Global Platform Team Lead and Senior Director - IT Security
Listed on 2026-01-01
-
IT/Tech
Cybersecurity, Systems Engineer
Locations:
Boston | Atlanta | London
Who We Are
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.
What You'll Do
The Global Platform Team Lead and Senior Director - IT Security is responsible for leading the design, delivery, and continuous evolution of BCG's security platforms across identity, device, and data protection domains. This role ensures end-to-end security engineering across all technology environments, including cloud, on-prem, and hybrid systems. The leader will drive strategic planning, execution, and operations of scalable, automated, and resilient security controls that protect BCG’s global operations and users, while enabling innovation and agility across BCG Core, BCG X, and CT worldwide.
This role is also accountable for embedding security within Dev Sec Ops practices, enforcing automation at scale, and applying Site Reliability Engineering (SRE) principles across all security services.
The role requires strong partnership with ISRM, with a focus on balancing and prioritizing security requirements, automation opportunities, user experience needs, and broader business outcomes.
Key Responsibilities:
- Strategic Leadership & Transformation:
- Define and execute a unified security engineering strategy that addresses identity, endpoint, and data protection across all environments.
- Lead the design and implementation of scalable, automated security solutions that integrate seamlessly into enterprise platforms and user experiences.
- Establish a global security architecture and engineering roadmap focused on prevention, detection, and rapid response.
- Drive continuous improvement of security posture while aligning with business needs, regulatory requirements, and user experience expectations.
- Champion Dev Sec Ops practices to embed security early into development and delivery workflows.
- Security Platform Engineering:
- Lead end-to-end engineering for identity and access management (IAM), including authentication, authorization, and privileged access controls.
- Oversee endpoint security architecture and enforcement, ensuring comprehensive coverage for threat detection, malware prevention, and device compliance.
- Build and operate scalable data protection solutions, including data loss prevention (DLP), secrets management, encryption, and classification.
- Integrate security controls into CI/CD pipelines, cloud-native services, and on-prem platforms to enforce security-by-design principles.
- Deliver security capabilities that support modern work scenarios, remote access, zero-trust networking, and AI/ML workloads.
- Leverage automation frameworks and IaC to improve scalability and reduce manual intervention.
- Operational Security, SRE & Assurance:
- Ensure security platforms are resilient, continuously monitored, and designed for 24x7 support and incident response readiness.
- Embed security telemetry and observability to enable proactive threat detection and automated response.
- Apply SRE principles to improve reliability, performance, and maintainability of security services.
- Lead platform health, patching automation, and vulnerability remediation workflows.
- Define service level objectives (SLOs) and key performance indicators (KPIs) for all security services.
- Compliance, Governance &
Risk Management:- Ensure alignment with global compliance requirements such as ISO 27001, NIST, SOC 2, GDPR,…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: