Volver a ofertas

Global Cybersecurity Associate - Security Operations

BCG · Gurgaon, Haryana, India · India

Join BCG in Gurgaon as a Global Cybersecurity Associate, driving secure application testing across web, mobile and AI systems. Contribute to protecting clients worldwide while advancing your career in cybersecurity.

Vista previa generada por IA

Join BCG in Gurgaon as a Global Cybersecurity Associate, driving secure application testing across web, mobile and AI systems.

Contribute to protecting clients worldwide while advancing your career in cybersecurity.

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.

To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.

What You'll Do

As part of BCG's Information Security & Risk Management, you will support application security assessments. This includes managing and performing penetration testing of applications across various platforms to identify vulnerabilities and support remediation efforts.

Your responsibilities include:

Perform penetration testing activities as per BCG’s established process.

Analyze and validate vulnerabilities identified through both automated and manual testing, including the identification and elimination of false positives.

Report, monitor, and support remediation efforts while coordinating with stakeholders to address and close identified vulnerabilities.

Triage and validate security issues reported through the Responsible Disclosure Program.

Perform configuration reviews and security assessments of SaaS and COTS products.

Maintain penetration testing, vulnerability management, and application compliance trackers.

Maintain and update security process documentation, standards, and operational procedures.

Develop and maintain automation scripts and processes to improve the efficiency of application security operations.

Prepare and deliver periodic vulnerability, risk, and program status reporting to technical and business stakeholders.

Manage and maintain GitHub Actions and CI/CD workflows to support application security processes.

Develop and execute Python scripts to extract, consolidate, and maintain application security findings within the organization's vulnerability management platform.

Coordinate and manage penetration testing engagements performed by external vendors, including scope validation, scheduling, stakeholder communication, report review, remediation tracking, and overall engagement management.

Collaborate with application owners, development teams, infrastructure teams, and other stakeholders to gather testing prerequisites, facilitate assessments, and support remediation activities.

What You'll Bring

1-3 years of experience in application & infrastructure penetration testing

Approximately 1 year of experience with DAST tools such as Acunetix360/Invicti and SAST tools such as Veracode.

Hands-on experience in application security testing, vulnerability management, and remediation workflows.

Experience coordinating with internal stakeholders and external security testing vendors is preferred.

Familiarity with identity and authentication technologies such as IdPs, SSO, SAML, OAuth 2.0, and OpenID Connect (OIDC).

Working knowledge of Windows and Linux OS, Active Directory, and network protocols (TCP/IP, IPv4, IPv6, DNS, HTTP/HTTPS).

Proficiency with scripting (Python, PowerShell).

Bachelor’s degree (or equivalent) in Computer Science, IT, or a related field

Exposure to security testing of AI-integrated applications, LLM-powered systems, AI agents, or MCP implementations is a plus.

Exposure to cloud platforms such as AWS, Azure, or GCP is a plus.

Industry certifications such as OSCP, eJPT, CEH, or equivalent are a plus.

Experience testing Kubernetes environments is a plus.

You’re Good At

Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.

BCG is an E - Verify Employer. Click here for more information on E-Verify.

Encuentra más ofertas como esta

Explora más ofertas activas de esta empresa o crea una cuenta en Insider Jobs para buscar, guardar y seguir oportunidades en todo el job board.