Cloud Security Operations Lead — Attack Surface

Boston Consulting Group

Lisboa

Presencial

EUR 90 000 - 140 000

Tempo integral

Há 12 dias
Gerador de candidaturas

Uma candidatura completa num minuto — currículo personalizado e carta de apresentação, prontos a enviar.

Ultrapassa os filtros ATS

Resumo da oferta

Boston Consulting Group seeks a senior security professional to lead attack surface management and cloud security operations. You will coordinate triage, risk assessment, and remediation across CNAPP capabilities in a global multi-cloud environment.

Responsibilities include translating findings into precise remediation guidance, strengthening shift-left security, and building automation for detection logic and runbooks across AWS, Azure, and Google Cloud.

Qualificações

  • 6-8 years in information security with cloud security operations focus.
  • Hands-on CNAPP experience: triage, posture reporting, policy tuning.
  • Strong knowledge of AWS, Azure or Google Cloud security controls.

Responsabilidades

  • Lead cloud security posture operations across CNAPP capabilities.
  • Translate complex findings into actionable remediation guidance for engineers.
  • Embed guardrails into CI/CD pipelines and improve IaC controls.

Conhecimentos

Cloud security operations
CNAPP
AWS/Azure/Google Cloud
Automation (Python/Bash/API)

Ferramentas

CI/CD tools
IaC security

Descrição da oferta de emprego

What You'll Do

You will join BCG's Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. In this role, you will help protect BCG's global multi-cloud environment by leading cloud security posture operations, translating complex findings into clear risk narratives, and driving risk-based remediation at scale.

You will serve as a technical authority across cloud security operations, working across AWS, Azure, and Google Cloud. You will look beyond scanner severity to understand exploitability, attack paths, blast radius, and business impact, helping teams fix the right issues in the right order.

You Will

Lead triage, risk assessment, and response decisions across CNAPP capabilities, including CSPM, CIEM, KSPM, CWPP, IaC security, secrets detection, SCA/SBOM, API security posture, and external attack surface management. Assess cloud security findings in context, evaluating attack path reachability, lateral movement potential, effective permissions, and downstream impact on critical assets. Use graph-based attack path analysis to identify toxic combinations and distinguish critical exposure paths from high-noise, low-impact misconfigurations.

Monitor zero-day and critical vulnerability exposure across cloud workloads, defining affected asset scope and prioritizing remediation based on risk. Evaluate AI and LLM security risks such as exposed inference endpoints, overly permissive model access, insecure secrets handling, vector store exposure, unsafe plugin or tool integrations, and LLMOps pipeline weaknesses.

Drive remediation from finding identification through confirmed closure, partnering with developers, cloud architects, security architects, and platform engineering teams. Translate complex technical issues into precise, actionable remediation guidance for different engineering and security audiences. Strengthen shift-left security by embedding guardrails into CI/CD pipelines, improving infrastructure-as-code controls, and reducing recurring misconfigurations at source. Build and improve automation, detection logic, saved queries, runbooks, and CNAPP policy inputs to reduce manual effort and improve signal quality.

What You'll Bring

6-8 years in information security, with at least 6 years focused on cloud security operations or cloud infrastructure security. Hands-on CNAPP experience across triage, posture reporting, and policy tuning. Deep knowledge of AWS, Azure, or Google Cloud security controls. Practical understanding of AI workload security, LLMOps pipelines, or inference endpoint risk. Strong discernment across exploitability, blast radius, permissions, attack paths, and data exposure. Experience driving remediation across engineering, platform, architecture, or AI enablement teams. Python, Bash, or API integration experience supporting automation and operational scale.

Who You'll Work With

You will be part of BCG's Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. You will work closely with cloud engineering, platform engineering, security architecture, threat intelligence, and DevSecOps teams to identify, prioritize, and reduce cloud security risk across BCG's global technology environment. The team operates in a highly collaborative, technically rigorous setting, with a shared focus on clear risk ownership, practical remediation, and continuous improvement.

Additional info

Preferred certifications are helpful but not required, including AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, or Certified Kubernetes Security Specialist.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.

BCG is an E - Verify Employer. Click here for more information on E-Verify.

Cloud Security Operations Lead - Attack Surface Moscavide E Portela, Portuguese Republic, PT

Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Cybersecurity Manager
Cybersecurity Manager

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 90 000 - 140 000
Cloud Security Operations Lead — Attack Surface
Cloud Security Operations Lead — Attack Surface

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 130 000
Global Cybersecurity Analyst- Cloud Security
Global Cybersecurity Analyst- Cloud Security

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 50 000 - 75 000
Cybersecurity Manager
Cybersecurity Manager

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 130 000
Cloud Security Ops Lead | CNAPP & Attack Surface
Cloud Security Ops Lead | CNAPP & Attack Surface

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 90 000 - 140 000
Cloud Security Ops Lead - Attack Surface Mastery
Cloud Security Ops Lead - Attack Surface Mastery

Boston Consulting Group • Lisboa

Presencial
EUR 90 000 - 140 000
Cloud Security & AI Risk Analyst
Cloud Security & AI Risk Analyst

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 50 000 - 75 000
Global Cybersecurity Program Lead
Global Cybersecurity Program Lead

Boston Consulting Group • Viseu

Presencial
EUR 70 000 - 110 000
Cybersecurity Manager - AI Architecture
Cybersecurity Manager - AI Architecture

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 70 000 - 90 000
Global Cybersecurity Senior Specialist - Program Operations
Global Cybersecurity Senior Specialist - Program Operations

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 120 000