Cyber Security (Offensive) Associate/Senior Associate (JP00359)
Indexed description
At PwC, our purpose is to build trust in society and solve important problems
We’re a network of firms in 149 countries with more than 370,000 people who are committed to delivering quality in assurance, advisory and tax services. PwC has been providing services to the Turkish business world since 1981, with a professional staff of 1700 in İstanbul, Ankara, Bursa, İzmir and Eskişehir.
At PwC, we are a group of employees with a rich variety of knowledge, skills and competencies. PwC’s problem-solving teams come together in unusual, untraditional new ways from various disciplines to create The New Equation strategy. The New Equation is our global strategy with a human-centered and tech-powered approach, that focuses on our clients and all stakeholders, and helps them build trust and drive sustainable results.
Cyber Security (Offensive) Associate/Senior Associate
What are we looking for?
- Minimum 1-year relevant experience for Associate (3+ years for Senior Associate)
- An offensive-security practitioner who thinks like an attacker and follows a disciplined, repeatable methodology to identify, validate and communicate real-world risks
- Possession of an industry-recognized offensive-security certification such as OSCP, OSWE, CREST, GPEN, LPT, GXPN or GWAPT is required
- Having or willingness to obtain TSE (Turkish Standards Institution) Penetration Tester certification is a plus
- Hands-on experience with offensive tools and platforms (e.g., Burp Suite, Metasploit, NetExec, Cobalt Strike, Nmap) and Breach & Attack Simulation solutions
- Solid understanding of IT infrastructure fundamentals: networking, operating systems, databases and cloud
- Desirable: cloud infrastructure, container technologies, public cloud (AWS, Azure, GCP), ICS/OT, AI and blockchain experience
- Familiarity with frameworks and standards such as MITRE ATT&CK, NIST CSF, OWASP and CIS
- Proficient English (minimum B1), both written and oral
- Proactive, collaborative, impact-focused, and able to manage multiple tasks
Role Description
- Perform red team / purple team engagements and penetration tests across web applications, networks, APIs, mobile, ICS/OT and cloud environments
- Execute testing using a repeatable, methodology-driven approach: threat modelling, controlled exploitation, validation and impact assessment
- Produce detailed, regulatory-compliant reports (e.g., SPK, BDDK) with clear findings and actionable remediation guidance
- Support clients in reducing risk and improving security posture against real-world attack scenarios
- Contribute to service development and work closely with the broader PwC Offensive Security network and global experts
--
PwC Türkiye şirketleri* olarak elektronik ortamda toplanan kimlik, iletişim, özgeçmiş ve CV’niz’de yer alan kişisel verilerinizi iş başvurusu süreçlerinin yürütülmesi amacıyla KVKK m. 5/2 (f) uyarınca, hukuki ihtilaf oluşması halinde yasal süreçlerin yürütülebilmesi amacıyla KVKK m. 5/2 (e) uyarınca işleyeceğiz. Kişisel verilerinizi mevzuattan dolayı kişisel verilerinizin paylaşılmasının zorunlu olduğu hallerde, ilgili ve yetkili kamu kurum ve kuruluşlarıyla KVKK m. 5/2 (ç) uyarınca paylaşabiliriz. Kişisel verilerinin KVKK m. 9 uyarınca merkezi yurt dışında bulunan Google sistemleri üzerinden işlenecektir. KVKK’nın 11. Maddesi kapsamındaki haklarınızı https://www.pwc.com.tr/tr/hakkimizda/pwc-turkiye-kvk-basvuru-formu.pdf linkinde bulunan Başvuru Formu ile veya [email protected] adresine, veya [email protected] adresine iletebilirsiniz.
*PwC Türkiye şirketleri; PwC Danışmanlık Hizmetleri A.Ş. & PwC Bağımsız Denetim ve Serbest Muhasebeci Mali Müşavirlik A.Ş. & PwC Yeminli Mali Müşavirlik A.Ş. & PwC Yönetim Danışmanlığı A.Ş., PwC Serbest Muhasebeci Mali Müşavirlik Ltd. Şti., Gago Türkmen Avukatlık Ortaklığı
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search