PricewaterhouseCoopers Jobs

Job Information

PwC Cyber Defense- Penetration Testing (CPT2) - Director in Washington, District Of Columbia

Specialty/Competency: Cybersecurity & Privacy

Industry/Sector: Not Applicable

Time Type: Full time

Travel Requirements: Up to 60%

A career in our Cybersecurity, Privacy and Forensics will provide you the opportunity to solve our clients most critical business and data protection related challenges. You will be part of a growing team driving strategic programs, data analytics, innovation, deals, cyber resilency, response, and technical implementation activities. You will have access to not only the top Cybersecurity, Privacy and Forensics professionals at PwC, but at our clients and industry analysts across the globe.

The Cyber Penetration Testing (CPT2) team focuses on delivering threat actor simulation services, device or application assessments, and penetration tests. You will help clients understand the tangible risks they face from a variety of threat actors and what they target to include different postures, scenarios, or targeted assets. Working as a member of CPT2 also provides the opportunity to directly help clients enhance or tune their preventative, and detective controls on a proactive basis.

Our team focuses on assessment and recommendation services that blend deep technical manual tradecraft with targeted automation to simulate real threats to a client’s environments. As a part of this center of excellence, you will drive change at PwC’s clients by providing risk outside of the theoretical while contributing to the technical acumen of the practice and amplifying your own personal capabilities.

To really stand out and make us fit for the future in a constantly changing world, each and every one of us at PwC needs to be an authentic and inclusive leader, at all grades/levels and in all lines of service. To help us achieve this we have the PwC Professional; our global leadership development framework. It gives us a single set of expectations across our lines, geographies and career paths, and provides transparency on the skills we need as individuals to be successful and progress in our careers, now and in the future.

As a Director, you'll work as part of a team of problem solvers, helping to solve complex business issues from strategy to execution. PwC Professional skills and responsibilities for this management level include but are not limited to:

  • Arrange appropriate assignments and experiences to support others' learning and development.

  • Seek out different ways to use current and relevant technological advances.

  • Analyse marketplace trends - economical, social, cultural, technological - to identify opportunities and create value propositions.

  • Deploy methods to keep up with, and stay ahead of, new developments and ideas.

  • Offer a global perspective in stakeholder discussions and when shaping solutions/recommendations.

  • Drive and take ownership for developing networks that help deliver what is best for stakeholders.

  • Proactively manage stakeholders to create positive outcomes for all parties.

  • Uphold the firm's code of ethics and business conduct.

Job Requirements and Preferences :

Basic Qualifications :

Minimum Degree Required :

Bachelor Degree

Minimum Years of Experience :

9 year(s)

Preferred Qualifications :

Preferred Fields of Study :

Computer and Information Science, Information Technology, Computer Applications, Computer Engineering, Information CyberSecurity, Electrical Engineering

Certification(s) Preferred :

Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN), Certified as GIAC Web Application Penetration Tester (GWAPT).

Preferred Knowledge/Skills :

Demonstrates thought leader-level abilities as a team leader, emphasizing the following areas:

  • Leadership and direction to positions of Senior Managers, Managers, and junior staff.;

  • Organizational discipline to ensure status updates, orchestration and planning for engagement delivery, oversight, and quality management.;

  • Experience with proposal development and relationship management key to building new business while ensuring long-term client support and success.;

  • Technical concepts such as application security, network segregation, access controls, IDS/IPS devices, physical security, and information security risk management;

  • Security testing tools, such as BurpSuite, Mimikatz, Cobalt Strike, PowerSploit, Metasploit, Core Impact, Sysinternals Tool Suite, or other solutions included within the Kali Linux distribution; - Networking protocols, TCP/IP stack, systems architecture, and operating systems;

  • Common programming and scripting languages, such as Python, PowerShell, Ruby, Perl, Bash, JavaScript, C/C# or VBScript;

  • Well-known Cybersecurity frameworks and industry-leading practices such as OWASP, PTES, NIST CSF, PCI DSS, and NY-DFS; and,

  • Traditional security operations, event monitoring, and Security Information and Event Management (SIEM) tools. - A familiarity with cloud platforms, cloud providers, cloud services, DevOps pipelines, operational technology, or hardware testing.

Demonstrates thought leader-level abilities as a team leader, emphasizing the following areas:

  • Performing penetration testing activities within a client’s environment, emphasizing manual stealthy testing techniques;

  • Presenting technical topics at conferences highlighting aspects of adversary attack simulations, technical attack techniques, risk management, custom malware design, or zero day attacks;

  • Leading and executing stealthy penetration testing, advanced red team, or adversary simulation engagements using commercially / freely available offensive security tools and utilities built into operating systems;

  • Understanding Windows and Linux operating system setup, management, and power usage, e.g., cmd, bash, network troubleshooting, virtual machines;

  • Identifying security critical vulnerabilities without utilizing a vulnerability scanning tool, i.e., knowledge of exploitable vulnerabilities and ability to execute stealthy penetration testing engagements;

  • Compromising Active Directory environments and demonstrating business impact by identifying and obtaining access to business critical assets/information;

  • Performing social engineering / phishing activities such as reconnaissance of targets, developing phishing campaigns (e.g., emails and websites), web hosting administrator, developing malicious phishing payloads, or pivoting through phished systems;

  • Performing and supervising various workstreams of client engagements that emphasize identifying and addressing client needs;

  • Participating actively in client discussions and meetings and communicating a broad range of potential add-on services based on identified weaknesses;

  • Managing engagements with junior staff;

  • Preparing concise and accurate documents, leveraging and utilizing MS Office and Google Docs to complete related project deliverables, as necessary;

  • Balancing project economics management with the occurrence of unanticipated issues.

  • Creating a positive environment by monitoring workloads of the team while meeting client expectations and respecting the work-life quality of team members;

  • Proactively seeking guidance, clarification, and feedback; and,

  • Keeping leadership informed of progress and issues.

At PwC, our work model includes three ways of working: virtual, in-person, and flex (a hybrid of in-person and virtual). Visit the following link to learn more:

PwC does not intend to hire experienced or entry level job seekers who will need, now or in the future, PwC sponsorship through the H-1B lottery, except as set forth within the following policy:

All qualified applicants will receive consideration for employment at PwC without regard to race; creed; color; religion; national origin; sex; age; disability; sexual orientation; gender identity or expression; genetic predisposition or carrier status; veteran, marital, or citizenship status; or any other status protected by law. PwC is proud to be an affirmative action and equal opportunity employer.

For positions based in San Francisco, consideration of qualified candidates with arrest and conviction records will be in a manner consistent with the San Francisco Fair Chance Ordinance.

For positions in Colorado, visit the following link for information related to Colorado's Equal Pay for Equal Work Act: