Senior Consultant - Cybersecurity - GRC - Toulouse - M/F

14 Minutes ago • 3-5 Years
Cyber Security

Job Description

PwC Cybersecurity in Toulouse offers a key role for a Senior Consultant in GRC. The team, built over ten years, focuses on competence and international reach, providing tailored approaches and tools for demanding clients in sectors like aerospace, defense, energy, banking, and public sector. This role involves transforming risk into strategic advantage by co-building security, compliance, and resilience systems. The consultant will analyze and manage risks, ensure compliance with standards like ISO 27001, DORA, and NIS2, and strengthen cyber governance.
Must Have:
  • Conduct risk analyses (EBIOS RM, ISO 27005, NIST RMF), including asset collection, attack scenario definition, impact, and likelihood assessment.
  • Define and monitor indicators/KRIs: critical risks, trends, remediation follow-up.
  • Challenge risk/cost/timeline trade-offs with business, IT, and CISO departments.
  • Perform compliance diagnostics and establish associated compliance plans (ISO 27001, DORA, NIS2, RGPD).
  • Pilot the implementation of corrective measures: controls, procedures (risk, vulnerability, security incident management), evidence collection, internal audits.
  • Build or strengthen governance frameworks (security policies, roles, processes, committees, KPIs, reporting).
  • Define or deploy transformation plans: security roadmap, employee awareness, risk culture promotion.
  • Support security-business integration: ensure cybersecurity is a decision-making lever, not a hindrance.
  • Co-lead workshops and structure deliverables (scoping notes, presentations, risk matrices, security policies, dashboards).
  • Present recommendations to clients (CISO, CIO, steering committee, business units).
  • Coach junior consultants to help them develop their skills.
  • 3 to 5 years minimum experience in GRC, security audit, compliance, cyber risk (ideally in consulting or a large group).
  • Solid mastery of standards and regulations: ISO 27001 / 27005, DORA, NIS2, RGPD, ISO 22301, EBIOS RM, NIST CSF.
  • Ability to quickly transition from a strategic to an operational vision.
  • Good interpersonal skills, ease in exchanges with decision-makers, and persuasive force.
  • Excellent written and oral communication, sense of pedagogy and leadership.
  • Team spirit, autonomy, curiosity, taste for new or evolving subjects.
  • Proficiency in English (C1 level recommended), essential in an international environment.
Perks:
  • Flexibility with the FlexWork charter: extended telework, geographical mobility, FlexTime, Dress for your day.
  • Crystal Park (Neuilly-sur-Seine site): 2-hectare private park, concierge, music room, gym, Café Joyeux.
  • International mobility and internal mobility after 12 months of seniority.
  • New World. New Skills program to develop skills on tomorrow's challenges (ESG, technologies, diversity inclusion) and access to an on-demand training platform.
  • Credit of 3 days per year on working time for societal engagement missions.
  • Sustainable mobility pass to cover your sustainable mobility expenses.
  • Be Well, Work Well program to take care of your health (Gymlib partnership, United heroes application, sports associations, mindfulness training).
  • Family Care program to support you in your parenting projects as well as in difficult times.
  • RTT (reduction of working time), health and provident insurance, company restaurants and meal vouchers, Inter-Company Committee benefits.
  • All our offers are open to people with disabilities.

Add these skills to join the top 1% applicants for this job

team-management
communication
risk-management
game-texts

Job Description & Summary

Offer Presentation

Cybersecurity at PwC is above all an adventure. That of a team that has been building for over ten years, based on legitimacy acquired through constant effort in competence and relevance (whether technological or not), and an international strike force.

It also involves tailor-made approaches and tools to meet the needs of demanding but loyal clients. And it's a strong, committed, and benevolent collective, within which everyone can develop skills, initiatives, and a rich perspective on a complex subject.

Within the Toulouse office, we help our clients transform risk into a strategic advantage. We operate in key sectors of the region (aerospace, space, defense, energy, banking/insurance, public sector) to co-build security, compliance, and resilience systems that last over time and support our clients in their transformation challenges.

As a Senior Consultant, you will play a key role in the development of PwC's GRC activity. You will be involved in:

1. Risk Analysis & Management

  • Conduct risk analyses (EBIOS RM, ISO 27005, NIST RMF…): asset collection, definition of concrete attack scenarios, impact and likelihood assessment.
  • Define & monitor indicators / KRIs: critical risks, trends, remediation follow-up.
  • Challenge risk / cost / timeline trade-offs with business, IT, and CISO departments.

2. Compliance Implementation

  • Perform compliance diagnostics and establish associated compliance plans (e.g., ISO 27001, DORA, NIS2, GDPR…).
  • Pilot the implementation of corrective measures: establishment of controls, formalization of procedures on key issues (risk management, vulnerability management, security incident management, etc.), evidence collection, preparation and conduct of internal audits.

3. Cyber Governance & Transformation

  • Build or strengthen governance frameworks (security policies, roles & responsibilities, essential processes, committees, KPIs and reporting).
  • Define or deploy transformation plans: construction of the security roadmap, employee awareness and engagement, promotion of risk culture.
  • Support security-business integration: ensure cybersecurity is a decision-making lever, not a hindrance.

4. Delivery & Management

  • Co-lead workshops and structure deliverables (scoping notes, presentations, risk matrices, security policies, dashboards, etc.).
  • Present your recommendations to clients (CISO, CIO, steering committee, business units).
  • Coaching junior consultants to support their skill development.

What we expect from you:

  • 3 to 5 years minimum experience in GRC, security audit, compliance, cyber risk (ideally acquired in a consulting firm or within a large group).
  • Solid mastery of standards and regulations: ISO 27001 / 27005, DORA, NIS2, GDPR, ISO 22301, EBIOS RM, NIST CSF.
  • Ability to quickly transition from a strategic to an operational vision.
  • Good interpersonal skills, ease in exchanges with decision-makers and persuasive force.
  • Excellent written and oral communication, sense of pedagogy and leadership.
  • Team spirit, autonomy, curiosity, taste for new or evolving subjects.
  • You are proficient in English (C1 level recommended), essential in an international environment.

These benefits we offer

Work Environment and Flexibility

  • Flexibility with the FlexWork charter: extended telework, geographical mobility, FlexTime, Dress for your day.
  • Crystal Park (Neuilly-sur-Seine site): 2-hectare private park, concierge, music room, gym, Café Joyeux.

Development

  • International mobility and internal mobility after 12 months of seniority.
  • New World. New Skills program to develop skills on tomorrow's challenges (ESG, technologies, diversity inclusion) and access to an on-demand training platform.

Commitment

  • Credit of 3 days per year on working time for societal engagement missions.
  • Sustainable mobility pass to cover your sustainable mobility expenses.

Health/Well-being

  • Be Well, Work Well program to take care of your health (Gymlib partnership, United heroes application, sports associations, mindfulness training).
  • Family Care program to support you in your parenting projects as well as in difficult times.

And also: RTT, health and provident insurance, company restaurants and meal vouchers, Inter-Company Committee benefits…

All our offers are open to people with disabilities.

Set alerts for more jobs like Senior Consultant - Cybersecurity - GRC - Toulouse - M/F
Set alerts for new jobs by PwC
Set alerts for new Cyber Security jobs in France
Set alerts for new jobs in France
Set alerts for Cyber Security (Remote) jobs

Contact Us
hello@outscal.com
Made in INDIA 💛💙