Manager, Application Security Engineer
KPMG
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering real results for our clients. It's also enabled by our culture, which encourages individual development, embraces an inclusive environment, rewards innovative excellence and supports our communities. With qualities like those, it's no wonder we're consistently ranked among the best companies to work for by Fortune Magazine, Consulting Magazine, Seramount, Fair360 and others. If you're as passionate about your future as we are, join our team.
KPMG is currently seeking a Manager, Application security Engineer to join our Global Technology & Knowledge group which is part of the KPMG International organization.
Responsibilities:
- Collaborate with development teams to incorporate security best practices and principles into application design and development
- Conduct manual and automated source code reviews to identify security vulnerabilities in software applications
- Perform application threat modeling to identify potential security weaknesses and risks in software architecture
- Identify, track and remediate vulnerabilities in applications and related infrastructure using security testing tools
- Work closely with Development, DevOps, and Infrastructure teams to automate security checks and ensure secure coding practices are followed
- Support security architects to generate and maintain regular reports on security posture of applications and infrastructure, including metrics, KPIs, vulnerabilities status, and more
Qualifications:
- Minimum four years of recent experience with relevant application development and information technology (IT) security experience
- Bachelor's degree from an accredited college or university in computer science, information technology or engineering or relevant work experience; professional certifications in information technology security
- Minimum four years of recent work experience writing production-level code in any programming language and/or developer frameworks, such as C#, ASP.NET, MVC, Python, Ruby, Go, and more; minimum four years of recent work experience identifying and mitigating security issues in software and knowledge of best practice secure code development
- Experience or knowledge of security tools such as GitHub Advanced Security, Fortify, Fortify On-Demand, Mend, Qualys, Visual Studio Team Suite, Microsoft Defender for Cloud, and more
- Proven communication skills and high attention to detail; experience in designing, analyzing and conducting threat model assessments of enterprise software and services; experience in penetration testing or red team operations preferred
- Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
https://kpmg.com/us/en/how-we-work/pay-transparency.html/?id=1302_9_25
California Salary Range: $101200 - $215100
KPMG LLP (the U.S. member firm of KPMG International) offers a comprehensive compensation and benefits package. KPMG is an affirmative action-equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding the firm's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.
KPMG does not currently require partners or employees to be fully vaccinated or test negative for COVID-19 in order to go to KPMG offices, client sites or KPMG events, except when mandated by federal, state or local law. In some circumstances, clients also may require proof of vaccination or testing (e.g., to go to the client site).
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.