Global Cybersecurity Director - Risk & Compliance - Washington
$176kBoston Consulting Group
Global Cybersecurity Director - Risk & Compliance - Washington, United States of America
Locations : Boston | Washington
Who We Are
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital venturesand business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.What You'll Do
BCG Federal operates within a federally regulated environment supporting consulting, cloud, software, data, and emerging AI technology capabilities. The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance, certification readiness, and control maturity agenda across all BCG Federal offerings.
The Director leads enterprise readiness and audit defense across key federal frameworks; including CMMC Level 2, NIST SP 800-171/53, FedRAMP and DFARS. Working closely with Security Architecture, the Director translates complex regulatory requirements into policy and control objectives, establishing the governance framework while Architecture designs the technical controls and secure cloud baselines.
Furthermore, this role pioneers Federal AI Governance, establishing guardrails, risk assessment protocols, and approval pathways for Generative AI and machine learning tools deployed across federal boundaries.
YOURE GOOD AT
You excel at leading complex federal cybersecurity and compliance programs by combining technical GRC expertise, executive communication, organizational change management, and trusted stakeholder relationships.
YOUR DUTIES WILL INCLUDE
- Lead the Federal GRC pillar strategy, roadmap, operating model, governance rhythm, reporting structure, and control maturity agenda across BCG Federal.
- Direct enterprise compliance initiatives supporting DFARS, CMMC Level 2, NIST 800-171/, FedRAMP, AI governance, cloud security, and related federal cybersecurity requirements.
- Partner closely with Security Architecture to align policies with technical engineering; defining what control outcomes are required while Architecture designs how technical controls and baselines are configured.
- Own organizational readiness for federal assessments and certifications, including assessment scoping, SSP development, evidence preparation, stakeholder preparation, audit defense, C3PAO engagement, and executive reporting.
- Establish and mature Federal AI Governance, including risk methodologies, safety frameworks (e.g., NIST AI RMF), boundary protections, and approval pathways for secure adoption of Generative AI and LLMs.
- Own the federal risk register governance model, including risk identification, severity assessment, mitigation planning, exception management, escalation, and reporting.
- Lead cybersecurity review of federal contracts, RFPs, client opportunities, software approvals, cloud service reviews, and third-party vendor risk management to support secure technology adoption.
- Lead organizational change management for federal cybersecurity and compliance initiatives, including stakeholder alignment, communications, training, readiness tracking, and sustainment of new governance processes.
- Oversee continuous monitoring (CONMON) governance, evidence traceability, recurring review cadences, POA&M tracking, and management reporting.
- Define and deliver executive-level metrics, dashboards, QBR content, risk reporting, compliance status updates, and decision-ready materials for leadership.
- Lead, mentor, onboard, and develop GRC personnel while improving team operating rhythms, accountability, prioritization, and delivery quality.
What You'll Bring
- 10+ years of experience in cybersecurity, information security, GRC, audit, compliance, risk management, or technology governance environments.
- Demonstrated experience leading federal cybersecurity compliance programs (preferably supporting CMMC Level 2, NIST 800-171/53, FedRAMP) in consulting, cloud, SaaS, or federal contracting environments.
- Direct experience leading or materially supporting external assessments, regulatory inquiries, audit readiness efforts, C3PAO assessments, evidence preparation, and audit defense.
- Proven track record establishing AI Security Governance, evaluating machine learning/GenAI security risks, and applying federal AI risk management frameworks.
- Proven ability to partner with Security Architecture, DevSecOps, and IT engineering teams to translate complex legal and federal requirements into practical operating baselines.
- Strong organizational change management experience, including leading cross-functional process adoption, stakeholder readiness, communications, training, and sustainment of new operating models.
- Excellent written and verbal communication skills, including experience developing executive briefings, policies, audit materials, and management-level reporting.
- Ability to obtain and maintain a U.S. Government Secret Clearance where required.
Additional info
*** For US locations only ***
In the US, we have a compensation transparency approach.
Total compensation for this role includes base salary, annual discretionary performance bonus, retirement contribution, and a market leading benefits package described below.
- The base salary range for this role begins at $176,000.00 in our lowest cost US region and goes up to $199,830.00 in our highest cost US region. Your recruiting contact can share more about the specific salary range for your preferred location during the hiring process.
This is an estimated range, however, specific base salaries within the range depend on various factors such as experience and skill set. It is not common for new BCG employees to be hired at the high-end of the salary range. BCG regularly reviews its ranges to ensure market competitiveness.
In addition to your base salary, your total compensation will include a bonus of up to 30% and a generous retirement contribution that starts at 5% and moves to 10% after 2 years.
