Cybersecurity Manager

The Boston Consulting Group GmbH

Lisboa

Presencial

EUR 90 000 - 140 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Boston Consulting Group is seeking a senior cloud security professional to join the Security Operations team. You will protect BCG’s multi-cloud environment by leading cloud security posture operations and translating findings into clear risk narratives.

You will work across AWS, Azure, and Google Cloud, evaluating exploitability and guiding remediation with engineering and platform teams. This role emphasizes shift-left security and automation to reduce misconfigurations.

Qualificações

  • 6–8 years in information security with cloud security focus.
  • Hands-on CNAPP experience across triage, posture reporting, and policy tuning.
  • Deep knowledge of AWS, Azure, and Google Cloud security controls.
  • Practical understanding of AI workload security and LLMOps risk.
  • Experience driving remediation across engineering and platform teams.
  • Scripting or automation experience (Python/Bash) to support scale.

Responsabilidades

  • Lead triage, risk assessment, and response decisions across CNAPP capabilities.
  • Assess cloud findings in context and prioritize remediation by risk.
  • Use attack path analysis to identify critical exposure paths.
  • Monitor vulnerability exposure across cloud workloads and prioritize fixes.
  • Translate complex issues into actionable remediation guidance for varied teams.
  • Embed guardrails into CI/CD and IaC controls to reduce misconfigurations.
  • Build automation, detection logic, runbooks, and CNAPP policy inputs.
  • Collaborate with cloud engineers, security architects, and DevSecOps teams.

Conhecimentos

CNAPP security
Cloud security operations
Threat assessment & risk modeling
Automation & scripting (Python/Bash/AP

Formação académica

Bachelor's degree in Computer Science or related field

Ferramentas

AWS
Azure
Google Cloud
CI/CD security tooling

Descrição da oferta de emprego

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.

What You'll Do

You will join BCG’s Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. In this role, you will help protect BCG’s global multi-cloud environment by leading cloud security posture operations, translating complex findings into clear risk narratives, and driving risk-based remediation at scale.

You will serve as a technical authority across cloud security operations, working across AWS, Azure, and Google Cloud. You will look beyond scanner severity to understand exploitability, attack paths, blast radius, and business impact, helping teams fix the right issues in the right order.

  • Lead triage, risk assessment, and response decisions across CNAPP capabilities, including CSPM, CIEM, KSPM, CWPP, IaC security, secrets detection, SCA/SBOM, API security posture, and external attack surface management.
  • Assess cloud security findings in context, evaluating attack path reachability, lateral movement potential, effective permissions, and downstream impact on critical assets.
  • Use graph-based attack path analysis to identify toxic combinations and distinguish critical exposure paths from high-noise, low-impact misconfigurations.
  • Monitor zero-day and critical vulnerability exposure across cloud workloads, defining affected asset scope and prioritizing remediation based on risk.
  • Evaluate AI and LLM security risks such as exposed inference endpoints, overly permissive model access, insecure secrets handling, vector store exposure, unsafe plugin or tool integrations, and LLMOps pipeline weaknesses.
  • Drive remediation from finding identification through confirmed closure, partnering with developers, cloud architects, security architects, and platform engineering teams.
  • Translate complex technical issues into precise, actionable remediation guidance for different engineering and security audiences.
  • Strengthen shift-left security by embedding guardrails into CI/CD pipelines, improving infrastructure-as-code controls, and reducing recurring misconfigurations at source.
  • Build and improve automation, detection logic, saved queries, runbooks, and CNAPP policy inputs to reduce manual effort and improve signal quality.
What You'll Bring
  • 6-8 years in information security, with at least 6 years focused on cloud security operations or cloud infrastructure security.
  • Hands‑on CNAPP experience across triage, posture reporting, and policy tuning.
  • Deep knowledge of AWS, Azure, or Google Cloud security controls.
  • Practical understanding of AI workload security, LLMOps pipelines, or inference endpoint risk.
  • Strong discernment across exploitability, blast radius, permissions, attack paths, and data exposure.
  • Experience driving remediation across engineering, platform, architecture, or AI enablement teams.
  • Python, Bash, or API integration experience supporting automation and operational scale.
Who You'll Work With

You will be part of BCG’s Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. You will work closely with cloud engineering, platform engineering, security architecture, threat intelligence, and DevSecOps teams to identify, prioritize, and reduce cloud security risk across BCG’s global technology environment. The team operates in a highly collaborative, technically rigorous setting, with a shared focus on clear risk ownership, practical remediation, and continuous improvement.

Additional Info

Preferred certifications are helpful but not required, including AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, or Certified Kubernetes Security Specialist.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E-Verify Employer. Click here for more information on E-Verify.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Cloud Security Ops Lead | CNAPP & Attack Surface
Cloud Security Ops Lead | CNAPP & Attack Surface

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 90 000 - 140 000
Global Cybersecurity Senior Specialist - Program Operations
Global Cybersecurity Senior Specialist - Program Operations

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 120 000
Global Cybersecurity Analyst - Security Engineer
Global Cybersecurity Analyst - Security Engineer

Boston Consulting Group • Portugal

Presencial
EUR 60 000 - 100 000
Senior Cyber Incident Manager
Senior Cyber Incident Manager

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 70 000 - 110 000
Global Cybersecurity Analyst - Security Engineer
Global Cybersecurity Analyst - Security Engineer

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 60 000 - 90 000
Global Cybersecurity Manager - Governance and Compliance
Global Cybersecurity Manager - Governance and Compliance

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 90 000 - 120 000
Global Cybersecurity Analyst - Security Engineer
Global Cybersecurity Analyst - Security Engineer

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 70 000 - 110 000
Global Cybersecurity Director - Architecture
Global Cybersecurity Director - Architecture

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 120 000 - 180 000
Global Cybersecurity Director - Architecture
Global Cybersecurity Director - Architecture

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 110 000 - 150 000
Global Cybersecurity Manager - Governance and Compliance
Global Cybersecurity Manager - Governance and Compliance

Boston Consulting Group • Portugal

Presencial
EUR 70 000 - 100 000