Overview
In this role you strengthen BCG’s Enterprise Risk Management program with a focus on IT Services, Cyber, Data and AI risk. You will translate complex tech and risk topics into clear insights for senior stakeholders and drive cross-functional risk initiatives across the firm. You’ll build dashboards, KRIs, and risk reporting to support proactive decision-making in a global, dynamic environment. This is an opportunity to shape digital risk governance and foster a risk-aware culture at scale.
Responsibilities
- Strengthen and evolve the ERM program focusing on IT Services & Cyber Risk and Data & AI Risk
- Partner with Digital, IT, Legal, Compliance, Privacy, and other functions to drive cross-functional risk initiatives
- Produce executive-ready presentations, dashboards, and reports with key risk insights and recommendations
- Monitor risk information to identify emerging IT, cyber, data, and AI risks and support mitigation planning
- Develop KRIs and risk sensing metrics and executive reporting for proactive risk management
- Escalate material risk issues through the enterprise risk governance framework
- Coordinate enterprise risk register reviews and integrate findings into governance processes
- Enable consistent risk reporting, governance, and communications across functions
- Lead cross-functional projects to advance strategic risk initiatives and improve ERM processes
- Contribute to ongoing enhancement of ERM methodologies and governance practices
Key requirements
- 7+ years in enterprise risk management, technology risk, cyber risk, IT services risk, or related field
- Experience assessing IT services, cyber, data, and AI risks in global organizations
- Knowledge of COSO ERM, ISO 31000, NIST CSF, ISO 27001, NIST AI RMF, and KRIs
- Excellent written and verbal communication to translate technical risk for senior stakeholders
- Proven ability to drive risk process adoption and influence without direct authority
- Understanding of legal and regulatory cybersecurity, data privacy, and AI considerations
- Experience with PowerPoint, Power BI or Tableau, and GRC platforms; collaboration tools like Teams, Slack, Trello
- Experience using AI/LLM tools for risk analysis and content development
- Bachelor’s degree in business, risk management, economics, computer science, information systems, cybersecurity, or related field
- Advanced degree or certifications (CRISC, CISA, CISM, CRM) are a plus
- Ability to work across time zones and travel as needed
- Strong analytical and problem-solving skills
- Fluent English and high professional integrity
- clear written and verbal communication
- stakeholder engagement and collaboration
- strong business judgment
- COSO ERM
- ISO 31000
- NIST CSF
…
