WHAT YOU'LL DO
The Gamma Security Architect provides internal BCG technical consulting around information security architecture and security design measures for new projects, ventures and systems. The architect defines the desired end state to meet solution Security Goals and overall business goals. The Security Architect ensures the digital applications, tools, and services protect our data, our clients data, and our intellectual property; are resilient to cyber-attack; meet BCG policy and standards, regulatory requirements, and industry best practices; while using a risk-based approach to meeting BCG business needs and objectives.
The Gamma Security Architect works with teams inside BCG to secure the building and maintenance of complex computing environments to train, deploy, and operate Artificial Intelligence/ML systems by determining security requirements; planning, implementing and testing security systems; participate in AI/ML projects as the Security Subject Matter Expert; preparing security standards, policies and procedures; and mentoring team members.
YOU'RE GOOD AT
The Gamma Security Architect is good at:
* Working closely with AI/ML, Data Engineering and Cybersecurity teams to design secure solutions in an agile environment utilizing both on-premise and cloud deployments.
* Determining security requirements by evaluating business strategies and requirements, implementing information security standards, conducting system security and vulnerability analyses and risk assessments, recommending secure architecture aligned to business architecture, and identifying/driving remediation of integration issues.
* Researching and analyzing emerging technologies, designing and advocating new technologies, architectures, and security products in collaboration with system and service owners.
* Providing expert knowledge of SDLC/application architecture as well as methodologies for the software and model development life cycle.
* Managing end to end delivery of projects with hands on involvement in the development and configuration of products.
* Maintaining security by ensuring compliance to standards, policies and procedures; conducting incident response analysis; and developing and conducting training programs.
* Self-managing progress and status of tasks and deliverables on projects and escalating issues and risks timely.
* Interacting with stakeholders and possessing the ability to influence direction, articulate risks and sell secure solutions/roadmaps.
* Completing market assessments on vendor products, packages and services; guiding tests and implementation of products solving enterprise information security requirements.
* Suggesting and implementing alternative security mitigations/compensating controls to allow for business to continue while protecting BCG's assets.
* Guiding the configuration, implementation, monitoring, and support for security software/systems that will help ensure compliance with regulatory, industry, and corporate policies and procedures.
* Partnering with cross functional teams to ensure compliance to industry and company standards including ISO 27001/SOC2, NIST.
* Understanding, as the subject matter expert of best practices and change management policies using Infrastructure-as-Code and CI/CD tools for all aspects of ML model deployment and service delivery.
* Updating job knowledge by tracking and understanding emerging security practices and standards; participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations.
* Excellent communication (written and oral) and leadership skills
YOU BRING (EXPERIENCE & QUALIFICATIONS)
* Bachelors degree (or equivalent);
* Preferred certification in one or more Information Security relevant areas such as SDLC (CSSLP), Security Professional (CISSP), Cloud Security (CCSP, CCSK)
* Minimum of 8 years of information security experience, with a strong background in cloud native infrastructure, network security, security applications and technologies.
* Subject matter expert in security practices that include the full administration of security control systems, vulnerability identification and mitigation, best practices for securing/hardening, and risk analysis.
* Expert technical knowledge with cumulative hands on experience across a vast array of security platforms.
* Understanding on ML model deployment and creation of CI/CD pipelines for data science workloads. A good understanding of software and solution development for consumption by external customers.
* Knowledge of secure software development lifecycle and practices such as threat modelling, security reviews, penetration tests, and security incident response.
* In-depth experience of vulnerabilities, intrusion detection systems, firewall management, network vulnerability analysis, cryptographic theory and practice, incident analysis and response, software testing and security assessment, malicious code and software exploitation techniques, continuous monitoring and event logging, cyber-crimes, computer forensics analysis and computer crime investigation.
YOU'LL WORK WITH
You will work in a fast-paced, intellectually intense, service-oriented environment to interpret rules and guidelines flexibly to enhance the business and in keeping with BCGs values and culture. You will be a part of a team of professionals in support of internal IT and business professionals, and consultants delivering business and management strategy to our clients. You will work with application developers and data analysts providing tools and support for our consultants. You will be an integral part of the BCG Information Security Risk Management team in delivering the security program for Gamma and all of BCG.
Boston, MA
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963.
To succeed, organizations must blend digital and human capabilities. BCG’s diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change through leading-edge management consulting as well as data science, technology and design, digital ventures, and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization to deliver results that help our clients thrive.
Whether you want to advance an idea, a capability, or the world at large, BCG is with you every step of the way. We excel in the business of human potential, and believe in its power to shape strategic, organizational, economic, societal change, and beyond.
Our consulting model is holistic and unique. Operating across industries and geographies as one integrated, multifunctional team, we bring customized solutions and the best of BCG to each client. Today, as a top consulting firm, we help clients with total transformation—driving complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
We partner with clients from the private, public, and not-for-profit sectors in all regions to identify their highest-value opportunities, address their most critical challenges, and transform their enterprises.