Senior Associate - Cyber Security Consultant

4 Months ago • 3 Years + • Cyber Security

Job Summary

Job Description

Lead penetration testing engagements, web/mobile app security assessments, network vulnerability analysis, and red teaming activities. Requires 3+ years of experience in penetration testing, strong knowledge of OWASP Top 10 & CWE Top 25, and ability to work under pressure.
Must have:
  • Penetration Testing
  • OWASP Top 10
  • CWE Top 25
  • Vulnerability Assessment
Good to have:
  • Red Teaming
  • Cyber-attack Simulation
  • Secure Development
  • DevSecOps
Perks:
  • Flexible Work
  • Certification Sponsorship

Job Details

Line of Service

Assurance

Industry/Sector

Not Applicable

Specialism

Cybersecurity & Privacy

Management Level

Senior Associate

Job Description & Summary

We are PwC, a global professional services company and a Big Four firm. We are seeking candidates who have experience in penetration testing, red teaming or secure source-code review/development for the role of Senior Consultant/Penetration Tester within the Cybersecurity and Privacy team. The role may be based either at our Hanoi office or Ho Chi Minh City offices. Joining PwC, the successful candidate will have opportunities to collaborate with cybersecurity experts throughout the PwC global network and deliver cybersecurity services for clients in various sectors.
● Work in a highly innovative and transformative business
● Work/life balance with access to flexible work arrangements
● Salary packaging – to suit your personal and financial circumstances
● Professional certification sponsorship – to develop your talent and enhance knowledge

What will your typical day look like?
Do you thrive on developing creative and innovative insights to solve complex challenges? Want to work on next-generation, cutting-edge products and services that deliver outstanding value and that are global in vision and scope? Work with other experts in your field? Work for a world-class organisation that provides an exceptional career experience with an inclusive and collaborative culture?

Responsibilities:

  • Lead the team in cybersecurity assessments, covering web application and mobile application penetration testing in accordance with OWASP Top 10 framework and CWE Top 25 most dangerous software weaknesses
  • Lead the team in network penetration tests and vulnerability assessments to identify potential issues against network access control and network segmentation
  • Conduct source code reviews to identify potential logical errors in program flows, misconfigurations, and exploitable vulnerabilities in the applications
  • Conduct red teaming engagement and cyber-attack simulation testing to assess clients cybersecurity strategies
  • Research, collect and analyse cyber threat intelligence from threat actors
  • Engage in establishing network infrastructure for red teaming activities, including but not limited to command & control ("C2") servers, SMTP relay mail servers, web servers, and reverse proxies
  • Design and launch phishing attacks to generate reports for increasing awareness of employees regarding different types of phishing techniques
  • Provide pragmatic recommendations on the identified risks
  • Deliver both management-level and detailed technical reporting of observations, along with assisting in giving presentations to both technical and business stakeholders
  • Train, coach and mentor junior penetration testers
  • Lead day-to-day penetration testing delivery activities, including client and internal communication management, as well as technical quality control
  • Work actively in supporting and following up on proposal processing in accordance with client expectations on a cross-border and global multinational basis
  • Continuously research and follow up on the latest IT security challenges and technologies (mobile, digital trust, IoT, cloud, blockchain etc.)

You are someone with:

  • 3+ years of proven experience in conducting either network and infrastructure or web/API or mobile application penetration testing and be able to independently manage engagement delivery
  • Experience in leading and supervising engagement teams in penetration testing and vulnerability assessment projects
  • Thorough understanding of common infrastructure and web application vulnerabilities and common vulnerability categorisations such as OWASP and CVSS
  • Knowledge of common software security vulnerabilities (CWE Top 25 Most Dangerous Software Weaknesses)
  • Experience in penetration testing and vulnerability assessment across one of the several following domains: web and mobile applications, cloud and container security, reverse engineering, applied cryptography, networks infrastructure, etc.
  • Ability to work under pressure and deliver quality work in tight timelines
  • Demonstrated experience of working with diverse stakeholders
  • Excellent communication and interpersonal skills
  • Willingness to take on new challenges, gain new skills and work collaboratively in a dynamic and rapidly growing team
  • One of the following industry certifications: OSCP, OSWA, eWPT, eCPPT, CRTP, PNPT, CREST CRT/CCT, or equivalent

