- Company Name
- Haystack
- Job Title
- Cyber Security Specialist
- Job Description
-
**Job Title**
Cyber Security Specialist
**Role Summary**
Lead the design, implementation, and continual evolution of BCG’s global IT security platform. Drive a unified strategy across identity, endpoint, and data protection, ensuring scalable, automated, and resilient controls. Apply SRE principles to enhance reliability and performance of security services while mentoring a worldwide team of security engineers.
**Expectations**
- 10+ years in cybersecurity/security engineering, with 5+ years in senior leadership overseeing enterprise‑scale security platforms.
- Proven track record of designing and scaling IAM, endpoint, and data protection solutions in hybrid and cloud‑native environments (AWS, Azure, GCP).
- Demonstrated success automating security controls, implementing zero‑trust models, and applying SRE practices.
- Deep understanding of compliance frameworks, risk management, and regulatory requirements.
- Strong leadership, communication, and mentorship skills with a record of building high‑performance engineering teams.
**Key Responsibilities**
- Define and execute a cohesive security engineering strategy across identity, endpoint, and data protection domains.
- Lead end‑to‑end IAM engineering including authentication, authorization, and privileged access controls.
- Oversee endpoint security architecture, threat detection, malware prevention, and device compliance enforcement.
- Build and operate scalable data protection services (DLP, secrets management, encryption, classification).
- Apply SRE principles to improve reliability, performance, and maintainability of security services.
- Mentor and grow a global security engineering team, fostering collaboration and continuous improvement.
**Required Skills**
- Expertise in IAM, endpoint security, and data protection technologies.
- Experience designing and operating security platforms in hybrid and cloud‑native environments (AWS, Azure, GCP).
- Proficiency in automating security controls, zero‑trust architecture, and policy‑as‑code.
- Knowledge of SRE practices, incident response, and reliability engineering.
- Strong understanding of compliance frameworks (GDPR, ISO 27001, NIST, SOC 2) and risk management.
- Leadership, coaching, stakeholder communication, and cross‑functional collaboration.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Professional certifications such as CISSP, CISM, or comparable security credentials preferred.