Manager/ Senior Manager – Cyber Security (DarkLab) Consulting

PwC

Hong Kong

On-site

HKD 900,000 - 1,800,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

PwC Hong Kong's DarkLab practice seeks a Manager/Senior Manager to lead cyber security engagements across managed defence, offensive security, and governance. You will drive delivery, shape solutions and oversee teams in a dynamic AI-powered SOC environment.

The role combines technical depth with business development, enabling you to lead large-scale client work, collaborate with cross-border teams, and mentor junior consultants while ensuring regulatory alignment and high-quality outcomes.

Qualifications

  • University degree majoring in computer science, information systems, engineering, information security or related discipline.
  • Professional qualifications: CISSP, CISM, CISA, CRISC, OSCP, CREST, GIAC or other security-related qualifications.
  • Minimum of 6 years of cyber security experience with a reputable firm, including at least 2 years leading engagements or service delivery.

Responsibilities

  • Lead delivery across the DarkLab practice, assembling specialists and owning end-to-end outcomes.
  • Scope, price and plan work across the portfolio, ensuring quality and advisory alignment.
  • Quality-review deliverables and act as senior escalation point on major incidents and engagements.
  • Convey pragmatic solutions to complex business problems through reports and executive briefings.

Skills

Security certifications
Leadership

Education

Bachelor's degree in Computer Science or related

Job description

Manager/ Senior Manager – Cyber Security (DarkLab) Consulting

DarkLab is PwC Hong Kong’s cyber defence practice — over 150 practitioners delivering managed defence, advisory and technology solutions to enterprise clients across Hong Kong, Mainland China and South East Asia. We are CREST-accredited, we publish original vulnerability research, and we operate managed detection and response, exposure management and attack surface management as live services.

We are now scaling the next generation of that business: an AI-powered Security Operations Centre and a portfolio of AI-enabled cyber solutions built on our own detection engineering, our threat intelligence, and partnerships including watchTowr, Microsoft, AWS and Palo Alto Networks.

DarkLab practice areas

You should expect to lead work drawing on any of these, and to be genuinely strong in one or two. Whether your strength is technical or advisory matters far less than that it is real.

Managed Cyber Defence

Cyber-as-a-Service: 24/7 monitoring, managed detection and response, detection engineering, SOC operations, and our AI-powered SOC

Continuous exposure validation, external attack surface discovery, vulnerability management, watchTowr-based services

Offensive Security

Penetration testing, red and purple teaming, adversary simulation, SDLC security, CREST-accredited and intelligence-led testing

Digital footprint reporting, dark web monitoring, threat research, bespoke intelligence assessments, vulnerability research

Incident readiness, investigation, containment and remediation, threat hunting, post-incident review

Cyber Strategy, Governance & Regulatory

Strategy and maturity assessment, NIST and ISO 27001 frameworks, HKMA C-RAF and iCAST, SFC requirements, third-party risk

Privacy & Data Protection

PDPO, GDPR and PIPL compliance, privacy impact assessment, China Cybersecurity Law, MLPS certification, cross-border data transfer

Cloud security strategy and architecture, CSPM/CNAPP, secure landing zones, container security, secure development pipelines

AI security and AI governance, blockchain and digital asset security, wallet and key management, security engineering and internal products

Key responsibilities

Leading delivery across the practice

  • Lead cyber security engagements that draw on more than one DarkLab specialty — assembling the right specialists, holding the parts together, and owing the outcome end to end.
  • Scope, price and plan work across the full portfolio, including areas where you are not personally the practitioner. You are expected to know what good looks like, who to put it on, and when something is off.
  • Quality-review deliverables across specialties, and act as a senior escalation point on major incidents and difficult engagements.
  • Convey pragmatic solutions to complex business problems through written reports and presentations to boards, audit committees and regulators.
  • Maintain and raise the quality bar — methodology, deliverable standards, peer review, and risk and quality management on every engagement.

Depth in your own specialties

  • Set the technical direction in the one or two practice areas where you are the specialist — owning methodology, tooling decisions and the standard of the work.
  • Act as the final technical reviewer in those areas, and as the firm’s subject matter expert in front of clients and regulators.
  • Develop the capability behind you: build the bench, run technical training, and grow the next specialists in your domain.
  • Stay current in your field and bring what is useful back into practice — research, tooling, tradecraft, new regulatory expectations.

Managed services and AI

  • Own the technical design of managed security service solutions: detection engineering, use case development, SIEM/SOAR architecture, client onboarding and transition, service levels and run-state operating models.
  • Bring AI into the detection and response lifecycle — automated triage and enrichment, agentic workflows for tier-1 and tier-2 analysis, LLM-assisted detection engineering and threat hunting — with measurable outcomes in mean time to triage, alert fatigue and detection coverage.
  • Advise clients on securing their own AI adoption, covering model and data risk, prompt injection, data leakage and AI governance.

