KPMG logo

Senior Consultant - Digital Trust (Cyber Defense)

KPMG
1 day ago
Full-time
On-site
United Arab Emirates

JobsCloseBy Editorial Insights

KPMG is seeking a Senior Consultant in Digital Trust (Cyber Defense) to deliver red team operations, penetration testing, adversarial emulations, and SOC maturity assessments for clients across sectors. This is a remote opportunity for candidates based in Egypt, with occasional on-site travel to the UAE and KSA as needed, and a UAE client-facing footprint. The role demands hands-on offensive and defensive security work, C2 setup, social engineering, and reporting grounded in MITRE ATT&CK, plus contributions to business development. Ideal candidates have 5+ years in cyber security, OSCP mandatory plus another certification, strong tool skills (Burp Suite, Nmap, Metasploit), scripting and coding ability, and superb communication. To apply, tailor your resume to show measurable outcomes, highlight client-facing delivery, and prepare for real-world attack scenarios and stakeholder conversations.


Job Description The Role

You will be a Senior Consultant within the Cyber Defense and Response team, supporting the delivery of red team operations, penetration testing, adversarial emulations, and SOC maturity assessment projects for our clients across various sectors. 


The ideal candidate will have hands-on experience simulating real-world attacks across enterprise environments and executing various types of assessments including web, mobile, API, and network VAPT. The candidate should be technically proficient in using offensive security tools, command-and-control (C2) infrastructure, and conducting social engineering engagements as part of red team operations.

This is a remote opportunity for candidates based in Egypt, with occasional on-site travel to UAE/KSA on a need basis.

In addition to technical responsibilities, you will assist with business development activities such as proposal preparation, effort estimation, and staffing inputs for offensive security projects.

If you are passionate about cyber security, enjoy solving complex technical challenges, and want to grow your career in offensive and defensive security, then this role is for you.

Responsibilities
  • Executing penetration tests of web applications, mobile applications, APIs, and network infrastructure.
  • Participating in red team and social engineering engagements, including phishing and physical intrusion scenarios under supervision or defined playbooks.
  • Setting up, maintaining, and operating C2 infrastructure using tools such as Cobalt Strike, Sliver, or similar frameworks.
  • Assisting in adversary emulation exercises based on frameworks like MITRE ATT&CK.
  • Preparing detailed, risk-based reports and presenting technical findings to internal and client teams.
  • Developing and maintaining internal tools, scripts, and documentation for offensive testing.
  • Collaborating with other teams including blue/purple teams to improve client defenses.
  • Staying up-to-date with the latest offensive security techniques, vulnerabilities, and tools.
  • Developing an understanding of KPMG’s broader offerings to enable identification of business opportunities.
  • Supporting with business development activities including proposal development, budgeting, etc.
  • Developing constructive client relationships, both inside and outside of KPMG.
  • Building out and maintaining a professional network.
  • Being a trusted advisor and a role model for quality and risk management practices.
  • Upholding KPMG’s values by acting with integrity.
The Person

We are looking for a technically strong and client-focused professional with experience in delivering and managing offensive and defensive security assessments. The ideal candidate should demonstrate:

  • At least 5+ years of experience in cyber security, with a focus on offensive security and VAPT.
  • Strong understanding and experience with common penetration testing methodologies (e.g., OWASP, PTES, NIST).
  • Practical experience in performing Web, Mobile, API, LLM, cloud and network-based VAPT assessments.
  • Practical experience in conducting secure source code reviews in languages such as JavaScript (Node.js), C#, Python, Swift, Java, Dart, SQL, etc.
  • Practical experience with red teaming & purple teaming concepts, such as social engineering, initial access, lateral movement, data exfiltration, security tooling etc.
  • Experience in setting up, using and maintaining C2 platforms (e.g., Cobalt Strike, Mythic, etc.).
  • Practical experience in conducting secure configuration reviews of network and application infrastructure components in line with industry leading benchmarks such as CIS and STIG.
  • Experience delivering cyber security services in a consulting environment is required; prior experience with a Big Four firm is a plus.
  • Strong problem-solving skills and attention to detail in execution and reporting.
  • Team-oriented attitude with a willingness to learn and contribute to project success.
  • Ability to work in fast-paced environments and meet deadlines.
  • Proven ability to deliver work at sustained levels of high intensity, and inspire drive and resilience in others.
  • Proven ability to analyze problems, identify core issues and recommend appropriate solutions.
Qualifications and Skills
  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • OSCP certification is mandatory. In addition, candidates must hold at least one of the following: OSEP, OSWE, CCT INF and CCT APP.
  • Proficiency with industry-standard tools such as Burp Suite, Nmap, Metasploit, BloodHound, etc.
  • Proficient in at least one scripting language such as Python, PowerShell, or Bash.
  • Proficient in at least one programming language such as Java, C#, or JavaScript.
  • Excellent presentation and communication skills (both written and oral).
  • Ability to interact with senior stakeholders in client organizations.
  • Commitment to continuous learning and professional development in offensive and defensive security.