Who We Are
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures\u2014and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.
What You'll Do
Security Continuous Monitoring Oversight
Establish and lead BCG\u2019s first enterprise-wide\u202FCybersecurity Continuous Monitoring (CSCM) program, ensuring continuous visibility into system, endpoint, network, and cloud activity.Define and implement governance models, including ownership of monitoring metrics (e.g.,\u202FMTTD, MTTR, false positive rate, coverage completeness).Stand up monitoring processes and integrate telemetry sources across\u202FSIEM, EDR, identity, network, and cloud platforms.Ensure monitoring outputs are actionable, enriching detection and response activities and informing risk and compliance stakeholders.Technical Architecture & Integration
Design and implement a\u202Fcontinuous monitoring reference architecture, leveraging SIEM, SOAR, UEBA, and threat intelligence.Establish enterprise logging standards covering\u202Flog coverage, retention, encryption, access, and integrity\u202Frequirements.Drive automation of monitoring workflows and correlation logic to reduce dwell time and improve detection accuracy.Collaborate with threat intelligence teams to ensure\u202Freal-time enrichment of event data\u202Fand alignment with MITRE ATT&CK adversary tactics.Program & Capability Development
Build the CCM capability\u202Ffrom the ground up, defining the operating model, reporting cadence, and engagement with SOC, risk, and compliance.Develop and track KPIs, ensuring CCM effectiveness is measurable and communicated to senior stakeholders.Prioritize creation of\u202Ftop 5\u201310 operational dashboards and reports\u202Fthat provide critical enterprise visibility.Mature the function from initial operational capability (M1) toward advanced maturity, embedding continuous improvement cycles.ShapeSTRATEGIC LEADERSHIP
Serve as the\u202Ffounding leader\u202Ffor the CCM function, creating the strategy, roadmap, and tactical build plan.Partner with enterprise stakeholders across IT, Risk, and Security to align monitoring with business risk tolerance and resilience objectives.Influence senior leaders by translating technical telemetry insights into\u202Fbusiness-relevant intelligence.Build, inspire, and retain a high-performing team of analysts and engineers over time, leveraging both full-time staff and contractors.Advise senior leadership (via SecOPS) on monitoring-driven insights, risks, and mitigation recommendations.What You'll Bring
Bachelor\u2019s degree (or equivalent). Master\u2019s preferred.10+ years in cybersecurity operations, with at least 5 years in security monitoring, SOC leadership, or equivalent detection & response functions.Proven track record of\u202Fbuilding or maturing monitoring capabilities\u202F(SIEM, SOAR, telemetry pipelines, UEBA, threat intel integration).Knowledge of\u202Flog ingestion, normalization, correlation, and enrichment\u202Fprocesses.Familiarity with leading monitoring technologies:\u202FSplunk, DataDog, Microsoft Defender, CrowdStrike Falcon, Azure/AWS/GCP telemetry, threat intelligence platforms.Expertise in\u202Fmetrics-driven monitoring: defining, tracking, and reporting MTTD, MTTR, false positive rates, and coverage completeness.Familiarity with frameworks like\u202FNIST CSF, MITRE ATT&CK, and ISO 27001, with experience applying these to monitoring.Experience in\u202Fthreat hunting, anomaly detection, and behavioral analytics.Strong leadership skills: able to recruit, mentor, and develop a high-performing team in a newly established function.Executive presence: able to present complex monitoring data and risks to senior leadership in clear, concise business terms.Additional info
COMPETENCIES: Director, Cybersecurity Continuous Monitoring
Leads a critical security function with measurable business impact. Establishes foundational capabilities, manages delivery, and develops a growing team to support BCG\u2019s enterprise security posture.
\u00A0
Technical & Functional Expertise
Develops and executes the\u202Fcontinuous monitoring strategy, aligned to enterprise security goals and SecOPS direction.Demonstrates deep technical expertise in\u202Ftelemetry ingestion, SIEM/SOAR integration, log management, and threat intelligence enrichment.Serves as a\u202Frecognized expert in monitoring and detection, providing guidance to peers and influencing related security domains.Codifies monitoring practices and standards into\u202Frepeatable processes and playbooks, reducing reliance on ad hoc approaches.Evaluates and pilots\u202Femerging monitoring technologies; ensures adoption of digital tools to scale efficiency and coverage.Problem Solving & Insight
Frames\u202Fmonitoring and detection challenges\u202Fin business-relevant terms (risk, resilience, compliance).Uses data-driven methods (metrics such as\u202FMTTD, MTTR, false positives) to identify control gaps and inform improvements.Translates complex monitoring outputs into actionable insights for stakeholders across IT, Risk, and Security.Innovates in detection methodologies, leveraging\u202Fbehavioral analytics, anomaly detection, and adversary simulations.Acts as a problem-solver during incidents, ensuring monitoring outputs guide rapid containment and response.Effectiveness & Value Creation
Leads the build-out of the\u202FCCM function from the ground up, establishing governance, processes, and reporting.Structures, plans, and executes monitoring programs and initiatives, balancing near-term needs with long-term maturity goals.Delivers measurable outcomes (visibility, faster detection, reduced dwell time) that\u202Fdirectly enhance business resilience.Proactively manages resources, balancing full-time staff and contractors to deliver capability within deadlines.Prioritizes actions with the highest impact on reducing enterprise cyber risk.Role Model
Operates with integrity, safeguarding BCG and client data through responsible monitoring practices.Promotes a culture of\u202Ftransparency, accountability, and data-driven decision-making\u202Fin the team.Demonstrates perseverance and adaptability in building a new function with high visibility and expectations.Creates an inclusive working environment that values diverse technical and analytical perspectives.Leads by example, modeling sustainable workload practices even under incident-driven pressure.Communication, Presence & Influence
Develops and delivers clear dashboards, reports, and executive communications on monitoring outputs.Shapes perspectives by\u202Ftranslating technical monitoring metrics into risk- and business-relevant insights.Communicates effectively across technical and non-technical audiences, ensuring alignment with IT and business leaders.Leads conversations in operational reviews, incident post-mortems, and governance forums.Encourages open dialogue within the team, and fosters credibility with cross-functional partners.Teaming & Collaboration
Builds strong partnerships with SOC, Offensive Security, IT Operations, and Security Architecture teams.Develops productive relationships across regions and business units to expand telemetry coverage.Works collaboratively with compliance, risk, and audit to align monitoring with enterprise governance.Anticipates and manages conflicts in data ownership, tool coverage, and priorities, resolving them constructively.Promotes knowledge-sharing across security teams, reducing silos and strengthening collective defense.People Development & Leadership
Defines the vision and purpose of the CCM function, instilling clarity and purpose for the team.Coaches and mentors analysts, engineers, and contractors to expand monitoring expertise.Provides stretch opportunities for team members to develop technical and leadership skills.Balances empowerment and oversight \u2014 ensuring autonomy in monitoring activities while maintaining governance discipline.Leads quality team meetings, defines clear objectives, and ensures alignment to SecOPS priorities.Provides frequent developmental feedback, fostering a culture of continuous learning and improvement.\u00A0
Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.\n
BCG is an E - Verify Employer. Click here for more information on E-Verify.