PwC SEA Consulting’s vision is to create meaningful relationships with our clients by powering the next generation digital enterprise.
Our Cybersecurity team helps our clients think more broadly about security and move boldly towards new possibilities. We offer our clients an end-to-end portfolio of services across four stages: assess, build, manage and respond.
Our focus areas are Cyber Risk Strategy, Digital Identity & Access Management, Data Privacy & Protection, Cyber Defence & SOC Optimisation.
About The Role
- Design and work on cybersecurity framework based on business objectives and strategic imperatives of the client organisation including goals, vision, mission, and operational plans
- Data pattern and trend identification via metric analysis, driving operational excellence and improvement
- Designing and implementing data protection and privacy programs for our clients and supporting their business
- Evaluating the data protection and privacy practices of our clients and Conducting Privacy Impact Assessments
- Monitor processes and drive improvements in efficiency and quality of cybersecurity programs
- Assist in development of workflows for transitioning strategic plans into implementation plans and operational readiness
- Facilitate strategic planning initiatives, documentation, technical roadmaps and security tool rationalisation
- Assist in designing the security organisation structure including cyber defense
- Develop security policies, procedures, standards based on the security strategy and roadmap
- Review of cybersecurity policies and processes to identify gaps in design of control based on comprehensive assessment framework
- Maintain continuous communication with key stakeholders in support of the security strategy, and plan and solicit feedbacks, to uplift the programs and capabilities
- Conduct security process implementation reviews to assess security effectiveness and reporting
- Conduct Current State Assessment of cybersecurity practices against the defined controls and provide recommendations for to-be state
- Run Cyber Security Diagnostic Assessments and develop programs for cybersecurity skill development and enhancement
- Provide certification advisory across Information Security Management System (ISMS)
- Implement security controls for realisation of the certification requirements and provide technology roadmap based on the security strategy
- Assisting in delivering privacy projects to acting as a subject matter expert on them or to leading a team towards excellent client experience
- Supporting and guiding our clients in adhering to the complex web of relevant national and international regulations (e.g. EU General Data Protection Regulation).
- Deploying processes and tools to help detect and prevent privacy breaches
- Ensuring a harmonised approach towards data protection and privacy by bringing together our client’s stakeholders (e.g. legal, compliance, risk, HR, security, business functions)
- Assisting clients in privacy related incident response activities
- Supporting the client’s team by acting as an interim team member (e.g. data protection officer, security officer, security manager, security analyst)
- Proactively identifying and pursuing opportunities for further business and team growth
- Bachelor’s degree in Computer Science, Information Systems, Information Technology, Engineering, or equivalent education
- Minimum 5+ years of prior relevant working experience
- Experience with vulnerability scanning solutions and cybersecurity systems
- Possession of relevant qualifications such as CIPM, CIPT, CIPP/E, CISM, CISSP, and/or HCISPP, as well as involvement in industry related organizations (e.g. IAPP, ISACA, (ISC)²…) or relevant certifications
- Knowledge in one or more of the following domains-
Security strategy, risk, and privacy management, Cyber security maturity and risk assessments with financial regulatory knowledge
Data and application protection, including data classification, data discovery, data governance, DLP, IRM, EDR, tokenization, encryption, blockchain, TDE, cloud, mobility, microservices, APIsec, devsecops, API, back-up/recovery and retention, etc.;
Security architecture, design, including working experience in products like Akamai, FireEye, Palo Alto Networks, Splunk, Tanium, CrowdStrike, Titus, Thales, Digital Guardian, Symantec, Airwatch, AWS, Azure, SafeNet, Gemalto, etc.
- Strong interpersonal and stakeholder management skills with ability to coordinate between technical and business teams
- Excellent verbal, written communication and interpersonal skills with stakeholders at all levels
- Knowledge and experience with relevant data protection and privacy laws and regulations (e.g. PDPA , EU GDPR, and Privacy Shield) and industry standards and frameworks, such as GAPP and BCR
- Ability to efficiently understand client organisations and their business model and to tailor relevant processes to privacy requirements
- An analytical mindset, strive for quality and are able to work in a result-oriented environment