Advisory Cyber Strategy, Risk & Privacy Director

PwC/LOS Overview
PwC is a network of firms committed to delivering quality in assurance, tax and advisory services.

We help resolve complex issues for our clients and identify opportunities. Learn more about us at

At PwC, we develop leaders at all levels. The distinctive leadership framework we call the PwC Professional ( provides our people with a road map to grow their skills and build their careers. Our approach to ongoing development shapes employees into leaders, no matter the role or job title.

Are you ready to build a career in a rapidly changing world? Developing as a PwC Professional means that you will be ready
- to create and capture opportunities to advance your career and fulfill your potential. To learn more, visit us at

PwC Advisory helps our clients with their most challenging imperatives from strategy through execution. We combine the breadth of knowledge of over 48,000 global professionals with deep industry knowledge to deliver custom solutions for our clients. We work with the world's largest and most complex companies and understand the unique business issues and opportunities our clients face.

Job Description
As we aim to rapidly grow our Cybersecurity and Privacy practice, we are looking for consultants who are passionate about how strategy and technology can improve the role of cybersecurity, privacy and data protection in our digital world.

We are looking for consultants with extensive consulting, technological and industry experience who will help our clients solve their complex business issues from strategy through execution. A Cybersecurity and Privacy consulting career will provide the opportunity to grow and contribute to our clients' business issues every day, applying a collection of information and Cyber security capabilities, including security and privacy strategy and governance, IT risk, security testing, technology implementation/operations, and cybercrime and breach response.

Our Strategy and Transformation services help clients understand the current cybersecurity and privacy landscape, make cybersecurity a collective priority, and develop and implement solutions across people, processes, and technologies. We provide the foundations to design, manage and operate a cybersecurity program aligned to business strategy, and increase organizational resilience in the face of an ever-changing threat landscape.

Position/Program Requirements
Minimum Year(s) of Experience: 10

Minimum Degree Required: Bachelor's degree

Certification(s) Preferred: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISACA Certified in Risk and Information Systems Control (CRISC)

Knowledge Preferred:

Demonstrates proven thought leadership and success in roles directing cyber-risk management, including the following areas:

- Being recognized as an industry leader, providing thought leadership in cyber-risk management and the financial services industry;
- Generating revenue and maintaining client relationships within the financial services industry; and,
- Managing and overseeing large projects involving information security, technology risk management, cybersecurity or cyber-risk management.
- Leading project workstreams and associated staff on complex cyber risk management engagements
- Familiarity with common regulatory requirements such as OCC HS, FFIEC, GLBA, NY DFS etc. as well as industry frameworks such as NIST CSF, COBIT, COSO and PCI

Skills Preferred:

Demonstrates proven thought leader abilities, competencies and success solving complex cyber-risk management issues, including the following areas:
- Design and development of IT Risk and Cyber security programs using industry frameworks and methodologies;
- Advising clients on complying with regulatory requirements such as OCC HS, FFIEC, GLBA, NY DFS etc. as well as industry frameworks such as NIST CSF, COBIT, COSO and PCI
- Building and operationalizing complex IT risk management and cyber security programs for clients
- Leading the development of frameworks, strategies, and operating models on IT risk management and cyber security for clients
­- Implementation and maintenance of enterprise-wide cyber risk governance frameworks;
- Assessment of enterprise-wide business risks and cyber threats;
­ Development of detailed business risk scenarios and cyber threat models;
­ Design and implementation of cyber risk management controls;
­ Monitoring and reporting of cyber risks, threats and vulnerabilities;
- Development, implementation and periodic testing of cyber resiliency plans;
­- Use of tools and technology to provide data analytics and business intelligence on cyber threats, risks and vulnerabilities.
- Designing KRIs and metrics to build risk reports for management

Demonstrates proven thought leader abilities to obtain and lead client engagements that identify and address client needs, including these areas:
­- Participating actively in client discussions and meetings;
­- Communicating a broad range of PwC services;
­- Managing and overseeing engagements;
­- Preparing concise and accurate documents – leveraging and utilizing MS Office and Lotus Notes to complete related project deliverable;
­- Managing project financials in line with agreed-upon budgets.

Demonstrates proven thought leadership abilities with directing and business functions and teams, including these areas:
­- Creating a positive working environment by monitoring and managing workloads of the team – balancing client expectations with the work-life quality of team members;
­- Providing candid, meaningful feedback in a timely manner to team members;
­- Keeping leadership informed of progress and issues

Share this Job

Other Locations For This Job