Global Cybersecurity Director - Architecture
Boston Consulting Group (BCG)
Job Description
What You'll Do
As the Infrastructure Security Architecture Lead, you will own the security architecture, standards, and Zero Trust direction for BCGâs core infrastructure across the identity, network, device, and data pillars, lineâmanage and grow the team of architects aligned to each pillar, and be accountable for the coherence, quality, and maturity of the architecture that protects the firmâs global infrastructure.
Key Responsibilities
- Lineâmanage, develop, and grow the architects aligned to the Secure Identity, Secure Network, Secure Device, and Secure Data pillars; set objectives, manage performance, and build the team out to full coverage.
- Establish consistent ways of working and quality bars so the domain operates as a coherent function, and act as mentor and escalation point for complex design decisions.
- Balance architectural capacity across pillars toward the highestârisk and highestâpriority initiatives.
- Own the security architecture strategy, reference architectures, and targetâstate roadmap across the identity, network, device, and data pillars, advancing ZTMM maturity aligned to NIST SP 800â207 and the CISA Zero Trust Maturity Model.
- Ensure architectural coherence across pillars, resolving crossâcutting dependencies (identity lifecycle propagation, certificate lifecycle, entitlement governance) rather than allowing point solutions to harden into enterprise patterns.
- Set the direction for strategic target architectures per control family, socialized with Enterprise Architecture and traceable to enterprise strategic targets.
- Lead the creation and maintenance of controlâfamily standards in alignment with Security Governance, Risk, and Compliance (SGRC), socializing standards with configuration item owners for viability before enforcement and agreeing control disposition with SGRC and SAVE.
- Own security architecture reviews and exception dispositions for the domain, ensuring decisions are consistent, defensible, and traceable to ISRM governance.
- Represent Infrastructure Security Architecture in enterprise governance forums (Change Advisory Boards, Design Authorities) and advocate for riskâbased prioritization across the Security Portfolio.
- Maintain and leverage the teamâs AIâassisted tooling for standards development and controlâalignment review, with appropriate human oversight.
- Serve as the architecture counterpart to the infrastructure engineering squads: validate feasibility and effectiveness of controls through implementation without assuming delivery ownership, and hold engineering accountable for meeting SecArch requirements.
- Reinforce the ISRM operating model: Security Architecture designs and governs; Security Operations owns monitoring, SIEM, and detection; assurance and audit sit with SAVE and SGRC. Specify the telemetry requirements needed for the domainâs services to be observable.
Youâre Good At
- Building and developing a highâperforming architecture team, and growing a function from a small base into full coverage.
- Building consensus while maintaining architectural integrity across complex, crossâdomain technology initiatives.
- Making defensible architectural decisions under ambiguity and time pressure, and making them stick.
- Influencing senior stakeholders across engineering, Enterprise Architecture, and security leadership in a matrixed global organization.
- Translating enterprise security strategy into practical standards and implementable engineering requirements.
What You'll Bring
- Bachelorâs degree in a relevant field or equivalent practical experience.
- 10+ years in security architecture, security engineering, or infrastructure security, including demonstrated architecture responsibility across more than one infrastructure domain.
- Prior peopleâmanagement or teamâlead experience, or clear readiness to take on line management of a technical team.
- Experience operating in large, auditâsensitive, or regulated enterprise environments with formal governance and exception processes.
- Strong understanding of Zero Trust architecture (NIST SP 800â207, CISA ZTMM), enterprise control frameworks, and hybrid cloud environments (Azure, AWS, GCP).
- Breadth across at least two of the infrastructure pillars (identity, network, device, data), with the ability to lead architects who hold deeper specialization in each.
- Command of the governance and lifecycle disciplines that cut across pillars: identity lifecycle management, certificate and key lifecycle, and entitlement governance.
- Experience applying AIâassisted tools to security architecture work, with a clear understanding of LLM capabilities, limitations, and the need for human oversight.
Preferred Qualifications
- Experience standing up or scaling a security architecture function or team.
- Handsâon architecture background in one or more of: enterprise identity (Entra ID, Okta, PAM), network security (SSE, ZTNA, segmentation), endpoint/device security, or data protection.
- Professional certifications such as CISSP, SABSA, TOGAF, or relevant cloud security certifications.
Who You'll Work With
You will lead the Infrastructure Security Architecture team within Information Security Risk Management (ISRM), managing the architects aligned to each infrastructure pillar and reporting to the Senior Director of Cybersecurity Architecture. You will own the security strategy, architectural standards, and governance that guide the design and evolution of BCGâs core infrastructure platforms across identity, network, device, and data. You will collaborate closely with engineering, cloud, identity, infrastructure, and security teams across BCGâs global technology organization to ensure security controls are consistently designed, implemented, and governed across the infrastructure domain.
You will partner with Enterprise Architecture, Security Operations, Risk Management, and architecture peers to strengthen Zero Trust capabilities, advance security maturity, and support enterpriseâwide cybersecurity initiatives.
Additional Info
Regular, FullâTime (local employment terms apply).
Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an EâVerify Employer.
#J-18808-Ljbffr