ApplySarthi

Senior Associate - Cyber Security Consultant (GRC/Pentest)

Pwc

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

3,284 open security roles across 420 companies are on ApplySarthi right now, most of them in Bengaluru (117), Pune (22), Hyderabad (20).

What security roles keep asking for: AWS (30%), Python (28%), SIEM (14%), CI/CD (14%), Azure (13%), GCP (13%), IAM (13%) — counted across their open postings here.

AWS jobs · Azure jobs · GCP jobs · Penetration testing jobs

Pwc has 3,006 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for security roles keep coming back to AWS, Python, SIEM, CI/CD. Practise those questions before you sit with Pwc.

Questions you are likely to be asked

  1. Why do you want to join Pwc?
  2. What is your experience with Penetration testing? Tell me one thing you learned the hard way.
  3. How do you keep secrets and access safe in your infrastructure?
  4. Walk me through how code gets from a commit to production where you work.
  5. Tell me about an outage you handled. What did you learn from it?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Senior Associate - Cyber Security Consultant (GRC/Pentest) at Pwc interview free →

Line of Service Assurance Industry/Sector Not Applicable Specialism Cybersecurity & Privacy Management Level Senior Associate Job Description & Summary We are PwC, a global professional services company and a Big Four firm. We are seeking candidates who have experience in penetration testing, red teaming or secure source-code review/development for the role of Consultant/ Senior Consultant within the Cybersecurity and Privacy team. The role may be based either at our Ho Chi Minh City office. Joining PwC, the successful candidate will have opportunities to collaborate with cybersecurity experts throughout the PwC global network and deliver cybersecurity services for clients in various sectors. ● Work in a highly innovative and transformative business ● Work/life balance with access to flexible work arrangements ● Salary packaging – to suit your personal and financial circumstances ● Professional certification sponsorship – to develop your talent and enhance knowledge Responsibilities: Lead the team in cybersecurity assessments, covering web application and mobile application penetration testing in accordance with OWASP Top 10 framework and CWE Top 25 most dangerous software weaknesses Lead the team in network penetration tests and vulnerability assessments to identify potential issues against network access control and network segmentation Conduct source code reviews to identify potential logical errors in program flows, misconfigurations, and exploitable vulnerabilities in the applications Conduct red teaming engagement and cyber-attack simulation testing to assess clients ’ cybersecurity strategies Research, collect and analyse cyber threat intelligence from threat actors Engage in establishing network infrastructure for red teaming activities, including but not limited to command & control ("C2") servers, SMTP relay mail servers, web servers, and reverse proxies Design and launch phishing attacks to generate reports for increasing awareness of employees regarding different types of phishing techniques Provide pragmatic recommendations on the identified risks Deliver both management - level and detailed technical reporting of observations, along with assisting in giving presentations to both technical and business stakeholders Deliver complex Cybersecurity consulting and engineering projects involving diverse technologies, and multidisciplinary delivery teams and stakeholder groups Collaborate with clients, colleagues, and technology alliance partners on identifying and developing solutions for assessing and enhancing cyber security operations Engage with threat intelligence, hunting, and incident response activities to keep up to date with trends in technology, security, and the threat landscape Train, coach and mentor junior team members Lead day-to-day delivery activities, including client and internal communication management, as well as technical quality control Work actively in supporting and following up on proposal processing in accordance with client expectations on a cross-border and global multinational basis Continuously research and follow up on the latest IT security challenges and technologies (mobile, digital trust, IoT, cloud, blockchain etc . ) You are someone with: 3+ years of proven experience in conducting either network and infrastructure or web/API or mobile application penetration testing and be able to independently manage engagement delivery Experience in leading and supervising engagement teams in penetration testing and vulnerability assessment projects Thorough understanding of common infrastructure and web application vulnerabilities and common vulnerability categorisations such as OWASP and CVSS Knowledge of common software security vulnerabilities (CWE Top 25 Most Dangerous Software Weaknesses) Experience in penetration testing and vulnerability assessment across one of the several following domains: web and mobile applications, cloud and container security, reverse engineering, applied cryptography, networks infrastructure, etc. Ability to work under pressure and deliver quality work in tight timelines Demonstrated experience of working with diverse stakeholders Excellent communication and interpersonal skills Willingness to take on new challenges, gain new skills and work collaboratively in a dynamic and rapidly growing team One of the following industry certifications: OSCP, OSWA, eWPT, eCPPT, CRTP, PNPT, CREST CRT/CCT, or equivalent Preferred: Experience in conducting red teaming engagements and cyber-attack simulation testing Experience in developing hacking scripts/tools Secure development and/or DevSecOps experience, including experience of securing code before deployment, code review, and vulnerability and dependency management Ability to communicate strategic information security topics, policies, and standards as well as risk-related concepts to technical and non - technical audiences Experience in bug bounty programs or CVE hunting is an advantage Preference will be given to candidates who hold relevant cloud certifications: AWS, Azure, GCP Strong preference will be given to candidates who hold one of the following industry certifications: OSWE, OSEP, OSCE, CRTO, CRTE, eCPTX, eWPTX, SANS Strong preference will be given to candidates who hold one of the following professional certifications: CISSP, CCSP, CSSLP, CISM, CRISC, PMP Education (if blank, degree and/or field of study not specified) Degrees/Field of Study required: Degrees/Field of Study preferred: Certifications (if blank, certifications not specified) Required Skills Optional Skills Accepting Feedback, Accepting Feedback, Active Listening, Agile Methodology, Analytical Thinking, Azure Data Factory, Communication, Creativity, Cybersecurity, Cybersecurity Framework, Cybersecurity Policy, Cybersecurity Requirements, Cybersecurity Strategy, Embracing Change, Emotional Regulation, Empathy, Encryption Technologies, Inclusion, Intellectual Curiosity, Learning Agility, Managed Services, Optimism, Privacy Compliance, Regulatory Response, Security Architecture {+ 8 more} Desired Languages (If blank, desired languages not specified) Travel Requirements Up to 20% Available for Work Visa Sponsorship? No Government Clearance Required? No Job Posting End Date January 18, 2027

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on workday · posted 2026-10-09. ApplySarthi collects openings and links to application pages; the role is advertised by Pwc, not by us.