Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr Director, Cyber Third-Party Risk Management

$237.1k - $296.38k

McDonald's Corporation

Company Description: McDonald’s is proud to be one of the most recognized brands in the world, with restaurants in over 100 countries that serve 70 million customers daily.We continue to operate from a position of strength. Our updated growth strategy is focused on staying ahead of what our customers want and realizing further growth potential. Our relentless ambition is why McDonald’s remains one of the world’s leading corporations after almost 70 years. Joining McDonald's means thinking big and preparing for a career that can have influence around the world. At McDonald’s, we see every day as a chance to create positive impact. We lead through our values centered on inclusivity, service, integrity, community and family. From support of Ronald McDonald House to our Youth Opportunity project and sustainability initiatives, our values keep us dedicated to using our scale for good: good for our customers, people, industry and planet. We also offer a broad rangeofoutstanding benefits including a sabbatical program, tuition assistance and flexible work arrangements. Department Overview The Senior Director of Cyber Third-Party Risk Management (TPRM) is accountable for leading and modernizing McDonald’s global third-party cyber risk management capability across a highly distributed, market-driven technology and supplier ecosystem. This role owns the design and execution of a scalable, intelligence-driven TPRM program that moves beyond traditional, questionnaire-centric approaches and delivers meaningful, defensible assurance over third-party cyber risk. The role places particular emphasis on third-party providers operating within IDL market segments, where complex technology integrations, data flows, and operational dependencies introduce elevated cyber and business risk. The Senior Director develops deep understanding of these integrations, works closely with security architecture and technical SMEs to validate control effectiveness, and ensures that third-party solutions supporting markets do not introduce unacceptable systemic or concentration risk. This leader partners closely with Global Supply Chain, Indirect Procurement, Legal, Privacy, ERM, and IDL Market CTOs to reduce fragmentation across markets by translating market-specific solution sets into standardized enterprise agreements, security configurations, and control expectations. A core mandate of the role is innovation: designing new, differentiated approaches to third-party assurance that leverage automation, technical validation, and continuous monitoring rather than relying solely on static questionnaires. Responsibilities Program Leadership & Modernization Own and evolve McDonald’s global TPRM strategy and operating model, ensuring it is scalable, risk-based, and aligned to enterprise cyber risk governance expectations. Transform TPRM from a primarily questionnaire-driven process into a modern program that blends survey efficiency with technical validation, continuous monitoring, and risk quantification. Establish and operate the full third-party risk lifecycle, including onboarding, inherent risk tiering, due diligence, technical assessment, ongoing monitoring, reassessment, and secure offboarding. Continuous Monitoring, Automation & Innovation Implement continuous monitoring capabilities to provide near real-time visibility into third-party cyber posture, control degradation, and emerging risk signals. Explore and deploy innovative approaches, including automation and AI-assisted techniques, for evidence collection, risk scoring, and exception management. Continuously evaluate emerging tools, data sources, and assurance models to improve coverage, reduce friction, and increase signal quality beyond traditional questionnaires. Governance, Reporting & Escalation Maintain a centralized inventory of third-party engagements, risk tiers, and risk treatment decisions across the enterprise. Provide clear, concise reporting on third-party cyber risk posture, trends, and concentration risk to the Vice President, Cyber GRC and senior leadership. Leadership & Collaboration Build and lead a high-performing team of third-party risk professionals and technical reviewers. Reinforce a culture of accountability, innovation, and constructive challenge consistent with McDonald’s values and operating principles Qualifications 12+ years of experience in cybersecurity, technology risk, or information security, with significant ownership of third‑party / supplier cyber risk management in large, complex enterprises. Proven experience designing and leading a global TPRM program , including the full third‑party risk lifecycle (onboarding, tiering, due diligence, monitoring, reassessment, and offboarding). Demonstrated success modernizing TPRM , moving beyond questionnaire‑centric models to risk‑based approaches that incorporate technical validation, automation, and continuous monitoring . Strong technical fluency across cloud, APIs, identity, data flows, and integration architectures, with the ability to partner credibly with security architects and technical SMEs. Experience overseeing deep technical assessments for high‑risk or critical third parties (e.g., architecture reviews, threat modeling, penetration testing results, vulnerability assessments). Ability to operate effectively in highly distributed, market‑driven or franchise‑based environments , translating local solutions into standardized enterprise security requirements. Demonstrated leadership experience, including building and leading high‑performing teams and influencing senior stakeholders across Technology, Procurement, Legal, Privacy, and ERM. Strong executive communication skills, with experience reporting third‑party cyber risk posture and trends to senior leadership. Preferred Familiarity with systemic, concentration, and fourth‑party risk . Working knowledge of NIST CSF, ISO 27001, GDPR, and CCPA . Relevant certifications (e.g., CISSP, CISM, CRISC, CISA ) Compensation Bonus Eligible: Yes Long - Term Incentive: Yes Benefits Eligible: Yes Salary Range The expected salary range for this role is $237,102 - $296,377 per year The above represents the expectedsalaryrange for this job requisition. Ultimately, in determining yourpay, we may also consider your experience, and other job-related factors. Additional Information: Benefits eligible: This position offers health and welfare benefits, including but not limited to comprehensive health insurance, which includes medical, prescription drug, mental health, dental, and vision coverage, as well as, life insurance. Bonus eligible: This position is eligible for a bonus, calculated based on individual and company performance. Long term Incentive eligible: This position is eligible for stock or other equity grants pursuant to McDonald’s long-term incentive plan. McDonald’s is an equal opportunity employer committed to the diversity of our workforce. We promote an inclusive work environment that creates feel-good moments for everyone. McDonald’s provides reasonable accommodations to qualified individuals with disabilities as part of the application or hiring process or to perform the essential functions of their job. If you need assistance accessing or reading this job posting or otherwise feel you need an accommodation during the application or hiring process, please contact View email address on click.appcast.io. Reasonable accommodations will be determined on a case-by-case basis. McDonald’s provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training. Nothing in this job posting or description should be construed as an offer or guarantee of employment. #J-18808-Ljbffr McDonald's Corporation

