4 Penetration Testers jobs in Hong Kong
FS Consulting - Cyber Security - Penetration Testing - Senior Consultant/Manager - Hong Kong
Posted 3 days ago
Job Viewed
Job Description
Overview
FS Consulting - Cyber Security - Penetration Testing - Senior Consultant/Manager - Hong Kong
Diversity is a core value at EY. We are passionate about building and sustaining an inclusive and equitable working environment for all of our people. We believe every member in our team enriches our diversity by exposing us to a broad range of ways to understand and engage with the world, identify challenges, and to discover, design and deliver solutions.
The opportunity
Do you like to create and innovate?
Cyber threats, emerging technologies, cloud adoption, digital disruption, and changing regulatory landscape are some of the challenges that customers face. EY teams are seeking people to join the fast growing EY businesses in helping our clients implement provable security at scale to combat these challenges. In particular, EY teams need people with proven experience and passion in penetration testing to help clients secure their application and infrastructure. If this is you, you will also have the opportunity to innovate on new ideas, technologies and explore new challenges.
Responsibilities- Lead a team to perform vulnerability scanning and penetration testing of web applications, mobile applications (Android and iOS), web services, API, network, thick client etc.
- Prepare and review testing reports and findings tracker sheets based on the provided template
- Lead a team to perform intelligence-led cyber attack simulation and run red teaming operations
- Communicate with customer stakeholders to explain and demonstrate vulnerabilities, and govern the mitigation of the identified vulnerabilities
- Research the latest security best practices and stay abreast of new threats and vulnerabilities
- Coach / mentor junior team members on VSPT and read teaming related knowledge and skills
- Participate in a fast-paced delivery in challenging projects of other cyber security domains
- Involve in customer relationship management, project management and team management
- Candidates with less experience will be considered as Senior Associate
- College degree or equivalent with minimum 5 years' related experience in penetration testing
- Mandatory Certification - any one of OSCP, CREST, GPXN, GPEN or equivalent
- Proven skills and knowledge in penetration testing and red teaming experiences and strong track records of projects delivered
- Good experience in using VSPT and red teaming tools (e.g. Nessus, AppScan, Accunetix, Burpsuite Pro, WebInspect, etc.) and Risk Rating Standards like DREAD, CVSS etc.
- Proficiency in written and oral English communication skills. Cantonese is an advantage
- Experience in static and dynamic secure code review will be an advantage
- Experience in application security architecture and assessment will be an advantage
- Experience in threat intelligence and threat modeling will be an advantage
- Exposures to working with industry leading organizations
- Opportunities to develop new skills by working together with leading professionals in penetration testing and red teaming fields
- Opportunity to fast track your career and achieve your initiatives
- The freedom and flexibility to handle your role in a way that’s right for you
- Support, coaching and feedback from some of the most engaging colleagues around
As a global leader in assurance, tax, strategy and transactions and consulting services, we’re using the finance products, knowledge and systems we’ve developed to build a better working world. That starts with a culture that believes in giving you the training, opportunities and creative freedom to make things better. Whenever you join, however long you stay, the exceptional EY experience lasts a lifetime. And with a commitment to hiring and developing the most passionate people, we’ll make our ambition to be the best employer by 2020 a reality.
If you can demonstrate that you meet the criteria above, please contact us as soon as possible.
Join us in building a better working world.
Job details- Seniority level: Mid-Senior level
- Employment type: Full-time
- Job function: Consulting, Information Technology, and Accounting/Auditing
- Industries: Professional Services
Referrals increase your chances of interviewing at EY by 2x
Get notified about new Business Consultant jobs in Hong Kong, Hong Kong SAR .
Note: This description reflects the core responsibilities and qualifications for the role and does not include external postings or unrelated listings.
#J-18808-LjbffrConsultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Con[...]
Posted 11 days ago
Job Viewed
Job Description
Join to apply for the Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ ) role at KPMG China
Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ )Join to apply for the Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ ) role at KPMG China
KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients’ needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment and community. At KPMG, you’ll translate insights into action and reveal opportunities for all—our teams, our clients and our world.
