普华永道
岗位信息
招聘岗位
Consulting - CyberData & Tech Risk Consulting Associate - Graduate Programme
工作城市
上海、广州、深圳
是否笔试
未明确
招聘批次
校招
发布日期
2026-08-03
📋 岗位职责 / 任职要求
Location: Beijing, Shanghai, Guangzhou, Shenzhen, Chengdu
Line of Service: Consulting
Type of employment: Full-time
About Our Business
Here in Consulting, we work with our clients as trusted allies to navigate challenges, spot opportunities, and help them achieve measurable, sustained outcomes. Combining human ingenuity and deep industry expertise with AI-powered solutions and a seamless approach, we help our clients define, implement, and operate their future.
We focus on four pillars: Business Model Reinvention, AI, Data and Tech, Trust and Substantify—to help our clients move at speed and scale with confidence. Within these pillars, our comprehensive solutions cover everything from strategic planning to implementation across key areas such as enterprise strategy, technology, cloud transformation, front office transformation, workforce optimization, risk and regulatory, sustainability, and actuarial services.
By joining us, you’ll work with experienced consultants who are passionate about solving business challenges, developing core skills, and creating impact to shape the future.
About Our Practice
We help our clients devise strategic plans and provide in-depth consulting services across key areas such as cyber, data and technology risk. This supports the effective implementation of strategy and helps clients address business challenges to achieve high-quality, sustainable growth.
The growing scale and sophistication of cyber threats have made an effective cybersecurity programme a critical business requirement. We help organisations protect against threats, enable transformation, and pursue growth.
We do not just protect business value — we create it, using cybersecurity and privacy as tools to transform businesses. As companies pivot towards digital business models, exponentially more data is generated and shared among organisations, partners, and customers. At the same time, business digitisation exposes companies to new digital vulnerabilities, making effective cybersecurity and privacy more important than ever. We bring together four key elements to help our clients take a broader view of cybersecurity and privacy as both protectors and enablers of the business:
• Cybersecurity strategy, transformation and compliance
• Data privacy and protection
• Implementation and operations of cybersecurity solutions
• Incident response and threat management
By embracing the transformative power of technology and data in pursuit of opportunity and value creation, our integrated solutions enable clients to build advanced, predictive risk management capabilities — from risk vision and strategy through to the people and processes required across the organisation. At the core of our integrated approach is the use of actionable intelligence to drive alignment and accountability across diverse organisational functions. We support clients in developing end-to-end governance and risk platforms that empower dynamic users, enable the creation of new risk detection metrics through big data and GenAI modelling, strengthen the correlation between KPIs and KRIs, and reinforce the integration of the three lines of defence to uphold robust governance and oversight.
By joining us, you will work with experienced consultants who are passionate about solving business challenges, developing core skills, and creating meaningful impact to help shape the future.
As an Associate, you will work in multidisciplinary engagement teams to support the delivery of complex solutions for our clients. Our client base includes multinationals, public sector organisations, and state-owned and private enterprises. You will work on engagements aligned with your educational background, experience, interests, and our clients’ needs. You may also collaborate with several teams to support the delivery of these engagements locally and regionally.
Working in PwC Cyber Security Team
As part of our Cyber, Data & Tech Risk Consulting Consulting team, you will have the opportunity to develop your career across one or more of the following competencies:
Cybersecurity Consultancy — design, build and advise:
• Offensive Security / Red Teaming — Hong Kong and Macau's largest ethical hacking team, running intelligence-led cyber-attack simulations that replicate real threat-actor tactics (mapped to MITRE ATT&CK) to uncover the blind spots that audits and reviews miss.
• Purple Teaming — collaborative “find and fix” exercises with clients' blue teams to validate and close detection and prevention gaps and increase the cost of attack.
• AI Security & Cloud Security — designing and reviewing AI-powered security operations (open-source LLMs, RAG architectures, SIEM/EDR integrations) and cloud-native security so that AI-driven threat hunting and alert triage are secure, explainable and effective.
• DevSecOps — embedding automated security testing (SAST, SCA, DAST/IAST, container and secrets scanning) and quality gates directly into clients' CI/CD pipelines.
• Cyber Security Assessment & Maturity Uplift — cybersecurity assessment and maturity uplift against legislative framework, regulatory requirements and industry recognized frameworks such as Cybersecurity Law (中华人民共和国网络安全法), Data Security Law (中华人民共和国数据安全法, Personal Information Protection Law (中华人民共和国个人信息保护法), Multi-Level Protection Scheme 2.0 (网络安全等级保护制度), ISO 27001/27002, NIST CSF, etc.
• Digital Trust, Risk Advisory & Regulatory Readiness — advising clients on risk management and control design and implementation to support the trusted launch of new digital services and the adoption of emerging technologies, helping them balance innovation, security, resilience and regulatory expectations.
Managed Security Services — engineer and operate:
• 24x7 Security Operations Centre (SOC) — round-the-clock monitoring, detection engineering and response, with custom detection logic across 200+ log sources and intelligence-driven defence.
• Digital Forensics & Incident Response (DFIR) and Threat Hunting — one of Hong Kong's most experienced incident-response teams, handling ransomware, business email compromise, APT and long-dwell intrusions, plus proactive threat hunting across endpoint, cloud, identity and network telemetry.
• Threat Intelligence (TI) — powered by our Research Lab: original research, CVE discovery and exploit development, tracking 230+ threat actors across Hong Kong, Mainland China and global markets to deliver strategic, operational and tactical intelligence.
• Threat & Vulnerability Management (TVM) — continuous, threat-informed identification, prioritisation and remediation of vulnerabilities across on-premise, cloud and hybrid environments.
• Pre-emptive Exposure Management (MSSP) & Dark Web Monitoring — continuous attack-surface and dark-web monitoring to surface exploitable exposures, leaked data and brand impersonation before attackers can act on them.
Requirements
We are looking for motivated and enthusiastic graduates from any discipline who are eager to learn and grow with us. We welcome candidates from diverse backgrounds and do not expect you to have all the answers — what matters most is your leadership, business acumen, attitude, curiosity, and willingness to develop. We are looking for candidates who demonstrate:
• Experience and enthusiasm relevant to our client services;
• Business acumen and appreciation of the use of IT systems, technology infrastructure and cloud computing;
• Strong analytical skills;
• Strong communication and interpersonal skills;
• Good organisation skills with influencing skills / leadership potential;
• Energy and drive;
• Flexibility to travel to out-of-town assignments;
• Ability to work under pressure and be flexible to work longer hours if needed;
• A strong command of English, Putonghua, Cantonese and/or Japanese.
If you are keen to build your career in cyber , we would especially like to see:
• AI fluency — you are comfortable using and reasoning about AI tools, and curious about how AI is reshaping both cyber attack and defence;
• Commercial and regulatory awareness — you demonstrate strong awareness of global trends and regulatory developments, coupled with sound business judgement and a keen eye for emerging risks and opportunities, and can recognise how these evolving forces are shaping the digital landscape.
• An open mindset and a strong problem-solving orientation, with the resilience to take on unfamiliar and ambiguous challenges;
• Strong communication skills, with the ability to explain technical findings clearly to both technical and business audiences;
• A solid foundation and genuine interest in cyber security — hands-on skills, certifications or project experience (for example CTFs, penetration testing or home labs) are a plus, though not essential.
We offer comprehensive business and technical training, professional examination training support as well as an excellent environment for career development.
If you wish to apply for this position, please access our online application system to submit your application.
We are looking forward to seeing you in PwC!
投递方式
投递入口为会员专属,登录 / 注册 后查看(注册送 15 天免费试用)🎯 AI校招画像 (来源:DeepSeek AI搜索)
🏢 公司文化与工作氛围
普华永道提倡“灵活办公”,并提供“带薪年假10天起”的福利。员工在年审结束后“能休一个多月”假期,休假文化较为宽松不过,从员工描述中可以推测,审计岗位存在“忙季”和“淡季”的明显节奏区分,忙季(1-4月)工作强度极高,而淡季则有较长的休假补偿。价值观方面,普华永道美国强调审计质量,97%的员工收到关于审计质量重要性的一致信息,99%的员工了解公司的审计质量目标,说明公司对专业质量高度重视。
另外,晋升路径清晰:顾问 – 高级顾问 – 经理 – 高级经理 – 总监 – 合伙人,每年有晋升及调薪机会,超过60%的员工在校招入职后第五年可以顺利晋升经理级别,属于“高成长、高压、高回报”的典型专业服务机构文化。
⏰ 加班情况与工作强度
- 忙季(1-4月):日均工作12小时左右,周末加班是常态。员工描述“年审一般三四个月”,期间“正常工作8小时,剩下的全算加班”。
- 加班费制度:正常工作8小时外的时长全部算加班,前36个小时会换算成钱。加班费倍率:正常工作日1.5倍,周末2倍,节假日3倍。
- 加班时长封顶:忙季积累的加班时长除前36小时换成钱外,剩余时长可以转化为休假,员工普遍能在年审结束后休一个多月假。
- 灵活办公:但未详细说明弹性工作制的具体执行方式。
💰 薪资待遇与年终奖
- 岗位:风控策略专家;薪资范围:30-40K/月;经验要求:5-10年
- 岗位:网络安全咨询顾问;薪资范围:20-35K·13薪;经验要求:3-5年
- 岗位:需求分析工程师;薪资范围:15-30K/月;经验要求:1-3年
- 岗位:软件测试工程师;薪资范围:10-12K·13薪;经验要求:1-3年
- 岗位:税务主管;薪资范围:14-25K·14薪;经验要求:3-5年
- 岗位:IT审计经理;薪资范围:25-50K/月;经验要求:3-5年
- 岗位:Manager, Cybersecurity;薪资范围:30-55K/月;经验要求:5-10年 - Qpay(CPA证书补贴):考过CPA有Qpay,每月3500元,且会计入基本工资,加班费和五险一金的基数也会同步增加。
- 加班费收入示例:小Senior级别,有Qpay,加满36个小时能拿到六千左右的加班费。
- 公积金:以上一年月平均工资为基数(含基本工资、Qpay、加班费和奖金),到中Senior级别公积金账户一个月接近6000元。
- 年底奖金:薪资待遇整体被描述为“高于行业平均薪资”。
🎁 福利体系
- 六险一金:普华永道中天会计师事务所北京分所明确提供六险一金(在五险一金基础上增加额外商业保险)。
- 公积金:按上一年月平均工资为基数缴纳,含基本工资、Qpay、加班费和奖金。
- 带薪年假:10天起。
- 灵活办公:提供灵活办公政策
- 项目加班费:按法定倍数支付(工作日1.5倍、周末2倍、节假日3倍)。
- 年底奖金:提供。
- 专业考试课程辅导及培训:校招入职后(3月-8月)会参加专业考试课程辅导及培训。
📋 校招流程经验
- 阶段:在线申请 + 游戏化测评;时间:即日起至10月16日
- 阶段:普华永道校招体验日;时间:9月
- 阶段:视频面试;时间:9月-10月
- 阶段:Superday面试;时间:10月-12月
- 阶段:录取通知书发放;时间:8月起(次年)
- 阶段:录取庆典;时间:12月
- 阶段:参与公司活动,结识新伙伴;时间:次年1月-9月
- 阶段:专业考试课程辅导及培训;时间:次年3月-8月
- 阶段:正式入职;时间:次年9月起 - 普华永道已将原来的OT题库换成游戏化测评 + 视频面试。
- 测评建议:需要安静环境、仔细阅读测评要求、合理安排时间、保持冷静自信。
- 测评内容包括能力、性格、潜力和适应能力的全面评估。
- 第一轮为视频面试(9月-10月)。
- 第二轮为Superday面试(10月-12月),这是普华永道经典的终面环节,通常为全天候的评估中心形式。
通过率与节奏:整体节奏为每年8月启动网申,次年9月入职,周期横跨一整年,节奏较为稳定但战线较长。
🚀 投递建议与避坑指南
可投递岗位方向:1. 审计及鉴证服务部
2. 风险及控制服务部
3. 咨询部-数字咨询
4. 可持续发展
5. 精算审计及精算咨询服务部
6. 咨询部-思略特战略和运营咨询
7. 咨询部-交易服务
8. 税务服务部
9. X-Venturer 创新领导力工程
工作地点:全国29座城市可选(北京、上海、广州、深圳、成都、重庆、武汉、西安、南京、杭州、苏州等)。
简历加分项:普华永道发布了“简历面试攻略”,但中详细展示。
- 审计岗忙季工作强度极高(日均12小时+),需对工作节奏有心理准备。
- 年审期间长达三四个月,加班时长可以积累并换休,但前期压力较大。
👥 员工口碑与离职率评价
员工满意度:- 积极面:员工认可加班费不薪酬核算严格、Qpay计入基数的做法,休假补偿机制较完善,“年审的各种辛苦基本就都忘了”。
- 消极面:审计岗忙季“日均工作12小时,周末加班是常态”,有员工直言“干3年没到20万,算混得差的”,反映高薪但高强度的现实。
- 员工级别:审计员;年平均离职率:13.4%
- 员工级别:高级审计员;年平均离职率:21.1%
- 员工级别:总监/经理层;年平均离职率:15.6%
- 员工级别:整体(审计员工);年平均离职率:16.5% 高级审计员离职率最高(21.1%),说明在晋升经理前后的阶段流失最为严重。
📈 热门岗位方向与招聘趋势
- 热门方向:其中“可持续发展”和“数字咨询”属于近年来重点发展的新兴方向。社招信息中网络安全咨询、风控策略、IT审计等岗位需求活跃,薪资水平较高(20-55K),反映这些领域人才需求旺盛。
- 薪资趋势:但普华永道美国报告显示其审计了超过700家SEC注册公司、超过25%的财富500强公司,业务规模较大。
- 员工构成(普华永道美国):2023年审计业务共14,923名员工,其中合伙人及董事总经理占7%,总监及经理占17%,高级审计员占18%,审计员占24%,其他员工占34%。女性员工占49%,合伙人中女性占25%。
ℹ️ 信息来源
本条招聘信息由校招宝转载自 Moka 招聘系统(企业校招官网),版权归原发布方所有,校招宝仅作信息聚合与导航。
该来源未提供原文链接
招聘信息以官方原文为准,投递前请核实截止日期与要求。如涉侵权或信息有误,请邮件联系 kknee@qq.com,我们将在 24 小时内处理。