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Sr Director, Cyber Third-Party Risk Management in Brooklyn, NY vacancy
  • $274k - $335k

    Job Summary Job Summary The Sr. Director, IT Sourcing is responsible for...  ...visibility and influence, managing large-scale partnerships, and...  ...enterprise value delivery and risk outcomes. Reports To: Global...  ...software, cloud, infrastructure, cyber, and digital services. Lead... 
    Cyber
    Senior
    Contract work
    Work at office
    Remote work

    CSL Plasma Inc.

    Brooklyn, NY
    5 days ago
  •  ...more details.The Global Director of Autonomous Incident...  ...budget planning, vendor management, and financial governance for global cyber operations tooling,...  ...staffing; optimize spend to risk reduction and service...  ...communications stakeholdersOversee third-party IR/forensics... 
    Cyber
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    1 day ago
  • $269.1k - $307.2k

    Director, Brex Integration Advisory & Oversight Capital One is...  ...quality, and data management. Technology & Data Risk Management (TDRM) is a small...  ...- $307,200 for Director, Cyber TechnicalRichmond, VA: $24...  ...guarantee and is not liable for third-party products, services, educational... 
    Cyber
    Full time
    Part time
    Interim role
    Local area
    Flexible hours

    Capital One National Association

    Brooklyn, NY
    2 days ago
  •  ...Cybersecurity GRC Analyst I, II, or III to support TPCRM through risk assessments, monitoring, and reporting across the vendor...  ..., Privacy, TPM, Procurement and Business Units to strengthen third-party cyber resilience. On-site position with strong growth opportunities... 
    Cyber

    New American Funding

    Brooklyn, NY
    1 day ago
  • $160k - $200k

     ...operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and...  ...by over 25,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations... 
    Cyber

    SecurityScorecard

    Jersey City, NJ
    1 day ago
  • $260k - $320k

     ...operating in 64 countries. Founded in 2013 by security and risk experts Dr. Alex Yampolskiy and Sam Kassoumeh and...  ...by over 25,000 organizations for self‑monitoring, third‑party risk management, board reporting, and cyber insurance underwriting — making all organizations... 
    Cyber

    SecurityScorecard

    Hoboken, NJ
    4 days ago
  •  ...with business stakeholders to update and manage business continuity plans, including...  ...relevant stakeholders Perform regular risk assessments of business practices toidentifyseverity...  ...network of support partners in Cyber, IT, Third-Party and Operational Resilience to spot... 
    Cyber
    Work at office
    Local area
    Work from home
    Worldwide