Service Line Overview
At KPMG's Consulting practice, we do not limit ourselves to either strategy or implementation. We deliver both. Our Hong Kong division is the fastest growing within KPMG China and represents a young and enthusiastic team that always pushes for success. Since our inception, we have acquired in-depth knowledge of an incredibly broad range of sectors and services.
KPMG is the firm that views cyber security as a business enabler, and not just an IT issue. From the boardroom to back office, we help clients through Strategy and Governance, Transformation, Cyber Defense and Cyber Response. So that they are prepared for uncertainty and use cyber security to advance the business, not stand in the way.
Our wide range of projects includes Cyber Strategy, Cyber Digital Transformation, Governance & Risk, as well as a strong presence in Penetration Testing or Ethical Hacking. We are keen to speaking with cyber security specialists with various expertise and experiences to join our growth story.
We are now seeking Consultant/ Senior Consultant candidates for Cyber Defense Team.
Key Responsibilities
- Perform vulnerability assessment and penetration tests on different platforms and technologies
- Simulate real-time cyber-attacks using red team / blue team / purple team exercises
- Conduct social engineering and email phishing attacks to simulate the theft of passwords, infiltrate systems, and download malware / ransomware
- Conduct source code review to identify software program vulnerabilities and detect malware or malicious embedded code
- Conduct cloud / server / network / middleware security configuration assessments
- Conduct architecture review for cloud / on-premise IT environments
- Prepare reports on identified security vulnerabilities and possible recommendations to remediate the vulnerabilities
- Assist in continuously enhancing the existing security assessment methodologies
- Support in developing marketing and training materials to help develop staff awareness within the company and communicate KPMG's capabilities to clients
- Remain up-to-date on the latest cybersecurity threats, vulnerabilities and regulatory requirements
- Develop constructive client relationships, both inside and outside of KPMG
- Bachelor’s degree in computer science, InformationTechnology, or related field.
- At least one professionally qualification required: CREST, GXPN, GPEN, GCTI, GWAPT, OSCE3, OSEP, OSWE, OSEP, OSCP, CRTE, eCPTX, CISSP, or other relevant qualifications.
- 2 years of relevant working experience preferred: Red/Blue/Purple Teaming, Web/Mobile/Network/OT/IoT/other Penetration Tests, Vulnerability Assessment, Source Code Review, Appliance/System/Cloud Configuration Review, Malware development, Social Engineering.
- Candidate with less experience will be considered as Consultant.
- Knowledge in threat intelligence, reverse engineering, security products, incident response, SOC operation or other related areas will be an advantage.
- Experience with at least one scripting language (e.g. Bash, PowerShell) or programming language (e.g. Python, C, Java) preferred.
- Able to understand basic networking concepts (e.g. routing, ALC, load balancers, SSL/TLS, TCP) is preferred.
- Understand the industry recognised testing standards and have knowledge of common red teaming tools·
- Knowledge base in enterprise technologies and operations, enterprise networking, internet application security, database security evaluation and architecture, with self-motivated learning ability.
- Be able to conduct research and development and solve technical problems independently.
- Be able to work as part of a team, and at the same time being an independent self-starter·
- Have strong analytical, problem solving and inter-personal skills·
- Commands excellent written and oral communication skills with the ability to present ideas and results to technical and non-technical audiences·
- Possess a recognised Degree in Computer Science, Cyber Security, Computer/Information Engineering, Information Technology or a related discipline (STEM) is preferred·
- Excellent written and verbal communication skills in English and Chinese (Mandarin or Cantonese)
KPMG is looking for someone who is passionate about helping our clients with their cyber security challenges. In return, we are helping you to develop your skills and career within the KPMG network.
- Well-structured career development and learning path, 1-to-1 coaching by our cybersecurity professionals
- Access to various cyber security learning resources
- Wide exposure to working with leading financial institutions and corporations
- Continuous sponsorship and support on professional certificate development (i.e. Offensive Security, GIAC, CREST, etc.)
- Opportunities for secondment / exchange within KPMG Global network based on staff performance and preference
- Opportunities to attend KPMG overseas Global Cyber Events – such as HackNet / BlackHat
- One annual professional membership sponsorship on the approved list
- Work in a passionate team with blended cybersecurity talents
At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level.
