PwC Cyber Risk Manager in New York, New York
PwC is a network of firms committed to delivering quality in assurance, tax and advisory services.
We help resolve complex issues for our clients and identify opportunities. Learn more about us at www.pwc.com/us.
At PwC, we develop leaders at all levels. The distinctive leadership framework we call the PwC Professional (http://pwc.to/pwcpro) provides our people with a road map to grow their skills and build their careers. Our approach to ongoing development shapes employees into leaders, no matter the role or job title.
Are you ready to build a career in a rapidly changing world? Developing as a PwC Professional means that you will be ready
- to create and capture opportunities to advance your career and fulfill your potential. To learn more, visit us at www.pwc.com/careers.
PwC Advisory helps our clients with their most challenging imperatives from strategy through execution. We combine the breadth of knowledge of over 48,000 global professionals with deep industry knowledge to deliver custom solutions for our clients. We work with the world's largest and most complex companies and understand the unique business issues and opportunities our clients face.
As we aim to rapidly grow our Cybersecurity and Privacy practice, we are looking for consultants who are passionate about how strategy and technology can improve the role of cybersecurity, privacy and data protection in our digital world.
We are looking for consultants with extensive consulting, technological and industry experience who will help our clients solve their complex business issues from strategy through execution. A Cybersecurity and Privacy consulting career will provide the opportunity to grow and contribute to our clients' business issues every day, applying a collection of information and Cyber security capabilities, including security and privacy strategy and governance, IT risk, security testing, technology implementation/operations, and cybercrime and breach response.
Our Strategy and Transformation services help clients understand the current cybersecurity and privacy landscape, make cybersecurity a collective priority, and develop and implement solutions across people, processes, and technologies. We provide the foundations to design, manage and operate a cybersecurity program aligned to business strategy, and increase organizational resilience in the face of an ever-changing threat landscape.
Minimum Year(s) of Experience: 6
Minimum Degree Required: Bachelor's degree
Certification(s) Preferred: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISACA, Certified in Risk and Information Systems Control (CRISC)
Demonstrates proven extensive knowledge and success in roles managing cyber-risk management, including the following areas:
Being recognized as an industry leader, providing industry-leading practices in cyber-risk management and the financial services industry; and,
Managing and overseeing large projects involving information security, technology risk management, cybersecurity or cyber-risk management.
Familiarity with common regulatory requirements such as OCC HS, FFIEC, GLBA, NY DFS etc. as well as industry frameworks such as NIST CSF, COBIT, COSO and PCI
Demonstrates proven and extensive abilities solving complex cyber-risk management issues, including the following areas:
Â- Design and development of IT Risk and Cyber security programs using industry frameworks and methodologies;
- Designing KRIs and metrics to build risk reports for management
Â- Implementation and maintenance of enterprise-wide cyber risk governance frameworks;
Â- Assessment of enterprise-wide business risks and cyber threats;
- Development of detailed business risk scenarios and cyber threat models;
Â Design and implementation of cyber risk management controls;
Monitoring and reporting of cyber risks, threats and vulnerabilities;
Development, implementation and periodic testing of cyber resiliency plans;
Use of tools and technology to provide data analytics and business intelligence on cyber threats, risks and vulnerabilities;
Advising clients on complying with regulatory requirements such as OCC HS, FFIEC, GLBA, NY DFS etc. as well as industry frameworks such as NIST CSF, COBIT, COSO and PCI;
Developing frameworks, strategies, and operating models on IT risk management and cyber security for clients;
Building and operationalizing complex IT risk management and cyber security programs for clients.
Demonstrates proven extensive abilities to manage and deliver client engagements that identify and address client needs, including the following areas:
Â- Leading project workstreams and associated staff on complex cyber risk management engagements;
- Participating actively in client discussions and meetings;
Â- Managing and overseeing engagements;
Â- Preparing concise and accurate documents, leveraging and utilizing MS Office and Lotus Notes to complete related project deliverables; and,
Â- Managing project financials in line with agreed-upon budgets
Demonstrates proven extensive abilities, competency and success with managing business functions and teams, including:
Â- Creating a positive working environment by monitoring and managing workloads of the team â€“ balancing client expectations with the work-life quality of team members;
Â- Providing candid, meaningful feedback in a timely manner to team members;
Â- Keeping leadership and engagement management informed of progress and issues.
All qualified applicants will receive consideration for employment at PwC without regard to race; creed; color; religion; national origin; sex; age; disability; sexual orientation; gender identity or expression; genetic predisposition or carrier status; veteran, marital, or citizenship status; or any other status protected by law.