Preferred:

  • Experience in conducting red teaming engagements and cyber-attack simulation testing
  • Experience in developing hacking scripts/tools
  • Secure development and/or DevSecOps experience, including experience of securing code before deployment, code review, and vulnerability and dependency management
  • Ability to communicate strategic information security topics, policies, and standards as well as risk-related concepts to technical and non-technical audiences
  • Experience in bug bounty programs or CVE hunting is an advantage
  • Preference will be given to candidates who hold relevant cloud certifications: AWS, Azure, GCP
  • Strong preference will be given to candidates who hold one of the following industry certifications: OSWE, OSEP, OSCE, CRTO, CRTE, eCPTX, eWPTX, SANS
  • Strong preference will be given to candidates who hold one of the following professional certifications: CISSP, CCSP, CSSLP, CISM, CRISC, PMP

Education (if blank, degree and/or field of study not specified)

Degrees/Field of Study required:

Degrees/Field of Study preferred: Bachelor Degree - Information CyberSecurity

Certifications (if blank, certifications not specified)

Required Skills

Cybersecurity, Cybersecurity Policy, Cyber Threat Analysis

Optional Skills

Desired Languages (If blank, desired languages not specified)

English, Vietnamese

Travel Requirements

Not Specified

Available for Work Visa Sponsorship?

No

Government Clearance Required?

No

Job Posting End Date

December 4, 2024

Similar Jobs

6sense - Contractor, Security Operations (SIEM/SOAR)

6sense

Pune, Maharashtra, India (On-Site)
4 Months ago
Reversing Labs - Federal Security Solutions Architect (Sales Engineer)

Reversing Labs

Washington, District Of Columbia, United States (Remote)
2 Months ago
PwC - Cybersecurity -Data Loss Prevention Senior Associate - Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Eleven Labs - Technical Investigator / Data Scientist - AI Safety

Eleven Labs

India (Remote)
3 Months ago
Trend Micro - Sr. Information Security Specialist

Trend Micro

Irving, Texas, United States (On-Site)
3 Months ago
PwC - IT Associate - Jordan

PwC

Amman, Amman Governorate, Jordan (On-Site)
4 Months ago
PwC - CD&E-Cybersecurity-ServiceNow developer - Senior Associate - Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Palo Alto Networks - Presales, Prisma Cloud Solutions Architect, Majors

Palo Alto Networks

Chicago, Illinois, United States (Remote)
2 Months ago
Normalyze - Customer Success Engineer - Data Security - Implementation - DSPM - Bangalore

Normalyze

Bengaluru, Karnataka, India (Remote)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Saviynt - Senior Manager – Cyber Defense/ Security Operations Center

Saviynt

Bengaluru, Karnataka, India (On-Site)
3 Months ago
Trend Micro - Sales Engineer

Trend Micro

Amsterdam, North Holland, Netherlands (On-Site)
4 Months ago
Rackspace Technology - SOC Lead (Sentinel exp is must) , Security Operations

Rackspace Technology

India (Remote)
3 Months ago
Kyruus Health - Staff SecOps Engineer

Kyruus Health

United States (Remote)
3 Months ago
N-iX - Junior Product Designer (#2422)

N-iX

Lviv, Lviv Oblast, Ukraine (Flexible)
2 Months ago
Google - Customer Engineer, Cloud Security

Google

(On-Site)
2 Months ago
Google - Security Engineer, Cloud Threat and Abuse Detection

Google

Hyderabad, Telangana, India (On-Site)
2 Months ago
Scientific Games  - Senior Information Security Analyst

Scientific Games

Bengaluru, Karnataka, India (On-Site)
3 Months ago
FCM Travel - Team Lead, IS Security Lead- Asia

