Manager, Pentesting

KTSA - KPMG Technology Services Americas All jobs
México, Mexico
13 hour(s) ago
Job Overview
Company KTSA - KPMG Technology Services Americas
Job Type Full-time
Job Level mid-senior
Category Information Technology
Posted 2026-08-28
Last Seen 13 hour(s) ago

Job Description

About KTSA We are KTSA – KPMG Technology Services Americas. A Service Delivery Center of KPMG US with offices in Mexico City Guadalajara and a growing network of remote talent across the country. We deliver high-value technology consulting and corporate support services to KPMG US and its clients. At KTSA our Employer Value Proposition is clear Explore . Explore isn’t just a word — it’s how we grow lead and thrive. It’s the mindset that drives our culture and shapes every opportunity Experience a collaborative inclusive and multicultural workplace where you belong. Excel by creating impact and leaving your mark on global projects. Expand your potential with real career paths learning programs and mentorship. Express your individuality — come as you are and thrive as your authentic self. And because we know that thriving at work also means thriving in life we back this mindset with KTSAMÁS our total rewards program designed to support your well-being goals and personal milestones.

Responsibilities

Conduct detailed application and network penetration testing engagements to identify exploitable vulnerabilities control gaps and practical paths to remediation.

  • Plan and execute penetration testing activities across web applications APIs external and internal networks cloud-hosted environments and supporting infrastructure as applicable to the engagement scope.
  • Assess common application and API security weaknesses including authentication flaws authorization issues injection vulnerabilities business logic flaws insecure configurations and exposure of sensitive data.
  • Document findings clearly including business impact technical evidence risk context reproducible steps and practical remediation guidance for member firm stakeholders.
  • Facilitate security assessments and support the resolution of identified vulnerabilities through clear communication retesting and coordination with application infrastructure and security teams.
  • Communicate assessment results to technical and non-technical stakeholders through written reports walkthroughs and remediation discussions.
  • Stay current with common and emerging security threats penetration testing techniques tooling and assessment methodologies relevant to application and network security. Requirements.
  • Bachelor’s degree with 5+ years of practical experience in cybersecurity f ocused on application penetration testing network penetration testing and related cloud security assessment activities.
  • Strong hands-on experience performing manual web application API network and infrastructure penetration testing including validation beyond automated scanning tools.
  • Strong familiarity with frameworks and methodologies such as MITRE ATT&CK OWASP Top 10 OWASP API Security Top 10 PTES.
  • Relevant certifications such as OSCP GPEN GWAPT OSCE GXPN or similar are highly preferred. CISSP and Azure or other cloud platform certifications are a plus.
  • Solid foundation in network application and cloud security concepts with hands-on experience identifying validating and explaining vulnerabilities in real-world environments.
  • Proficiency in scripting and automation with experience in Python Bash or PowerShell.
  • Experience with common and emerging security threats scanning tools exploitation techniques assessment methodologies and secure remediation practices.
  • Demonstrated understanding of security principles IT security controls and related technologies and products.
  • Strong verbal and written communication problem solving analytical and independent judgment skills to support an environment driven by customer service collaboration and teamwork.
  • Experience working directly with clients project stakeholders or business units to clarify scope communicate findings and support remediation efforts. Expand your possibilities with KTSA through KTSAMÁS where you can access Extended maternity paternity and adoption leaves Above-market vacation benefits Learning opportunities training and certification programs Extended marriage leave and daycare support Wellness and Employee Assistance Programs (EAP) Comprehensive medical plan life insurance car insurance and funeral assistance Visit www.ktsa.com.mx to learn more. At KTSA we celebrate and support everyone’s individuality. We do not discriminate against any race religion color national origin gender sexual orientation gender identity or expression age marital status or disability. We are supportive of helping you to achieve a balance between your home and work demands. We are happy to discuss specific requirements and our range of flexible working arrangements could be of interest. Please ask to find out more. We strongly state that we DO NOT require a certificate of non-pregnancy or HIV in order to participate in any of our processes. Explore KTSA we dare to be different! Home - KTSA KTSA - KPMG Technology Services of Americas

Unlock: Sign Up for free / Sign In and use the searches from your home page or the links in the footer.