McDonald's Corporation
MC

Senior Director, Cyber Third-Party Risk Management

McDonald's Corporation
Chicago, IL
Hybrid
Full-time
$237k - $296k
2d ago

Apt Insight

In this executive leadership role, you will be accountable for designing, leading, and modernizing McDonald’s global third-party cyber risk management (TPRM) capability across a complex, distributed international technology and supplier ecosystem. You will spearhead the transformation of TPRM from traditional, questionnaire-driven processes into an intelligence-driven, automated program utilizing technical validation, continuous monitoring, and risk quantification to protect the brand from systemic and concentration risk.

Is This a Good Match for You?

Fact Focus95Conscientiousness83Logic Focus88Analytical Nature75Detail Orientation90
The graph above shows a positive alignment between your profile and the role of this job. Your working style and professional priorities appear compatible with their organizational approach, which provides useful context when evaluating opportunities here.Beyond the specific role you're considering, understanding the company itself helps you make a better decision. Our analysis factors in elements like culture, management style, and organizational stability—things that significantly impact day-to-day satisfaction but are hard to glean from a job description alone. The graph above summarizes how this job stacks up against your stated preferences.
Unlock your full match with Apt ProStart with the AI-powered career test to unlock your personal career mentor, full company insights, and a personalized job board designed around your goals.

Responsibilities

Own and evolve the global third-party risk management strategy and operating model to ensure alignment with enterprise cyber risk governance expectations.
Oversee the end-to-end third-party risk lifecycle, including onboarding, inherent risk tiering, due diligence, technical assessment, continuous monitoring, and secure offboarding.
Drive the adoption of automation, continuous monitoring tools, and AI-assisted techniques to evaluate third-party cyber posture and emerging risk signals in real time.
Partner with cross-functional leaders across Global Supply Chain, Procurement, Legal, Privacy, Enterprise Risk Management, and market CTOs to standardize enterprise security configurations.
Oversee in-depth technical risk reviews for high-risk vendors, including threat modeling, architecture reviews, and vulnerability assessments.
Maintain a centralized enterprise inventory of third-party engagements and deliver executive reporting on risk trends and concentration posture to the VP of Cyber GRC.
Build, mentor, and lead a high-performing team of third-party risk professionals and technical assessment specialists.

Qualifications

At least 12 years of experience in cybersecurity, technology risk, or information security with significant ownership of supplier cyber risk management in large enterprise environments.
Proven track record of designing and leading a global end-to-end TPRM program across the full supplier lifecycle.
Demonstrated success modernizing TPRM capabilities by integrating technical validation, continuous monitoring, and automation.
Strong technical fluency across cloud infrastructure, APIs, identity management, data flows, and modern integration architectures.
Demonstrated leadership experience building and managing high-performing security teams and influencing executive stakeholders across business and technical domains.
Nice to Have
Familiarity with assessing systemic, concentration, and fourth-party risks across complex supply chains.
Working knowledge of industry frameworks and regulations such as NIST CSF, ISO 27001, GDPR, and CCPA.
Industry-recognized professional security and risk certifications such as CISSP, CISM, CRISC, or CISA.

Work Environment

The position is based in Chicago, Illinois, operating under a hybrid work arrangement.
The role requires collaborating globally across distributed, market-driven, and franchise-based operations.
You will lead in a collaborative, fast-paced corporate environment that emphasizes inclusivity, accountability, and technical innovation.
Standard full-time business hours of 40 hours per week apply, with occasional flexibility required for global stakeholder collaboration.

Benefits & Perks

The role offers an expected base salary range of $237,102 to $296,377 per year, depending on experience.
Eligible for annual performance bonuses and McDonald's long-term incentive plan (stock and equity grants).
Comprehensive health and welfare benefits including medical, prescription drug, dental, vision, mental health coverage, and life insurance.
Access to generous leave and education programs, including sabbatical opportunities and tuition assistance.