All of our plans provide best in class coverage:
Zero dollar ($0) health insurance premiums for BCG employees, spouses, and children
Low $10 (USD) copays for trips to the doctor, urgent care visits and prescriptions for generic drugs
Dental coverage, including up to $5,000 in orthodontia benefits
Vision insurance with coverage for both glasses and contact lenses annually
Reimbursement for gym memberships and other fitness activities
Fully vested Profit Sharing Retirement Fund contributions made annually, whether you contribute or not, plus the option for employees to make personal contributions to a 401(k) plan
Paid Parental Leave and other family benefits such as elective egg freezing, surrogacy, and adoption reimbursement
Generous paid time off including 12 holidays per year, an annual office closure between Christmas and New Years, and 15 vacation days per year (earned at 1.25 days per month)
Paid sick time on an as needed basis
Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E - Verify Employer. Click here for more information on E-Verify.
$208.55k - $254.85k
...facilitating messages between providers.Job Summary:The Director of Governance, Risk and Compliance provides strategic oversight of the Governance Risk... ...such as finance, technology, human resources, cybersecurity, competition, and environmentalExperience managing a...SuggestedFull timeCasual workWork at officeLocal areaImmediate startFlexible hours$154 per hour
...Global Cybersecurity Senior Manager - Data Protection Engineer - Washington, United States of America Locations : Washington | Boston... ...with business, client and compliance requirements Translate... ...improvements Collaborate with Risk and Security teams to define...SuggestedWork at officeLocal area$47.35 - $76.2 per hour
...Senior Manager Of Risk Management And ComplianceThis... ...Risk Management and Compliance supports and monitors... ...applicable regulations, and cybersecurity and IT policies. This... ...will help Marriott's Global Technology team build... ...35 to $76.20 per hour.Washington Applicants Only:...SuggestedHourly payTemporary workRemote workFlexible hours$254.9k
...help you succeed in a globally connected powerhouse of... ...Global Lead Security Compliance & Enforcement owns the... ...Technology Assurance, Risk & Policy. The role transforms... ...governance. The Director creates clear global... ...York City Metro Area, Washington State and California (...SuggestedFull timeSummer holidayLocal areaFlexible hours$147.9k - $200.1k
...cloud? Amazon Web Services (AWS) is leading the next paradigm shift in computing and the AWS Global Government Delivery Organization (GGDO) team is looking for a motivated Risk Manager to join our fast-paced organization. The GGDO, manages direct US Government programs...SuggestedWorldwideFlexible hoursShift work- Capital One Financial Corporation in McLean, VA seeks a Director to lead the PMO within the Global Payment Network Business Risk Office. The role drives strategic governance, executive communication, and cross-functional program delivery across a regulated financial services...Work at office
$100k
...! Become a member of a global community! The international... ...in Seattle, Washington. As a Fortune 500 company... ...Job Description The Director, Global Legal Services (Compliance) (“DGLSC”), will join a world... ...analyze complex issues, manage risk, and drive practical business...Work at officeFlexible hours- ...RecruitmentLocation: Washington, DC,United StatesRequired... ...’ll join a diverse, global community working... ...Context: The WBG Chief Risk Officer (CRO) Vice Presidency... ...and report to the Director of the Credit Risk Department... ...implement and monitor compliance with talent management...Temporary workWork at officeWorldwide
- CrossCountry Consulting is seeking an Associate Director in Risk and Advisory to deliver integrated financial and operational risk engagements. You will lead client delivery, drive teams, and develop junior members while expanding services with innovative AI-enabled solutions...
- ...Capital One seeks a Director of Product Management for the GRCx Product Management team to drive transformation of core risk management products. You will lead cross-functional teams to deliver customer-focused, technology-driven solutions and align product strategy with...
- ...office presence as needed based on business needs. Overview: The Compliance, Risk and Business Manager is responsible for advancing the Company... ...environment preferred. Experience collaborating across global teams, including U.S. and India-based stakeholders, is preferred...Work experience placementH1b2 days per week
$112k - $236k
Viatris is seeking a Director, Regulatory Strategist in Washington, DC to lead global regulatory strategies for complex projects. The ideal candidate will have extensive regulatory experience and a proven track record of successful interactions with health authorities....Work at office$99k - $176k
...products and capabilities. As a Risk Advice Senior Manager,... ...as functional groups, such as Compliance, Law Group and Enterprise Group... ...-$176,000, (Boston, Chicago, Washington DC), $90,000-$160,000, (Minneapolis... ...of a highly qualified global workforce and plays a critical...Full timeFlexible hours$180.78k - $271.17k
...the implementation and completion of the Risk Monitoring Program for a specific... ...Serves as a primary resource to the Senior Director for updates; responsible for identifying... ...600 Tysons, VA: $154,400 - $299,600 Washington, DC: $154,400 - $299,600 Woodbridge, NJ...Full timeTemporary workFor contractorsFor subcontractorWork at officeLocal areaImmediate start$74.2k - $129.8k
Export Compliance Manager, Global Trade Services Job ID: 10560816 | Amazon.com Services LLC Do you see compliance as a business enabler? Do you... ...candidate will support various aspects of export governance, risk management, and regulatory compliance (regulatory...Flexible hours- Capital One is seeking a Product Design Director to lead the Anti-Money Laundering and Compliance & Ethics teams within the Risk Design portfolio. You will oversee 10-12 designers, collaborate with researchers, product, and tech leadership, and drive high-impact, complex...
