Senior Associate, Application Security, DevSecOps
Overview
As a Senior Associate in Application Security, DevSecOps, you will help secure AI-enabled development at scale within KPMG's Enterprise Security Services. You’ll assess AI tool security, define guardrails, and drive automation for security testing and metrics. You work closely with developers and platform teams to implement robust controls and remediation. This role combines hands-on security evaluation with cross-functional collaboration to protect data, models, and IP. Join a team focusing on innovative AI security in a leading professional services firm.
Compensation / Benefitscomprehensive compensation and benefits packagemedical and dental plansvision coverage401(k) planspersonal well-being benefitspaid time off and holidays
ResponsibilitiesStay abreast of AI application security threats and develop baselines and guardrails for AI appsConduct hands-on security evaluations of AI-enabled development tools, reviewing architectures, data flows, configurations, integrations, and security controlsApply standardized AppSec checklists and criteria to AI tools/use cases for consistent assessmentsDocument findings with risks, controls, remediation, and residual risk, and present to AppSec leadershipDevelop automation for metrics collection and automated testing for AI tool evaluations and maintain related dashboards and inventoriesProvide security guidance to developers and platform teams on controls and compensating measures and validate remediation activitiesRepresent integrity and professionalism in line with KPMG values
Key requirementsMinimum four years of experience in application security, DevSecOps, or secure software engineeringBachelor’s degree preferred; high school diploma or GED requiredCertifications such as GWAPT, GPEN, CEH, GWEB, CISSP, CISM or equivalentProgramming/scripting proficiency in Java, C#, JavaScript, Python, and SQLStrong knowledge of core security principles, risk assessment, and methods like threat modeling, OWASP Top 10Experience with SAST/DAST and cloud security concepts, with Azure preferenceExcellent written and verbal English communication for diverse audiencesAuthorized to work in the U.S. without visa sponsorship now or in the futureClear written and verbal communicationAbility to explain complex risks to diverse audiencesCollaborative cross-functional teamworkDevSecOps practices and CI/CD integrationAI-specific AppSec threats (prompt injection, data leakage, IP protection)Threat modeling and architecture reviews