Global Cybersecurity Director - Security Operations in Ewell
Global Cybersecurity Director - Security Operations

Global Cybersecurity Director - Security Operations in Ewell

Ewell Full-Time 72000 - 108000 ÂŁ / year (est.) No home office possible
C

At a Glance

  • Tasks: Lead BCG's Cybersecurity Continuous Monitoring program and enhance security operations.
  • Company: Join Boston Consulting Group, a leader in business strategy and transformation.
  • Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
  • Why this job: Make a significant impact on global cybersecurity while working with top industry experts.
  • Qualifications: 10+ years in cybersecurity with strong leadership and technical skills.
  • Other info: Dynamic role with potential for career advancement in a collaborative environment.

The predicted salary is between 72000 - 108000 ÂŁ per year.

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation‑inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom‑line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading‑edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.

What You’ll Do

  • Security Continuous Monitoring Oversight: Establish and lead BCG’s first enterprise‑wide Cybersecurity Continuous Monitoring (CSCM) program, ensuring continuous visibility into system, endpoint, network, and cloud activity. Define and implement governance models, including ownership of monitoring metrics (e.g., MTTD, MTTR, false positive rate, coverage completeness). Stand up monitoring processes and integrate telemetry sources across SIEM, EDR, identity, network, and cloud platforms. Ensure monitoring outputs are actionable, enriching detection and response activities and informing risk and compliance stakeholders.
  • Technical Architecture & Integration: Design and implement a continuous monitoring reference architecture, leveraging SIEM, SOAR, UEBA, and threat intelligence. Establish enterprise logging standards covering log coverage, retention, encryption, access, and integrity requirements. Drive automation of monitoring workflows and correlation logic to reduce dwell time and improve detection accuracy. Collaborate with threat intelligence teams to ensure real‑time enrichment of event data and alignment with MITRE ATT&CK adversary tactics.
  • Program & Capability Development: Build the CCM capability from the ground up, defining the operating model, reporting cadence, and engagement with SOC, risk, and compliance. Develop and track KPIs, ensuring CCM effectiveness is measurable and communicated to senior stakeholders. Prioritize creation of top 5–10 operational dashboards and reports that provide critical enterprise visibility. Mature the function from initial operational capability (M1) toward advanced maturity, embedding continuous improvement cycles.
  • Strategic Leadership: Serve as the founding leader for the CCM function, creating the strategy, roadmap, and tactical build plan. Partner with enterprise stakeholders across IT, Risk, and Security to align monitoring with business risk tolerance and resilience objectives. Influence senior leaders by translating technical telemetry insights into business‑relevant intelligence. Build, inspire, and retain a high‑performing team of analysts and engineers over time, leveraging both full‑time staff and contractors. Advise senior leadership (via SecOPS) on monitoring‑driven insights, risks, and mitigation recommendations.

What You’ll Bring

  • Bachelor’s degree (or equivalent). Master’s preferred.
  • 10+ years in cybersecurity operations, with at least 5 years in security monitoring, SOC leadership, or equivalent detection & response functions.
  • Proven track record of building or maturing monitoring capabilities (SIEM, SOAR, telemetry pipelines, UEBA, threat intel integration).
  • Knowledge of log ingestion, normalization, correlation, and enrichment processes.
  • Familiarity with leading monitoring technologies: Splunk, DataDog, Microsoft Defender, CrowdStrike Falcon, Azure/AWS/GCP telemetry, threat intelligence platforms.
  • Expertise in metrics‑driven monitoring: defining, tracking, and reporting MTTD, MTTR, false positive rates, and coverage completeness.
  • Familiarity with frameworks like NIST CSF, MITRE ATT&CK, and ISO 27001, with experience applying these to monitoring.
  • Experience in threat hunting, anomaly detection, and behavioral analytics.
  • Strong leadership skills: able to recruit, mentor, and develop a high‑performing team in a newly established function.
  • Executive presence: able to present complex monitoring data and risks to senior leadership in clear, concise business terms.

Additional info

COMPETENCIES: Director, Cybersecurity Continuous Monitoring. Leads a critical security function with measurable business impact. Establishes foundational capabilities, manages delivery, and develops a growing team to support BCG’s enterprise security posture.

Technical & Functional Expertise: Develops and executes the continuous monitoring strategy, aligned to enterprise security goals and SecOPS direction. Demonstrates deep technical expertise in telemetry ingestion, SIEM/SOAR integration, log management, and threat intelligence enrichment. Serves as a recognized expert in monitoring and detection, providing guidance to peers and influencing related security domains. Codifies monitoring practices and standards into repeatable processes and playbooks, reducing reliance on ad‑hoc approaches. Evaluates and pilots emerging monitoring technologies; ensures adoption of digital tools to scale efficiency and coverage.

Problem Solving & Insight: Frames monitoring and detection challenges in business‑relevant terms (risk, resilience, compliance). Uses data‑driven methods (metrics such as MTTD, MTTR, false positives) to identify control gaps and inform improvements. Translates complex monitoring outputs into actionable insights for stakeholders across IT, Risk, and Security. Innovates in detection methodologies, leveraging behavioral analytics, anomaly detection, and adversary simulations. Acts as a problem‑solver during incidents, ensuring monitoring outputs guide rapid containment and response.

Effectiveness & Value Creation: Leads the build‑out of the CCM function from the ground up, establishing governance, processes, and reporting. Structures, plans, and executes monitoring programs and initiatives, balancing near‑term needs with long‑term maturity goals. Delivers measurable outcomes (visibility, faster detection, reduced dwell time) that directly enhance business resilience. Proactively manages resources, balancing full‑time staff and contractors to deliver capability within deadlines. Prioritises actions with the highest impact on reducing enterprise cyber risk.

Role Model: Operates with integrity, safeguarding BCG and client data through responsible monitoring practices. Promotes a culture of transparency, accountability, and data‑driven decision‑making in the team. Demonstrates perseverance and adaptability in building a new function with high visibility and expectations. Creates an inclusive working environment that values diverse technical and analytical perspectives. Leads by example, modeling sustainable workload practices even under incident‑driven pressure.

Communication, Presence & Influence: Develops and delivers clear dashboards, reports, and executive communications on monitoring outputs. Shapes perspectives by translating technical monitoring metrics into risk‑ and business‑relevant insights. Communicates effectively across technical and non‑technical audiences, ensuring alignment with IT and business leaders. Leads conversations in operational reviews, incident post‑mortems, and governance forums. Encourages open dialogue within the team, and fosters credibility with cross‑functional partners.

Teaming & Collaboration: Builds strong partnerships with SOC, Offensive Security, IT Operations, and Security Architecture teams. Develops productive relationships across regions and business units to expand telemetry coverage. Works collaboratively with compliance, risk, and audit to align monitoring with enterprise governance. Anticipates and manages conflicts in data ownership, tool coverage, and priorities, resolving them constructively. Promotes knowledge‑sharing across security teams, reducing silos and strengthening collective defense.

People Development & Leadership: Defines the vision and purpose of the CCM function, instilling clarity and purpose for the team. Coaches and mentors analysts, engineers, and contractors to expand monitoring expertise. Provides stretch opportunities for team members to develop technical and leadership skills. Balances empowerment and oversight — ensuring autonomy in monitoring activities while maintaining governance discipline. Leads quality team meetings, defines clear objectives, and ensures alignment to SecOPS priorities. Provides frequent developmental feedback, fostering a culture of continuous learning and improvement.

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E-Verify Employer.

Global Cybersecurity Director - Security Operations in Ewell employer: code4

At Boston Consulting Group, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation. Our commitment to employee growth is evident through our comprehensive training programmes and opportunities for advancement, particularly in the rapidly evolving field of cybersecurity. Located in Epsom and Ewell, UK, we provide a supportive environment where diverse perspectives are valued, ensuring that our team members can thrive while making a meaningful impact on global security challenges.
C

Contact Detail:

code4 Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Global Cybersecurity Director - Security Operations in Ewell

✨Tip Number 1

Network like a pro! Get out there and connect with folks in the cybersecurity field. Attend industry events, webinars, or even local meetups. The more people you know, the better your chances of landing that dream job.

✨Tip Number 2

Show off your skills! Create a portfolio or a personal website where you can showcase your projects, achievements, and any relevant certifications. This gives potential employers a taste of what you can bring to the table.

✨Tip Number 3

Prepare for interviews like it’s game day! Research the company, understand their cybersecurity needs, and be ready to discuss how your experience aligns with their goals. Practice common interview questions and have your own questions ready to show your interest.

✨Tip Number 4

Don’t forget to apply through our website! We’ve got loads of opportunities waiting for you. Plus, applying directly shows your enthusiasm and commitment to joining our team at BCG.

We think you need these skills to ace Global Cybersecurity Director - Security Operations in Ewell

Cybersecurity Operations
Security Monitoring
SIEM
SOAR
Telemetry Integration
Threat Intelligence
Log Management
Metrics-Driven Monitoring
NIST CSF
MITRE ATT&CK
Anomaly Detection
Behavioral Analytics
Leadership Skills
Communication Skills
Team Development

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the role of Global Cybersecurity Director. Highlight your experience in cybersecurity operations, especially in security monitoring and SOC leadership. We want to see how your skills align with what we’re looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re passionate about cybersecurity and how your background makes you the perfect fit for BCG. Don’t forget to mention specific achievements that demonstrate your expertise.

Showcase Your Leadership Skills: As a director, we need to see your leadership chops! Include examples of how you've built and led teams in the past. Share stories that illustrate your ability to inspire and develop high-performing teams in cybersecurity.

Apply Through Our Website: We encourage you to apply through our website for the best chance of being noticed. It’s super easy and ensures your application goes directly to us. Plus, you’ll get to see all the other cool opportunities we have at BCG!

How to prepare for a job interview at code4

✨Know Your Cybersecurity Stuff

Make sure you brush up on your knowledge of cybersecurity operations, especially around continuous monitoring and the technologies mentioned in the job description. Familiarise yourself with SIEM, SOAR, and threat intelligence platforms like Splunk and CrowdStrike Falcon. Being able to discuss these confidently will show that you're ready to lead BCG's Cybersecurity Continuous Monitoring programme.

✨Showcase Your Leadership Skills

As a potential leader for the CCM function, it's crucial to demonstrate your ability to build and inspire a high-performing team. Prepare examples of how you've successfully led teams in the past, focusing on mentoring and developing talent. Highlight your experience in creating strategies and roadmaps that align with business objectives.

✨Translate Tech Talk into Business Speak

You’ll need to communicate complex technical insights to senior leadership in a way that’s relevant to their business goals. Practice explaining technical metrics like MTTD and MTTR in simple terms, and think about how these metrics impact overall business resilience. This skill will be key in influencing decision-makers at BCG.

✨Prepare for Scenario-Based Questions

Expect to face scenario-based questions that assess your problem-solving skills during incidents. Think through past experiences where you had to act quickly and effectively in a crisis. Be ready to discuss how you used monitoring outputs to guide your response and what you learned from those situations.

Global Cybersecurity Director - Security Operations in Ewell
code4
Location: Ewell

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

C
  • Global Cybersecurity Director - Security Operations in Ewell

    Ewell
    Full-Time
    72000 - 108000 ÂŁ / year (est.)
  • C

    code4

    50-100
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>