Jobs · Finance · Massachusetts

Global Cybersecurity Director - Risk & Compliance

Boston Consulting Group (BCG) · Boston, MA · 1 mo ago
Finance$176k/yrFull-time

What You'll Do

BCG Federal operates within a federally regulated environment supporting consulting, cloud, software, data, and emerging AI technology capabilities. The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance, certification readiness, and control maturity agenda across all BCG Federal offerings. The Director leads enterprise readiness and audit defense across key federal frameworks; including CMMC Level 2, NIST SP 800-171/53, FedRAMP and DFARS. Working closely with Security Architecture, the Director translates complex regulatory requirements into policy and control objectives, establishing the governance framework while Architecture designs the technical controls and secure cloud baselines. Furthermore, this role pioneers Federal AI Governance, establishing guardrails, risk assessment protocols, and approval pathways for Generative AI and machine learning tools deployed across federal boundaries.

You're Good At

  • Leading complex federal cybersecurity and compliance programs by combining technical GRC expertise, executive communication, organizational change management, and trusted stakeholder relationships.

Your Duties Will Include

  • Lead the Federal GRC pillar strategy, roadmap, operating model, governance rhythm, reporting structure, and control maturity agenda across BCG Federal.
  • Direct enterprise compliance initiatives supporting DFARS, CMMC Level 2, NIST 800-171/, FedRAMP, AI governance, cloud security, and related federal cybersecurity requirements.
  • Partner closely with Security Architecture to align policies with technical engineering; defining what control outcomes are required while Architecture designs how technical controls and baselines are configured.
  • Own organizational readiness for federal assessments and certifications, including assessment scoping, SSP development, evidence preparation, stakeholder preparation, audit defense, C3PAO engagement, and executive reporting.
  • Establish and mature Federal AI Governance, including risk methodologies, safety frameworks (e.g., NIST AI RMF), boundary protections, and approval pathways for secure adoption of Generative AI and LLMs.
  • Own the federal risk register governance model, including risk identification, severity assessment, mitigation planning, exception management, escalation, and reporting.
  • Lead cybersecurity review of federal contracts, RFPs, client opportunities, software approvals, cloud service reviews, and third-party vendor risk management to support secure technology adoption.
  • Lead organizational change management for federal cybersecurity and compliance initiatives, including stakeholder alignment, communications, training, readiness tracking, and sustainment of new governance processes.
  • Oversee continuous monitoring (CONMON) governance, evidence traceability, recurring review cadences, POA&M tracking, and management reporting.
  • Define and deliver executive-level metrics, dashboards, QBR content, risk reporting, compliance status updates, and decision-ready materials for leadership.
  • Lead, mentor, onboard, and develop GRC personnel while improving team operating rhythms, accountability, prioritization, and delivery quality.

What You'll Bring

  • 10+ years of experience in cybersecurity, information security, GRC, audit, compliance, risk management, or technology governance environments.
  • Demonstrated experience leading federal cybersecurity compliance programs (preferably supporting CMMC Level 2, NIST 800-171/53, FedRAMP) in consulting, cloud, SaaS, or federal contracting environments.
  • Direct experience leading or materially supporting external assessments, regulatory inquiries, audit readiness efforts, C3PAO assessments, evidence preparation, and audit defense.
  • Proven track record establishing AI Security Governance, evaluating machine learning/GenAI security risks, and applying federal AI risk management frameworks.
  • Proven ability to partner with Security Architecture, DevSecOps, and IT engineering teams to translate complex legal and federal requirements into practical operating baselines.
  • Strong organizational change management experience, including leading cross-functional process adoption, stakeholder readiness, communications, training, and sustainment of new operating models.
  • Excellent written and verbal communication skills, including experience developing executive briefings, policies, audit materials, and management-level reporting.
  • Ability to obtain and maintain a U.S. Government Secret Clearance where required.

Pay & Benefits

Base Salary Range: $176,000 – $199,830 (varies by US region; specific range for preferred location available during hiring process).

Total Compensation: Includes base salary, annual discretionary performance bonus (up to 30%), and retirement contribution (starts at 5%, moves to 10% after 2 years).

Benefits include:

  • $0 health insurance premiums for employees, spouses, and children
  • Low $10 copays for doctor visits, urgent care, and generic prescriptions
  • Dental coverage (up to $5,000 in orthodontia benefits)
  • Vision insurance (glasses and contact lenses annually)
  • Reimbursement for gym memberships and fitness activities
  • Fully vested Profit Sharing Retirement Fund contributions (whether or not you contribute) plus 401(k) option
  • Paid Parental Leave and family benefits (elective egg freezing, surrogacy, adoption reimbursement)
  • Generous paid time off: 12 holidays per year, annual office closure between Christmas and New Year’s, 15 vacation days per year (earned at 1.25 days/month)
  • Paid sick time on an as-needed basis
This response is AI-generated, for reference only.

Similar jobs