PwC seeks a Senior Associate to lead supply chain cyber risk advisory engagements in Zürich, focusing on regulatory compliance (DORA, NIS2) and third-party risk management for financial and non-financial clients.
This position plays a central part in expanding the firm's supply chain cyber risk capabilities across various industries. The specialist will assist clients in fortifying their third-party risk programs, ensuring adherence to regulations like DORA and NIS2, and addressing threats within intricate global supply networks. The role supports multi-year transformation projects for a diverse client base.
Responsibilities
- Execute client projects centered on supply chain security, third-party risk, and regulatory compliance with DORA and NIS2.
- Create and deploy supplier segmentation strategies, risk assessments, control testing, and monitoring processes within broader IT GRC transformations.
- Partner with clients to establish future Third Party Risk Management operating models, defining roles, escalation procedures, and response strategies.
- Develop AI-enhanced TPRM workflows using platforms like ServiceNow, ProcessUnity, BitSight, RiskRecon, and SecurityScorecard, including configuration and integration.
- Provide actionable recommendations and roadmaps to enhance cyber risk governance, continuous monitoring, and incident management throughout the third-party lifecycle.
- Facilitate workshops, prepare reports, and deliver executive presentations to CISO, CIO, Risk, Compliance, and Procurement leaders.
- Contribute to internal capability development, thought leadership, proposal responses, and account growth initiatives.
- Mentor junior staff and promote a high-performance, inclusive team environment.
Requirements
- Minimum of five years in cybersecurity, third-party risk, or supply chain risk management.
- Bachelor's or Master's degree in business administration, computer science, or equivalent professional qualification.
- Demonstrated experience with financial services clients, preferably in regulatory contexts such as DORA and NIS2.
- Solid grasp of supply chain security frameworks, supplier segmentation, control testing, and cyber risk quantification.
- Knowledge of supply chain risk tools like ProcessUnity, ServiceNow, BitSight, RiskRecon, or similar.
- Exceptional communication and stakeholder engagement abilities.
- Strong verbal and written skills for interacting with all management levels.
- Fluency in English; German and/or French proficiency is preferred.
- High initiative, self-organization, and sense of responsibility.
Nice to have
- Certifications such as CISM, CRISC, ISO 27001 Lead Implementer, or CISSP are advantageous.
About the company
PwC operates as a tech-forward, people-empowered network dedicated to helping clients build trust and reinvent their operations. The firm assists organizations in turning complexity into competitive advantage by accelerating and sustaining momentum across audit, assurance, tax, legal, workforce, deals, and consulting services.
- Empowering people within a tech-driven network.
- Helping clients turn complexity into competitive advantage.
- Building trust and reinventing client operations.
Quelle: öffentlich zugängliche Karriereseite des Arbeitgebers. Batchly ist nicht der Arbeitgeber und steht nicht notwendigerweise in einem Vertragsverhältnis mit dem Unternehmen.