Global Cybersecurity Manager - Governance and Compliance

The Boston Consulting Group GmbH

Lisboa

Presencial

EUR 90 000 - 120 000

Tempo integral

14 dias+
Gerador de candidaturas

Uma candidatura completa num minuto — currículo e carta de apresentação personalizados, prontos a enviar.

Ultrapassa os filtros ATS

Resumo da oferta

Boston Consulting Group seeks a Global Information Security Manager to join CAS, supporting due diligence activities for strategic clients. You will work with Information Security, Legal, Risk, and client teams to communicate BCG's security posture and controls across a global client portfolio.

You will help maintain CAS tools, templates, and knowledge assets, ensuring consistent, high‑quality responses and documentation while aligning with ISO 27001, SOC 2, GDPR, and NIST frameworks.

Qualificações

  • Minimum 5–8 years of experience in information security, risk management, compliance, or related field.
  • Experience supporting client‑facing information security, assurance, audits, compliance, or advisory activities.
  • Strong understanding of information security frameworks and standards including ISO 27001, SOC 2, NIST CSF, GDPR.
  • Experience responding to client security questionnaires, due diligence requests, audits or RFPs with clear communication to non‑technical audiences.
  • Relevant certifications such as CISSP, CISM, CISA, Security+ or ISO 27001 Lead Auditor/Implementer preferred.
  • Strong communication, organization, and stakeholder management skills across global teams.
  • Prior experience in professional services, financial services, technology, or consulting preferred.
  • Fluent written and spoken English and German required.

Responsabilidades

  • Serve as a key contact for clients conducting information security assessments; respond to questionnaires, RFPs, and audit requests; explain BCG's controls and risk practices.
  • Support maintenance and improvement of CAS tools, templates, knowledge repositories, and automation initiatives.
  • Collaborate with Information Security, Legal, Risk, Compliance and client‑facing teams to ensure accurate, compliant responses.
  • Help clients understand BCG's compliance with ISO 27001, SOC 2, GDPR, NIST and translate security concepts into business‑relevant responses.
  • Support continuous improvement of CAS through knowledge management and documentation updates.
  • Maintain and enhance the CAS knowledge base, standard response library, and supporting documentation.

Conhecimentos

Information security
Risk management
Compliance
Audits & due diligence
Security standards
Communication
Stakeholder management

Formação académica

Bachelor's degree in a related field
Professional certifications (CISSP/CISM/CISA)

Descrição da oferta de emprego

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.

To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.

What You’ll Do

As a Global Information Security Manager / Global Client Assurance Services Manager within BCG's Client Assurance Services (CAS) team, you will play an important role in supporting BCG's strategic clients with their information security due diligence activities. You will work closely with Information Security, Legal, Risk, and client-facing teams to help communicate BCG's security posture, policies, and practices to clients and prospects globally.

In this role, you will contribute to the delivery of client assurance activities and support the ongoing development of CAS tools, processes, and knowledge assets that enable the team to operate effectively and consistently across BCG's client portfolio. Your key responsibilities will include:

  • Client Due Diligence Support: Serve as a key contact for clients and prospects conducting information security assessments of BCG. Respond to security questionnaires, RFPs, and audit requests; participate in client calls and workshops; and provide clear explanations of BCG's security controls, certifications, and risk management practices.
  • CAS Tool & Process Support: Support the maintenance and continuous improvement of CAS tools, templates, knowledge repositories, and automation initiatives to improve the efficiency and consistency of client assurance activities.
  • Stakeholder Collaboration: Partner closely with BCG's Information Security, Legal, Risk, Compliance, and client-facing teams to gather accurate information regarding BCG's security posture and ensure consistent and compliant responses to client inquiries.
  • Risk & Compliance Support: Support clients in understanding BCG's compliance with relevant frameworks (e.g. ISO 27001, SOC 2, GDPR, NIST) and help translate technical security concepts into business‑relevant assurance responses.
  • Quality & Continuous Improvement: Support the continuous improvement of Client Assurance Services by identifying opportunities to enhance response quality, improve operational efficiency, and strengthen knowledge management. Contribute to maintaining high‑quality documentation, templates, and best practices that enable consistent service delivery across client engagements.
  • Knowledge Management & Documentation: Maintain and enhance the CAS knowledge base, standard response library, and supporting documentation to ensure client assurance materials remain accurate, current, and easily accessible across the team.
What You’ll Bring
  • Minimum 5–8 years of experience in information security, cybersecurity, risk management, compliance, or a related field.
  • Experience supporting client‑facing information security, assurance, audit, compliance, or advisory activities.
  • Strong understanding of information security frameworks and standards including ISO 27001, SOC 2, NIST CSF, GDPR, and relevant regional data protection regulations.
  • Experience responding to client security questionnaires, due diligence requests, audits, or RFPs, with the ability to communicate technical concepts clearly to non‑technical audiences.
  • Relevant professional certifications such as CISSP, CISM, CISA, Security+, or ISO 27001 Lead Auditor/Implementer are preferred.
  • Strong communication, organization, and stakeholder management skills, with the ability to collaborate effectively across global and matrixed organizations.
  • Prior experience in a professional services, financial services, technology, or consulting environment is preferred.
  • Fluent written and spoken English and German are required.
Additional Info

BCG’s Client Assurance Services (CAS) team sits at the intersection of information security, client trust, and business development. We support BCG’s most important global client relationships by serving as the dedicated team that handles information security due diligence requests, security assessments, and assurance inquiries from current and prospective clients. As client expectations around data protection and cybersecurity continue to evolve, CAS plays a critical role in demonstrating BCG’s security maturity, building client confidence, and enabling BCG to win and retain strategic engagements. The team partners closely with Information Security, Legal, Risk, and client‑facing teams across the firm.

Some international travel may be required for client engagements.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E-Verify Employer. Click here for more information on E-Verify.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Global Cybersecurity Manager - Governance and Compliance
Global Cybersecurity Manager - Governance and Compliance

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 140 000
Global Cybersecurity Manager - Governance and Compliance
Global Cybersecurity Manager - Governance and Compliance

Boston Consulting Group • Portugal

Presencial
EUR 70 000 - 100 000
Global Information Security & Client Assurance Lead
Global Information Security & Client Assurance Lead

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 140 000
Global Information Security & Client Assurance Lead
Global Information Security & Client Assurance Lead

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 90 000 - 120 000
Global Risk Manager - Governance and Team Operations
Global Risk Manager - Governance and Team Operations

Boston Consulting Group • Portugal

Presencial
EUR 65 000 - 90 000
Global Information Security & Client Assurance Lead
Global Information Security & Client Assurance Lead

Boston Consulting Group • Portugal

Presencial
EUR 70 000 - 100 000
Global Risk Manager – Governance and Team Operations
Global Risk Manager – Governance and Team Operations

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 90 000 - 120 000
Global Risk Strategy & Operations Analyst
Global Risk Strategy & Operations Analyst

Boston Consulting Group (BCG) • Lisboa

Híbrido
EUR 35 000 - 55 000
Global Cybersecurity Director – Data Loss Prevention
Global Cybersecurity Director – Data Loss Prevention

Boston Consulting Group (BCG) • Portugal

Presencial
EUR 90 000 - 120 000
Global Risk Manager
Global Risk Manager

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 70 000 - 120 000