The BCG Federal Organization is seeking a skilled and proactive Enterprise Security Service Director to oversee and manage comprehensive security operations that safeguard the organization’s digital and physical assets. In this role, you will be responsible for directing a wide range of security measures, ensuring the robustness and resilience of our IT infrastructure in alignment with industry standards and best practices, particularly NIST 800-171 and CMMC guidelines.
As the Enterprise Security Service Director, you will lead critical functions including vulnerability management, penetration testing, and business continuity planning. You will oversee Data Loss Prevention (DLP) strategies and encryption practices to secure sensitive data. Additionally, you will develop and enforce data classification policies, ensure the effective management of the data lifecycle, and lead our compliance and governance efforts. Your leadership will be instrumental in ensuring that all security measures are proactive, compliant, and aligned with our organizational objectives.
Your duties will include:
Vulnerability Management & Patch Governance: Direct and enhance the organization's capabilities in identifying, assessing, and mitigating vulnerabilities. Oversee the development and implementation of a systematic patch management strategy to ensure timely updates and compliance with industry standards.
Penetration Testing & Red Team Program: Lead and manage penetration testing initiatives to identify security weaknesses before they can be exploited. Additionally, supervise the red team operations designed to simulate real-world attacks to test and improve the organization's defenses.
Business Continuity & Disaster Recovery Governance: Develop and maintain policies and procedures to ensure that the organization can continue operating and quickly recover in the event of a disruption or disaster. This includes regular updates and tests of disaster recovery plans to ensure effectiveness.
Data Loss Prevention (DLP) and Encryption: Implement and manage DLP strategies to protect sensitive data from loss or unauthorized access. Additionally, oversee the encryption practices to secure data at rest, in motion, and in use.
Data Classification: Lead the development and enforcement of policies for classifying data based on sensitivity and compliance requirements to ensure that protective measures align with the potential risks.
Strong comprehensive problem-solving skills to identify and solve issues quickly
Ability to work well independently as well as part of a virtual, geographically dispersed team bringing a sense of urgency to the tasks at hand
Effectively handle difficult and stressful situations with poise, tact and patience, while demonstrating a sense of urgency
Strong analytical skills, detail-oriented, and quality-minded
Exceptional verbal and written communication and presentation skills
10+ years of experience in information security
5+ years leading cross-functional teams and managing security initiatives in complex environments.
3+ years of:
Data Classification technical capabilities and strategies
Encryption and Data Loss Prevention (DLP) experience
Experience with Business Continuity to include backup capabilities
Knowledge of security issues, trends and best practices
Experience with Microsoft Azure and O365
U.S. Citizenship required
Ability to obtain and maintain a Secret Security Clearance
BCG’s information technology group collaboratively delivers the latest digital technologies that enable our consultants to lead and our business to grow. For our IT jobs, we seek individuals with expertise in the areas of IT infrastructure, application development, business systems, collaborative and social technologies, information security, and project leadership.
BCG pioneered strategy consulting more than 50 years ago, and we continue to innovate and redefine the industry. We offer multiple career paths for the world’s best talent to have a real impact on business and society. As part of our team, you will benefit from the breadth and diversity of what we are doing today and where we are headed next. We count on your authenticity, exceptional work, and strong integrity. In return we are committed to supporting you in discovering the most fulfilling career journey possible—and unlocking your potential to advance the world. Our team called Global Services (GS) provides corporate support to business areas such as Finance, Legal, HR, Marketing and IT. This diverse team of experts, operators and specialists represent all levels from Partner to entry level staff, operating across the globe in multiple countries. Global Services is in short, the backbone of BCG.
BCG is an Equal Employment Opportunity employer and is committed to a policy of administering all employment decisions and actions without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
#LI-HYBRID