CybersecurityJobs.io
← Back to all jobs

Job Description

Based in Boston, MA with a hybrid work arrangement, Bain & Co. offers a compelling security leadership role that directly influences the resilience of the private equity platform deployed on Azure AKS. You will advance zero trust, strengthen supply chain protections, enforce data boundaries, and govern AI egress controls while weaving security into the development lifecycle across cross-functional teams. This position pairs hands-on engineering with collaboration across Platform Engineering, Data Governance, and AI security disciplines, backed by a robust benefits package and a culture that prioritizes secure, scalable delivery.

Responsibilities

  • Oversee the platform’s security posture end to end, covering core controls such as HashiCorp Vault or Azure Key Vault, Istio mTLS, Cilium network policies, Pod Security Standards, and OPA/Gatekeeper policies.
  • Architect and implement a zero-trust security model across the estate, applying defense in depth and least privilege principles.
  • Perform lightweight STRIDE threat modeling for new services and major features, documenting risks, mitigations, and residual risk decisions.
  • Manage supply chain security controls, including image scanning and signing, SBOM generation, and dependency vulnerability management.
  • Define and enforce identity and access controls with SAML/OIDC patterns, JWT/OAuth concepts, and enterprise IdP integration guidance (Okta/Entra).
  • Establish data classification controls at the platform layer with governed access, masking/tokenization, and API-layer enforcement.
  • Own runtime detection controls by maintaining Falco rules, establishing escalation pathways, and integrating signals with the central SIEM to keep alerts actionable.
  • Lead security incident response for the platform, guiding containment, remediation, and post-incident reviews with clear follow-up actions.
  • Conduct regular security reviews of the AI layer, focusing on Agent Gateway egress controls, prompt injection risks, PII handling, and data exfiltration controls for model interactions.
  • Maintain security runbooks and drive quarterly internal security reviews across teams, ensuring controls are tested, auditable, and kept current.
  • Engage in select PE squad ceremonies to surface security concerns early and define testability and operability requirements for security controls.
  • Collaborate with Platform Engineering on secure-by-default templates and guardrails, including policy-as-code libraries, reusable CI checks, and pre-commit hooks.
  • Partner with the Data Governance Lead on PII classification, tokenization policy, and regulatory requirements (SOC 2 Type II, ISO 27001, GDPR).
  • Work with the centralized Application Security team to promote secure AI tooling, accelerate threat modeling, draft security policies, and triage CVEs with expert judgment before adoption.
  • Communicate security risks in business terms and prioritize controls that meaningfully reduce risk.

Requirements

  • Hybrid work model with in-office presence at least one day per week in Boston, MA.
  • Bachelor’s degree in Computer Science, Engineering, Information Systems, Cybersecurity, or a related field, or equivalent practical experience.
  • Minimum six years of security engineering, infrastructure security, SRE/DevOps with security focus, or platform engineering with hands-on security ownership.
  • Proven experience implementing and operating security controls in Kubernetes production environments, including policy enforcement, workload isolation, network controls, and runtime detection.
  • Experience designing and operating secrets management and identity/access controls (HashiCorp Vault and/or Azure Key Vault, PKI, OIDC/SAML patterns, enterprise IdP integration).
  • Experience implementing supply chain security practices (scanning, signing, SBOMs, dependency management) and integrating controls into CI/CD pipelines.
  • Experience leading or contributing to security incident response, including post-incident reviews and remediation planning.
  • Demonstrated ability to work cross-functionally as an enabling partner, raising security standards without unduly blocking delivery.

Technologies

  • HashiCorp Vault, Azure Key Vault, Istio, Cilium, Pod Security Standards, OPA, Gatekeeper
  • SAML 2.0, OIDC, JWT, OAuth 2.0
  • Okta, Azure AD
  • Falco, Trivy, Cosign, Sigstore, Syft, Dependabot, Renovate
  • Kubernetes, Kyverno, Rego
  • Python, Bash
  • AWS Macie

Benefits

  • Health coverage for medical, dental, and vision premiums paid in full for the employee
  • Paid time off including parental leave, sick leave, and holidays
  • Fully vested employer contribution to the 401(k) plan
  • Employer 401(k) contribution at 4.5 percent, increasing after three years and fully vested from day one
  • Life insurance and long-term disability coverage
  • Annual fitness reimbursement

Compensation

In Boston, Massachusetts, the target annual salary range is $147,250 to $176,750. In Chicago, Illinois, the range is $141,000 to $169,250. Compensation includes a discretionary annual performance bonus, plus Bain's 401(k) plan with employer contributions and the comprehensive benefits package described above.

Similar Jobs