img
Contract

Global Platform Team Lead and Senior Director - IT Security

London
money-bag Negotiable
F425CB814F6C3A2F061303161D0A229D
Posted 2 days ago

OverviewGlobal Platform Team Lead and Senior Director - IT Security is responsible for leading the design, delivery, and continuous evolution of BCG''s security platforms across identity, device, and data protection domains. This role ensures end-to-end security engineering across all technology environments, including cloud, on-prem, and hybrid systems. The leader will drive strategic planning, execution, and operations of scalable, automated, and resilient security controls that protect BCG’s global operations and users, while enabling innovation and agility across BCG Core, BCG X, and CT worldwide. This role is also accountable for embedding security within DevSecOps practices, enforcing automation at scale, and applying Site Reliability Engineering (SRE) principles across all security services. The role requires strong partnership with ISRM, focusing on balancing security requirements, automation opportunities, user experience needs, and broader business outcomes.

What You''ll Do

Strategic Leadership and Transformation:

Define and execute a unified security engineering strategy that addresses identity, endpoint, and data protection across all environments.

Lead the design and implementation of scalable, automated security solutions that integrate seamlessly into enterprise platforms and user experiences.

Establish a global security architecture and engineering roadmap focused on prevention, detection, and rapid response.

Drive continuous improvement of security posture while aligning with business needs, regulatory requirements, and user experience expectations.

Champion DevSecOps practices to embed security early into development and delivery workflows.

Security Platform Engineering:

Lead end-to-end engineering for identity and access management (IAM), including authentication, authorization, and privileged access controls.

Oversee endpoint security architecture and enforcement, ensuring comprehensive coverage for threat detection, malware prevention, and device compliance.

Build and operate scalable data protection solutions, including data loss prevention (DLP), secrets management, encryption, and classification.

Integrate security controls into CI/CD pipelines, cloud-native services, and on-prem platforms to enforce security-by-design principles.

Deliver security capabilities that support modern work scenarios, remote access, zero-trust networking, and AI/ML workloads.

Leverage automation frameworks and IaC to improve scalability and reduce manual intervention.

Operational Security, SRE and Assurance:

Ensure security platforms are resilient, continuously monitored, and designed for 24x7 support and incident response readiness.

Embed security telemetry and observability to enable proactive threat detection and automated response.

Apply SRE principles to improve reliability, performance, and maintainability of security services.

Lead platform health, patching automation, and vulnerability remediation workflows.

Define service level objectives (SLOs) and key performance indicators (KPIs) for all security services.

Compliance, Governance and Risk Management:

Ensure alignment with global compliance requirements such as ISO 27001, NIST, SOC 2, GDPR, and others.

Partner with governance, legal, and ISRM teams to implement enforceable policies and standards across identity, endpoint, and data domains.

Operationalize policy enforcement through automated controls and continuous compliance checks.

Lead risk mitigation efforts with technical solutions that scale across diverse user and system profiles.

Financial and Vendor Management:

Manage security platform budgets and investments with a focus on cost optimization and long-term value.

Evaluate and manage third-party vendors and partners, ensuring they meet technical, contractual, and security expectations.

Lead procurement and renewal cycles in alignment with operational and architectural strategies.

Leadership and Talent Development:

Build and mentor a global team of security engineers, fostering a high-performance, collaborative, and forward-thinking culture.

Drive internal knowledge sharing and upskilling programs across security architecture, automation, and secure software engineering.

Collaborate cross-functionally with platform, product, and enterprise architecture teams to embed security early and often.

Required Qualifications

10+ years of experience in cybersecurity, security engineering, or platform security roles.

5+ years in a senior leadership position with accountability for enterprise-scale security platforms.

Deep expertise in IAM, endpoint security, and data protection technologies, with proven ability to design and scale global solutions.

Experience with security engineering in hybrid and cloud-native environments (AWS, Azure, GCP).

Proven track record in automating security controls, implementing zero-trust models, and supporting 24x7 security operations.

Strong understanding of compliance frameworks and risk management strategies.

Preferred Qualifications

Certifications such as CISSP, CCSP, CISM, AWS/Azure Security Specialty, or equivalent.

Experience with tools like Okta, Azure AD, CrowdStrike, Tanium, Zscaler, Vault, and other modern security platforms.

Familiarity with DevSecOps principles, Infrastructure as Code, and secure software development practices.

Work Environment and Additional Information

Hybrid or on-site work model.

Occasional travel may be required for business, vendor, or team engagement.

Ability to operate in a fast-paced, complex environment, balancing long-term strategy with operational agility.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable.

Seniority level

Director

Employment type

Full-time

Job function

Information Technology

Industries

Business Consulting and Services

#J-18808-Ljbffr

Other jobs of interest...

Boston Consulting Group (BCG)
London
money-bagNegotiable
The Boston Consulting Group GmbH
London
money-bagNegotiable
TieTalent
London
money-bag£50,000-55,000 per annum
Group M Worldwide Inc.
London
money-bagNegotiable
Boston Consulting Group
LondonYesterday
money-bag10000-500000 Annual
Boston Consulting Group
LondonYesterday
money-bag10000-500000 Annual

Perform a fresh search...

  • Create your ideal job search criteria by
    completing our quick and simple form and
    receive daily job alerts tailored to you!

Jobs. Straight to your inbox!