Experience Must have six years of experience in an information systems security domain with a background in mobile device security, endpoint protection, wireless protection, vulnerability management, incident response and mitigation, threat research and cyber intelligence analysis or other cyber security domain.. Certification/Registration/Licensure Must have a current CompTIA Security+ Certification or equivalent in industry certification, background and knowledge within 6 months of placement into the position.. Direct experience with anti-virus software, intrusion detection, firewalls and content filtering Experience with hacker techniques and network security principles.. Collect threat intelligence and automate systems to consume threat feeds and track adversaries.. Examples of such tools are web filtering technology, IDS/IPS appliances, SIEM tools, anti-spam/antivirus systems, data leakage appliances, content screening servers, VPN systems and firewalls.
Provide expert-level technical analysis and incident response for complex cyber threats, including data exfiltration attempts and insider risks.. Conduct in-depth research using global threat intelligence feeds to stay ahead of emerging attack techniques, tools, and adversary tactics.. Collaborate with cross-functional teams to enhance DLP policies, detection rules, and response workflows.. Proven experience in cybersecurity operations, with a strong focus on DLP technologies and threat intelligence.. Deep understanding of threat actor methodologies, MITRE Attack framework, and incident response lifecycle.
Join to apply for the Manager, Cyber Penetration Testing role at KPMG US. KPMG is currently seeking a Manager, Cyber Penetration Tester to join our Enterprise Security Services organization. Minimum five years of recent practical experience in cybersecurity, focusing on network and web application penetration testing, red teaming, AI red teaming, cloud penetration testing, and security assessments.. Bachelor's degree from an accredited college or university is preferred; relevant certifications such as GIAC Penetration Tester (GPEN), Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Certified Information Systems Security Professional (CISSP), or similar are highly preferred; Certifications in Azure is preferred.. Proficiency in scripting and automation with experience in Python, Bash, or PowerShell; background with adversarial machine learning techniques, as well as familiarity with common ML frameworks and tools such as prompt injection, data poisoning, and model evasion