Solutioning and business development

  • Act as solution lead for DarkLab’s AI-powered SOC and AI security offerings, taking them to market with our client-facing teams in Hong Kong and the region.
  • Run the pre-sales cycle: qualify the opportunity, scope it, shape the commercial and technical business case, and build the solution.
  • Prepare proposals, presentations and statements of work, and lead technical responses to RFIs, RFPs and tenders.
  • Work with commercial constructs that suit managed services — tiered, consumption-based and multi-year models — and understand the margin behind them.
  • Present to audiences from CISO and CIO through to CEO, CFO and the board, and run workshops, proofs of concept and executive briefings that convert interest into signed work.
  • Build and sustain your own network of client relationships and industry contacts, and act as a trusted adviser across both the pre-sales and post-sales lifecycle.
  • Own the handover from sale to delivery, so that what we sold is what the client receives.
  • Contribute to offering development — service design, reference architectures, pricing constructs and enablement material — and to our alliances with security and cloud vendors.
  • Represent DarkLab externally through thought leadership, research publication, conference speaking and industry bodies.

People and practice

  • Supervise, coach, develop and lead multi-disciplinary teams of consultants and SOC analysts, including performance management and career development.
  • Build the capability bench — recruitment, technical training, certification pathways and knowledge management.
  • Contribute to the commercial management of the practice: resourcing, engagement economics, utilisation and delivery profitability.
Requirements
  • University degree majoring in computer science, information systems, engineering, information security or related discipline.
  • Professional qualifications: CISSP, CISM, CISA, CRISC, OSCP, CREST, GIAC or other security-related qualifications.
  • Minimum of 6 years of cyber security experience with a reputable professional / consulting firm, managed security service provider, system integrator, security vendor or multi-national corporation, including at least 2 years leading engagements or service delivery. Candidates with more experience will be considered for the Senior Manager or Associate Director position.

Depth. Genuine depth in one or two of the DarkLab practice areas listed above — deep enough that you set the direction, own the methodology, and are the person who signs off the work in that area. Depth in an advisory domain counts as much as depth in a technical one: cyber strategy, governance and regulatory, or privacy and data protection, sit on the same footing here as offensive security or detection engineering.

Breadth. Working command of most of the remainder — enough to scope it, price it, quality-review it, lead a specialist team delivering it, and hold a credible conversation with a client across the whole portfolio. You are not expected to be the technical expert in every area. You are expected to know what good looks like, who to put on it, and when something is off.

  • A demonstrable commercial track record: shaping and winning work, contributing to proposals and bids, or carrying a solution or revenue target.
  • Working knowledge of the Hong Kong regulatory environment, including HKMA C-RAF and iCAST, SFC requirements and the PDPO; and where relevant Mainland China’s Cybersecurity Law, MLPS and PIPL.
  • Excellent communication skills in both oral and written English and Chinese. Cantonese is required for Hong Kong client delivery; Mandarin is a strong advantage for regional work.
  • Proven experience as a team leader and coach.
  • Ability to interact with executive levels of client and firm management.
  • Flexibility to travel to out-of-town engagements within Greater China and South East Asia.

Preferred background (any of the following)

  • Practical experience building, running or selling a managed detection and response or SOC service — not just consuming one.
  • Genuine fluency in applying AI to security operations: agentic workflows, LLM-assisted analysis, automation of triage and response, and an honest view of where it works and where it does not.
  • Experience securing enterprise AI adoption, or in AI red teaming.
  • A track record of taking a new service offering to market — building it, pricing it, positioning it and selling the first deals.
  • Vendor experience across the platforms we work with, including watchTowr, Microsoft Security, Palo Alto Networks and AWS.
  • Published research, CVE credits, conference speaking or an active presence in the security community.
  • Experience operating across Hong Kong, Mainland China and Southeast Asia.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI‑Powered Cyber Security Leader | Managed SOC & Strategy
AI‑Powered Cyber Security Leader | Managed SOC & Strategy

PwC • Hong Kong

On-site
HKD 900,000 - 1,800,000
Senior Cloud Security Consultant (Public Cloud, DevSecOps & AI Security)
Senior Cloud Security Consultant (Public Cloud, DevSecOps & AI Security)

PwC • Hong Kong

On-site
HKD 600,000 - 900,000
IT Cyber Security Manager
IT Cyber Security Manager

Recruit Squad Limited • Hong Kong

On-site
HKD 600,000 - 900,000
Managing Director, Greater China
Managing Director, Greater China

Blackpanda • Hong Kong

On-site
HKD 900,000 - 1,500,000
Director, Deputy Head of Information Security, IT
Director, Deputy Head of Information Security, IT

Be Myjob Company Limited • Hong Kong

On-site
HKD 900,000 - 1,500,000
Deputy Head of Information Security, IT
Deputy Head of Information Security, IT

CLSA • Hong Kong

On-site
HKD 1,500,000 - 2,600,000
Cybersecurity Analyst
Cybersecurity Analyst

Jane Street • Hong Kong

On-site
HKD 480,000 - 900,000
Cybersecurity Manager (Technical Controls, Infrastructure Security) (Bank)
Cybersecurity Manager (Technical Controls, Infrastructure Security) (Bank)

Classy Wheeler Limited • Hong Kong

On-site
HKD 800,000 - 1,200,000
Manager - Cybersecurity
Manager - Cybersecurity

Leadingnation • Hong Kong

Hybrid
HKD 600,000 - 1,200,000
Security Manager
Security Manager

Automated Systems (HK) Ltd • Sha Tin

On-site
HKD 900,000 - 1,300,000