IN_Associate _ VAPT SOC _Managed Services_ Advisory _Mumbai

PwC India


Date: 1 week ago
City: Mumbai, Maharashtra
Contract type: Full time
Line of Service

Advisory

Industry/Sector

FS X-Sector

Specialism

Risk

Management Level

Associate

Job Description & Summary

In-depth knowledge of application development processes and at least one programming and one scripting language (e.g., Java, Scala, C#, JavaScript, Angular, ReactJs, Ruby, Perl, Python, Shell).

  • Knowledge on OS security (Windows, Unix/Linux systems, Mac OS, VMware), network security and cloud security.
  • Why PWC


At PwC, you will be part of a vibrant community of solvers that leads with trust and creates distinctive outcomes for our clients and communities. This purpose-led and values-driven work, powered by technology in an environment that drives innovation, will enable you to make a tangible impact in the real world. We reward your contributions, support your wellbeing, and offer inclusive benefits, flexibility programmes and mentorship that will help you thrive in work and life. Together, we grow, learn, care, collaborate, and create a future of infinite experiences for each other. Learn more about us.

At PwC, we believe in providing equal employment opportunities, without any discrimination on the grounds of gender, ethnic background, age, disability, marital status, sexual orientation, pregnancy, gender identity or expression, religion or other beliefs, perceived differences and status protected by law. We strive to create an environment where each one of our people can bring their true selves and contribute to their personal growth and the firm’s growth. To enable this, we have zero tolerance for any discrimination and harassment based on the above considerations. "

Responsibilities

Preferred Knowledge/Skills:  

Requirement Criteria

  • Graduation in EC or CS or IT or Information Security or Cyber Security or MCA.
  • Working experience as a Penetration Testing Expert for 5 year(s)
  • Hands on experience with security testing frameworks such as the PTES, OWASP, OSSTMM, SANS.
  • In-depth knowledge of application development processes and at least one programming and one scripting language (e.g., Java, Scala, C#, JavaScript, Angular, ReactJs, Ruby, Perl, Python, Shell).
  • Knowledge on OS security (Windows, Unix/Linux systems, Mac OS, VMware), network security and cloud security.
  • Hands on experience in BurpSuite, Nessus, Checkmarx, Acunetix and Kali Linux penetration testing tools etc.
  • Knowledge on Threat Modelling, Source Code Reviews, Secure Architecture Reviews
  • One of the certifications – OSWE/OSCP/OSCE/eJPT/CPENT- ECCouncil /LPT(Licensed Penetration Tester-ECCouncil)/GPEN(GIAC Penetration Tester)/ GWAPT(GIAC Web Application Penetration Tester) is mandatory (preferably OSCP)


High Level Responsibilities

  • Security testing of mobile applications, web applications, APIs etc.
  • Perform SAST, DAST & VAPT with new standards from time to time. Review sufficient security controls are in place as per, but not limited to, client's policy, industry best practice/process and regulatory requirements.
  • Identify the Individual Application security risk portfolio / threats. Gaps identified along with recommendations to be submitted in Customized reports as requested by client.
  • Review of API/middleware/SFTP etc. interfaces between applications.
  • Develop/Review Baseline document for OS/Application Security/ API.
  • Review the security architecture of various applications deployed/to be deployed (including cloud based) and assess risk associated and suggest mitigation & resolution.
  • Evaluation/Security Assessment of open-source applications.
  • Vetting of Network and data flow Diagrams, with respect to security aspect, for new applications, in co-ordination with the vendors and clients.
  • Review application architecture, data flow diagram, network diagram, database configuration, crypto standards.
  • Perform Application threat modeling.
  • Gap assessment of the Cloud applications, solutions, platforms, process to fill the gaps.


Education

  • Minimum Qualification: BE/ BTech/MBA/Mtech/MCA (Non Mechanical)
  • Postgraduates in any stream would be preferred (not mandatory)


Mandatory Skill Sets

"vapt" and ("oscp" or "EJPT" or "OSWE" or "CPENT" or "GPEN" or "GWAPT" or "OSCE") and security and "Penetration Testing" and mobile

Preferred Skill Sets

ISO

Years Of Experience Required

5+ Years

Education Qualification

BE, B.tech, ME, M.tech, MCA, (non mechanical)

Education (if blank, degree and/or field of study not specified)

Degrees/Field of Study required: Bachelor of Engineering, Master of Engineering

Degrees/Field Of Study Preferred

Certifications (if blank, certifications not specified)

Required Skills

Penetration Testing

Optional Skills

Accepting Feedback, Accepting Feedback, Active Listening, Agile Methodology, Azure Data Factory, Communication, Cybersecurity, Cybersecurity Framework, Cybersecurity Policy, Cybersecurity Requirements, Cybersecurity Strategy, Emotional Regulation, Empathy, Encryption Technologies, Inclusion, Intellectual Curiosity, Managed Services, Optimism, Privacy Compliance, Regulatory Response, Security Architecture, Security Compliance Management, Security Control, Security Incident Management, Security Monitoring {+ 3 more}

Desired Languages (If blank, desired languages not specified)

Travel Requirements

Not Specified

Available for Work Visa Sponsorship?

No

Government Clearance Required?

No

Job Posting End Date

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Head Marketing - India

Radiometer, Mumbai, Maharashtra
2 days ago
When life takes an unexpected turn, our technology and solutions enable caregivers to make informed diagnostic decisions to improve patient care. This is our shared purpose at Radiometer and what unites all +4000 of us - no matter our roles or where in the world we’re located. Creating impactful innovations like ours, doesn’t happen overnight - it requires uncompromising persistency,...

Associate - SaT - CHS - SaT - TCF - Transaction Diligence - Mumbai

EY, Mumbai, Maharashtra
5 days ago
Requisition Id : 1520761The opportunity : Associate-CHS-SaT-SaT - TCF - Transaction Diligence - MumbaiCHS :CHS consists of Consumer Products and Healthcare sectors.Consumer products largely entail, Retail and Agri business. Companies in this sector meet the demands of consumers all around the world, every day; providing everything from agricultural crops to food, clothes, durables and retail experiences. We help clients to...

Manager - Product (Home)

Dream11, Mumbai, Maharashtra
1 week ago
Product Management @Dream11:The Product team is at the forefront of Dream11's user-first approach, with a single-minded focus towards building a scalable fantasy sports platform that makes every game exciting for all sports fans. From analysing consumer and industry trends to conceptualising features and strategy roadmaps, the Dream11 Product team facilitates cross-functional collaboration to develop innovative solutions that drive retention and...