Global Cybersecurity Director - Risk & Compliance
$176kBoston Consulting Group
Locations: Boston | WashingtonWho We AreBoston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.What You'll DoBCG Federal operates within a federally regulated environment supporting consulting, cloud, software, data, and emerging AI technology capabilities. The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance, certification readiness, and control maturity agenda across all BCG Federal offerings.The Director leads enterprise readiness and audit defense across key federal frameworks; including CMMC Level 2, NIST SP 800-171/53, FedRAMP and DFARS. Working closely with Security Architecture, the Director translates complex regulatory requirements into policy and control objectives, establishing the governance framework while Architecture designs the technical controls and secure cloud baselines.Furthermore, this role pioneers Federal AI Governance, establishing guardrails, risk assessment protocols, and approval pathways for Generative AI and machine learning tools deployed across federal boundaries.YOU’RE GOOD AT You excel at leading complex federal cybersecurity and compliance programs by combining technical GRC expertise, executive communication, organizational change management, and trusted stakeholder relationships.YOUR DUTIES WILL INCLUDELead the Federal GRC pillar strategy, roadmap, operating model, governance rhythm, reporting structure, and control maturity agenda across BCG Federal.Direct enterprise compliance initiatives supporting DFARS, CMMC Level 2, NIST 800-171/, FedRAMP, AI governance, cloud security, and related federal cybersecurity requirements.Partner closely with Security Architecture to align policies with technical engineering; defining what control outcomes are required while Architecture designs how technical controls and baselines are configured.Own organizational readiness for federal assessments and certifications, including assessment scoping, SSP development, evidence preparation, stakeholder preparation, audit defense, C3PAO engagement, and executive reporting.Establish and mature Federal AI Governance, including risk methodologies, safety frameworks (e.g., NIST AI RMF), boundary protections, and approval pathways for secure adoption of Generative AI and LLMs.Own the federal risk register governance model, including risk identification, severity assessment, mitigation planning, exception management, escalation, and reporting.Lead cybersecurity review of federal contracts, RFPs, client opportunities, software approvals, cloud service reviews, and third-party vendor risk management to support secure technology adoption.Lead organizational change management for federal cybersecurity and compliance initiatives, including stakeholder alignment, communications, training, readiness tracking, and sustainment of new governance processes.Oversee continuous monitoring (CONMON) governance, evidence traceability, recurring review cadences, POA&M tracking, and management reporting.Define and deliver executive-level metrics, dashboards, QBR content, risk reporting, compliance status updates, and decision-ready materials for leadership.Lead, mentor, onboard, and develop GRC personnel while improving team operating rhythms, accountability, prioritization, and delivery quality.What You'll Bring10+ years of experience in cybersecurity, information security, GRC, audit, compliance, risk management, or technology governance environments.Demonstrated experience leading federal cybersecurity compliance programs (preferably supporting CMMC Level 2, NIST 800-171/53, FedRAMP) in consulting, cloud, SaaS, or federal contracting environments.Direct experience leading or materially supporting external assessments, regulatory inquiries, audit readiness efforts, C3PAO assessments, evidence preparation, and audit defense.Proven track record establishing AI Security Governance, evaluating machine learning/GenAI security risks, and applying federal AI risk management frameworks.Proven ability to partner with Security Architecture, DevSecOps, and IT engineering teams to translate complex legal and federal requirements into practical operating baselines.Strong organizational change management experience, including leading cross-functional process adoption, stakeholder readiness, communications, training, and sustainment of new operating models.Excellent written and verbal communication skills, including experience developing executive briefings, policies, audit materials, and management-level reporting.Ability to obtain and maintain a U.S. Government Secret Clearance where required.Additional info*** For US locations only ***In the US, we have a compensation transparency approach.Total compensation for this role includes base salary, annual discretionary performance bonus, retirement contribution, and a market leading benefits package described below.The base salary range for this role begins at $176,000.00 in our lowest cost US region and goes up to $199,830.00 in our highest cost US region. Your recruiting contact can share more about the specific salary range for your preferred location during the hiring process.This is an estimated range, however, specific base salaries within the range depend on various factors such as experience and skill set. It is not common for new BCG employees to be hired at the high-end of the salary range. BCG regularly reviews its ranges to ensure market competitiveness.In addition to your base salary, your total compensation will include a bonus of up to 30% and a generous retirement contribution that starts at 5% and moves to 10% after 2 years.All of our plans provide best in class coverage:Zero dollar ($0) health insurance premiums for BCG employees, spouses, and childrenLow $10 (USD) copays for trips to the doctor, urgent care visits and prescriptions for generic drugsDental coverage, including up to $5,000 in orthodontia benefitsVision insurance with coverage for both glasses and contact lenses annuallyReimbursement for gym memberships and other fitness activitiesFully vested Profit Sharing Retirement Fund contributions made annually, whether you contribute or not, plus the option for employees to make personal contributions to a 401(k) planPaid Parental Leave and other family benefits such as elective egg freezing, surrogacy, and adoption reimbursementGenerous paid time off including 12 holidays per year, an annual office closure between Christmas and New Years, and 15 vacation days per year (earned at 1.25 days per month)Paid sick time on an as needed basisBoston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify.Job SummaryJob number: 58850Profession: Legal Team and Risk Management
$229.5k - $310.5k
...impact to millions of patients. Our Cybersecurity organization is evolving to match... ..., and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature... ...science, enable our business, and meet global regulatory obligations. Reporting...SuggestedFull timeTemporary workWork at officeLocal areaFlexible hours$155k - $214k
About This Role:As the Associate Director, Global Quality Risk Management, you will be at the forefront of Biogen’s commitment to quality excellence. Leading the charge in designing, implementing, and sustaining the enterprise Quality Risk Management (QRM) capabilities,...SuggestedFull timeTemporary workLocal area- Community Resources For Justice, Inc. is seeking a Senior Director, Compliance & Continuous Improvement to lead organization-wide compliance governance across all programs and service lines. The role partners with leadership to monitor licensing, accreditation, and contractual...SuggestedRemote work
- Join Starr, a global leader in commercial insurance with over a century of expertise. We empower our employees to innovate, make impactful... ...ability to drive real progress.The Group Head of Catastrophe Risk Analytics is responsible for leading Catastrophe risk analytics...SuggestedFull timeWorldwide
$155.6k - $306.8k
...: The mission of Quality and Risk Management (QRM) is to manage... ...services.Facilitates internal compliance with contract terms, risk... ...Partners, Principals, Managing Directors, and engagement teams on Requests... ...direct your inquiries to the Global Call Center (GCC) at...SuggestedContract workFor subcontractorWork at officeLocal area- Massachusetts Bay Transportation Authority (MBTA) seeks a Deputy Director of IT Risk & Compliance Management to provide strategic and operational leadership across enterprise technology risk, compliance, and governance functions. This role safeguards information assets...
- State Street is seeking the Global Head of Regulatory Examination Management within the Global Regulatory Liaison Office to lead... ...knowledge, executive communication, and the ability to influence Risk, Compliance, Legal and boards, while building a high-performing team and...Work at office
$124k - $280k
...Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager, you will play a pivotal role in... ...navigate complex regulatory landscapes- Managing cybersecurity risk management initiatives to protect client data...Full timeH1b$99k - $232k
...Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Manager, you will play a pivotal role in guiding... ...expectations- Guiding teams in the application of cybersecurity risk management and compliance frameworks- Providing...Full timeH1b$140k - $160k
...DynatraceDynatrace is looking for an IT Compliance Lead to join our Business Systems organization... ...Program activities that will include risk assessments, IT governance, internal/... ...enterprises and millions of end customers globally, striving for a world where software...Work experience placementWork at officeRelocation2 days per week- ...& Company is seeking a Manager for the Third-Party Risk Strategy within Optimize to lead the global supplier onboarding program. You will shape risk-based... ...risk frameworks, and collaborate with Ethics & Compliance, Finance, Legal and Cyber teams across multiple offices...
- Anthropic seeks a Head of Enterprise Risk to lead programs ensuring resilience as the company scales globally. You will own enterprise-risk disciplines and oversee specialist leaders responsible for EH&S, access management, third-party risk, and new-facility security programs...
$317.5k - $365k
...the foundation of a more open, global economy through digital... ...Global Head of Product Security & Risk, you will define and lead the... ...of Product, Security, Compliance, Risk, Legal, Policy, and Engineering... ...evolving AML, payments, cybersecurity, and digital asset regulations...WorldwideFlexible hours$102.8k - $176k
...professional services to the middle market globally, our purpose is to instill confidence... ...Organization to focus on growing our cybersecurity and risk consulting practice. The Strategic... ...RSM’s full suite of cyber, risk, compliance, privacy, resilience, and technology...Full timeContract workWork experience placementInternshipWork at officeLocal area$128.55k - $222.82k
Job DescriptionThe Director, GWAM Business Risk Management, is a first line (Line 1B) risk management role... ...-Assessment (RCSA) Program across Global Wealth and Asset Management (GWAM). The... ...owners, and control owners to ensure compliance with enterprise risk management...Full timeTemporary workLocal areaFlexible hours$220k - $330k
Job DescriptionThe Senior Director, Enterprise Third Party Risk Leader, will lead an expanded third-party risk management E2E process, including leading... ...at any time. #LI-HybridCompany InformationVertex is a global biotechnology company that invests in scientific innovation...Full timeSummer workImmediate startRemote workFlexible hours2 days per week- ...development of overall Corporate Tax Strategies, Risk Management and Talent Development. This... ...to executives, auditors, and global teams. Applies strong analytical judgment... ...country of the vacancy will be subject to compliance with the applicable immigration requirements...Local area
- ...DescriptionGeneral Summary:The CMC Quality Compliance Director is responsible for inspection readiness... ...“how”, ensuring phase appropriate and risk-based compliance.Key Duties and... ...Knowledge and Skills:Expert knowledge of global GMP requirements and experience across...Full timeWork experience placementSummer workRemote workFlexible hours2 days per week
$170.6k - $256k
...pivotal role at Hasbro, where you can lead our global trade compliance efforts and advance our mission? We are seeking a highly skilled Director Global Trade Compliance to join our team... ...and reduce financial and reputational risks. Serve as the primary trade compliance...Worldwide- John Hancock in Boston, MA, seeks a Director, GWAM Business Risk Management, to lead the Risk and Control... ...-Assessment (RCSA) program across Global Wealth and Asset Management. You will... ...partner with business leaders to ensure compliance with enterprise risk standards and...
- Dana-Farber Cancer Institute is seeking a Director of Billing Compliance responsible for maintaining the integrity and compliance of billing practices. The Director will oversee the development of compliance programs and audits within the organization. Qualified candidates...
$163.4k - $322.1k
...the cyber and organizational risk profiles of leading companies... ...opportunities businesses face in cybersecurity. Join our team to deliver... ...experience with governance, risk, or compliance initiatives involving common... ...direct your inquiries to the Global Call Center (GCC) at...Local areaVisa sponsorship- The Deputy Director of IT Risk & Compliance Management provides strategic and operational leadership over enterprise technology risk, compliance... ...Five (5)years of progressive IT risk, compliance, or cybersecurity governance experience within large, complex environments...
- ...includes attendance, participation, and contribution in local safety committee meetings as needed. Job Summary The Deputy Director of IT Risk & Compliance Management provides strategic and operational leadership over enterprise technology risk, compliance, and governance...Local area
$175k - $225k
...The Director, Investment Risk will establish a centralized investment risk function within the Enterprise Data & Analytics team. Building upon... ...with investment professionals, Product Management, Legal & Compliance, Information Technology, and senior leadership to enhance...Work at officeLocal areaRemote work1 day per week- Hasbro in Boston, MA is seeking a Director of Global Trade Compliance to lead worldwide trade compliance strategy across all operations. You will advise executive leadership, manage a 12-person team, and ensure adherence to customs and export controls while enabling cost...Worldwide
$196.7k - $353.4k
...RoleModerna is seeking an individual to lead development and execution of global regulatory strategy for programs in its oncology portfolio. This... ...and across alliances to align on strategyAnticipate regulatory risks and proactively mitigate themBuild and develop high-performing...Permanent employmentFull timeWork at officeWork from home- Vertex Pharmaceuticals LLC seeks a Director, Compliance Business Partner to advise Global and US teams on initiatives, addressing legal and compliance risks while protecting the company’s integrity. The role sits in OBIE and collaborates with Legal, HR, and Internal Audit...
- Vertex Pharmaceuticals Incorporated is seeking a Senior Director, Global Quality Systems to lead and enhance the Quality Management System... ...substantial leadership experience, strong regulatory compliance expertise, and a commitment to quality culture across global...Flexible hours
- State Street’s Cyber DNA team seeks a Global Operational Excellence Lead to establish governance, resilience, and continuous improvement across cyber data, analytics, and AI platforms. You will partner with global Cyber Security, Infrastructure, and Enterprise Continuity...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Global Cybersecurity Director - Risk & Compliance. Be the first to apply!
- cyber security lead Boston, MA
- director - cyber security Boston, MA
- cybersecurity manager Boston, MA
- senior manager cyber security Boston, MA
- director credit risk Boston, MA
- head of risk management Boston, MA
- risk management associate Boston, MA
- operational risk manager Boston, MA
- risk management specialist Boston, MA
- director of risk management Boston, MA

