About this role
Locations : Washington | Boston
Who We Are
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.
What You'll Do
The Chief Information Security Officer (CISO) serves as the primary executive authority on enterprise cybersecurity strategy, risk governance, and federal compliance for BCG Federal. Reporting regularly to the Government Security Committee (GSC) and executive leadership, the CISO holds direct authority to define and approve the federal IT security boundary, manage enterprise risk, and escalate unresolved security exposures. Operating as an executive peer alongside business and technology leaders, the CISO balances client mission enablement with rigorous defense compliance mandates.
The CISO leads a dedicated cyber organization of approximately 25 professionals and directs the strategic security interface between BCG Federal and BCG Global IT and Security. In this capacity, the CISO ensures our streamlined cloud environment—primarily Microsoft 365 GCC-High, Azure Government, and AWS DevOps pipelines—remains properly isolated and compliant with Defense Counterintelligence and Security Agency (DCSA) standards, while safely leveraging global shared capabilities where permitted.
Key Responsibilities
- Executive Governance & GSC Advisory: Define enterprise security strategy, deliver regular security and compliance briefings to the Government Security Committee (GSC), and maintain risk governance aligned with federal missions and strategic corporate growth.
- Team Leadership & Cyber Operations: Direct a ~15-person cybersecurity organization across core functions, including security operations, compliance, cloud security architecture, IAM, and vulnerability management.
- Global Parent Alignment & Boundary Integrity: Partner with BCG Global CISO and IT leadership to maintain boundary isolation, data barriers, and access controls separating BCG Federal enclaves from commercial global infrastructure.
- Cloud Architecture & Enclave Protection: Oversee the security architecture and boundary controls for a focused cloud environment centered on Microsoft 365 GCC-High, Azure Government, and AWS DevOps pipelines, ensuring strict protection of Controlled Unclassified Information (CUI) and export-controlled data.
- Federal Compliance & Audit Ownership: Own enterprise compliance for NIST SP 800-171, NIST SP 800-53, DFARS 252.204-7012, and CMMC Level 2, leading System Security Plan (SSP) maintenance, SPRS scoring, and C3PAO/federal audit readiness.
- Technology Controls Administration: Collaborate with Legal, the Facility Security Officer (FSO), and leadership to administer the Technology Control Plan (TCP) and ensure systems adhere to DCSA security requirements and governance obligations.
- Business Development & Mission Enablement: Partner with capture and client delivery teams to architect compliant, secure solutions for client enclaves and support proposal responses.
- AI Security Governance: Provide security and compliance oversight for vetting, deploying, and governing AI tools, LLMs, and emerging technologies within CUI-constrained environments.
- Supply Chain & Third-Party Risk (SCRM): Oversee vendor risk assessments, software supply chain security, and FedRAMP cloud service provider evaluations across subcontractors and external integrations.
What You'll Bring
- Experience: 7–10+ years of IT security and information assurance experience, including 2–4+ years operating within the Defense Industrial Base (DIB) or a directly comparable national security environment.
- People Leadership: 7+ years of demonstrated success directly managing multi-disciplinary IT teams, setting operational rhythms, and mentoring technical leads.
- Cloud & Infrastructure Mastery: Strong architectural knowledge of Microsoft GCC-High / Azure Government (Entra ID, Purview, Defender, Intune) and foundational AWS DevOps/IAM security baselines.
- Regulatory Expertise: In-depth understanding of NIST SP 800-171, DFARS 7012, CMMC Level 2, and DCSA oversight requirements.
- Clearance: Active Top Secret clearance required
- Education & Certifications: Bachelor’s degree in a relevant technical or government/business discipline. Recent coursework in AI and Cybersecurity a plus.
Additional info
At BCG, our people and relationships are at the heart of everything we do. We believe that in-person collaboration plays an important role in our culture, mentorship, and professional development.
For this role, you will generally be expected to work from a BCG office or in person with clients on a regular basis (typically around 50% of working time), depending on business needs and in line with local policies and practices.
We aim to provide a dynamic and collaborative environment that fosters connection and teamwork.
*** For US locations only ***
In the US, we have a compensation transparency approach.
Total compensation for this role includes base salary, annual discretionary performance bonus, retirement contribution, and a market leading benefits package described below.
- The base salary range for this role begins at $225,000 in our lowest cost US region and goes up to $ 262,500 in our highest cost US region. Your recruiting contact can share more about the specific salary range for your preferred location during the hiring process.
This is an estimated range, however, specific base salaries within the range depend on various factors such as experience and skill set. It is not common for new BCG employees to be hired at the high-end of the salary range. BCG regularly reviews its ranges to ensure market competitiveness.
In addition to your base salary, your total compensation will include a bonus of up to 45% and a generous retirement contribution that starts at 10%. Senior Directors/Executive Directors are also eligible for a Firm Performance Bonus.
All of our plans provide best in class coverage:
- Zero dollar ($0) health insurance premiums for BCG employees, spouses, and children
- Low $10 (USD) copays for trips to the doctor, urgent care visits and prescriptions for generic drugs
- Dental coverage, including up to $5,000 in orthodontia benefits
- Vision insurance with coverage for both glasses and contact lenses annually
- Reimbursement for gym memberships and other fitness activities
- Fully vested Profit Sharing Retirement Fund contributions made annually, whether you contribute or not, plus the option for employees to make personal contributions to a 401(k) plan
- Paid Parental Leave and other family benefits such as elective egg freezing, surrogacy, and adoption reimbursement
- Generous paid time off including 12 holidays per year, an annual office closure between Christmas and New Years, and 15 vacation days per year (earned at 1.25 days per month)
- Paid sick time on an as needed basis
Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E - Verify Employer. Click here for more information on E-Verify.