TymblHub

© 2026 TymblHub

Penetration Tester ( F2F Interviews - Mumbai )

KPMG
Posted on
KPMG logo

Experience
2 - 7 yrs
Salary (CTC)
₹5.3L - ₹7.7L
Job Location
Mumbai, India
Vacancy
18
Designation
Penetration Tester
Job Type
ONSITE

Job Description

Key Responsibilities

Penetration Testing & Security Assessment

  • Conduct Web Application, Mobile Application, API, Network, and Cloud Penetration Testing.
  • Perform Vulnerability Assessments and identify security risks across enterprise systems.
  • Execute black-box, grey-box, and white-box security testing.
  • Simulate real-world cyberattacks to evaluate security controls.
  • Validate vulnerabilities and work with development teams for remediation.
  • Prepare detailed technical and executive-level security assessment reports.

AI Security & Emerging Technologies

  • Assess security risks associated with AI/ML applications and Large Language Models (LLMs).
  • Perform security testing on AI-powered applications, chatbots, and GenAI solutions.
  • Identify vulnerabilities such as prompt injection, model poisoning, jailbreaks, insecure output handling, and data leakage.
  • Support secure AI development practices and AI governance initiatives.
  • Evaluate third-party AI tools and integrations from a security perspective.

Security Operations Support

  • Collaborate with SOC, DevSecOps, and Development teams to enhance security posture.
  • Support threat modeling exercises and secure architecture reviews.
  • Participate in red team activities and adversary simulations.
  • Provide security awareness and technical guidance to internal stakeholders.

Required Skills

Technical Skills

  • Strong understanding of OWASP Top 10, SANS Top 25, MITRE ATT&CK Framework.
  • Hands-on experience with:
    • Burp Suite Pro
    • Nmap
    • Metasploit
    • Nessus / Qualys
    • Wireshark
    • OWASP ZAP
    • Kali Linux
  • Experience in Web, API, Network, Cloud, and Wireless Security Testing.
  • Knowledge of authentication mechanisms, OAuth, JWT, SAML, and IAM concepts.
  • Familiarity with secure coding practices and SDLC.

AI Security Skills

  • Understanding of AI/ML concepts and Generative AI applications.
  • Knowledge of OWASP Top 10 for LLM Applications.
  • Awareness of prompt injection, adversarial attacks, model poisoning, and data privacy risks.
  • Experience with AI frameworks such as OpenAI, Azure AI, LangChain, or similar platforms is preferred.

Programming/Scripting

  • Python
  • PowerShell
  • Bash
  • JavaScript (preferred)

No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.