We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients to help them achieve their ESG goals. View Our Impact Plan to learn more about our ESG commitments and progress across four key pillars - Governance, People, Planet and Prosperity – and how we make a positive impact on our people, environment and society.
We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information.
You acknowledge and agree that all personal information hereby provided regarding yourself will be used by KPMG China for its candidate selection purposed only. KPMG China collects, uses, processes, and retains your personal information in accordance with KPMG China’s Online Privacy Statement and/or KPMG China Privacy Statement (collectively "Privacy Statement "). During the recruitment process, KPMG China may need to store personal information of candidates in a designated third-party application tracking platform.
If you have any questions regarding the information you provided in the form or your job application in general, please contact KPMG China’s HR personnel in the location where your application is submitted (see here). Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Engineering and Information Technology
- Industries Professional Services
Referrals increase your chances of interviewing at KPMG China by 2x
Sign in to set job alerts for “Senior Java Consultant” roles. Senior Java Backend Developer - Web3 / Fintech / Financial Services (Senior) Staff Engineer - Java (Compliance Platform) Principal/Senior Engineer - Core - Platform Tool (Java) Senior/Staff Java Trading Developer, Liquidity Platform Principal/Senior Java Engineer - Multi-Language & Localization Lead Software Engineer, Java, Order Management System for Equities Trading Senior Engineer - Compliance Platform(Java) Principal/Senior Java Engineer - Defi - Earn Senior Engineer - Java (Exchange Platform - Financial Product) Lead Software Engineer, Electronic Trading Technology, Java Principal/Senior Engineer - Defi - Explorer(Java)We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrFS Consulting - Cyber Security - Penetration Testing - Senior Consultant/Manager - Hong Kong
Posted 3 days ago
Job Viewed
Job Description
FS Consulting - Cyber Security - Penetration Testing - Senior Consultant/Manager - Hong Kong
Diversity is a core value at EY. We are passionate about building and sustaining an inclusive and equitable working environment for all of our people. We believe every member in our team enriches our diversity by exposing us to a broad range of ways to understand and engage with the world, identify challenges, and to discover, design and deliver solutions.
The opportunity
Do you like to create and innovate?
Cyber threats, emerging technologies, cloud adoption, digital disruption, and changing regulatory landscape are some of the challenges that customers face. EY teams are seeking people to join the fast growing EY businesses in helping our clients implement provable security at scale to combat these challenges. In particular, EY teams need people with proven experience and passion in penetration testing to help clients secure their application and infrastructure. If this is you, you will also have the opportunity to innovate on new ideas, technologies and explore new challenges.
Responsibilities- Lead a team to perform vulnerability scanning and penetration testing of web applications, mobile applications (Android and iOS), web services, API, network, thick client etc.
- Prepare and review testing reports and findings tracker sheets based on the provided template
- Lead a team to perform intelligence-led cyber attack simulation and run red teaming operations
- Communicate with customer stakeholders to explain and demonstrate vulnerabilities, and govern the mitigation of the identified vulnerabilities
- Research the latest security best practices and stay abreast of new threats and vulnerabilities
- Coach / mentor junior team members on VSPT and read teaming related knowledge and skills
- Participate in a fast-paced delivery in challenging projects of other cyber security domains
- Involve in customer relationship management, project management and team management
- Candidates with less experience will be considered as Senior Associate
- College degree or equivalent with minimum 5 years' related experience in penetration testing
- Mandatory Certification - any one of OSCP, CREST, GPXN, GPEN or equivalent
- Proven skills and knowledge in penetration testing and red teaming experiences and strong track records of projects delivered
- Good experience in using VSPT and red teaming tools (e.g. Nessus, AppScan, Accunetix, Burpsuite Pro, WebInspect, etc.) and Risk Rating Standards like DREAD, CVSS etc.
