Global Cybersecurity Analyst- Cloud Security

Boston Consulting Group (BCG)

Lisboa

Presencial

EUR 50 000 - 75 000

Tempo integral

há 38 horas
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Destaca-te para esta função — cria um currículo personalizado e uma carta de apresentação em cerca de um minuto.

Ultrapassa os filtros ATS

Resumo da oferta

Boston Consulting Group (BCG) is seeking a security operations professional to protect our global multi-cloud environment. You will monitor, triage, and investigate CNAPP and cloud security findings, and provide developer-facing guidance to remediate issues across AWS, Azure, and Google Cloud.

You will also assess AI-related exposure and collaborate with cloud and platform teams to reduce risk. You will work with security, cloud engineering, and DevSecOps teams to elevate priorities and ensure

Qualificações

  • 2-4 years in information security, including cloud security operations.
  • Hands-on experience triaging findings in CNAPP or cloud security platforms.
  • Working knowledge of AWS, Azure, or Google Cloud security fundamentals.
  • Ability to assess exploitability, permissions, data exposure, and attack path context.

Responsabilidades

  • Monitor and triage findings across CNAPP capabilities and cloud security tooling.
  • Apply contextual risk reasoning to cloud and AI-adjacent findings.
  • Identify toxic configurations that raise exposure when chained.
  • Translate findings into actionable guidance for developers and engineers.
  • Support shift-left security by reviewing IaC and CI/CD findings.

Conhecimentos

CNAPP
Cloud security
Python scripting
Triage findings

Ferramentas

AWS
Azure
GCP

Descrição da oferta de emprego

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.

What You'll Do

You will join BCG's Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. In this role, you will help protect BCG's global multi-cloud environment by monitoring and triaging cloud security findings, applying contextual risk reasoning, and supporting remediation across AWS, Azure, and Google Cloud.

You will also support BCG's growing AI security coverage by helping identify exposure across AI and LLM workloads, cloud services that support AI-enabled applications, and emerging AI-adjacent attack paths. You will work with more senior team members to interpret risk, elevate priority issues, and provide clear, actionable guidance to engineering and platform teams.

You Will
  • Monitor, triage, and investigate findings across CNAPP capabilities, including CSPM, CIEM, KSPM, CWPP, IaC security, secrets detection, SCA/SBOM, API security posture, external attack surface management, and AI workload exposure.
  • Apply contextual risk reasoning to cloud and AI-adjacent findings, considering exploitability, attack path reachability, effective permissions, data exposure, model access, and potential blast radius.
  • Help identify toxic combinations across cloud, identity, workload, API, and AI service configurations that may create meaningful exposure when chained together.
  • Investigate zero-day and critical vulnerability exposure across cloud workloads, containerized services, inference endpoints, orchestration layers, and supporting data stores.
  • Monitor AI and LLM workload risks such as exposed inference endpoints, overly permissive model access, unsafe secrets handling, vector store exposure, and LLMOps pipeline misconfigurations.
  • Support remediation by translating findings into clear, developer-actionable guidance, tracking open items, following up with asset owners, and escalating aged or blocked issues with clear risk context.
  • Contribute to shift-left security by reviewing IaC and CI/CD findings, supporting security guardrail adoption, and helping reduce recurring cloud and AI workload misconfigurations.
  • Write scripts, improve saved queries, update runbooks, and contribute observations that improve CNAPP signal quality, automation, and operational consistency.
What You'll Bring
  • 2-4 years in information security, including 2+ years in cloud security operations.
  • Hands-on experience triaging findings in CNAPP or cloud security platforms.
  • Working knowledge of AWS, Azure, or Google Cloud security fundamentals.
  • Ability to assess exploitability, permissions, data exposure, and attack path context.
  • Basic awareness of AI workload risks, including model access and inference endpoint exposure.
  • Clear written communication for developer-facing findings, remediation steps, and escalation notes.
  • Python, Bash, or API experience for triage automation and finding enrichment.
Who You'll Work With

You will be part of BCG's Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. You will work closely with cloud engineering, platform engineering, security architecture, threat intelligence, and DevSecOps teams to identify, prioritize, and reduce cloud security risk across BCG's global technology environment. The team operates in a highly collaborative, technically rigorous setting, with a shared focus on clear risk ownership, practical remediation, and continuous improvement.

Additional info

Preferred certifications are helpful but not required, including AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, or Certified Kubernetes Security Specialist.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.

BCG is an E- Verify Employer.

Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Cybersecurity Manager
Cybersecurity Manager

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 90 000 - 140 000
Cybersecurity Manager
Cybersecurity Manager

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 130 000
Cloud Security Operations Lead — Attack Surface
Cloud Security Operations Lead — Attack Surface

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 130 000
Cloud Security Operations Lead — Attack Surface
Cloud Security Operations Lead — Attack Surface

Boston Consulting Group • Lisboa

Presencial
EUR 90 000 - 140 000
Cloud Security & AI Risk Analyst
Cloud Security & AI Risk Analyst

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 50 000 - 75 000
Cloud Security Ops Lead | CNAPP & Attack Surface
Cloud Security Ops Lead | CNAPP & Attack Surface

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 90 000 - 140 000
Cloud Security Ops Lead - Attack Surface Mastery
Cloud Security Ops Lead - Attack Surface Mastery

Boston Consulting Group • Lisboa

Presencial
EUR 90 000 - 140 000
Cybersecurity Manager - AI Architecture
Cybersecurity Manager - AI Architecture

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 70 000 - 90 000
Global Cybersecurity Senior Specialist - Program Operations
Global Cybersecurity Senior Specialist - Program Operations

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 120 000
Global Cybersecurity Manager - Governance and Compliance
Global Cybersecurity Manager - Governance and Compliance

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 140 000