CybersecurityJobs.io
← Back to all jobs

Job Description

BCG Federal is looking for a Data Protection Engineer to help operate and maintain data protection architecture across multiple GCC High platforms, aligned to NIST 800-171, DFARS 7012, CMMC Level 2, and security best practices. This role supports a fast-paced, product-oriented environment where security guidance helps build, implement, and protect secure SaaS solutions for clients.

Benefits that support your life outside work

  • $0 health insurance premiums for BCG employees, spouses, and children
  • $10 copays for trips to the doctor, urgent care visits, and prescriptions for generic drugs
  • Dental coverage, including up to $5,000 in orthodontia benefits
  • Vision insurance covering glasses and contact lenses annually
  • Reimbursement for gym memberships and other fitness activities
  • Fully vested Profit Sharing Retirement Fund contributions made annually, whether you contribute or not, plus the option to contribute to a 401(k) plan
  • Paid Parental Leave and family benefits including elective egg freezing, surrogacy, and adoption reimbursement
  • Generous paid time off: 12 holidays per year, annual office closure between Christmas and New Years, and 15 vacation days per year (earned at 1.25 days per month)
  • Paid sick time on an as needed basis

What you will do

  • Enhance and maintain the Data Classification and labeling technical strategy based on business, client, and compliance requirements
  • Translate compliance and client contractual obligations into an operational data schema
  • Collaborate with Engineering and IT Service teams to drive process improvements and effective execution
  • Work with Risk and Security teams to define a restrictive labeling strategy
  • Refine data protection policies to align with security needs
  • Present data analysis and recommendations to senior stakeholders
  • Lead data-driven egress monitoring and evolve related controls
  • Architect new data controls and strategy within emerging AI architecture
  • Evolve security tools and reporting with embedded AI security tooling
  • Collaborate with vendor technical teams to enable progress
  • Use newer technologies to automate containment and isolation while improving user behaviors
  • Conduct technical research to address new challenges

What you bring

  • 5-8+ years of experience in Information Security and Data Protection
  • 3-5+ years of Data Protection technical operational capabilities and strategies
  • Experience with data handling in AI tooling and management
  • Proficiency in data classification and tracking strategies
  • Familiarity with relevant standards and frameworks, including Fedramp, NIST 800-171, and CMMC
  • Encryption and Data Loss Prevention (DLP) experience using sensitivity labeling
  • Excellent data analysis skills and presentation skills
  • Ability to anticipate risks and identify mitigation strategies
  • Knowledge of security issues, trends, and best practices
  • Experience with Microsoft Azure, M365, Purview, Defender, and Zscaler within a GCC High environment
  • Ability to obtain and maintain a Security Clearance (if required)

Tools and standards you will work with

AWS, MS Azure, M365, Purview, Defender, Zscaler, sensitivity labeling, DLP, and compliance alignment with NIST 800-171, DFARS 7012, CMMC Level 2, and Fedramp.

Location and work model

  • Boston, MA (onsite)
  • Washington

You will help application developers, engineering, and cloud infrastructure teams by providing security expertise and guidance, supporting an enthusiastic and motivated group of security professionals delivering secure SaaS solutions to clients.

Similar Jobs