About the Role
As the Global Digital Enterprise Risk Manager, you will strengthen BCG’s Enterprise Risk Management (ERM) program, focusing on IT Services & Cyber Risk and Data & AI Risk. You will ensure the firm’s risk management approach is forward-looking by enhancing capabilities to identify, assess, monitor, and respond to emerging digital risks. This role involves translating complex technology and risk information into actionable insights and supporting consistent enterprise risk management practices.
Responsibilities
- Support the continued evolution of BCG’s Enterprise Risk Management program, with primary responsibility for IT Services & Cyber Risk and Data & AI Risk.
- Build strong partnerships with stakeholders across IT Services & Cyber Risk and Data & AI Risk domains, delivering responsive, high-quality risk support and guidance.
- Partner with ERM workstreams and cross-functional stakeholders to drive a coordinated, enterprise-wide approach to digital risk management.
- Develop executive-ready presentations, dashboards, and reports that communicate key risk insights, trends, and recommendations.
- Monitor and analyze enterprise risk information to proactively identify emerging IT services, cyber, data, and AI risks, assess potential business impacts, and support mitigation planning.
- Develop and maintain key risk indicators (KRIs), risk sensing metrics, and executive reporting that support the proactive identification, monitoring, and communication of emerging risks.
- Escalate material IT Services & Cyber Risk and Data & AI Risk issues through BCG’s enterprise risk governance and escalation framework.
- Coordinate periodic enterprise risk register reviews for the IT Services & Cyber Risk and Data & AI Risk domains.
- Enable consistent risk reporting, governance, and communications across functions, promoting transparency and informed decision-making.
- Lead cross-functional projects and influence stakeholders to advance strategic risk initiatives and improve enterprise risk processes.
- Contribute to the ongoing enhancement of ERM methodologies, reporting frameworks, and governance practices.
Requirements
- 7+ years of experience in enterprise risk management, technology risk, cyber risk, IT services risk, or related discipline.
- Experience assessing and managing IT services, cyber, data, and AI-related risks within complex, global organizations.
- Knowledge of enterprise risk management frameworks (COSO ERM, ISO 31000), security frameworks (NIST CSF, ISO 27001), AI risk frameworks (NIST AI RMF), and key risk indicators (KRIs).
- Excellent written and verbal communication skills, with the ability to translate complex, technical risk concepts into decision-ready materials for both technical and non-technical senior stakeholders.
- Proven ability to drive adoption of risk processes and influence outcomes across business units without direct authority.
- Solid understanding of legal and regulatory considerations related to cybersecurity, data privacy, and AI in a global business environment.
- Experience developing executive-ready presentations, dashboards, and reporting using PowerPoint, Power BI or Tableau, and governance, risk, and compliance (GRC) platforms.
- Practical experience using AI and large language model (LLM) tools to accelerate risk analysis, reporting, and content development.
- Ability to work across time zones; occasional travel may be required.
- Strong analytical and problem-solving skills.
- Fluent English and high professional integrity.
- Strong business judgment, intellectual curiosity, and a collaborative mindset.
- Comfortable navigating ambiguity, adapting to evolving priorities, and balancing multiple initiatives in a dynamic global environment.
- Ability to build trusted relationships across senior stakeholders, cross-functional partners, and teams.
- Ability to communicate complex risk topics with clarity and diplomacy.
- Ability to translate evolving non-financial risks into practical business insights that enable informed decision-making.
Skills
- Enterprise Risk Management
- Technology Risk
- Cyber Risk
- IT Services Risk
- COSO ERM
- ISO 31000
- NIST CSF
- ISO 27001
- NIST AI RMF
- Key Risk Indicators (KRIs)
- PowerPoint
- Power BI
- Tableau
- GRC platforms
- Microsoft Teams
- Slack
- Trello
- AI tools
- Large language model (LLM) tools
Location
- London
- Lisbon
Work Type
- Global
- Hybrid
Experience Level
- 7+ years of experience
Education Level
- Bachelor’s degree in business, risk management, economics, computer science, information systems, cybersecurity, or related field.
- Advanced degree or professional certification (CRISC, CISA, CISM, or CRM) is a plus.
About the Company
- Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities.
- BCG was the pioneer in business strategy when it was founded in 1963.
- Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
- To succeed, organizations must blend digital and human capabilities.
- Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change.
- BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose.
- We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.
Equal Opportunity
- Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
- BCG is an E - Verify Employer.
