IT Risk
Manager, Information Security & IT Risk

KTSA - KPMG Technology Services Americas • Región Centro

Híbrido
MXN 1.000.000 - 1.600.000
Hybrid work model
KTSAMÁS rewards program
Learning and certification programs
+2
Sr. Associate Fullstack (Node, REACT)
Sr. Associate Fullstack (Node, REACT)

KTSA - KPMG Technology Services Americas • Región Centro

Presencial
MXN 70.000 - 120.000
KTSAMÁS total rewards program
Learning opportunities and certif ica
Flexible working arrangements
Manager, Cybersecurity Threat Intelligence - Advanced English
Manager, Cybersecurity Threat Intelligence - Advanced English

KTSA - KPMG Technology Services Americas • México

Híbrido
MXN 1.455.000 - 1.820.000
Extended maternity, paternity, and adoption leaves
Learning opportunities, training, and certification programs
Comprehensive medical plan and life insurance
Sr. Engineer, Fullstack Dev (.Net, Angular)
Sr. Engineer, Fullstack Dev (.Net, Angular)

KTSA - KPMG Technology Services Americas • Región Centro

Presencial
MXN 420.000 - 720.000
Extended leaves
Training programs
Daycare support
+2
Senior Penetration Testing Manager
Senior Penetration Testing Manager

KTSA - KPMG Technology Services Americas • Ciudad de México

Presencial
MXN 900.000 - 1.500.000
Wellness programs
Learning and certification programs
Comprehensive medical plan
AI & IT Services Inventory Coordinator
AI & IT Services Inventory Coordinator

KTSA - KPMG Technology Services Americas • Región Centro

Presencial
MXN 360.000 - 480.000
KTSAMÁS rewards program
Extended parental leaves
Learning and certification programs
+2
Sr. Associate – Fixed Assets
Sr. Associate – Fixed Assets

KTSA - KPMG Technology Services Americas • Región Centro

Presencial
MXN 420.000 - 700.000
Extended maternity leave
Learning opportunities and training
Wellness programs
+1