Manager, Penetration Testing (Ciudad de México)

Manager, Penetration Testing (Ciudad de México)

29 ago
|
KTSA - KPMG Technology Services Americas
|
Ciudad de México

29 ago

KTSA - KPMG Technology Services Americas

Ciudad de México

About KTSA

We are KTSA – KPMG Technology Services Americas.

A Service Delivery Center of KPMG US, with offices in Mexico City, Guadalajara, and a growing network of remote talent across the country. We deliver high-value technology, consulting, and corporate support services to KPMG US and its clients.

At KTSA, our Employer Value Proposition is clear: Explore.

Explore isn’t just a word — it’s how we grow, lead, and thrive. It’s the mindset that drives our culture and shapes every opportunity:

- Experience a collaborative, inclusive, and multicultural workplace where you belong.
- Excel by creating impact and leaving your mark on integral projects.
- Expand your potential with real career paths, learning programs, and mentorship.
- Express your individuality — come as you are, and thrive as your authentic self.

Key Responsibilities:

- Conduct detailed application and network penetration testing engagements to identify exploitable vulnerabilities, control gaps, and practical paths to remediation.
- Plan and execute penetration testing activities across web applications, APIs, external and internal networks, cloud-hosted environments, and supporting infrastructure, as applicable to the engagement scope.
- Assess common application and API security weaknesses, including authentication flaws, authorization issues, injection vulnerabilities, business logic flaws, insecure configurations, and exposure of sensitive data.
- Document findings clearly, including business impact, technical evidence, risk context, reproducible steps, and practical remediation guidance for member firm stakeholders.
- Facilitate security assessments and support the resolution of identified vulnerabilities through clear communication, retesting, and coordination with application, infrastructure, and security teams.




- Communicate assessment results to technical and non-technical stakeholders through written reports, walkthroughs, and remediation discussions.
- Stay current with common and emerging security threats, penetration testing techniques, tooling, and assessment methodologies relevant to application and network security.

Qualifications:

- Bachelor’s degree with 5+ years of practical experience in cybersecurity, focused on application penetration testing, network penetration testing, and related cloud security assessment activities.
- Strong hands-on experience performing manual web application, API, network, and infrastructure penetration testing, including validation beyond automated scanning tools.
- Strong familiarity with frameworks and methodologies such as MITRE ATT&CK;, OWASP Top 10, OWASP API Security Top 10, PTES.
- Relevant certifications such as OSCP, GPEN, GWAPT, OSCE, GXPN, or similar are highly preferred. CISSP and Azure or other cloud platform certifications are a plus.
- Solid foundation in network, application, and cloud security concepts, with hands-on experience identifying, validating, and explaining vulnerabilities in real-world environments.
- Proficiency in scripting and automation with experience in Python, Bash, or PowerShell.
- Experience with common and emerging security threats, scanning tools, exploitation techniques, assessment methodologies, and secure remediation practices.
- Demonstrated understanding of security principles,



IT security controls, and related technologies and products.
- Strong verbal and written communication, problem solving, analytical, and independent judgment skills to support an environment driven by customer service, collaboration, and teamwork.
- Experience working directly with clients, project stakeholders, or business units to clarify scope, communicate findings, and support remediation efforts.

And because we know that thriving at work also means thriving in life, we back this mindset with KTSAMÁS, our total rewards program, designed to support your well-being, goals, and personal milestones.

Expand your possibilities with KTSA through KTSAMÁS, where you can access:

- Extended maternity, paternity, and adoption leaves
- Above-market vacation benefits
- Hybrid work model
- Learning opportunities, training, and certification programs
- Extended marriage leave and daycare support
- Wellness and Employee Assistance Programs (EAP)
- Comprehensive medical plan, life insurance, car insurance, and funeral assistance

Visit www.ktsa.com.mx to learn more. At KTSA, we celebrate and support everyone’s individuality. We do not discriminate against any race, religion, color, national origin, gender, sexual orientation, gender identity or expression, age, marital status, or disability. We are supportive of helping you to achieve a balance between your home and work demands.

We are happy to discuss specific requirements and our range of flexible working arrangements could be of interest. Please ask to find out more. We strongly state that we DO NOT require a certificate of non-pregnancy or HIV in order to participate in any of our processes.

Explore KTSA, we dare to be different!

Home - KTSA

KTSA - KPMG Technology Services of Americas

📌 Manager, Penetration Testing (Ciudad de México)
🏢 KTSA - KPMG Technology Services Americas
📍 Ciudad de México

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: manager, penetration testing (ciudad de méxico) / ciudad de méxico

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: manager, penetration testing (ciudad de méxico) / ciudad de méxico