PwC

Associate - Cybersecurity

PwC Kuala Lumpur, Kuala Lumpur, Malaysia

Professional Services · 10,001+ employees

1 h ago
security Junior (0-2 yrs) Full-time Malaysia
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will support engagement teams in identifying, exploiting, and remediating security vulnerabilities across client environments. Additionally, you will contribute to broader cybersecurity engagements, including threat analysis and advisory work, while maintaining strict confidentiality.

What they look for

Cybersecurity Penetration testing Vulnerability assessment Network security Web application testing Mobile application testing Risk management NIST ISO 27001 MITRE ATT&CK Burp Suite Nmap Metasploit TCP/IP Linux Windows

Requirements

Candidates should have a degree in Cybersecurity, Information Security, or a related field, with 0-1 year of experience preferred. Strong foundational knowledge of networking, operating systems, and offensive security tools is required.

Full description

Line of Service

Assurance

Industry/Sector

Not Applicable

Specialism

Risk Architecture

Management Level

Associate

Job Description & Summary

A career in our Cybersecurity practice will provide the opportunity to help clients strengthen their security posture through offensive security testing and broader cyber risk services. In this role, you'll support engagement teams in identifying, exploiting, and helping remediate security vulnerabilities across client environments — while remaining agile enough to contribute across a wider range of cybersecurity engagements beyond penetration testing.

You'll work alongside experienced practitioners to deliver technical assessments, communicate findings clearly to clients, and continuously develop your offensive and defensive security skills. As the threat landscape evolves, you'll play an integral part in helping our clients stay resilient against real-world adversaries.

To really stand out and make us fit for the future in a constantly changing world, each and every one of us at PwC needs to be a purpose-led and values-driven leader at every level. To help us achieve this, we have the PwC Professional — our global leadership development framework. It gives us a single set of expectations across our lines, geographies, and career paths, and provides transparency on the skills we need as individuals to be successful and progress in our careers, now and in the future. 

As an Associate, you'll work as part of a team of problem solvers, helping clients identify and address security weaknesses before real-world adversaries can exploit them. PwC Professional skills and responsibilities for this level include but are not limited to: 

  • Support the planning and execution of penetration tests and offensive security assessments under the guidance of senior team members. 
  • Support a broad range of technical security assessments, including web and mobile application testing, network and infrastructure testing, and configuration reviews. 
  • Assist in conducting security maturity assessments, gap analyses, and reviews against recognised frameworks and standards (e.g., NIST, ISO 27001, MITRE ATT&CK). 
  • Identify, validate, and safely exploit vulnerabilities across networks, applications, and systems. 
  • Assist in the setup, configuration, and use of offensive security tools and testing environments. 
  • Conduct research on emerging vulnerabilities, exploits, and attack techniques to support ongoing assessments. 
  • Contribute to broader cybersecurity engagements beyond penetration testing (e.g., threat analysis and advisory work) as required. 
  • Document findings clearly and provide practical, actionable recommendations and remediation advice to clients. 
  • Handle sensitive client data and assessment results responsibly, maintaining strict confidentiality at all times. 
  • Follow established rules of engagement, testing methodologies, and risk management procedures. 
  • Keep up to date with the latest attack techniques, tools, vulnerabilities, and industry best practices. 
  • Communicate technical findings and recommendations confidently and clearly — both verbally and in written reports — to technical and non-technical audiences alike. 
  • Invite and give in-the-moment feedback in a constructive manner. 
  • Collaborate effectively within the team and share knowledge to strengthen collective capability. 
  • Uphold the firm's code of ethics and business conduct at all times. 

Experience and Qualifications: 

  • Degree in Cybersecurity, Information Security, or a related field. Equivalent experience may be considered. 
  • 0–1 year of experience in offensive security, penetration testing, information security, or a related field preferred. 

Skills and Competencies: 

  • Strong understanding of networking concepts and protocols (TCP/IP, DNS, HTTP, etc.). 
  • Working knowledge of common operating systems (Windows, Linux) and their security configurations. 
  • Foundational understanding of offensive security concepts (e.g., the penetration testing lifecycle, common attack techniques, and tools such as Burp Suite, Nmap, or Metasploit). 
  • Familiarity with cybersecurity frameworks and standards (e.g., NIST, MITRE ATT&CK, OWASP, ISO 27001). 
  • Strong analytical, problem-solving, and troubleshooting skills. 
  • Excellent written and verbal communication skills. 
  • Adaptable and agile — comfortable taking on varied tasks and learning quickly in a fast-paced environment. 

Certifications: 

  • Relevant certifications such as CompTIA Security+, Certified Ethical Hacker (CEH), OSCP, PNPT, eJPT, or GIAC (e.g., GPEN, GSEC) are a plus. 

Education (if blank, degree and/or field of study not specified)

Degrees/Field of Study required:

Degrees/Field of Study preferred:

Certifications (if blank, certifications not specified)

Required Skills

Optional Skills

Accepting Feedback, Accepting Feedback, Active Listening, Auditing, Auditing Standards, Audit Internal Controls, Audit Preparation, Audit Reporting, Audit Risk Assessments, Audit Support, Business Process Improvement, Communication, Compliance and Standards, Compliance Assurance, Compliance Auditing, Compliance Risk Assessment, Compliance Training, Data Analysis and Interpretation, Developing Policies and Guidelines, Emotional Regulation, Empathy, Ethics Training, External Audit, Inclusion, Intellectual Curiosity {+ 21 more}

Desired Languages (If blank, desired languages not specified)

Travel Requirements

Up to 60%

Available for Work Visa Sponsorship?

No

Government Clearance Required?

No

Job Posting End Date

Similar roles