CybersecurityJobs.io
← Back to all jobs

Job Description

Oversee the enterprise Attack Surface Management program at BCG, translating security findings into prioritized risk decisions and measurable remediation outcomes across infrastructure, cloud, network, and identity security in collaboration with ISRM and cross-functional teams.

Responsibilities

  • Triage Attack Surface Findings Review misconfigurations and vulnerabilities surfaced across scanning platforms covering infrastructure and endpoint exposure; cloud misconfigurations and workload risk; network vulnerabilities and segmentation gaps; identity and privilege-related exposures. Leverage AI powered vulnerability assessment tools to continuously scan, correlate, and surface high priority findings across domains at scale. Classify findings by criticality and risk to inform remediation priorities.
  • Interpret and contextualise attack surface risk Determine the business impact of open findings including unpatched critical vulnerabilities, exposed assets and services, misconfigured cloud and network controls, and privilege escalation pathways. Map findings to real attack paths and regulatory requirements. Apply AI generated risk scoring and attack-path simulation to enrich contextualisation and identify non-obvious exposure chains. Translate technical results into plain-English risk narratives for stakeholders.
  • Drive remediation outcomes Recommend actions such as patch prioritisation and deployment; misconfiguration remediation; asset hardening and configuration baseline enforcement; policy or process refinement. Use AI driven prioritisation models to rank remediation actions by predicted impact, exploitability likelihood, and asset criticality. Partner with Infrastructure, Cloud, Network, Identity, and GRC teams to drive remediation to closure. Track findings through resolution and validation.
  • Build repeatable playbooks Develop playbooks for critical vulnerability triage and escalation; cloud misconfiguration remediation; network exposure management; identity and privilege related attack surface risks. Embed AI assisted triage and classification steps within playbooks to enable faster, more consistent execution across teams. Define severity thresholds and risk scoring criteria; escalation criteria and ownership assignment; SLA expectations for remediation by risk tier. Tune scanning cadence and thresholds.
  • Serve as the internal Attack Surface Management expert Be a go-to subject matter expert on Attack Surface Management for the Cybersecurity team. Help teams understand dashboards, risk trends, and exposure reports from scanning platforms, including AI generated insights and predictive risk indicators. Champion the adoption of AI led vulnerability assessment and reporting capabilities across ISRM and partner teams. Support audit and compliance inquiries with evidence-based risk documentation.

Requirements

  • Experience 8+ years in cybersecurity, with at least 3 years focused on attack surface management, vulnerability management, or exposure management.
  • Vulnerability lifecycle Strong understanding of the vulnerability lifecycle and risk-based prioritisation.
  • Configuration risks Misconfiguration risks across cloud, network, and infrastructure environments.
  • Identity exposure Identity and privilege-related attack surface exposure.
  • Hands-on tools Hands-on experience with Tenable, Wiz, and Microsoft Defender for Endpoint.
  • Communication Ability to analyse complex, multi-domain risk landscapes and communicate clearly to executive stakeholders.
  • Leadership Proven experience leading security teams and driving cross-functional remediation programmes.

Technologies

  • Tenable
  • Wiz
  • Microsoft Defender for Endpoint

Benefits

  • Zero dollar health insurance premiums for employees, spouses, and children
  • Low $10 copays for doctor visits, urgent care, and prescriptions for generic drugs
  • Dental coverage, including up to $5,000 in orthodontia benefits
  • Vision insurance covering glasses and contact lenses annually
  • Reimbursement for gym memberships and fitness activities
  • Fully vested Profit Sharing Retirement Fund contributions each year, with optional 401(k) contributions
  • Paid parental leave and family benefits such as elective egg freezing, surrogacy, and adoption reimbursement
  • Generous paid time off including 12 holidays, year-end office closure, and 15 vacation days per year
  • Paid sick time on an as-needed basis

Who you'll work with

  • Join the Information Security Risk Management (ISRM) organization within Security Operations and collaborate with cybersecurity professionals protecting BCG's global technology environment.
  • Partner with Infrastructure, Cloud, Network, Identity, Endpoint Security, and Governance, Risk, and Compliance teams to prioritize enterprise cyber risk, improve remediation effectiveness, and strengthen the firm's security posture. Work with senior technology and security leaders to provide actionable insights for strategic cybersecurity decision-making.

Additional info

  • For US locations only
  • In the US, compensation transparency applies

Similar Jobs