Global Cybersecurity Senior Manager
Job in
Atlanta, Fulton County, Georgia, 30383, USA
Listed on 2026-07-20
Listing for:
Boston Consulting Group
Full Time
position Listed on 2026-07-20
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures-and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.
What You'll Do
As the Global Cybersecurity Senior Manager for Attack Surface Management, you will lead BCG's enterprise Attack Surface Management service, transforming technical security findings into prioritized risk decisions and measurable remediation outcomes. Working across infrastructure, cloud, network, and identity security domains, you will provide continuous visibility into enterprise cyber exposure while enabling technology teams to reduce organizational risk through effective remediation.
You will serve as an enterprise subject matter expert for Attack Surface Management within Information Security Risk Management (ISRM). By partnering across Security Operations, Infrastructure, Cloud, Identity, Network, and Governance, Risk, and Compliance (GRC) teams, you will drive consistent risk prioritization, improve operational processes, and deliver executive-level reporting that strengthens BCG's cybersecurity posture.
Your responsibilities will include:
1. Triage Attack Surface Findings (Heart of the Role)
- Review misconfigurations and vulnerabilities surfaced across scanning platforms covering:
- Infrastructure and endpoint exposure
- Cloud misconfigurations and workload risk
- Network vulnerabilities and segmentation gaps
- Identity and privilege-related exposures
- Leverage AI-powered vulnerability assessment tools to continuously scan, correlate, and surface high-priority findings across domains at scale
- Classify findings by:
- Criticality per BCG risk index
- Acceptable vs. contextual risk vs. noise
- Use AI-assisted triaging workflows to accelerate initial classification, pattern detection, and anomaly identification across large volumes of findings
- Remove false positives using business context and asset criticality scoring, augmented by AI-driven noise reduction and contextual filtering
- Prioritise remediation based on severity, exploitability, blast radius, and business alignment
- Determine the business impact of open findings including:
- Unpatched critical vulnerabilities
- Exposed assets and services
- Misconfigured cloud and network controls
- Privilege escalation pathways
- Map findings to real attack paths and regulatory requirements
- Apply AI-generated risk scoring and attack path simulation to enrich contextualisation and identify non-obvious exposure chains
- Translate technical findings into plain-English risk narratives for both technical teams and executive stakeholders including CISO, CIO, CTO, and CRO
- Leverage AI-assisted reporting to generate structured, executive-ready risk summaries and trend analyses, reducing manual reporting effort and improving consistency
- Recommend specific actions such as:
- Patch prioritisation and deployment
- Misconfiguration remediation
- Asset hardening and configuration baseline enforcement
- Policy or process refinement
- Utilise AI-driven prioritisation models to rank remediation actions by predicted impact, exploitability likelihood, and asset criticality
- Partner with Infrastructure, Cloud, Network, Identity, and GRC teams to drive remediation to closure
- Track findings through resolution and validate measurable reduction in attack surface exposure
- Develop playbooks for:
- Critical vulnerability triage and escalation
- Cloud misconfiguration remediation
- Network exposure management
- Identity and privilege-related attack surface risks
- Embed AI-assisted triage and classification steps within playbooks to enable faster, more consistent execution across teams
- Define:
- Severity thresholds and risk scoring criteria
- Escalation criteria and ownership assignment
- SLA expectations for remediation by risk tier
- Tune scanning tool policies to reduce noise and improve signal quality across Tenable, Wiz, and Microsoft Defender for Endpoint, incorporating AI-based tuning recommendations where available
- Be one of the go-to subject matter experts on Attack Surface Management for the Cybersecurity team
- Help teams understand dashboards, risk trends, and exposure reports from scanning platforms, including…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×