Global Platform Team Lead and Senior Director - IT Security (Boston) Job at Boston Consulting Group (BCG), Boston, MA

VzRGYm9sNVBsUWhSMUU3VU56enQyRmFiOHc9PQ==
  • Boston Consulting Group (BCG)
  • Boston, MA

Job Description

Global Platform Team Lead and Senior Director - IT Security

Locations : London | Atlanta | Boston

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG helps clients with total transformationenabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise to spark change, delivering solutions through management consulting, technology and design, corporate and digital ventures, and business purpose.

We work in a collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.

What You'll Do

The Global Platform Team Lead and Senior Director - IT Security is responsible for leading the design, delivery, and continuous evolution of BCG's security platforms across identity, device, and data protection domains. This role ensures end-to-end security engineering across all technology environments, including cloud, on-prem, and hybrid systems. The leader will drive strategic planning, execution, and operations of scalable, automated, and resilient security controls that protect BCGs global operations and users, while enabling innovation and agility across BCG Core, BCG X, and CT worldwide. This role is also accountable for embedding security within DevSecOps practices, enforcing automation at scale, and applying Site Reliability Engineering (SRE) principles across all security services.

The role requires strong partnership with ISRM, with a focus on balancing and prioritizing security requirements, automation opportunities, user experience needs, and broader business outcomes.

Key Responsibilities

  • Strategic Leadership & Transformation: Define and execute a unified security engineering strategy that addresses identity, endpoint, and data protection across all environments.
  • Strategic Leadership & Transformation: Lead the design and implementation of scalable, automated security solutions that integrate into enterprise platforms and user experiences.
  • Strategic Leadership & Transformation: Establish a global security architecture and engineering roadmap focused on prevention, detection, and rapid response.
  • Strategic Leadership & Transformation: Drive continuous improvement of security posture while aligning with business needs, regulatory requirements, and user experience expectations.
  • Strategic Leadership & Transformation: Champion DevSecOps practices to embed security early into development and delivery workflows.
  • Security Platform Engineering: Lead end-to-end engineering for identity and access management (IAM), including authentication, authorization, and privileged access controls.
  • Security Platform Engineering: Oversee endpoint security architecture and enforcement, ensuring coverage for threat detection, malware prevention, and device compliance.
  • Security Platform Engineering: Build and operate scalable data protection solutions, including data loss prevention (DLP), secrets management, encryption, and classification.
  • Security Platform Engineering: Integrate security controls into CI/CD pipelines, cloud-native services, and on-prem platforms to enforce security-by-design principles.
  • Security Platform Engineering: Deliver security capabilities that support modern work scenarios, remote access, zero-trust networking, and AI/ML workloads.
  • Security Platform Engineering: Leverage automation frameworks and IaC to improve scalability and reduce manual intervention.
  • Operational Security, SRE & Assurance: Ensure security platforms are resilient, continuously monitored, and designed for 24x7 support and incident response readiness.
  • Operational Security, SRE & Assurance: Embed security telemetry and observability to enable proactive threat detection and automated response.
  • Operational Security, SRE & Assurance: Apply SRE principles to improve reliability, performance, and maintainability of security services.
  • Operational Security, SRE & Assurance: Lead platform health, patching automation, and vulnerability remediation workflows.
  • Operational Security, SRE & Assurance: Define service level objectives (SLOs) and key performance indicators (KPIs) for all security services.
  • Compliance, Governance & Risk Management: Ensure alignment with global compliance requirements such as ISO 27001, NIST, SOC 2, GDPR, and others.
  • Compliance, Governance & Risk Management: Partner with governance, legal, and ISRM teams to implement enforceable policies and standards across identity, endpoint, and data domains.
  • Compliance, Governance & Risk Management: Operationalize policy enforcement through automated controls and continuous compliance checks.
  • Compliance, Governance & Risk Management: Lead risk mitigation efforts with technical solutions that scale across diverse user and system profiles.
  • Financial & Vendor Management: Manage security platform budgets and investments with a focus on cost optimization and long-term value.
  • Financial & Vendor Management: Evaluate and manage third-party vendors and partners, ensuring they meet technical, contractual, and security expectations.
  • Financial & Vendor Management: Lead procurement and renewal cycles in alignment with operational and architectural strategies.
  • Leadership & Talent Development: Build and mentor a global team of security engineers, fostering a high-performance, collaborative culture.
  • Leadership & Talent Development: Drive internal knowledge sharing and upskilling programs across security architecture, automation, and secure software engineering.
  • Leadership & Talent Development: Collaborate cross-functionally with platform, product, and enterprise architecture teams to embed security early and often.

What You'll Bring

Required Qualifications

  • 10+ years of experience in cybersecurity, security engineering, or platform security roles.
  • 5+ years in a senior leadership position with accountability for enterprise-scale security platforms.
  • Deep expertise in IAM, endpoint security, and data protection technologies, with proven ability to design and scale global solutions.
  • Experience with security engineering in hybrid and cloud-native environments (AWS, Azure, GCP).
  • Proven track record in automating security controls, implementing zero-trust models, and supporting 24x7 security operations.
  • Strong understanding of compliance frameworks and risk management strategies.

Preferred Qualifications

  • Certifications such as CISSP, CCSP, CISM, AWS/Azure Security Specialty, or equivalent.
  • Experience with tools like Okta, Azure AD, CrowdStrike, Tanium, Zscaler, Vault, and other modern security platforms.
  • Familiarity with DevSecOps principles, Infrastructure as Code, and secure software development practices.

Work Environment & Additional Information

  • Hybrid or on-site work model.
  • Occasional travel may be required for business, vendor, or team engagement.
  • Ability to operate in a fast-paced, complex environment, balancing long-term strategy with operational agility.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.

#J-18808-Ljbffr

Job Tags

Full time, Local area, Remote work, Worldwide,

Similar Jobs

ANISTAR TECHNOLOGIES INC

Senior Travel Safety Coordinator OSHA 30 Expert Job at ANISTAR TECHNOLOGIES INC

 ...A respected staffing agency is seeking a Sr Safety Coordinator (Travel) responsible for planning and maintaining safety programs to ensure...  ...technical safety support, and ensuring compliance with OSHA regulations. Suitable candidates must have an OSHA 30 certification... 

University Hospitals

Pharmacy Tech I - II, Bolwell Retail Job at University Hospitals

 ...Certified Technicians Free Parking A Brief Overview The Pharmacy Technician 2 is accountable for assisting pharmacists in the...  ...Pharmacist. What You Will Do For Inpatient Pharmacy Tech 2, activities include but are not limited to: Accurate... 

Link Up Overseas

Junior Level / Data Entry Clerk (Remote) Job at Link Up Overseas

 ...About the job Junior Level / Data Entry Clerk (Remote) Job Opening: Remote Entry-Level Data Entry Clerk Are you looking to kickstart your career in the world of data management? Do you have an eye for detail and a passion for organizing information? If so, we... 

Jasa Group

Construction Project Manager Job at Jasa Group

 ...a network of skilled subcontractors and design professionals to ensure seamless project execution. Our services encompass construction management, general contracting, interior and exterior finishes, roofing, and custom carpentry. Notable projects have been completed in... 

RSM US LLP

UKG Pro WFM Project Manager Senior Consultant Job at RSM US LLP

 ...growing team seeking a qualified professional UKG Workforce Management Project Manager. The selected individual will be expected to...  ...email at ****@*****.***. RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future...