Global Risk Manager

Boston Consulting Group
Boston Consulting Group

London, UK

Posted on Jul 30, 2026

Locations: London | Lisbon

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.

To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.



What You'll Do

As the Global Digital Enterprise Risk Manager, you will help strengthen BCG’s Enterprise Risk Management (ERM) program with a primary focus on IT Services & Cyber Risk and Data & AI Risk. Working across global teams, you will help ensure the firm’s risk management approach remains forward-looking by strengthening capabilities to proactively identify, assess, monitor, and respond to emerging risks across the rapidly evolving digital landscape. You will translate complex technology, IT Services, cyber, data, and AI risks into clear, actionable insights while supporting consistent, transparent enterprise risk management practices across the firm.

In this role, you will partner with colleagues across Digital, Information Technology, Information Security, Privacy, Legal, Compliance, and other business functions to drive cross-functional risk initiatives. You will translate complex risk information into clear, executive-ready insights, enabling informed decision-making, and helping foster a strong risk-aware culture across BCG.

  • Support the continued evolution of BCG’s Enterprise Risk Management program, with primary responsibility for IT Services & Cyber Risk and Data & AI Risk.
  • Build strong partnerships with stakeholders across IT Services & Cyber Risk and Data & AI Risk domains, delivering responsive, high-quality risk support and guidance while balancing pace, rigor, and business need.
  • Partner with ERM workstreams and cross-functional stakeholders to drive a coordinated, enterprise-wide approach to digital risk management.
  • Develop executive-ready presentations, dashboards, and reports that communicate key risk insights, trends, and recommendations.
  • Monitor and analyze enterprise risk information to proactively identify emerging IT services, cyber, data, and AI risks, assess potential business impacts, and support mitigation planning.
  • Develop and maintain key risk indicators (KRIs), risk sensing metrics, and executive reporting that support the proactive identification, monitoring, and communication of emerging technology, IT Services, Cyber, Data, and AI risks across the enterprise.
  • Escalate material IT Services & Cyber Risk and Data & AI Risk issues through BCG’s enterprise risk governance and escalation framework, ensuring timely executive visibility, effective decision-making, and appropriate risk oversight.
  • Coordinate periodic enterprise risk register reviews for the IT Services & Cyber Risk and Data & AI Risk domains, ensuring risks are appropriately assessed, documented, and integrated into the broader Enterprise Risk Management risk register, reporting, and governance processes.
  • Enable consistent risk reporting, governance, and communications across functions, promoting transparency and informed decision-making.
  • Lead cross-functional projects and influence stakeholders to advance strategic risk initiatives and improve enterprise risk processes.
  • Contribute to the ongoing enhancement of ERM methodologies, reporting frameworks, and governance practices to support a scalable and effective risk management program.


What You'll Bring

  • 7+ years of experience in enterprise risk management, technology risk, cyber risk, IT services risk, or related discipline.
  • Experience assessing and managing IT services, cyber, data, and AI-related risks within complex, global organizations.
  • Knowledge of enterprise risk management frameworks (COSO ERM, ISO 31000), security frameworks (NIST CSF, ISO 27001), AI risk frameworks (NIST AI RMF), and key risk indicators (KRIs).
  • Excellent written and verbal communication skills, with the ability to translate complex, technical risk concepts into decision-ready materials for both technical and non-technical senior stakeholders.
  • Proven ability to drive adoption of risk processes and influence outcomes across business units without direct authority, building credibility, trust, and buy-in through collaboration, sound judgment, and effective stakeholder engagement.
  • Solid understanding of legal and regulatory considerations related to cybersecurity, data privacy, and AI in a global business environment.
  • Experience developing executive-ready presentations, dashboards, and reporting using PowerPoint, Power BI or Tableau, and governance, risk, and compliance (GRC) platforms. Experience with collaboration tools such as Microsoft Teams, Slack, or Trello is preferred.
  • Practical experience using AI and large language model (LLM) tools to accelerate risk analysis, reporting, and content development.
  • Bachelor’s degree in business, risk management, economics, computer science, information systems, cybersecurity, or related field. An advanced degree or professional certification, such as CRISC, CISA, CISM, or CRM, is a plus.
  • Ability to work across time zones; occasional travel may be required.
  • Strong analytical and problem-solving skills.
  • Fluent English and high professional integrity.

Success in this role requires strong business judgment, intellectual curiosity, and a collaborative mindset. You are comfortable navigating ambiguity, adapting to evolving priorities, and balancing multiple initiatives in a dynamic global environment. You build trusted relationships across senior stakeholders, cross-functional partners, and teams, communicate complex risk topics with clarity and diplomacy, and translate evolving non-financial risks into practical business insights that enable informed decision-making.



Who You'll Work With

You will be part of BCG’s Enterprise Risk Management team, partnering with colleagues across the firm to strengthen enterprise-wide risk management capabilities and support informed decision-making.

In this role, you will work closely with the Head of Enterprise Risk Management, Chief Risk Officer (CRO), Chief Information Officer (CIO), Chief Information Security Officer (CISO), and teams across Digital, Data Governance & AI, Legal, Privacy, Compliance, and Internal Audit. You will also collaborate with business leaders and cross-functional stakeholders around the world to identify emerging risks, strengthen governance, and enable consistent risk management practices.

As part of a globally connected team, you will help shape the firm’s enterprise approach to managing technology, cyber, data, and AI risks while contributing to strategic initiatives that strengthen BCG’s enterprise risk program and foster a strong risk-aware culture.



Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E - Verify Employer. Click here for more information on E-Verify.