> Markdown version of [/jobs/ext/2228162-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/2228162-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst - **Company:** The Boston Consulting Group, Inc. - **Location:** Atlanta, GA, United States - **Experience:** Experienced - **Salary:** $77,000.0 - $90,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Data Stores, Python (Programming Language), Cloud Services, Google Cloud, Software Security, Cyber Threat Analysis, Machine Learning Operations, Api Design, Devsecops - **Published:** August 25, 2026 - **Apply:** https://www.dice.com/job-detail/7f2c3763-cea3-4d99-be52-a2d46f34d637 ## About the Role * 2-4 years in information security, including 2+ years in cloud security operations. * Hands-on experience triaging findings in CNAPP or cloud security platforms. * Working knowledge of AWS, Azure, or Google Cloud security fundamentals. * Ability to assess exploitability, permissions, data exposure, and attack path context. * Basic awareness of AI workload risks, including model access and inference endpoint exposure. * Clear written communication for developer-facing findings, remediation steps, and escalation notes. * Python, Bash, or API experience for triage automation and finding enrichment., Preferred certifications are helpful but not required, including AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer, CCSP, or Certified Kubernetes Security Specialist. ## Description You will join BCG's Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. In this role, you will help protect BCG's global multi-cloud environment by monitoring and triaging cloud security findings, applying contextual risk reasoning, and supporting remediation across AWS, Azure, and Google Cloud. You will also support BCG's growing AI security coverage by helping identify exposure across AI and LLM workloads, cloud services that support AI-enabled applications, and emerging AI-adjacent attack paths. You will work with more senior team members to interpret risk, escalate priority issues, and provide clear, actionable guidance to engineering and platform teams. You will: * Monitor, triage, and investigate findings across CNAPP capabilities, including CSPM, CIEM, KSPM, CWPP, IaC security, secrets detection, SCA/SBOM, API security posture, external attack surface management, and AI workload exposure. * Apply contextual risk reasoning to cloud and AI-adjacent findings, considering exploitability, attack path reachability, effective permissions, data exposure, model access, and potential blast radius. * Help identify toxic combinations across cloud, identity, workload, API, and AI service configurations that may create meaningful exposure when chained together. * Investigate zero-day and critical vulnerability exposure across cloud workloads, containerized services, inference endpoints, orchestration layers, and supporting data stores. * Monitor AI and LLM workload risks such as exposed inference endpoints, overly permissive model access, unsafe secrets handling, vector store exposure, and LLMOps pipeline misconfigurations. * Support remediation by translating findings into clear, developer-actionable guidance, tracking open items, following up with asset owners, and escalating aged or blocked issues with clear risk context. * Contribute to shift-left security by reviewing IaC and CI/CD findings, supporting security guardrail adoption, and helping reduce recurring cloud and AI workload misconfigurations. * Write scripts, improve saved queries, update runbooks, and contribute observations that improve CNAPP signal quality, automation, and operational consistency., You will be part of BCG's Security Operations team within Information Security and Risk Management, focused on Attack Surface Management. You will work closely with cloud engineering, platform engineering, security architecture, threat intelligence, and DevSecOps teams to identify, prioritize, and reduce cloud security risk across BCG's global technology environment. The team operates in a highly collaborative, technically rigorous setting, with a shared focus on clear risk ownership, practical remediation, and continuous improvement. ## Related Videos - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [API Design - Getting Started](https://www.wearedevelopers.com/videos/33-api-design-getting-started) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)