About this role
Locations : Gurgaon | Lisbon
Who We Are
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.
What You'll Do
As the Infrastructure Security Architect – Secure Network, you will serve as the dedicated security architecture partner for BCG’s Secure Network Engineering Squad, defining the security strategy, architecture, and governance that protect the firm’s global network infrastructure spanning Security Service Edge, segmentation, DNS, and cloud network environments. You will establish the security requirements, architectural standards, and design guardrails that enable secure, scalable, and resilient network platforms while advancing BCG’s Zero Trust strategy and enterprise security objectives.
As part of the Infrastructure Security Architecture team within Information Security Risk Management (ISRM), you will operate through a shared accountability model with Platform Engineering. You will provide architectural direction, governance, and design oversight throughout the solution lifecycle, while engineering teams retain ownership for implementation, delivery, and operational management. Success in this role requires strong technical leadership, sound architectural judgment, and the ability to influence global stakeholders across a matrixed organization.
- Define and maintain network security architecture for the enterprise: Security Service Edge (SSE), Zero Trust Network Access (ZTNA), secure web gateway, and CASB patterns.
- Own architectural requirements for the enterprise Security Service Edge (SSE) platform, including FQDN-based policy enforcement and elimination of direct IP access patterns, in alignment with published SSE security standards.
- Define network segmentation and zoning strategy across offices, data centers, and cloud environments to constrain lateral movement, consistent with NIST SP 800-207 zero trust principles.
- Define DNS and web-layer security architecture requirements, including protective DNS, domain governance interfaces, and egress control.
- Own security architecture requirements for cloud network infrastructure: VPC/ VNet design patterns, firewall zoning, next-generation firewall and cloud gateway placement, and secure interconnects.
- Define secure remote access architecture (ZTNA/VPN) and the deprecation path for legacy perimeter access patterns.
- Author and maintain the security standards, reference architectures, and control requirements that govern the Secure Network domain, mapped to CSF-09 (Security Architecture – Network & Cloud/Systems Security) and ZTMM maturity targets.
- Conduct security architecture reviews for secure network initiatives; issue dispositions, conditions, and architectural decision records traceable to ISRM governance.
- Contribute domain expertise to ZTMM maturity assessments, control gap analyses, and the security architecture roadmap.
- Serve as the dedicated architecture counterpart to the Secure Network Engineering Squad, validating feasibility and effectiveness of security controls through implementation without assuming delivery ownership.
- Define network segmentation and zoning strategy across offices, data centers, and cloud environments, underpinned by authoritative network asset inventory and topology mapping
- Define logging, telemetry, and monitoring requirements (CSF-12) for secure network services in partnership with Security Operations, which owns SIEM, detection engineering, and continuous monitoring.
- Drive automation and policy-as-code adoption for network security controls, partnering with engineering to move enforcement and drift detection from manual review toward continuous, automated validation.
What You'll Bring
- Bachelor’s degree in a relevant field or equivalent practical experience.
- 6–10 years in security architecture, security engineering, or infrastructure security with demonstrated architecture responsibility.
- Experience operating in large, audit-sensitive, or regulated enterprise environments with formal governance and exception processes.
- Strong understanding of zero trust architecture (NIST SP 800-207, CISA ZTMM), enterprise control frameworks, and hybrid cloud environments (Azure, AWS, GCP).
- Deep hands-on architecture experience with SSE platforms (Zscaler, Palo Alto Prisma Access, or equivalent), ZTNA design, and enterprise segmentation programs
- Strong command of NIST SP 800-207 and practical zero trust network design in hybrid environments (on-prem, Azure, AWS, GCP).
- Working knowledge of DNS security, SD-WAN, cloud-native network controls, and network detection and response (NDR) integration points.
Preferred Qualifications
- Experience with cloud workload protection, CNAPP, CSPM, and cloud security posture management.
- Familiarity with network compliance, conditional access, and identity-driven security controls.
- Professional certifications such as CISSP, SABSA, or relevant cloud security certifications.
Who You'll Work With
You will join the Infrastructure Security Architecture team within Information Security Risk Management (ISRM), serving as the dedicated security architecture partner for BCG’s Secure Network Engineering Squad. In this role, you will help define the security strategy, architectural standards, and governance that guide the design and evolution of secure network platforms spanning SSE, segmentation, DNS, and cloud network infrastructure.
You will collaborate closely with engineering, cloud, identity, infrastructure, and security teams across BCG’s global technology organization to ensure security controls are consistently designed, implemented, and governed across the network domain. You will also partner with Security Operations, Risk Management, and architecture peers to strengthen Zero Trust capabilities, advance security maturity, and support enterprise-wide cybersecurity initiatives.
Working within a highly collaborative, matrixed environment, you will influence technical direction, build alignment on architectural decisions, and help teams deliver secure, scalable solutions that balance business objectives, operational effectiveness, and risk management.
Additional info
At BCG, our people and relationships are at the heart of everything we do. We believe that in-person collaboration plays an important role in our culture, mentorship, and professional development.
For this role, you will generally be expected to work from a BCG office or in person with clients on a regular basis (typically around 50% of working time), depending on business needs and in line with local policies and practices.
We aim to provide a dynamic and collaborative environment that fosters connection and teamwork.
You’re Good At
- Translating enterprise security standards into practical, implementable engineering requirements.
- Holding architecture authority constructively: enabling delivery teams rather than blocking them, while keeping governance boundaries intact.
- Communicating precisely across engineering squads, architecture peers, and senior security leadership.
Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E - Verify Employer. Click here for more information on E-Verify.