Global Platform Team Lead & Senior Director – Identity Security

Boston Consulting GroupLondon, EnglandOn-siteFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

Locations : London | Lisbon

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.

To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.

What You'll Do

The Senior Director – Identity Security Lead is responsible for leading the strategy, engineering, and operational excellence of BCG's global identity security practice across both Human and Agentic identity domains. This role owns the end-to-end identity lifecycle, from modernising enterprise directory services and privileged access management to pioneering the design of next-generation agentic AI identity management frameworks that will define how BCG secures autonomous agents and non-human workloads.

The leader will oversee four core teams — Directory Services, Privileged User Management, Identity Governance & Administration (IGA), and Secure Data — ensuring a coherent, automated, and resilient identity security capability that underpins BCG Core, BCG X, and Consulting Team (CT) worldwide. The role requires a rare combination of deep technical identity expertise, a forward-thinking perspective on AI-era security, and the ability to collaborate with ISRM, platform engineering, and business leadership to shape BCG's identity posture for the next decade.

Key Responsibilities

Strategic Leadership & Transformation

- Define and execute a unified Identity Security strategy that spans human identity modernisation and the emerging domain of agentic AI identity — establishing BCG as a leader in how AI agents are authenticated, authorised, and governed.
- Lead the ongoing modernisation of BCG's enterprise identity infrastructure, transitioning legacy directory and access systems to a scalable, cloud-native, zero-trust identity fabric.
- Develop and publish BCG's Agentic Identity framework — including standards, patterns, and controls for non-human identities, service accounts, AI agents, and automated workloads at scale.
- Align identity security strategies with broader digital transformation, BCG X product delivery, and AI/ML platform initiatives.
- Establish a global identity observability and telemetry capability, enabling real-time visibility into identity risks, access anomalies, and compliance posture.

Directory Services

- Oversee the strategy and execution of BCG's enterprise directory modernisation programme, including Active Directory (AD) rationalisation and transition to cloud-based identity providers.
- Drive AD modernisation towards a strategic, cloud-based identity foundation, reducing legacy dependencies while maintaining operational stability.
- Ensure directory services meet high availability, performance, and security standards across global BCG offices and hybrid environments.
- Embed automation into directory lifecycle management, provisioning, and group policy governance.

Privileged User Management

- Lead the design, delivery, and operational management of Privileged Access Management (PAM) solutions, ensuring comprehensive control over standing and just-in-time privileged access.
- Extend PAM principles to cover agentic and service identities, ensuring non-human privileged access is governed with equivalent rigour to human privileged users.
- Drive continuous reduction of standing privilege across BCG's environment through automation, credential vaulting, and session monitoring.
- Implement privileged access telemetry and behavioural analytics to detect and respond to anomalous privileged activity.

Identity Governance & Administration (IGA)

- Oversee the IGA programme, ensuring consistent enforcement of access lifecycle management, access certifications, segregation of duties (SoD), and role-based access control (RBAC) across all enterprise systems.
- Drive IGA automation to reduce manual access provisioning, improve access review efficiency, and enforce least-privilege principles at scale.
- Design and implement governance frameworks that extend to AI agent identities, covering creation, scoping, review, and decommissioning of agentic permissions.
- Partner with HR, Legal, and ISRM to ensure identity governance processes remain compliant with evolving regulatory and audit requirements.

Secure Data (Secrets Management, DLP & Observability)

- Lead the engineering and operations of BCG's secrets management platform, ensuring credentials, API keys, certificates, and tokens are centrally vaulted, rotated, and audited — with particular focus on non-human and agentic workloads.
- Drive the Data Loss Prevention (DLP) programme, ensuring sensitive data is classified, monitored, and protected across endpoints, cloud services, and AI-generated outputs.
- Build out identity-centric security observability, integrating identity telemetry with broader security monitoring to enable detection of identity-based threats and lateral movement.
- Ensure secrets management practices are embedded into CI/CD pipelines, platform engineering workflows, and AI/ML development practices across BCG.

IT Service Management & Operational Excellence

- Establish SRE-based operational metrics — SLOs, SLIs, and error budgets — for all identity security services, ensuring platform reliability and availability.
- Implement 24x7 operational support models for critical identity services, with follow-the-sun coverage for incident response.
- Drive continuous improvement of identity platform health, including patching automation, certificate lifecycle management, and vulnerability remediation.
- Ensure ITSM compliance across all identity teams, with standardised incident, change, and problem management workflows.

Security, Compliance & Risk Management

- Ensure alignment with ISO 27001, NIST, SOC 2, GDPR, and applicable identity-specific compliance frameworks across all teams.
- Partner closely with ISRM to translate policy requirements into enforceable, automated technical controls.
- Lead risk mitigation in areas of identity sprawl, shadow IT identities, agentic permission creep, and privileged access exposure.
- Operationalise continuous compliance through automated access certification, policy enforcement, and audit-ready reporting.

Financial & Vendor Management

- Manage the Identity Security budget with a focus on consolidation, cost optimisation, and strategic platform investment.
- Lead vendor selection, contract negotiation, and relationship management for identity and access technology platforms.
- Evaluate and rationalise the identity tooling landscape, ensuring the portfolio is coherent, integrated, and aligned with future-state architecture.

Leadership & Talent Development

- Build and lead a high-performing, globally distributed Identity Security team across Directory Services, PAM, IGA, and Secure Data disciplines.
- Foster a culture of automation-first engineering, continuous learning, and cross-domain collaboration.
- Develop and maintain a talent pipeline with expertise in both traditional identity engineering and emerging agentic identity domains.
- Promote knowledge sharing and capability uplift across identity, platform, and security communities within BCG IT.

What You'll Bring

Required Qualifications

- 12+ years of experience in identity security, IAM, or related cybersecurity engineering disciplines.
- 5+ years in a senior leadership role with accountability for enterprise-scale identity platforms across global, hybrid environments.
- Deep expertise in identity architecture, spanning directory services, PAM, IGA, and secrets management.
- Demonstrated experience in identity modernisation programmes — including AD transformation, cloud identity migration, and zero-trust identity adoption.
- Proven understanding of, or experience with, non-human identity management — including service accounts, API credentials, and automated workloads — with appetite to shape the emerging agentic identity domain.
- Strong understanding of compliance frameworks and their identity implications (ISO 27001, NIST, SOC 2, GDPR).
- Excellent leadership, communication, and stakeholder management skills with the ability to engage from engineering teams to executive leadership.

Preferred Qualifications

- Certifications: CISSP, CISM, CCSP, or vendor-specific identity certifications (Microsoft Identity, Okta, SailPoint, CyberArk, HashiCorp Vault).
- Experience with tools such as Azure AD / Entra ID, CyberArk, SailPoint IdentityNow, HashiCorp Vault, Okta, Saviynt, or equivalent enterprise identity platforms.
- Familiarity with AI/ML security patterns, including identity and authorisation models for LLM-based agents and agentic workflows.
- Experience applying SRE principles to security platforms, including SLO definition and automated remediation.
- Background in DevSecOps and integrating identity controls into CI/CD and platform engineering workflows.

Who You'll Work With

Work Environment & Additional Information

- Hybrid or on-site work model.
- Occasional travel may be required for leadership meetings, vendor engagements, or global team events.
- Ability to operate in a fast-paced, high-stakes environment balancing a multi-year modernisation agenda with day-to-day operational excellence.

Additional info

About This Role

The Senior Director – Identity Security Lead is a defining leadership role at the intersection of identity modernisation and AI-era security. With BCG in the midst of transforming its human identity infrastructure and simultaneously charting the future of agentic AI identity management, this leader will set the standard for how BCG secures its people, its systems, and its autonomous agents. If you are a technically deep, strategically minded identity leader with the vision to build identity security for the next generation of enterprise AI, we invite you to apply.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.

BCG is an E - Verify Employer. Click here for more information on E-Verify.