    SMBC Group

    Brooklyn, NY
    1 day ago
  • $149k - $248k

    Job Family: Management Consulting Travel Required: Up to...  ...Financial Services Risk Management & Regulatory...  ...experienced Associate Director to help clients address...  ...model risk management, third‑party risk management, and...  ...related topics such as cyber risk, data & AI governance... 
    Cyber
    Temporary work
    Immediate start
    Flexible hours

    Dovel Technologies, Inc

    Brooklyn, NY
    5 days ago
  • $140k - $225k

     ...you have.We are seeking a hands-on Sr HR Reporting & Analytics Manager to join our HRIS team and enhance our...  ....You’ll report to the Sr. Director of Total Rewards & HRIS and work from...  ...service analyticsEvaluate the need for third-party people analytics platforms and, if... 
    Senior
    Full time
    Work at office
    Immediate start
    Remote work
    Worldwide
    Flexible hours
    Shift work

    Collectors

    Jersey City, NJ
    18 hours ago
  •  ...overall cybersecurity posture, developing risk management plans, identifying practical...  ...while integrating findings from trusted third-party technical testing providers (e.g., penetration...  ...utilities build a complete picture of their cyber risk exposure and maturity, and guide... 
    Cyber
    Full time
    Temporary work
    Part time
    Casual work
    Live in
    Work at office
    Local area
    Remote work
    Flexible hours

    Stantec Consulting International Ltd.

    Brooklyn, NY
    4 days ago
  • $135k - $160k

    Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and... 
    Cyber
    Full time
    Remote work
    Flexible hours
    Shift work

    BitSight

    Brooklyn, NY
    5 days ago
  • $155.6k - $306.8k

     ...The mission of Quality and Risk Management (QRM) is to manage the risk...  .... Work you’ll do Deloitte’s Cyber QRM team is seeking a Quality...  ...Partners, Principals, Managing Directors, and engagement teams on...  ...vendor contracts (buy-side) for third-party software providers,... 
    Cyber
    Senior
    Contract work
    For subcontractor
    Work at office
    Local area

    Deloitte

    Jersey City, NJ
    4 days ago
  • $131k - $164k

     ...HR Business Partner (Sr. HRBP) to join our Global...  ...Change Management: Lead cross-functional...  ...diagnose organizational risk, and deliver proactive...  ...Engineering VPs, Product Directors, and UX leaders regarding...  ...will not pay fees to any third-party agency or company that... 
    Senior
    Work at office
    Local area
    Remote work
    Flexible hours
    Shift work

    Triwill Group

    Brooklyn, NY
    1 day ago
  • $152.7k - $294k

     ...Security program a step ahead of evolving business demands and cyber risks.Key Responsibilities:Strategic Program Development: Define...  ...Strategic Leadership: Exceptional program leadership and stakeholder management skills. Proven ability to lead cross-functional initiatives... 
    Cyber
    Summer holiday
    Local area
    Flexible hours
    Shift work

    EY (Ernst & Young)

    Hoboken, NJ
    18 hours ago
  • $76.6k - $157k

     ...and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative...  ....Coordinating with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams -... 
    Cyber
    Work at office
    Local area
    Visa sponsorship
    Shift work

    Deloitte

    Jersey City, NJ
    3 days ago
  • $218k - $272k

    ## Sr. Director - IT Govern, Strat, & InnovSolicitarlocations: Estados Unidos, Massachusetts,...  ...regulatory compliance and regulatory IT budget management** for Avangrid IT.The position ensures...  ...visibility into delivery performance, risks, dependencies, and outcomes.* Ensure the... 
    Senior
    Work experience placement
    Work at office
    Flexible hours
    Shift work

    Iberdrola Group

    Brooklyn, NY
    4 days ago
  • $170k - $185k

     ...deliverable. The Technical Program Director (TPD) is accountable for the...  ...and surfacing and resolving risks before they threaten the...  ...is explicitly not a product management role. The TPD does not own product...  ...infrastructure, vendor, and third‑party dependencies before they... 
    Shift work

    Cast & Crew Entertainment Services, LLC

    Brooklyn, NY
    4 days ago
  • $163.4k - $322.1k

     ...Summary Our Deloitte Cyber team understands the unique challenges...  ...powerful solutions and managed services that simplify...  ...execute strategies for integrated risk management (IRM), governance,...  ...)Security Operations (SecOps)Third-Party Risk Management (TPRM)10+... 
    Cyber
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    2 days ago
  • $150k - $225k

    Join Mizuho as a Cyber Defense, Adversary Emulation Director! The Cyber Defense organization within Mizuho Americas...  ...responsibility for vulnerability management, threat intelligence, threat hunting...  ...translate threat insight into measurable risk reduction. Automation, AI‑enabled... 
    Cyber
    Work at office
    Local area
    Remote work
    Worldwide

    Mizuho Financial Group Inc.

