Boston Consulting Group
Global Risk Manager

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Locations: London | Lisbon
Who We Are
Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation—inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.
To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.
What You'll Do
As the Global Digital Enterprise Risk Manager, you will help strengthen BCG’s Enterprise Risk Management (ERM) program with a primary focus on IT Services & Cyber Risk and Data & AI Risk. Working across global teams, you will help ensure the firm’s risk management approach remains forward-looking by strengthening capabilities to proactively identify, assess, monitor, and respond to emerging risks across the rapidly evolving digital landscape. You will translate complex technology, IT Services, cyber, data, and AI risks into clear, actionable insights while supporting consistent, transparent enterprise risk management practices across the firm.
In this role, you will:
- Partner with colleagues across Digital, Information Technology, Information Security, Privacy, Legal, Compliance, and other business functions to drive cross-functional risk initiatives.
- Translate complex risk information into clear, executive-ready insights, enabling informed decision-making, and helping foster a strong risk-aware culture across BCG.
- Support the continued evolution of BCG’s Enterprise Risk Management program, with primary responsibility for IT Services & Cyber Risk and Data & AI Risk.
- Build strong partnerships with stakeholders across IT Services & Cyber Risk and Data & AI Risk domains, delivering responsive, high-quality risk support and guidance while balancing pace, rigor, and business need.
- Partner with ERM workstreams and cross-functional stakeholders to drive a coordinated, enterprise-wide approach to digital risk management.
- Develop executive-ready presentations, dashboards, and reports that communicate key risk insights, trends, and recommendations.
- Monitor and analyze enterprise risk information to proactively identify emerging IT services, cyber, data, and AI risks, assess potential business impacts, and support mitigation planning.
- Develop and maintain key risk indicators (KRIs), risk sensing metrics, and executive reporting that support the proactive identification, monitoring, and communication of emerging technology, IT Services, Cyber, Data, and AI risks across the enterprise.
- Escalate material IT Services & Cyber Risk and Data & AI Risk issues through BCG’s enterprise risk governance and escalation framework, ensuring timely executive visibility, effective decision-making, and appropriate risk oversight.
- Coordinate periodic enterprise risk register reviews for the IT Services & Cyber Risk and Data & AI Risk domains, ensuring risks are appropriately assessed, documented, and integrated into the broader Enterprise Risk Management risk register, reporting, and governance processes.
- Enable consistent risk reporting, governance, and communications across functions, promoting transparency and informed decision-making.
- Lead cross-functional projects and influence stakeholders to advance strategic risk initiatives and improve enterprise risk processes.
- Contribute to the ongoing enhancement of ERM methodologies, reporting frameworks, and governance practices to support a scalable and effective risk management program.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What You'll Bring
- 7+ years of experience in enterprise risk management, technology risk, cyber risk, IT services risk, or related discipline.
- Experience assessing and managing IT services, cyber, data, and AI-related risks within complex, global organizations.
- Knowledge of enterprise risk management frameworks (COSO ERM, ISO 31000), security frameworks (NIST CSF, ISO 27001), AI risk frameworks (NIST AI RMF), and key risk indicators (KRIs).
- Excellent written and verbal communication skills, with the ability to translate complex, technical risk concepts into decision-ready materials for both technical and non-technical senior stakeholders.
- Proven ability to drive adoption of risk processes and influence outcomes across business units without direct authority, building credibility, trust, and buy-in through collaboration, sound judgment, and effective stakeholder engagement.
- Solid understanding of legal and regulatory considerations related to cybersecurity, data privacy, and AI in a global business environment.
- Experience developing executive-ready presentations, dashboards, and reporting using PowerPoint, Power BI or Tableau, and governance, risk, and compliance (GRC) platforms. Experience with collaboration tools such as Microsoft Teams, Slack, or Trello is preferred.
- Practical experience using AI and large language model (LLM) tools to accelerate risk analysis, reporting, and content development.
- Bachelor’s degree in business, risk management, economics, computer science, information systems, cybersecurity, or related field. An advanced degree or professional certification, such as CRISC, CISA, CISM, or CRM, is a plus.
- Ability to work across time zones; occasional travel may be required.
- Strong analytical and problem-solving skills.
- Fluent English and high professional integrity.
- Success in this role requires strong business judgment, intellectual curiosity, and a collaborative mindset. You are comfortable navigating ambiguity, adapting to evolving priorities, and balancing multiple initiatives in a dynamic global environment. You build trusted relationships across senior stakeholders, cross-functional partners, and teams, communicate complex risk topics with clarity and diplomacy, and translate evolving non-financial risks into practical business insights that enable informed decision-making.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Who You'll Work With
You will be part of BCG’s Enterprise Risk Management team, partnering with colleagues across the firm to strengthen enterprise-wide risk management capabilities and support informed decision-making.
In this role, you will work closely with the Head of Enterprise Risk Management, Chief Risk Officer (CRO), Chief Information Officer (CIO), Chief Information Security Officer (CISO), and teams across Digital, Data Governance & AI, Legal, Privacy, Compliance, and Internal Audit. You will also collaborate with business leaders and cross-functional stakeholders around the world to identify emerging risks, strengthen governance, and enable consistent risk management practices.
As part of a globally connected team, you will help shape the firm’s enterprise approach to managing technology, cyber, data, and AI risks while contributing to strategic initiatives that strengthen BCG’s enterprise risk program and foster a strong risk-aware culture.
Boston Consulting Group is an Equal Opportunity Employer.
All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E - Verify Employer. Click here for more information on E-Verify.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location