Industry/Sector
Not ApplicableSpecialism
Cybersecurity & PrivacyManagement Level
Senior AssociateJob Description & Summary
At PwC our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients providing advice and solutions. They help organisations navigate complex regulatory landscapes and enhance their internal controls to mitigate risks effectively.Position Requirements
Cyber Due Diligence (Buy-Side & Sell-Side)
Perform rapid-cycle cybersecurityand technology risk assessments toidentifyissues that mayimpactvaluation deal structure or closing.
Assess current-state security postureidentifymaterial threats/exposures and evaluate alignment to leading frameworks (NIST CSF ISO/IEC 27001 CIS).
Evaluate thetargetscyber governance tools architecture policies SOC operations identity cloud posture vulnerability management incident response and disaster recovery capabilities.
Quantify one-time and recurring cyber uplift costs build issue backlogs and articulate impacts on TSA Day 1 readiness and integration/separation plans.
Review security incidentsbreachhistory and regulatory exposures including assessing adequacy of past remediation.
Regulatory & Compliance Assessment
Evaluatetargetscompliance with regulatory and sector-specific obligations (e.g. FFIEC HIPAA FDA PCI DSS SOXGDPR CCPA).
Conduct regulatory gap assessments andidentifyrequired uplift for post-close operation.
Developremediationplaybooks reporting packages and risk-based recommendations for senior executives deal teams and boards.
Support regulatory readiness for high-risk domains including acquisition approvals data transfer requirements or supervisory expectations.
Integration Separation and Value Creation
Support development of Day 1/Day 100 cybersecurity integration or separation plans including TSA scoping control uplift planning tool rationalization and architectural roadmaps.
Identifyand quantifysynergyopportunities related to consolidation of cyber tools SOC operations identity platforms endpoint protection and cloud security.
Assess inherited cyber risk and define interim-state controlsduring integration/carve-out.
Facilitate workshops and cross-functional sessions with deal teams CISOs CIOs legal privacy and infrastructure leads.
AI/GenAI Risk & Modern Technology Environments
Assess AI/GenAI use cases and evaluate risk governance responsible AI controls and model lifecycle management.
Support integration of AI-enabled capabilities into deal diligence risk quantification automation and compliance workflows.
Review modern architectures (cloud-native SaaS identity platforms zero trust) for security and operational risks relevant to deal value.
Minimum years experience required
5-8 Years
Desired Knowledge
Strong understanding of cybersecurity principles enterprise technology environments and common cyber control domains.
Understanding of the M&A lifecycle including how cybersecurity technology risk and regulatory exposures influence valuation deal structure TSAs and post-close integration or separation planning.
Ability to translate technical cyber findings into business and financial impacts includingissuematerialitysynergyopportunities one-time/recurring cost estimates and risks relevant to investment decisions.
Working knowledge of AI/GenAI risks responsible AI frameworks and emerging regulatory expectations.
Familiarity with cloud architecture and cloud security principles (Azure AWS GCP).
Experience in at least 23 core areas: cyber risk assessment regulatory compliance GRC cloud security incident response SOC operations data protection or audit.
Ability to communicate complex cyber and technology risks clearly to senior stakeholders deal teams and non-technical audiences.
Strong analytical problem-solving and structured reporting skills; ability to deliver high-quality work under tight deal timelines.
Demonstrated ability to build presentations reports cost models and dashboards tailored to executive and board-level stakeholders.
Ability to deliver training lead workshops and create client-facing content.
Proven ability to work in fast-paced environments with ambiguity and shifting priorities.
Professional & Educational Background
MBA /MCA / BE / B Tech / MS (Field of Study: Computer and Information Science Information Cybersecurity Information Technology Management Information Systems)from a premiuminstitute
Certification(s) Preferredbut not mandatory: Certified Information Systems Auditor (CISA) Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) Certified inRiskand Information Systems Control (CRISC).
Travel Requirements
Not SpecifiedJob Posting End Date
Required Experience:
Senior IC
At PwC, our purpose is to build trust in society and solve important problems. We’re a network of firms in 155 countries with over 284,000 people who are committed to delivering quality in assurance, advisory and tax services. Find out more and tell us what matters to you by vis ... View more