    Brooklyn, NY
    1 day ago
  • $176.72k - $265.08k

     ...Development, ProfessionalCompany: CitiThe Cyber Risk Remediation & Technology Modernization, Senior Vice President is a senior management level position responsible for...  ...from design to implementation including third party reviews and vulnerability assessments.Process... 
    Cyber
    Senior
    Full time

    Citigroup

    Jersey City, NJ
    1 day ago
  • $208.22k - $260.27k

     ...Organization Activation COE, is seeking a Sr. Director, Organization Activation Lead to drive...  ...together Organizational Design, Change Management, Communications, and Talent Strategy to...  ...change initiatives. Drive alignment, manage risks, and ensure strategic objectives are... 
    Senior
    Local area
    Flexible hours

    McDonald's Corporation

    Brooklyn, NY
    4 days ago
  •  ...HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with...  ...security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto... 
    Cyber
    Senior
    Remote work
    Shift work

    Society of Defense Financial Management

    Brooklyn, NY
    2 days ago
  • Senior Director, Cyber Strategy & Risk Advisory Cybersecurity Cybersecurity | United States | 2101478...  ..., risk leaders, boards, and senior management teams. Lead cyber maturity assessments...  ...CISO services, board advisory, third‑party risk management, cloud and technology... 
    Cyber
    Senior
    Temporary work
    Flexible hours

    Kroll

    Brooklyn, NY
    1 day ago
  •  ...Senior Director, HR Operations (Strategy, Transformation & Enablement) Full-time Employee...  ...structures, including change management, risk management, and delivery accountability...  ...authorities. By clicking the link above or any third-party link within this posting, you are... 
    Senior
    Full time
    Work at office
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    ServiceNow

    Brooklyn, NY
    1 day ago
  •  ...with strong domain expertise across Custody, Wealth, and Asset Management to define, shape, and deliver modern platform architecture aligned...  ...with architects, engineers, platform leads, data teams, cyber/security teams, and business leaders.Communicate architecture decisions... 
    Cyber
    Senior
    Worldwide

    Hackajob

    Jersey City, NJ
    1 day ago
  • $100k - $120k

     ...updates to the project manager. As part of a project team...  ...involving: NIST Risk Management Framework (RMF...  ...implementation and validation. Cyber compliance reviews and...  ...Reports to a manager, director, or executive-level...  ...will not pay a fee to any third-party agency without a valid... 
    Cyber
    Senior
    Remote job
    Full time
    Work at office
    Flexible hours

    American Bureau of Shipping

    Brooklyn, NY
    5 days ago
  • Fairview Cyber is seeking a summer to fall intern to help with vendor diligence, privacy, and cyber/data security tasks in Raleigh, NC. You will draft summaries, coordinate with third-party providers, and participate in committee meetings. The role offers development opportunities... 
    Cyber
    Internship
    Summer internship

    Fairview, LLC

    Brooklyn, NY
    2 days ago
  •  ...including hiring and developing a Treasury Lead Oversee global cash management, liquidity planning, working capital optimization, and cash...  ...and banking structure Develop and execute foreign exchange risk management and hedging strategies Support capital structure... 
    Senior
    Permanent employment

    Jobtailor

    Jersey City, NJ
    1 day ago
  •  ...of what's possible together. As a Senior Director of Software Engineering at JPMorgan Chase...  ...Technology, you lead multiple technical areas, manage the activities of multiple departments,...  ...ecosystem and related application-owner, risk, and vendor-performance governanceDrives... 
    Senior

    JP Morgan Chase

    Jersey City, NJ
    1 day ago
  • $231.3k - $272.1k

    Senior Director of Information Risk & Governance Remote - US Modern Health Modern...  ...someone wants to proactively manage stress or treat depression,...  ...incident commander for cyber incidents; the Compliance &...  ..., ISO 27001 readiness, and third-party HIPAA risk assessments. The... 
    Cyber
    Senior
    Remote job
    Full time
    Work from home
    Flexible hours

    Modern Health

    Brooklyn, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr Director, Cyber Third-Party Risk Management. Be the first to apply!