Line of Service
Internal Firm ServicesIndustry/Sector
Not ApplicableSpecialism
IFS - Risk & Quality (R&Q)Management Level
AssociateJob Description & Summary
Meet your future team
Join the Information Security team within Risk and Quality, an internal service team acting independently from IT and operational teams as part of the second line of defence. You will work closely with technical teams, Risk and Quality stakeholders, internal and external clients, and peers across the PwC Network’s information security community.
What your role will look like
As a Junior Information Security Officer, you will contribute to the governance side of information and cyber security, helping maintain a strong security posture in line with PwC Network requirements, applicable laws and regulations, and client expectations. Your work will help connect security standards, operational realities and stakeholder needs into practical, well-followed actions.
- Contribute to vulnerability management by analysing reports, contextualising risks, coordinating remediation with IT specialists and following action plans through to closure.
- Support the Data Loss Prevention programme by helping define risk scenarios, contributing to the firm’s DLP strategy and identifying appropriate remediation measures.
- Assess the security posture of service providers and help identify related risks for the firm.
- Respond to client due diligence requests by providing clear information on the firm’s information security measures and posture.
- Contribute to security hygiene activities, technical investigations and the handling of information security incidents when alerts or issues are raised.
- Support audits and the Information Security Management System by collecting evidence, following up recommendations, and contributing to procedures and policies.
- Act as a security contributor on local and international projects, maintaining clear communication with IT, Risk and Quality teams, clients, leaders and PwC Network stakeholders.
Your growth and opportunities
Build strong exposure to information security governance, risk management, audits, client due diligence and security operations in a role connected to both the Luxembourg firm and the wider PwC Network. Over time, you will strengthen your ability to translate technical security topics into practical risk-based recommendations and expand your contribution across local and international initiatives.
The skills you bring
- A Master’s degree in Computer Science or equivalent, with a specialisation in information security.
- English: CEFR level to be confirmed — professional proficiency required for written and verbal communication.
- Vulnerability management: Working knowledge — able to analyse vulnerability information and support remediation follow-up.
- Windows and Linux environments, cloud security in Azure and AWS, and risk-analysis methods: Working knowledge.
- Communication and writing skills to share security information clearly with technical and non-technical stakeholders.
Ways of working
- You evaluate information from different angles, challenge assumptions constructively and use structured thinking to support sound security decisions.
- You contribute actively to team efforts, build trust with peers and prioritise shared outcomes over individual recognition.
- You seek feedback, learn from new situations and use stretch tasks to grow your security and risk understanding.
- You act with integrity, handle confidential information with care, and uphold high ethical standards in every situation.
Take your next step
Build your information security career in a role where governance, risk, technology and stakeholder collaboration meet. Contribute to work that strengthens trust, quality and resilience across the firm while growing your expertise alongside experienced security professionals and the wider PwC Network. Grow here. Go further.
Education (if blank, degree and/or field of study not specified)
Degrees/Field of Study required:Degrees/Field of Study preferred:Certifications (if blank, certifications not specified)
Required Skills
Optional Skills
Accepting Feedback, Accepting Feedback, Active Listening, Azure Data Factory, Communication, Cybersecurity, Cybersecurity Governance, Data Architecture Development, Data Archiving, Data Flow Mapping, Data Privacy Act, Emotional Regulation, Empathy, Enterprise Content Management, Incident Response Plan, Inclusion, Information Rights Management (IRM), Information Security, Information Security Governance, Information Security Management System (ISMS), Intellectual Curiosity, IT Infrastructure, Operating Model, Optimism, Privacy and Security {+ 6 more}Desired Languages (If blank, desired languages not specified)
Travel Requirements
Not SpecifiedAvailable for Work Visa Sponsorship?
NoGovernment Clearance Required?
NoJob Posting End Date
