This position is no longer accepting applications
Closed on August 12, 2026.
This role is filled β get an email when new Information Security roles open on CybersecurityJobs.io:
Senior Specialist, MAST Application Penetration Tester
Senior
Application Security
Burp Suite
Checkmarx
Cybersecurity Tools
Information Security
InfoSec
Investigative Skills
Penetration Testing
Security
Security Testing
Specialist
View similar jobs
Get alerted when similar jobs are posted — set up a New Information Security jobs on CybersecurityJobs.io alert.
See other roles at KPMG.
Job Description
KPMG's Managed Services practice offers a comprehensive compensation and benefits package and a respectful, professional environment. This on-site role in San Francisco, CA provides access to essential benefits and retirement savings options, along with programs focused on well-being and work-life balance.
Benefits
- Comprehensive compensation and benefits package
- Medical and dental plans
- Vision coverage
- Disability and life insurance
- 401(k) plans
- Personal well-being benefits
- Personal Time Off
- Paid holidays
Responsibilities
- Conduct manual application penetration testing against APIs (REST/SOAP), Web Applications, Mobile applications, and thick client applications
- Perform objective based on abstract penetration testing engagements
- Execute threat modeling, evaluate application business logic, and perform application architecture reviews
- Demonstrate application testing experience in real time via demos to both internal and external audiences
- Function independently in penetration testing engagements, with minimal oversight and guidance
- Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
Requirements
- Minimum three years of recent experience in application penetration testing of API's, web applications, or mobile applications
- Bachelor's degree from an accredited college/university or equivalent industry experience
- Ability to communicate reporting results with technical and non-technical audiences and lead remediation conversations
- Experience with Burp Suite Pro and other app testing tools such as Netsparker and Checkmarx
- One or more major ethical hacking certifications not required but preferred; GWAPT, CREST, OSWE, OSWA
- Ability to travel as required
- Authorized to work in the United States without visa sponsorship now or in the future; KPMG will not sponsor for this opportunity
Technologies
- Burp Suite Pro
- Netsparker
- Checkmarx
Similar Jobs
J