Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Boston Consulting Group’s Security Operations team within Information Security and Risk Management seeks an experienced security professional to join the Attack Surface Management effort in Atlanta. You will monitor cloud and AI workload exposure, triage CNAPP findings, and translate risks into actionable guidance for engineers and platform teams.
This role emphasizes collaboration with cloud and platform engineering, security architecture, and DevSecOps.
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation‑inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom‑line impact.
You will join BCG’s Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. In this role, you will help protect BCG’s global multi‑cloud environment by monitoring and triaging cloud security findings, applying contextual risk reasoning, and supporting remediation across AWS, Azure, and Google Cloud.
You will also support BCG’s growing AI security coverage by helping identify exposure across AI and LLM workloads, cloud services that support AI‑enabled applications, and emerging AI‑adjacent attack paths. You will work with more senior team members to interpret risk, escape priority issues, and provide clear, actionable guidance to engineering and platform teams.
You will be part of BCG’s Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. You will work closely with cloud engineering, platform engineering, security architecture, threat intelligence, and DevSecOps teams to identify, prioritize, and reduce cloud security risk across BCG’s global technology environment. The team operates in a highly collaborative, technically rigorous setting, with a shared focus on clear risk ownership, practical remediation, and continuous improvement.
Preferred certifications are helpful but not required, including AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, or Certified Kubernetes Security Specialist.
Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E - Verify Employer. Click here for more information on E-Verify.