jobszurich.ch
← All jobs

Senior Associate / Manager - Cybersecurity Consultant and Auditor 100%

PwC Zurich

Employment type
Full-time
Location
Zürich
First posted
Apply now

Your Team Strengthen our Cybersecurity & Privacy team and work in an interdisciplinary environment with consultants, risk experts, and technology specialists. Together, we support organizations in effectively managing cyber risks, strengthening their digital resilience, and sustainably fulfilling regulatory requirements. The role combines cyber strategy, governance, risk management, technology, and transformation with cybersecurity audits, assessments, and reviews in regulated and unregulated environments. Your Impact Development, implementation, and auditing of cyber (risk) strategies, governance and risk management models, and transformation initiatives, taking into account regulatory, organizational, and technological requirements. Execution of cybersecurity audits and assessments (e.g., maturity assessments) in regulated and unregulated environments to create transparency regarding risks, maturity levels, and the need for action. Translation of international frameworks (such as ISO 27001, NIST CSF, and CIS) as well as regulatory requirements (such as FINMA, DORA, and NIS2) into viable governance models, standards, and controls. Assessment of third-party and supply chain cyber risks as well as participation in the further development of continuous monitoring and governance mechanisms. Support in the further development of measures in the areas of Cloud Security, Identity & Access Management, Data Security, Threat & Vulnerability Management, Security Monitoring, and Incident Response. Conduct of workshops, interviews, briefings, as well as creation of high-quality results such as reports, playbooks, risk registers, control matrices, and presentation-ready documents. Contribution to business development through participation in proposals, methodological results, and the development of point-of-view papers (e.g., whitepapers) on current topics. Promotion of a culture of collaboration and quality as well as continuous engagement with threat and regulation trends. Your Skill Set 2-7 years of relevant professional experience in cybersecurity, IT, or technology risk, preferably in a consulting, Big-4, or regulated environment. Bachelor's or Master's degree in computer science, business informatics, business administration, engineering, or an equivalent professional qualification. Certifications such as CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Implementer are an advantage. Understanding of relevant cybersecurity standards, frameworks, and best practices, particularly ISO/IEC 27001/27002, NIST CSF, the CRI profile, CIS Controls, CIS benchmarks, MITRE ATT&CK, and comparable reference works are an advantage. Experience with or strong interest in regulatory requirements and resilience-related issues with a technology focus (such as FINMA 2023/01, DORA, NIS2). Familiarity with central subject areas such as cyber governance, IT and cyber risk management, security controls, cloud security, identity & access management, data security, and security operations, as well as their business-relevant classification. Structured, analytical, and quality-oriented way of working as well as the ability to prepare complex matters in a target-group-oriented manner. Strong communication, presentation, and stakeholder management skills in exchange with specialist departments, risk and control functions, and top management. Very good German and English skills; French skills are an advantage. High degree of initiative, self-organization, and sense of responsibility in a dynamic, team-oriented environment.

Automatically translated from the original.

Posted 1 week ago

Location

View on Google Maps