Who We Are
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.
What You'll Do
We are seeking a high-performing Global Cybersecurity Manager – Governance & Compliance to lead the strategy, execution, and continuous evolution of our global cybersecurity governance, compliance, and certification program. This individual will own the end-to-end delivery of external security certifications while partnering across Engineering, Product, Infrastructure, Legal, Privacy, Risk, and business teams to ensure security controls are effectively designed, implemented, and continuously improved.
This is a highly execution-oriented role responsible for driving complex cross-functional initiatives, building scalable governance and compliance processes, and modernizing the certification lifecycle through automation and continuous compliance practices. The successful candidate will serve as the primary owner of the firm’s external certification portfolio, helping strengthen client trust while ensuring compliance with evolving global regulatory and industry standards.
This role is ideal for an experienced cybersecurity professional progressing toward senior leadership who enjoys building programs, influencing stakeholders, and delivering measurable outcomes across a global organization.
What You'll Bring
Key Responsibilities
Qualifications
Required
-
5–8+ years of experience in Cybersecurity, Information Security, Governance, Risk & Compliance (GRC), Security Assurance, Compliance, Risk Management, or IT Audit.
-
Demonstrated experience leading enterprise security certification or compliance programs within complex global organizations.
-
Strong working knowledge of industry frameworks including ISO/IEC 27001, SOC 2, and other internationally recognized security standards.
-
Experience partnering with Engineering, Product, Infrastructure, Legal, Privacy, and Risk teams.
-
Excellent program management, stakeholder management, organizational, and communication skills.
-
Proven ability to lead multiple complex initiatives simultaneously while managing competing priorities.
Preferred
Experience supporting one or more of the following:
-
ISO/IEC 27017
-
ISO/IEC 42001
-
TISAX
-
HITRUST
-
Cyber Essentials / Cyber Essentials Plus
-
ENS
-
Experience within a global technology, consulting, or professional services organization.
-
Familiarity with cloud environments including AWS, Azure, and Google Cloud Platform.
-
Experience implementing or managing GRC platforms and workflow automation solutions.
-
Professional certifications such as CISSP, CISA, CRISC, ISO 27001 Lead Auditor, or ISO 27001 Lead Implementer.
Additional info
What Success Looks Like
-
Successfully delivers all global certification and compliance activities on schedule while maintaining high-quality outcomes.
-
Establishes scalable, repeatable, and efficient governance and compliance processes across the organization.
-
Modernizes the cybersecurity governance program through automation and continuous compliance practices.
-
Builds trusted partnerships across Engineering, Product, Infrastructure, Legal, Privacy, Risk, and business leadership.
-
Anticipates emerging regulatory and certification requirements, ensuring the organization remains ahead of evolving customer and industry expectations.
-
Strengthens the firm’s cybersecurity governance and compliance posture while enabling business growth, client trust, and operational excellence.
At BCG, our people and relationships are at the heart of everything we do. We believe that in-person collaboration plays an important role in our culture, mentorship, and professional development.
For this role, you will generally be expected to work from a BCG office or in person with clients on a regular basis (typically around 50% of working time), depending on business needs and in line with local policies and practices.
We aim to provide a dynamic and collaborative environment that fosters connection and teamwork.
Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E - Verify Employer. Click here for more information on E-Verify.