Boston Consulting Group

Cybersecurity Senior Analyst

Boston Consulting Group Lisbon, Portugal

Business Consulting and Services · 10,001+ employees

Yesterday
security Mid (2-5 yrs) Full-time Portugal
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The role involves supporting strategic clients with information security due diligence, including responding to security questionnaires and RFPs. You will collaborate with internal teams to communicate BCG's security posture and ensure compliance with regulatory requirements.

What they look for

Cybersecurity Information Security Risk Management Compliance Stakeholder Management Client Assurance Due Diligence Audit Data Protection Privacy Technical Advisory Communication Analytical Skills German Language English Language

Requirements

Candidates should have professional experience in areas such as compliance, risk, audit, or cybersecurity, along with strong analytical and stakeholder management skills. Fluency in both written and spoken English and German is required for this position.

Full description

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.

To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.

What You'll Do

As a Global Information Security Manager / Global Client Assurance Services Manager within BCG's Client Assurance Services (CAS) team, you will play an important role in supporting BCG's strategic clients with their information security due diligence activities.

 

You will work closely with Information Security, Legal, Risk, and client-facing teams to help communicate BCG's security posture, policies, and practices to clients and prospects globally.

 

This is a highly collaborative and client-facing role requiring strong communication, analytical, and stakeholder-management skills. We welcome candidates from a range of technical, compliance, regulatory, risk, legal, or assurance backgrounds. Prior cybersecurity or Client Assurance experience is helpful but not required.

 

Key Responsibilities

  • Client Due Diligence Support:• Serve as a key contact for clients and prospects conducting information security assessments of BCG.
  • Respond to client security questionnaires, RFPs, due diligence requests and audit requests.
  • Participate in client calls and workshops and provide clear explanations of BCG's security controls, certifications and risk management practices.
  • Review and interpret client security, contractual, compliance and regulatory requirements.
  • Coordinate with relevant BCG subject-matter experts to develop accurate and appropriate responses to client requirements.
  • Support German-speaking clients and BCG teams with German-language security requirements, documentation and client discussions where required.
  • Stakeholder Collaboration:
  • Partner closely with BCG's Information Security, Legal, Risk, Compliance, Data Protection and client-facing teams.
  • Gather accurate information regarding BCG's security posture and ensure consistent and compliant responses to client inquiries.
  • Build effective relationships across BCG's global and matrixed organization.
  • Help translate technical, compliance and regulatory topics into clear, business-relevant communications for clients and internal stakeholders.
  • CAS Tools, Processes & Continuous Improvement:
  • Support the maintenance and continuous improvement of CAS tools, templates, knowledge repositories and automation initiatives.
  • Identify opportunities to improve the efficiency and consistency of client assurance activities.
  • Contribute to scalable approaches, best practices, and knowledge sharing across client engagements.
  • Knowledge Management & Documentation:• Maintain and enhance the CAS knowledge base, standard response library and supporting documentation.
  • Help ensure client assurance materials remain accurate, current and easily accessible across the team.

 

What You'll Bring

We welcome candidates from a range of professional backgrounds and recognize that the skills needed to succeed in Client Assurance can be gained through different career paths. Relevant transferable experience is valued, and prior Client Assurance or cybersecurity experience is not required.

  • Relevant professional experience in areas such as compliance, risk, audit/assurance, IT or technical support, technical advisory, data protection/privacy, business law, information security/cybersecurity, or another relevant client-facing field.
  • Strong analytical skills and the ability to understand and interpret technical, contractual, regulatory, or compliance requirements.
  • Strong communication and stakeholder-management skills, including confidence engaging directly with clients.
  • Ability to explain complex topics clearly to technical and non-technical audiences.
  • Strong organizational skills and the ability to manage multiple priorities in a fast-paced, global environment.
  • Interest in information security and the ability to quickly develop relevant subject-matter knowledge.
  • Collaborative, pragmatic, and service-oriented working style.
  • Fluent written and spoken English and German are required.

Helpful, but not required:

  • Experience with security questionnaires, RFPs, due diligence, audits, or assurance activities.
  • Familiarity with information security or compliance frameworks such as ISO 27001, SOC 2, NIST, or GDPR.

Additional info

BCG’s Client Assurance Services (CAS) team sits at the intersection of information security, client trust, and business development. We support BCG’s most important global client relationships by serving as the dedicated team that handles information security due diligence requests, security assessments, and assurance inquiries from current and prospective clients. As client expectations around data protection and cybersecurity continue to evolve, CAS plays a critical role in demonstrating BCG’s security maturity, building client confidence, and enabling BCG to win and retain strategic engagements. The team partners closely with Information Security, Legal, Risk, and client-facing teams across the firm.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.

BCG is an E - Verify Employer. Click here for more information on E-Verify.

Similar roles