$145k - $200k
...advisory solutions spanning accounting and risk, technology-enabled transformation, and... ...for future success. As an Associate Director at CrossCountry Consulting specializing... ...Outsourcing/Co-sourcing. Sarbanes-Oxley Compliance (SOX), and Governance, Risk and Compliance...Local areaFlexible hours$134.5k - $265.1k
...Position Summary Cyber Security & Risk Strategy Manager Our Deloitte Cyber team understands... ...and opportunities businesses face in cybersecurity. Join our team to deliver powerful... ...process, please direct your inquiries to the Global Call Center (GCC) at USTalentCICInbox@...Local areaVisa sponsorship- ...Healthcare Financial/Actuarial Director you will be a key member of... ...Guides teams on cost avoidance, risk and funding strategies and... ...calculating reserves Partners with Global Delivery Centers and Client... ...Time Off (only included for Washington roles) Retirement Benefits:...Temporary workWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours
- Oversee projects with multiple workstreams, including Internal Audit Outsourcing/Co-sourcing, Sarbanes-Oxley Compliance (SOX), and Governance, Risk and Compliance (GRC) Develop project scopes and approaches leveraging digital tools and data-driven techniques Attract, interview...
- ...Description CyberLinx Solutions LLC is seeking a forward thinking Cybersecurity GRC Lead / Cyber Risk Manager responsible for leading the organization’s cybersecurity governance, risk, and compliance (GRC) program. This role oversees enterprise risk assessments, regulatory...
$190k
...BCG Platinion | Manager, Cybersecurity - Washington, United States of America Locations : Atlanta... ...Boston Consulting Group (BCG) is a global consulting firm that partners with leaders... ...Software, Cybersecurity, and Technology Risk Management. Our Tech Advisory and...Work at officeLocal area$90k - $120k
...with guidance and adherence to stated deadlines. Partner with Global Delivery Centers and Client Service teams to deliver superior project... ...Parental and Adoption Leave), Paid Time Off (only included for Washington roles) Retirement Benefits: Qualified contributory pension plan...Temporary workWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours- Chevy Chase Trust, a private investment management firm in the Washington, D.C. metropolitan area, seeks a Portfolio Manager to manage client assets on a discretionary basis. You will work within the Global Thematic Equity framework, discuss goals with clients, and contribute...
$230.72k - $345k
...12948 Position Summary The Senior Director, Global Regulatory Strategy is a senior regulatory... ...portfolio planning, governance, and risk management activities, ensuring alignment... ...indications, and maintain regulatory compliance. Health Authority Interactions Establish...Full timeTemporary workLocal areaRemote workWorldwideFlexible hours- ...Executive Director, Authorization Risk ManagementThe Executive Director will be responsible for developing... ...with Risk Governance, Legal and Compliance to ensure policies are in compliance... ...the diverse talents they bring to our global workforce are directly linked to our...
- ...SET Development is seeking a Cyber Security Product Risk Manager to support the security and resilience of... ...hardware. This role sits at the intersection of cybersecurity, space systems engineering, and compliance , ensuring that cyber risks are identified, assessed...
- ...About the Position The Political Risk Insurance Projects Director supports a U.S. Government Agency in... ...sectors. This position is based in the Washington, D.C. metropolitan area, and is... ...to help solve today's most pressing global political, social, and economic challenges...Contract workLocal areaOverseas
$100k - $135k
...starts with our people. We’re a global close-knit community,... ...DescriptionDepartment Overview: The cybersecurity assessments department... ...protection, governance, risk, and compliance assessments using common frameworks... ...: New York, US Offsite; Washington, US Offsite; Utah, US...Full timeRemote workRelocation$117.2k - $176.7k
...future of Salesforce.The ExperienceThe Global Compliance and Certification (GCC) team is responsible... ...information needed to make strategic, risk-based decisions. The GCC team is a... ...benefits, as applicable.SummaryLocation: Washington - Bellevue; California - San FranciscoType...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Global Cybersecurity Director - Risk & Compliance - Washington. Be the first to apply!
- cyber security lead Washington DC
- director - cyber security Washington DC
- cybersecurity manager Washington DC
- enterprise risk manager Washington DC
- head of risk management Washington DC
- director credit risk Washington DC
- risk management associate Washington DC
- director of risk management Washington DC
- risk management specialist Washington DC
- risk management manager Washington DC