FCM Travel

Bengaluru, Karnataka, India (On-Site)
4 Months ago
N-iX - Senior Python Engineer (#2435)

N-iX

Ukraine (Remote)
2 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Ho Chi Minh City, Ho Chi Minh City, Vietnam

Autodesk - License Compliance Inside Sales Executive, Vietnam

Autodesk

Ho Chi Minh City, Ho Chi Minh City, Vietnam (On-Site)
3 Months ago
Virtuos - Lead Level Artist

Virtuos

Vietnam (On-Site)
2 Months ago
Amanotes - Game Product Owner (Music Entertainment Platform)

Amanotes

Ho Chi Minh City, Ho Chi Minh City, Vietnam (On-Site)
2 Months ago
KBG Blockchain Game Studios - QC Engineer

KBG Blockchain Game Studios

Thành Phố Hồ Chí Minh, Vietnam (On-Site)
6 Months ago
USE Insider - Account Director - Vietnam HCMC

USE Insider

Ho Chi Minh City, Ho Chi Minh City, Vietnam (Hybrid)
3 Months ago
Sun Studio - Senior QA Engineer - App Game

Sun Studio

Ho Chi Minh City, Ho Chi Minh City, Vietnam (On-Site)
3 Months ago
Sun Studio - 3 Motion Graphics Editors for Video - Casual Games

Sun Studio

Ho Chi Minh City, Ho Chi Minh City, Vietnam (On-Site)
2 Months ago
NinjaVan - Sales Manager (B2B)

NinjaVan

Ho Chi Minh City, Ho Chi Minh City, Vietnam (On-Site)
3 Months ago
Sun Studio - Senior/Principal Unity Game Developer (Casual Games)

Sun Studio

Ho Chi Minh City, Ho Chi Minh City, Vietnam (On-Site)
2 Months ago
Amanotes - Product Owner - New Game (Hybrid Casual Game)

Amanotes

Ho Chi Minh City, Ho Chi Minh City, Vietnam (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

ION - Senior Security Architect

ION

London, England, United Kingdom (On-Site)
3 Months ago
ByteDance - Senior SRE Architect, Security Engineering

ByteDance

Singapore (On-Site)
2 Months ago
Smarsh - Senior Technical Product Manager - Runtime Network and Security

Smarsh

United Kingdom (Remote)
3 Months ago
Anavation - Cybersecurity Policy and Compliance Certified Professional

Anavation

Fort Belvoir, Virginia, United States (On-Site)
3 Months ago
PwC - IN-Associate_Azure Data Engineer_MS Engg_Advisory_Kolkata

PwC

Kolkata, West Bengal, India (On-Site)
3 Months ago
Axinous - Staff Software Engineer - Automation

Axinous

Sahibzada Ajit Singh Nagar, Punjab, India (On-Site)
2 Months ago
PwC - Cybersecurity-IAM - Sailpoint Developer -Senior Associate

PwC

Hyderabad, Telangana, India (On-Site)
3 Months ago
OpenText - Software Security Research

OpenText

Bengaluru, Karnataka, India (On-Site)
4 Months ago
CloudLinux - Senior Go Developer for Imunify (worldwide remote)

CloudLinux

Bucharest, Bucharest, Romania (Remote)
3 Months ago

Get notifed when new similar jobs are uploaded

About The Company

At PwC, our purpose is to build trust in society and solve important problems. We’re a network of firms in 152 countries with over 327,000 people who are committed to delivering quality in assurance, advisory and tax services. Find out more and tell us what matters to you by visiting us at www.pwc.com. PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity.


Content on this page has been prepared for general information only and is not intended to be relied upon as accounting, tax or professional advice. Please reach out to your advisors for specific advice.

Gqeberha, Eastern Cape, South Africa (On-Site)

Athens, Greece (Remote)

Qormi, Malta (On-Site)

Detroit, Michigan, United States (Remote)

Kolkata, West Bengal, India (On-Site)

Olivos, Buenos Aires Province, Argentina (On-Site)

View All Jobs

Get notified when new jobs are added by PWC

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug