Cybersecurity Analyst

Boston Consulting Group (BCG)

Atlanta (GA)

On-site

USD 77,000 - 90,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Boston Consulting Group’s Security Operations team within Information Security and Risk Management seeks an experienced security professional to join the Attack Surface Management effort in Atlanta. You will monitor cloud and AI workload exposure, triage CNAPP findings, and translate risks into actionable guidance for engineers and platform teams.

This role emphasizes collaboration with cloud and platform engineering, security architecture, and DevSecOps.

Qualifications

  • 2–4 years in information security, including 2+ years in cloud security operations.
  • Hands-on experience triaging findings in CNAPP or cloud security platforms.
  • Working knowledge of AWS, Azure, or Google Cloud security fundamentals.
  • Ability to assess exploitability, permissions, data exposure, and attack path context.
  • Basic awareness of AI workload risks, including model access and inference endpoint exposure.
  • Clear written communication for developer-facing findings, remediation steps, and escalation notes.
  • Python, Bash, or API experience for triage automation and finding enrichment.

Responsibilities

  • Monitor, triage, and investigate findings across CNAPP capabilities, including cloud security and AI workload exposure.
  • Apply contextual risk reasoning to cloud and AI-adjacent findings, considering exploitability and attack path context.
  • Help identify toxic combinations across cloud, identity, workload, API, and AI service configurations.
  • Investigate zero‑day and critical vulnerability exposure across cloud workloads, containerized services, and data stores.
  • Monitor AI and LLM workload risks such as exposed inference endpoints and model access.
  • Translate findings into developer-facing remediation guidance and track open items.
  • Review IaC and CI/CD findings to support guardrail adoption and reduce misconfigurations.
  • Write scripts, update runbooks, and improve CNAPP signal quality.

Skills

Cloud security operations
CNAPP triage
AWS/Azure/GCP
Exploitability assessment
AI workload risk
Technical communication
Automation scripting

Tools

Python
Bash
APIs

Job description

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation‑inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom‑line impact.

What You'll Do

You will join BCG’s Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. In this role, you will help protect BCG’s global multi‑cloud environment by monitoring and triaging cloud security findings, applying contextual risk reasoning, and supporting remediation across AWS, Azure, and Google Cloud.

You will also support BCG’s growing AI security coverage by helping identify exposure across AI and LLM workloads, cloud services that support AI‑enabled applications, and emerging AI‑adjacent attack paths. You will work with more senior team members to interpret risk, escape priority issues, and provide clear, actionable guidance to engineering and platform teams.

You Will
  • Monitor, triage, and investigate findings across CNAPP capabilities, including CSPM, CIEM, KSPM, CWPP, IaC security, secrets detection, SCA/SBOM, API security posture, external attack surface management, and AI workload exposure.
  • Apply contextual risk reasoning to cloud and AI‑adjacent findings, considering exploitability, attack path reachability, effective permissions, data exposure, model access, and potential blast radius.
  • Help identify toxic combinations across cloud, identity, workload, API, and AI service configurations that may create meaningful exposure when chained together.
  • Investigate zero‑day and critical vulnerability exposure across cloud workloads, containerized services, inference endpoints, orchestration layers, and supporting data stores.
  • Monitor AI and LLM workload risks such as exposed inference endpoints, overly permissive model access, unsafe secrets handling, vector store exposure, and LLMOps pipeline misconfigurations.
  • Support remediation by translating findings into clear, developer‑actionable guidance, tracking open items, following up with asset owners, and escalating aged or blocked issues with clear risk context.
  • Contribute to shift‑left security by reviewing IaC and CI/CD findings, supporting security guardrail adoption, and helping reduce recurring cloud and AI workload misconfigurations.
  • Write scripts, improve saved queries, update runbooks, and contribute observations that improve CNAPP signal quality, automation, and operational consistency.
What You'll Bring
  • 2–4 years in information security, including 2+ years in cloud security operations.
  • Hands‑on experience triaging findings in CNAPP or cloud security platforms.
  • Working knowledge of AWS, Azure, or Google Cloud security fundamentals.
  • Ability to assess exploitability, permissions, data exposure, and attack path context.
  • Basic awareness of AI workload risks, including model access and inference endpoint exposure.
  • Clear written communication for developer‑facing findings, remediation steps, and escalation notes.
  • Python, Bash, or API experience for triage automation and finding enrichment.
Who You'll Work With

You will be part of BCG’s Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. You will work closely with cloud engineering, platform engineering, security architecture, threat intelligence, and DevSecOps teams to identify, prioritize, and reduce cloud security risk across BCG’s global technology environment. The team operates in a highly collaborative, technically rigorous setting, with a shared focus on clear risk ownership, practical remediation, and continuous improvement.

Additional Info

Preferred certifications are helpful but not required, including AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, or Certified Kubernetes Security Specialist.

Compensation
  • The base salary range for this role in Atlanta is $77,000-$90,000.
  • Base salary, annual discretionary performance bonus, retirement contribution, and a market leading benefits package described below.
  • In addition to your base salary, your total compensation will include a bonus of up to 12% and a generous retirement contribution that starts at 5% and moves to 10% after 2 years.
All Of Our Plans Provide Best In Class Coverage
  • Zero dollar ($0) health insurance premiums for BCG employees, spouses, and children.
  • Low $10 (USD) copays for trips to the doctor, urgent care visits and prescriptions for generic drugs.
  • Dental coverage, including up to $5,000 in orthodontia benefits.
  • Vision insurance with coverage for both glasses and contact lenses annually.
  • Reimbursement for gym memberships and other fitness activities.
  • Fully vested Profit Sharing Retirement Fund contributions made annually, whether you contribute or not, plus the option for employees to make personal contributions to a 401(k) plan.
  • Paid Parental Leave and other family benefits such as elective egg freezing, surrogacy, and adoption reimbursement.
  • Generous paid time off including 12 holidays per year, an annual office closure between Christmas and New Years, and 15 vacation days per year (earned at 1.25 days per month).
  • Paid sick time on an as needed basis.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.

BCG is an E - Verify Employer. Click here for more information on E-Verify.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst
Cybersecurity Analyst

The Boston Consulting Group GmbH • Atlanta (GA)

On-site
USD 77,000 - 90,000
Health insurance
401(k) plan
Paid time off
+2
Attack Surface Security Analyst: Cloud & AI
Attack Surface Security Analyst: Cloud & AI

Boston Consulting Group (BCG) • Atlanta (GA)

On-site
USD 77,000 - 90,000
Global Cybersecurity Senior Manager
Global Cybersecurity Senior Manager

Boston Consulting Group (BCG) • Atlanta (GA)

On-site
USD 144,000 - 176,000
Bonus program
Retirement plan
Comprehensive benefits
+1
BCG Platinion | Senior AI Tech Consultant, Cybersecurity
BCG Platinion | Senior AI Tech Consultant, Cybersecurity

Boston Consulting Group • New York (NY)

On-site
USD 150,000
Zero-dollar health premiums
Fully vested retirement contributions
Global Cybersecurity Director - Risk & Compliance
Global Cybersecurity Director - Risk & Compliance

Boston Consulting Group (BCG) • Boston (MA)

On-site
USD 176,000 - 200,000
Zero dollar health insurance
Low $10 copays
Dental coverage
+6
Global Cybersecurity Director - Risk & Compliance
Global Cybersecurity Director - Risk & Compliance

Boston Consulting Group (BCG) • Washington

On-site
USD 176,000 - 200,000
Health insurance
Dental coverage
Paid parental leave
BCG Platinion | Manager, Cybersecurity
BCG Platinion | Manager, Cybersecurity

Boston Consulting Group (BCG) • Washington

On-site
USD 180,000 - 210,000
Comprehensive benefits
Profit sharing
Discretionary bonus eligibility
BCG Platinion | Manager, Cybersecurity
BCG Platinion | Manager, Cybersecurity

Boston Consulting Group • New York (NY)

On-site
USD 161,000 - 219,000
Health insurance
Parental leave
Retirement contributions
BCG Platinion | Manager, Cybersecurity
BCG Platinion | Manager, Cybersecurity

Boston Consulting Group (BCG) • Austin (TX)

On-site
USD 171,000 - 209,000
Zero dollar health insurance premiums
Generous paid time off
Paid Parental Leave
+1
BCG Platinion | Manager, Cybersecurity
BCG Platinion | Manager, Cybersecurity

Boston Consulting Group (BCG) • Chicago (IL)

On-site
USD 171,000 - 209,000
Zero dollar health insurance premiums
Generous paid time off
Paid Parental Leave