- Proficiency in written and oral English communication skills. Cantonese is an advantage
- Experience in static and dynamic secure code review will be an advantage
- Experience in application security architecture and assessment will be an advantage
- Experience in threat intelligence and threat modeling will be an advantage
- Exposures to working with industry leading organizations
- Opportunities to develop new skills by working together with leading professionals in penetration testing and red teaming fields
- Opportunity to fast track your career and achieve your initiatives
- The freedom and flexibility to handle your role in a way that’s right for you
- Support, coaching and feedback from some of the most engaging colleagues around
As a global leader in assurance, tax, strategy and transactions and consulting services, we’re using the finance products, knowledge and systems we’ve developed to build a better working world. That starts with a culture that believes in giving you the training, opportunities and creative freedom to make things better. Whenever you join, however long you stay, the exceptional EY experience lasts a lifetime. And with a commitment to hiring and developing the most passionate people, we’ll make our ambition to be the best employer by 2020 a reality.
If you can demonstrate that you meet the criteria above, please contact us as soon as possible.
Join us in building a better working world.
Job details- Seniority level: Mid-Senior level
- Employment type: Full-time
- Job function: Consulting, Information Technology, and Accounting/Auditing
- Industries: Professional Services
Referrals increase your chances of interviewing at EY by 2x
Get notified about new Business Consultant jobs in Hong Kong, Hong Kong SAR .
Note: This description reflects the core responsibilities and qualifications for the role and does not include external postings or unrelated listings.
#J-18808-LjbffrConsultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Con[...]
Posted 16 days ago
Job Viewed
Job Description
Join to apply for the Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ ) role at KPMG China
Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ )Join to apply for the Consultant/Senior Consultant, Cyber Security (Penetration Testing/ Red Teaming), Technology Consulting (MJ ) role at KPMG China
KPMG China provides multidisciplinary services from audit and tax to advisory, with a strong focus on serving our clients’ needs and their industries. Not only do we have an overriding commitment to provide the highest quality services for our clients, but we also strive to become a responsible corporate citizen that has a positive impact on our environment and community. At KPMG, you’ll translate insights into action and reveal opportunities for all—our teams, our clients and our world.
Service Line Overview
At KPMG's Consulting practice, we do not limit ourselves to either strategy or implementation. We deliver both. Our Hong Kong division is the fastest growing within KPMG China and represents a young and enthusiastic team that always pushes for success. Since our inception, we have acquired in-depth knowledge of an incredibly broad range of sectors and services.
KPMG is the firm that views cyber security as a business enabler, and not just an IT issue. From the boardroom to back office, we help clients through Strategy and Governance, Transformation, Cyber Defense and Cyber Response. So that they are prepared for uncertainty and use cyber security to advance the business, not stand in the way.
Our wide range of projects includes Cyber Strategy, Cyber Digital Transformation, Governance & Risk, as well as a strong presence in Penetration Testing or Ethical Hacking. We are keen to speaking with cyber security specialists with various expertise and experiences to join our growth story.
We are now seeking Consultant/ Senior Consultant candidates for Cyber Defense Team.
Key Responsibilities
- Perform vulnerability assessment and penetration tests on different platforms and technologies
- Simulate real-time cyber-attacks using red team / blue team / purple team exercises
- Conduct social engineering and email phishing attacks to simulate the theft of passwords, infiltrate systems, and download malware / ransomware
- Conduct source code review to identify software program vulnerabilities and detect malware or malicious embedded code
- Conduct cloud / server / network / middleware security configuration assessments
- Conduct architecture review for cloud / on-premise IT environments
- Prepare reports on identified security vulnerabilities and possible recommendations to remediate the vulnerabilities
- Assist in continuously enhancing the existing security assessment methodologies
- Support in developing marketing and training materials to help develop staff awareness within the company and communicate KPMG's capabilities to clients
- Remain up-to-date on the latest cybersecurity threats, vulnerabilities and regulatory requirements
- Develop constructive client relationships, both inside and outside of KPMG
- Bachelor’s degree in computer science, InformationTechnology, or related field.
- At least one professionally qualification required: CREST, GXPN, GPEN, GCTI, GWAPT, OSCE3, OSEP, OSWE, OSEP, OSCP, CRTE, eCPTX, CISSP, or other relevant qualifications.
- 2 years of relevant working experience preferred: Red/Blue/Purple Teaming, Web/Mobile/Network/OT/IoT/other Penetration Tests, Vulnerability Assessment, Source Code Review, Appliance/System/Cloud Configuration Review, Malware development, Social Engineering.
- Candidate with less experience will be considered as Consultant.
- Knowledge in threat intelligence, reverse engineering, security products, incident response, SOC operation or other related areas will be an advantage.
- Experience with at least one scripting language (e.g. Bash, PowerShell) or programming language (e.g. Python, C, Java) preferred.
- Able to understand basic networking concepts (e.g. routing, ALC, load balancers, SSL/TLS, TCP) is preferred.
- Understand the industry recognised testing standards and have knowledge of common red teaming tools·
- Knowledge base in enterprise technologies and operations, enterprise networking, internet application security, database security evaluation and architecture, with self-motivated learning ability.
- Be able to conduct research and development and solve technical problems independently.
- Be able to work as part of a team, and at the same time being an independent self-starter·
- Have strong analytical, problem solving and inter-personal skills·
- Commands excellent written and oral communication skills with the ability to present ideas and results to technical and non-technical audiences·
- Possess a recognised Degree in Computer Science, Cyber Security, Computer/Information Engineering, Information Technology or a related discipline (STEM) is preferred·
- Excellent written and verbal communication skills in English and Chinese (Mandarin or Cantonese)
KPMG is looking for someone who is passionate about helping our clients with their cyber security challenges. In return, we are helping you to develop your skills and career within the KPMG network.
- Well-structured career development and learning path, 1-to-1 coaching by our cybersecurity professionals
- Access to various cyber security learning resources
- Wide exposure to working with leading financial institutions and corporations
- Continuous sponsorship and support on professional certificate development (i.e. Offensive Security, GIAC, CREST, etc.)
- Opportunities for secondment / exchange within KPMG Global network based on staff performance and preference
- Opportunities to attend KPMG overseas Global Cyber Events – such as HackNet / BlackHat
- One annual professional membership sponsorship on the approved list
- Work in a passionate team with blended cybersecurity talents
At KPMG China, we are committed to being an equal opportunity employer, with zero tolerance for any form of discrimination against any persons. It is important for us to create an inclusive, diverse and agile workplace for our people to develop and thrive at both a personal and professional level.
We strive to make ESG (environmental, social and governance) a watermark running through our organisation; from empowering our people to become agents of positive change, to providing better solutions and services to our clients to help them achieve their ESG goals. View Our Impact Plan to learn more about our ESG commitments and progress across four key pillars - Governance, People, Planet and Prosperity – and how we make a positive impact on our people, environment and society.
We encourage you to come as you are, and we welcome all qualified candidates to apply, and hope you unlock opportunities with us. Visit KPMG China website for more company information.
You acknowledge and agree that all personal information hereby provided regarding yourself will be used by KPMG China for its candidate selection purposed only. KPMG China collects, uses, processes, and retains your personal information in accordance with KPMG China’s Online Privacy Statement and/or KPMG China Privacy Statement (collectively "Privacy Statement "). During the recruitment process, KPMG China may need to store personal information of candidates in a designated third-party application tracking platform.
If you have any questions regarding the information you provided in the form or your job application in general, please contact KPMG China’s HR personnel in the location where your application is submitted (see here). Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Engineering and Information Technology
- Industries Professional Services
Referrals increase your chances of interviewing at KPMG China by 2x
Sign in to set job alerts for “Senior Java Consultant” roles. Senior Java Backend Developer - Web3 / Fintech / Financial Services (Senior) Staff Engineer - Java (Compliance Platform) Principal/Senior Engineer - Core - Platform Tool (Java) Senior/Staff Java Trading Developer, Liquidity Platform Principal/Senior Java Engineer - Multi-Language & Localization Lead Software Engineer, Java, Order Management System for Equities Trading Senior Engineer - Compliance Platform(Java) Principal/Senior Java Engineer - Defi - Earn Senior Engineer - Java (Exchange Platform - Financial Product) Lead Software Engineer, Electronic Trading Technology, Java Principal/Senior Engineer - Defi - Explorer(Java)We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrBe The First To Know
About the latest Penetration testers Jobs in Hong Kong !