Demo

Penetration Tester - SCA (contract)

KPMG US
Charlotte, NC Contractor
POSTED ON 3/26/2025 CLOSED ON 4/25/2025

What are the responsibilities and job description for the Penetration Tester - SCA (contract) position at KPMG US?

KPMG Assignment Select is geared toward independent professionals interested in temporary or project-based work. Our team is comprised of highly trained third-party professional individuals who are in the right place, at the right time, with the right skillset.

KPMG is working through its partnership with MBO Partners and is currently seeking a remote contractor in the United States.

Penetration Testers - SCA

Remote

Responsibilities

  • Conduct manual application penetration testing against APIs (REST/SOAP), web applications, mobile applications, and thick client applications.
  • Perform objective-based, abstract penetration testing engagements independently with minimal oversight and guidance.
  • Conduct threat modeling, evaluate application business logic, and perform detailed application architecture reviews.
  • Demonstrate application testing experience live via demos to both internal and external audiences.
  • Perform manual security code reviews for common programming languages (Java, .NET).
  • Conduct automated testing of running applications and static code (SAST, DAST).
  • Identify and exploit vulnerabilities in web applications, internal applications, APIs, internal and external networks, and mobile applications through manual penetration testing.
  • Use formal programming experience in Java/C# (minimum 6 months) to understand and test applications effectively.
  • Develop new testing methods to identify vulnerabilities and potential entry points for attackers to exploit applications, networks, and systems.
  • Act with integrity, professionalism, and personal responsibility to uphold the firm’s respectful and courteous work environment.

Qualifications

  • 3-5 years of hands-on experience in application penetration testing.
  • Proven experience in performing manual security code reviews using common programming languages (Java, .NET).
  • Proficiency in conducting automated testing (SAST, DAST) and manual application penetration tests on various systems, including web applications, APIs, and mobile applications.
  • Formal programming experience in Java or C# for at least 6 months.
  • Ability to create new testing methods to identify vulnerabilities and attackers' entry points.
  • One or more major ethical hacking certifications (not required but preferred), such as GWAPT, OSWE, or OSWA.
  • Demonstrated ability to conduct complex and abstract penetration testing engagements.
  • Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)

KPMG complies with all local/state regulations in regard to displaying pay rate ranges. The pay rate range(s) displayed is/are specifically for those contracted who will perform work in or reside in the location(s) listed below, if selected for the role. Pay is determined based on a variety of factors including market data, ranges, applicant's skills and prior relevant experience, certain degrees and certifications (e.g. JD, technology), and specific location, for example. Additionally, applicants may be required to apply and become employed by a service provider utilized by KPMG, and final pay rate(s) and/or eligibility for additional benefits may be determined by such provider.

KPMG and MBO Partners are equal opportunity employers/contractors. All qualified applicants are considered without regard to race, color, creed, religion, age, sex/gender, national origin, ancestry, citizenship status, marital status, sexual orientation, gender identity or expression, disability, physical or mental handicap unrelated to ability, pregnancy, veteran status, unfavorable discharge from military service, genetic information, or other legally protected status.

Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Pay Rate Range

Min Pay Rate Max Pay Rate Currency Unit 75 85 USD hourly

Lead Penetration Tester
Lensa -
Charlotte, NC
Lead Penetration Tester
Honeywell -
Charlotte, NC
Sr. Web Application Penetration Tester
The Hartford -
Charlotte, NC

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Penetration Tester - SCA (contract)?

Sign up to receive alerts about other jobs on the Penetration Tester - SCA (contract) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$92,729 - $118,963
Income Estimation: 
$118,965 - $150,754
Income Estimation: 
$141,372 - $178,696
Income Estimation: 
$174,706 - $217,614
Income Estimation: 
$92,729 - $118,963
Income Estimation: 
$118,965 - $150,754
Income Estimation: 
$76,865 - $99,440
Income Estimation: 
$92,729 - $118,963
Income Estimation: 
$118,965 - $150,754
Income Estimation: 
$141,372 - $178,696
This job has expired.
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at KPMG US

KPMG US
Hired Organization Address Anchorage, AK Full Time
At KPMG, you can become an integral part of a dynamic team at one of the world's top tax firms. Enjoy a collaborative, f...
KPMG US
Hired Organization Address Anchorage, AK Full Time
At KPMG, you can become an integral part of a dynamic team at one of the world's top tax firms. Enjoy a collaborative, f...
KPMG US
Hired Organization Address Colchester, VT Full Time
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizatio...
KPMG US
Hired Organization Address Colchester, VT Full Time
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizatio...

Not the job you're looking for? Here are some other Penetration Tester - SCA (contract) jobs in the Charlotte, NC area that may be a better fit.

Penetration Tester

Syntricate Technologies, Charlotte, NC

Penetration Tester

Stella Contracting, Inc, Charlotte, NC

AI Assistant is available now!

Feel free to start your new journey!