McDonalds

Sr Director, Cyber Third-Party Risk Management

McDonalds$237K — $296K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years in cybersecurity, technology risk, or information security with a focus on third-party cyber risk management in large enterprises.
  • Proven track record of designing and leading comprehensive TPRM programs through the entire risk lifecycle.
  • Experience modernizing TPRM beyond questionnaires to include technical validation and continuous monitoring methodologies.
  • Strong technical fluency across cloud technologies, APIs, and data flows, facilitating partnership with security architects.
  • Experience in conducting in-depth technical assessments for high-risk third parties, including threat modeling and vulnerability assessments.
  • Ability to navigate and standardize security requirements in distributed or franchise-based environments.
  • Leadership experience in building effective teams and influencing senior stakeholders in cross-functional areas.

Responsibilities

  • Own and enhance McDonald's global TPRM strategy to ensure alignment with enterprise cyber risk governance.
  • Transform TPRM processes to integrate technical validation and continuous monitoring.
  • Manage the full lifecycle of third-party risk, from onboarding to secure offboarding.
  • Implement near real-time continuous monitoring for third-party cyber posture and emerging risk signals.
  • Explore and apply innovative techniques for evidence collection and risk assessment.
  • Maintain a comprehensive inventory of third-party engagements and treatment decisions across the enterprise.
  • Lead a high-performing team of third-party risk professionals, fostering a culture of accountability and innovation.

Benefits

  • Comprehensive health insurance including medical, dental, vision, and mental health coverage.
  • Life insurance coverage for employees.
  • Bonus program based on individual and company performance.
  • Long-term incentive plans providing potential for stock or equity grants.
Full Job Description
Department Overview

The Senior Director of Cyber Third-Party Risk Management (TPRM) is accountable for leading and modernizing McDonald's global third-party cyber risk management capability across a highly distributed, market-driven technology and supplier ecosystem. This role owns the design and execution of a scalable, intelligence-driven TPRM program that moves beyond traditional, questionnaire-centric approaches and delivers meaningful, defensible assurance over third-party cyber risk.

The role places particular emphasis on third-party providers operating within IDL market segments, where complex technology integrations, data flows, and operational dependencies introduce elevated cyber and business risk. The Senior Director develops deep understanding of these integrations, works closely with security architecture and technical SMEs to validate control effectiveness, and ensures that third-party solutions supporting markets do not introduce unacceptable systemic or concentration risk.

This leader partners closely with Global Supply Chain, Indirect Procurement, Legal, Privacy, ERM, and IDL Market CTOs to reduce fragmentation across markets by translating market-specific solution sets into standardized enterprise agreements, security configurations, and control expectations. A core mandate of the role is innovation: designing new, differentiated approaches to third-party assurance that leverage automation, technical validation, and continuous monitoring rather than relying solely on static questionnaires.

Responsibilities

Program Leadership & Modernization
  • Own and evolve McDonald's global TPRM strategy and operating model, ensuring it is scalable, risk-based, and aligned to enterprise cyber risk governance expectations.
  • Transform TPRM from a primarily questionnaire-driven process into a modern program that blends survey efficiency with technical validation, continuous monitoring, and risk quantification.
  • Establish and operate the full third-party risk lifecycle, including onboarding, inherent risk tiering, due diligence, technical assessment, ongoing monitoring, reassessment, and secure offboarding.


Continuous Monitoring, Automation & Innovation
  • Implement continuous monitoring capabilities to provide near real-time visibility into third-party cyber posture, control degradation, and emerging risk signals.
  • Explore and deploy innovative approaches, including automation and AI-assisted techniques, for evidence collection, risk scoring, and exception management.
  • Continuously evaluate emerging tools, data sources, and assurance models to improve coverage, reduce friction, and increase signal quality beyond traditional questionnaires.


Governance, Reporting & Escalation
  • Maintain a centralized inventory of third-party engagements, risk tiers, and risk treatment decisions across the enterprise.
  • Provide clear, concise reporting on third-party cyber risk posture, trends, and concentration risk to the Vice President, Cyber GRC and senior leadership.

Leadership & Collaboration
  • Build and lead a high-performing team of third-party risk professionals and technical reviewers.
  • Reinforce a culture of accountability, innovation, and constructive challenge consistent with McDonald's values and operating principles


Qualifications

  • 12+ years of experience in cybersecurity, technology risk, or information security, with significant ownership of third-party / supplier cyber risk management in large, complex enterprises.
  • Proven experience designing and leading a global TPRM program, including the full third-party risk lifecycle (onboarding, tiering, due diligence, monitoring, reassessment, and offboarding).
  • Demonstrated success modernizing TPRM, moving beyond questionnaire-centric models to risk-based approaches that incorporate technical validation, automation, and continuous monitoring.
  • Strong technical fluency across cloud, APIs, identity, data flows, and integration architectures, with the ability to partner credibly with security architects and technical SMEs.
  • Experience overseeing deep technical assessments for high-risk or critical third parties (e.g., architecture reviews, threat modeling, penetration testing results, vulnerability assessments).
  • Ability to operate effectively in highly distributed, market-driven or franchise-based environments, translating local solutions into standardized enterprise security requirements.
  • Demonstrated leadership experience, including building and leading high-performing teams and influencing senior stakeholders across Technology, Procurement, Legal, Privacy, and ERM.
  • Strong executive communication skills, with experience reporting third-party cyber risk posture and trends to senior leadership.


Preferred
  • Familiarity with systemic, concentration, and fourth-party risk.
  • Working knowledge of NIST CSF, ISO 27001, GDPR, and CCPA.
  • Relevant certifications (e.g., CISSP, CISM, CRISC, CISA)


Compensation

Bonus Eligible: Yes

Long - Term Incentive: Yes

Benefits Eligible: Yes

Salary Range

The expected salary range for this role is $237,102 - $296,377 per year

The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we may also consider your experience, and other job-related factors.

Additional Information:

Benefits eligible: This position offers health and welfare benefits, including but not limited to comprehensive health insurance, which includes medical, prescription drug, mental health, dental, and vision coverage, as well as, life insurance.

Bonus eligible: This position is eligible for a bonus, calculated based on individual and company performance.

Long term Incentive eligible: This position is eligible for stock or other equity grants pursuant to McDonald's long-term incentive plan.

About McDonalds

McDonald's Careers

Join the vibrant team at McDonald's, a global leader in the fast-food industry, and be part of a company known for its exceptional culture and commitment to innovation and leadership. At McDonald's, we offer a range of job opportunities that cater to a variety of skills and professional aspirations, making it an ideal place to jumpstart or advance your career. Work You'll Do At McDonald's, every position is an opportunity to grow. Whether you're looking for an entry-level role or a managerial position, you'll find that McDonald's supports your career ambitions with robust training programs and growth opportunities. Our team is dedicated to helping you develop the leadership and professional skills necessary for success in any endeavor. Join our diverse team and contribute to a culture that values innovation, leadership, and diversity. McDonald's is not just a workplace but a community where you can thrive professionally and personally. McDonald's Employment Benefits Choose a career at McDonald's and enjoy a comprehensive benefits package that supports both your professional and personal life. From competitive salaries and health benefits to employee discounts and flexible schedules, McDonald's is committed to the well-being of our team members. We also offer exclusive leadership and diversity training programs that empower our employees to take on new challenges and lead with confidence. Internship Opportunities Kickstart your career with a McDonald's internship. Our internships provide invaluable workplace experience and a chance to develop essential skills in a supportive environment. Interns at McDonald's work on real projects, learn from industry leaders, and gain exposure to the operational excellence that drives our global success. Innovation at McDonald's At the heart of McDonald's culture is a drive for innovation. We continuously seek innovative solutions to enhance the dining experience of our customers and improve our operational efficiencies. By joining our team, you'll collaborate on exciting projects that push the boundaries of what's possible in the fast-food industry. Networking and Professional Development McDonald's encourages professional development and networking through various initiatives and platforms. Connect with colleagues, mentors, and industry leaders who can help you navigate your career path and achieve your professional goals. Our commitment to career development is reflected in our ongoing training programs and our proactive approach to internal promotions and hiring. Join Our Team Explore the job opportunities at McDonald's and find the position that matches your skills and interests. We are hiring creative, curious, and motivated individuals who are ready to contribute to our dynamic team. Check out our open positions and apply today to take the first step towards a rewarding career at McDonald's. Stay Connected Keep up to date with the latest career tips, company news, and industry insights—all from the people who work here at McDonald's. Subscribe to our careers blog and personalize your experience to receive updates that align with your career interests. McDonald's is more than just a company—it's a place where you can make a difference. Join us and help shape the future of the fast-food industry while building a career that you can be proud of.
Learn more about McDonalds
Size
200,000 employees
Market Cap
$194.1 billion
Industry
Net Income
$4.7 billion
Founded
1955
5 Year Trend
-1.2%
Revenue
$19.2 billion
NASDAQ

Similar Jobs

More Jobs at McDonalds

More Information Technology Jobs

Find similar Sr Director, Cyber Third-Party Risk Management jobs: