KPMG logo

Cyber Assessment Manager (Penetration Testing)

KPMG Kingston, Jamaica

hybridfull-time
Posted Aug 3, 2026Apply by Sep 2, 2026

**Role & seniority: ** Offensive Security / Penetration Testing & Red Teaming; appears mid-to-senior (≥5 years experience; may mentor juniors).

**Stack/tools: **

  • Pen testing/red teaming frameworks: MITRE ATT&CK, MITRE ATLAS, OWASP, PTES, NIST

  • Certifications (preferred): GPEN, OSCP, OSCE, CISSP; Azure certs a plus

  • Scripting/automation: Python, Bash, PowerShell

  • Cloud penetration testing (preferred); network/cloud security concepts

  • AI security / ML adversarial techniques: prompt injection, data poisoning, model evasion; familiarity with common ML frameworks

  • Uses KPMG-approved Generative AI tools for daily work

  • Top 3 responsibilities:

    • Lead network and web application penetration tests to identify vulnerabilities and assess infrastructure risk

    • Run red teaming exercises to test real-world threat behavior and security detection/response

    • Manage end-to-end security assessments and vulnerability remediation lifecycles with technical teams

  • Must-have skills:

    • Hands-on experience in network/web pentesting, red teaming, and security assessments (≥5 years)

    • Strong understanding of security principles/controls and testing methodologies

    • Proficiency with offensive testing frameworks (MITRE/OWASP/PTES/NIST)

    • Scripting/automation using Python/Bash/PowerShell

    • Strong analytical, problem-solving, and communication skills; can work independently and meet

Full Description

OVERVIEW

  • KPMG Jamaica has a delivery center named Jamaica Extended Support Services (“JESS”) operating from Kingston, which is contracted to provide support to its member firm KPMG United States (“the Client”).

JOB SUMMARY

  • In this role, you will focus on offensive security assessment work with a significant emphasis on penetration testing and red teaming. You will lead initiatives to discover, exploit, and analyze system vulnerabilities while collaborating with security operations and development teams to align with security objectives and risk mitigation goals. Your expertise in advanced penetration testing frameworks and emerging AI security practices will guide efforts to analyze and recommend robust security enhancements. You will manage vulnerability remediation lifecycles.

JOB RESPONSIBILITIES Lead comprehensive network and web application penetration tests to identify security vulnerabilities and assess organizational infrastructure risk Conduct red teaming exercises to emulate real-world cyber threats and evaluate security operations detection and response capabilities Engage in advanced AI Red Teaming initiatives to discover vulnerabilities and improve the overall security, safety, and robustness of artificial intelligence systems Facilitate end-to-end security assessments and manage the remediation and resolution of identified vulnerabilities, collaborating with technical teams to ensure timely mitigation Track and analyze the latest cybersecurity trends, threat intelligence, and offensive techniques to keep testing methodologies current and adaptive Mentor, guide, and support junior team members to enhance their technical competencies and support overall professional development

EDUCATION/EXPERIENCE Bachelor's degree in Computer Science, Cybersecurity, or a related field Minimum of five (5) years’ practical experience in cybersecurity, focusing on network and web application penetration testing, red teaming, AI red teaming, cloud penetration testing, and security assessments Proficiency in network and cloud security concepts, with hands-on experience in cloud penetration testing, and strong understanding of network penetration testing is preferred Strong familiarity with frameworks such as MITRE ATT&CK and MITRE ATLAS, OWASP, PTES, and NIST, with relevant certifications such as GPEN, OSCP, OSCE, CISSP, or similar are highly preferred; Certifications in Azure a plus Proficiency in scripting and automation with experience in Python, Bash, or PowerShell Experience with adversarial machine learning techniques and familiarity with common ML frameworks and tools. (prompt injection, data poisoning, and model evasion) Experience with common and emerging security threats, scanning tools, and assessment methodologies and demonstrated experience and understanding of security principles, IT security controls and related technologies and products Solid verbal/written communication, problem-solving, analytical, and independent judgement skills to support an environment driven by customer service and teamwork Strong problem-solving skills, project management skills, and attention to detail Ability to work independently and work well within a team Strong organizational and time management skills; ability to adhere to deadlines Proficient in Microsoft Office Suite applications including Word, Excel, PowerPoint, and Outlook

SPECIAL CONDITIONS JESS uses a hybrid work model, allowing staff to work from home in Jamaica or in the office. Employees must be in the office at least five days per month, with more days possible if required by business needs. You are expected to use KPMG-approved Generative AI tools to support your daily work tasks. Expected to work in a fast-paced team environment. Will be working primarily in a paperless environment and expected to be using information systems for the entire workday to access data or perform activities. May be required to work extended hours periodically or on public holidays.

© 2026 KPMG Jamaica Extended Support Services Limited, a company incorporated in Jamaica and a member firm of the KPMG global organization of independent member firms affiliated with KPMG International Limited, a private English company limited by guarantee. All rights reserved.

Penetration TestingRed TeamingAI Red TeamingNetwork SecurityWeb Application SecurityCloud Penetration TestingVulnerability ManagementPythonBashPowerShellAdversarial Machine LearningMITRE ATT&CKOWASPNISTProject ManagementSecurity Assessmentsmulti-location

Cookies & analytics consent

We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.

Read how we use data in our Privacy Policy and Terms of Service.