Senior Associate / Manager - Cybersecurity Consultant and Auditor
- Employment type
- Full-time
- Location
- Zürich
- First posted
Your Team ##
Strengthen our Cybersecurity & Privacy team and work in an interdisciplinary environment with consultants, risk experts, and technology specialists. Together, we support organizations in effectively managing cyber risks, strengthening their digital resilience, and sustainably meeting regulatory requirements.
The role combines cyber strategy, governance, risk management, technology, and transformation with cybersecurity audits, assessments, and reviews in regulated and unregulated environments.
Zürich, genf, Zürich
By arrangement
100%
Management Consulting
All welcome
ID: 740023WD
Your Impact ##
• Development, implementation, and auditing of cyber (risk) strategies, governance and risk management models, and transformation initiatives, taking into account regulatory, organizational, and technological requirements.
• Conducting cybersecurity audits and assessments (e.g., maturity assessments) in regulated and unregulated environments to create transparency regarding risks, maturity levels, and the need for action.
• Translating international frameworks (such as ISO 27001, NIST CSF, and CIS) as well as regulatory requirements (such as FINMA, DORA, and NIS2) into viable governance models, standards, and controls.
• Assessment of third-party and supply chain cyber risks as well as participation in the further development of continuous monitoring and governance mechanisms.
• Support in the further development of measures in the areas of Cloud Security, Identity & Access Management, Data Security, Threat & Vulnerability Management, Security Monitoring, and Incident Response.
• Conducting workshops, interviews, briefings, and creating high-quality results such as reports, playbooks, risk registers, control matrices, and presentation-ready documents.
• Contribution to business development through participation in proposals, methodological results, and the development of point-of-view papers (e.g., whitepapers) on current topics.
• Promoting a culture of collaboration and quality, as well as continuous engagement with threat and regulation trends.
Your Skill Set ##
• 2-7 years of relevant professional experience in cybersecurity, IT, or technology risk, preferably in a consulting, Big 4, or regulated environment.
• Bachelor's or Master's degree in computer science, business informatics, business administration, engineering, or an equivalent professional qualification.
• Certifications such as CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Implementer are an advantage.
• Understanding of relevant cybersecurity standards, frameworks, and best practices, particularly ISO/IEC 27001/27002, NIST CSF, the CRI profile, CIS Controls, CIS Benchmarks, MITRE ATT&CK, and comparable reference works is an advantage.
• Experience with or a strong interest in regulatory requirements and resilience-related issues with a technology focus (such as FINMA 2023/01, DORA, NIS2).
• Familiarity with central subject areas such as cyber governance, IT and cyber risk management, security controls, cloud security, identity & access management, data security, and security operations, as well as their business-relevant classification.
• Structured, analytical, and quality-oriented way of working as well as the ability to prepare complex matters appropriately for the target audience.
• Strong communication, presentation, and stakeholder management skills in exchange with specialist departments, risk and control functions, as well as top management.
• Very good German and English skills; French skills are an advantage.
• High degree of initiative, self-organization, and sense of responsibility in a dynamic, team-oriented environment.
Your Benefits ##
Hybrid Flexible Working Model Our working model allows you to spend part of your time in the office and part at home (if you wish) - unless you are on-site with a client, which naturally always has priority. This way, you can adapt your schedule to your personal working style.
Education and Training Our learning and development offerings help you acquire valuable skills and knowledge to advance your career - not just at PwC. We offer a variety of internal and external courses for education and training. Recognize your strengths and your potential for improvement and develop new skills to achieve your professional goals. This will help you strengthen your confidence, improve your performance, and advance your career.
Sustainable Performance PwC is committed to creating an environment characterized by sustainable performance. We therefore provide a range of corresponding resources, such as workshops on Sustainable Performance, training in Self-Leadership, resilience and mindfulness training, nutrition webinars, and yoga classes.
Vacation and Leave From maternity, paternity, and adoption leave to vacation and paid leave: We know how important it is to take time away from work. At PwC, you can use vacation as well as a variety of leave options to recover, relax, or achieve personal goals.
Volunteering Do you like to commit yourself to a good cause and want to make a difference? That's great, because we feel the same way. Therefore, we encourage you to engage in volunteer work through our Corporate Sustainability programs by offering you paid time off for voluntary activities.
My Benefits Portal My Benefits is our platform for special offers and discounts. It gives you access to exclusive offers and discounts for a variety of products and services. Regardless of whether you are interested in the latest fashion trends, the trendiest tech products, or the best travel deals: On u
Automatically translated from the original.
Posted 7 weeks ago