logo

Technical Cybersecurity Specialist (Middle Pentester)

Almaty/Astana · Technology Consulting, Cybersecurity
Apply

We are looking for a motivated and technically strong Technical Cybersecurity Specialist (Middle Pentester) to join our Cybersecurity, Technology Consulting team. This role offers an opportunity to work on a variety of client engagements, helping organizations identify and address cybersecurity risks, strengthen their security posture, and improve their resilience.

Responsibilities

  • Independently plan and execute penetration testing engagements covering external infrastructure, internal networks, web applications, APIs, mobile applications, and cloud environments.
  • Identify, validate, and demonstrate security vulnerabilities, analyze attack paths, and assess their potential business impact.
  • Take ownership of project delivery from planning and execution through reporting, remediation, and clear, risk-based recommendations to improve clients’ security posture.
  • Contribute to security assessments, architecture reviews, AppSec initiatives, SOC maturity assessments, and security strategy projects.


Requirements

Required:

  • Bachelor’s or Master’s degree in Information Technology, Cybersecurity, Computer Science, or a related field.
  • 1+ years of hands-on experience in penetration testing, red teaming, application security, or offensive security assessments.
  • Strong practical knowledge of:
    - Web Application Security
    - Active Directory Security
  • Ability to communicate effectively with clients and explain technical issues in a clear and business-oriented manner.

Preferred:

  • Experience designing or implementing Application Security (AppSec) processes, including secure SDLC, threat modeling, security code review, or DevSecOps practices.
  • Experience with Security Operations Centers (SOC), threat detection, incident response, or security monitoring processes.
  • Understanding of cybersecurity frameworks and industry standards, including NIST CSF, ISO 27001, CIS Controls, and MITRE ATT&CK.
  • Experience with scripting or software development (Python, PowerShell, Java, C#, Go, or similar).
  • Hands-on participation in Hack The Box, TryHackMe, PortSwigger Academy, bug bounty programs, or Capture The Flag (CTF) competitions.
  • Experience working in cybersecurity consulting or client-facing environments.
  • Relevant certifications such as OSCP, OSWE, OSEP, CPTS, CRTO, PNPT, or equivalent.

Conditions

  • Continuous Learning
    Grow professionally with internal and external training programs, certifications, and opportunities to develop both soft and hard skills.
  • Bravo Recognition Program
    Be recognized for your outstanding contributions with the Bravo program, rewarding exceptional dedication and commitment to the firm.
  • Health & Life Insurance
    Get access to top-tier medical services and life insurance, ensuring stability and security.
  • Annual Bonuses
    Earn performance-based bonuses that reward your individual achievements and contributions to the company’s success.
  • Exclusive Discounts
    Take advantage of special discounts to stay active, comfortable, and enjoy great deals on various services.
  • Extended Vacation
    Take advantage of 24-30 days off annually, including 5 additional sick leave days, ensuring you have time to rest and recharge.
Share this job opening

Application:

I agree to the processing of my personal data in accordance with the KPMG Caucasus and Central Asia Privacy Policy