Global Cybersecurity Director – Architecture (bcg Federal)

BCG BCG · Consulting · Boston, MA +3 · Technology and Engineering

This role focuses on cybersecurity architecture and governance within a US federally compliant environment. The Director will lead the technical core of the cybersecurity program, integrating advanced architecture, technical risk management, and regulatory compliance. Key responsibilities include designing and validating technical security systems, managing technical risk profiles, setting cloud hardening standards, and establishing security guardrails for emerging AI capabilities. The role also involves overseeing secure DevSecOps and SDLC practices, and providing expert technical security advisory.

What you'd actually do

  1. Pillar Leadership & Strategy: Lead the GRC and technical architecture perspective of the BCG Federal Cybersecurity program, driving strategic alignment between business goals and deep technical security controls
  2. Technical Framework Interpretation: Interpret complex regulatory, federal, and contractual compliance mandates into precise, actionable technical architectures and engineering designs for application, network, and cloud environments
  3. Enterprise Risk Management: Manage the enterprise security risk register for technical risks. Review, approve, and document sophisticated technical security exceptions and alternative compensating controls to enable business continuity while protecting BCG Federal assets.
  4. Cloud & Platform Hardening: Oversee and approve the design, implementation, and security configuration of Azure Government Community Cloud (GCC) High and AWS Gov environments
  5. AI & Emerging Tech Security: Lead the technical security assessment, architectural standards, and threat modeling of Artificial Intelligence (AI) and Generative AI (GenAI) capabilities, developing robust mitigation strategies to safeguard federal and corporate data across compliant cloud and enterprise environments

Skills

Required

  • Minimum of 8–10+ years of information security experience, with a proven track record of leading technical architecture, cloud native security engineering, and technical GRC initiatives
  • Subject matter expertise in federal security compliance frameworks, specifically NIST SP 800-171, NIST SP 800-53, CMMC, and DFARS 7012
  • In-depth engineering familiarity with secure CI/CD pipelines, automated scanning configurations (SAST/DAST), threat modeling, and Azure/AWS cloud infrastructures
  • Ability to obtain and maintain a US Government Secret Clearance

Nice to have

  • Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), or equivalent industry credentials

What the JD emphasized

  • strict compliance with US Government security requirements (including NIST SP 800-171, NIST SP 800-53, FedRAMP, and CMMC)
  • Subject matter expertise in federal security compliance frameworks, specifically NIST SP 800-171, NIST SP 800-53, CMMC, and DFARS 7012