Experienced Associate - Cyber Security
Hanoi, Vietnam
â ď¸ We'll shut down after Aug 1st - try foođŚ for all jobs in tech â ď¸
PwC
We unite expertise and tech so you can outthink, outpace and outperformâ.Line of Service
AssuranceIndustry/Sector
Not ApplicableSpecialism
Conduct and ComplianceManagement Level
AssociateJob Description & Summary
We are PwC, a global professional services company and a Big Four firm. We are seeking candidates who have experience in penetration testing, red teaming or secure source-code review/development for the role of Associate Consultant/Penetration Tester within the Cybersecurity and Privacy team. The role may be based at either our Hanoi office or Ho Chi Minh City office. Joining PwC, the successful candidate will have opportunities to collaborate with cybersecurity experts throughout the PwC global network and deliver cybersecurity services for clients in various sectors.Work in a highly innovative and transformative business
Work/life balance with access to flexible work arrangements
Salary packaging â to suit your personal and financial circumstances
Professional certification sponsorship â to develop your talent and enhance knowledge
What will your typical day look like?
Do you thrive on developing creative and innovative insights to solve complex challenges? Want to work on next-generation, cutting-edge products and services that deliver outstanding value and that are global in vision and scope? Work with other experts in your field? Work for a world-class organisation that provides an exceptional career experience with an inclusive and collaborative culture?
Responsibilities:Â
Conduct cybersecurity assessments, covering web application and mobile application penetration testing in accordance with OWASP Top 10 and CWE Top 25Â Â
Conduct internal/external network penetration testing to assess clientsâ network security risks and evaluate clientsâ cybersecurity controlsÂ
Perform network vulnerability assessments to identify potential issues against network access controls and network segmentation Â
Engage in red teaming engagement projects and cyber-attack simulation testing to assess clientsâ cybersecurity strategiesÂ
Engage source code reviews to identify potential logical errors in program flows, misconfigurations, and exploitable vulnerabilities in applications Â
Research, collect and analyse cyber threat intelligence from threat actors Â
Work actively in supporting and following up on proposal processing in accordance with client expectations on a cross-border and global multinational basis Â
Continuously research and follow up on the latest IT security challenges and technologies (mobile, digital trust, IoT, cloud, blockchain etc.)Â Â
Â
You are someone with: Â
Experience in web application development and software engineeringÂ
Knowledge of common infrastructure and web application vulnerabilities and common vulnerability categorisations such as OWASP, CVSSÂ
Experience in security testing, including application testing, penetration testing, and vulnerability assessmentÂ
Experience in implementing network systems and deep understanding of common misconfigurations leading to security vulnerabilities in network systemsÂ
Ability to work under pressure and deliver quality work in tight timelines Â
Demonstrated experience of working with diverse stakeholdersÂ
Good communication and interpersonal skillsÂ
Willingness to take on new challenges, gain new skills and work collaboratively in a dynamic and rapidly growing teamÂ
Training on self-development platforms (TryHackMe, HackTheBox, PentesterLabs, PortSwigger Web Security Academy, etc.)Â
Â
Preferred:Â
Thorough understanding of common software security vulnerabilities (CWE Top 25 Most Dangerous Software Weaknesses)Â
Experience of conducting red teaming engagements and cyber-attack simulation testingÂ
Demonstrated knowledge of penetration testing across several domains such as cloud and container security, applied cryptography, networks infrastructure, etc.Â
Knowledge of developing hacking scripts/toolsÂ
Knowledge of secure development and/or DevSecOps experience, including experience in securing code before deployment, code review, and vulnerability and dependency managementÂ
Experience in bug bounty programs or CVE hunting is an advantageÂ
Preference will be given to candidates who hold one of the following industry certifications: OSCP, OSWA, eWPT, eCPPT, CRTP, PNPT, CREST CRT/CCT, or equivalent Â
Preference will be given to candidates who hold relevant cloud certifications: AWS, Azure, GCPÂ
Strong preference will be given to candidates who hold one of the following industry certifications: OSWE, OSEP, OSCE, CRTO, CRTE, eCPTX, eWPTX, SANSÂ
Â
Education (if blank, degree and/or field of study not specified)
Degrees/Field of Study required:Degrees/Field of Study preferred:Certifications (if blank, certifications not specified)
Required Skills
Optional Skills
Accepting Feedback, Accepting Feedback, Active Listening, Agile Methodology, Azure Data Factory, Communication, Cybersecurity, Cybersecurity Framework, Cybersecurity Policy, Cybersecurity Requirements, Cybersecurity Strategy, Emotional Regulation, Empathy, Encryption Technologies, Inclusion, Intellectual Curiosity, Managed Services, Optimism, Privacy Compliance, Regulatory Response, Security Architecture, Security Compliance Management, Security Control, Security Incident Management, Security Monitoring {+ 3 more}Desired Languages (If blank, desired languages not specified)
Travel Requirements
Available for Work Visa Sponsorship?
Government Clearance Required?
Job Posting End Date
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index đ°
Tags: Agile AWS Azure Blockchain Clearance Clearance Required Cloud Compliance CREST Cryptography CVSS DevSecOps Encryption eWPT eWPTx GCP IoT Monitoring Network security OSCE OSCP OSWE OWASP Pentesting Privacy Red team SANS Strategy Threat intelligence Vulnerabilities
Perks/benefits: Career development Flex hours
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.