Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr Director, Cyber Third-Party Risk Management

$237.1k - $296.38k

McDonald's

Job Description: Company Description: McDonald’s is proud to be one of the most recognized brands in the world, with restaurants in over 100 countries that serve 70 million customers daily.We continue to operate from a position of strength. Our updated growth strategy is focused on staying ahead of what our customers want and realizing further growth potential. Our relentless ambition is why McDonald’s remains one of the world’s leading corporations after almost 70 years. Joining McDonald's means thinking big and preparing for a career that can have influence around the world. At McDonald’s, we see every day as a chance to create positive impact. We lead through our values centered on inclusivity, service, integrity, community and family. From support of Ronald McDonald House to our Youth Opportunity project and sustainability initiatives, our values keep us dedicated to using our scale for good: good for our customers, people, industry and planet. We also offer a broad range ofoutstanding benefits including a sabbatical program, tuition assistance and flexible work arrangements. Department Overview The Senior Director of Cyber Third-Party Risk Management (TPRM) is accountable for leading and modernizing McDonald’s global third-party cyber risk management capability across a highly distributed, market-driven technology and supplier ecosystem. This role owns the design and execution of a scalable, intelligence-driven TPRM program that moves beyond traditional, questionnaire-centric approaches and delivers meaningful, defensible assurance over third-party cyber risk. The role places particular emphasis on third-party providers operating within IDL market segments, where complex technology integrations, data flows, and operational dependencies introduce elevated cyber and business risk. The Senior Director develops deep understanding of these integrations, works closely with security architecture and technical SMEs to validate control effectiveness, and ensures that third-party solutions supporting markets do not introduce unacceptable systemic or concentration risk. This leader partners closely with Global Supply Chain, Indirect Procurement, Legal, Privacy, ERM, and IDL Market CTOs to reduce fragmentation across markets by translating market-specific solution sets into standardized enterprise agreements, security configurations, and control expectations. A core mandate of the role is innovation: designing new, differentiated approaches to third-party assurance that leverage automation, technical validation, and continuous monitoring rather than relying solely on static questionnaires. Responsibilities Program Leadership & Modernization Own and evolve McDonald’s global TPRM strategy and operating model, ensuring it is scalable, risk-based, and aligned to enterprise cyber risk governance expectations. Transform TPRM from a primarily questionnaire-driven process into a modern program that blends survey efficiency with technical validation, continuous monitoring, and risk quantification. Establish and operate the full third-party risk lifecycle, including onboarding, inherent risk tiering, due diligence, technical assessment, ongoing monitoring, reassessment, and secure offboarding. Continuous Monitoring, Automation & Innovation Implement continuous monitoring capabilities to provide near real-time visibility into third-party cyber posture, control degradation, and emerging risk signals. Explore and deploy innovative approaches, including automation and AI-assisted techniques, for evidence collection, risk scoring, and exception management. Continuously evaluate emerging tools, data sources, and assurance models to improve coverage, reduce friction, and increase signal quality beyond traditional questionnaires. Governance, Reporting & Escalation Maintain a centralized inventory of third-party engagements, risk tiers, and risk treatment decisions across the enterprise. Provide clear, concise reporting on third-party cyber risk posture, trends, and concentration risk to the Vice President, Cyber GRC and senior leadership. Leadership & Collaboration Build and lead a high-performing team of third-party risk professionals and technical reviewers. Reinforce a culture of accountability, innovation, and constructive challenge consistent with McDonald’s values and operating principles Qualifications 12+ years of experience in cybersecurity, technology risk, or information security, with significant ownership of third‑party / supplier cyber risk management in large, complex enterprises. Proven experience designing and leading a global TPRM program, including the full third‑party risk lifecycle (onboarding, tiering, due diligence, monitoring, reassessment, and offboarding). Demonstrated success modernizing TPRM, moving beyond questionnaire‑centric models to risk‑based approaches that incorporate technical validation, automation, and continuous monitoring. Strong technical fluency across cloud, APIs, identity, data flows, and integration architectures, with the ability to partner credibly with security architects and technical SMEs. Experience overseeing deep technical assessments for high‑risk or critical third parties (e.g., architecture reviews, threat modeling, penetration testing results, vulnerability assessments). Ability to operate effectively in highly distributed, market‑driven or franchise‑based environments, translating local solutions into standardized enterprise security requirements. Demonstrated leadership experience, including building and leading high‑performing teams and influencing senior stakeholders across Technology, Procurement, Legal, Privacy, and ERM. Strong executive communication skills, with experience reporting third‑party cyber risk posture and trends to senior leadership. Preferred Familiarity with systemic, concentration, and fourth‑party risk. Working knowledge of NIST CSF, ISO 27001, GDPR, and CCPA. Relevant certifications (e.g., CISSP, CISM, CRISC, CISA) Compensation Bonus Eligible: Yes Long - Term Incentive: Yes Benefits Eligible: Yes Salary Range The expected salary range for this role is $237,102 - $296,377 per year The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we may also consider your experience, and other job-related factors. Additional Information: Benefits eligible: This position offers health and welfare benefits, including but not limited to comprehensive health insurance, which includes medical, prescription drug, mental health, dental, and vision coverage, as well as, life insurance. Bonus eligible: This position is eligible for a bonus, calculated based on individual and company performance. Long term Incentive eligible: This position is eligible for stock or other equity grants pursuant to McDonald’s long-term incentive plan. McDonald’s is an equal opportunity employer committed to the diversity of our workforce. We promote an inclusive work environment that creates feel-good moments for everyone. McDonald’s provides reasonable accommodations to qualified individuals with disabilities as part of the application or hiring process or to perform the essential functions of their job. If you need assistance accessing or reading this job posting or otherwise feel you need an accommodation during the application or hiring process, please contact View email address on click.appcast.io. Reasonable accommodations will be determined on a case‑case basis. McDonald’s provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training. Nothing in this job posting or description should be construed as an offer or guarantee of employment. #J-18808-Ljbffr McDonald's

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Sr Director, Cyber Third-Party Risk Management in Chicago, IL vacancy
  • McDonald’s is seeking a Senior Director of Cyber Third-Party Risk Management to lead and modernize our global TPRM program. You will own the strategy, drive continuous monitoring, and implement enterprise‑grade assurances for third‑party cyber risk across markets. You will... 
    Cyber
    Senior

    McDonald's

    Chicago, IL
    2 days ago
  • McDonald’s Corporation in the United States seeks a Senior Director of Cyber Third-Party Risk Management to lead a scalable, intelligence-driven program spanning global markets. You will partner with Global Supply Chain, Legal, Privacy, and ERM to reduce fragmentation and... 
    Cyber
    Senior

    McDonald's Corporation

    Chicago, IL
    2 days ago
  • $118.3k - $207.4k

    Third‑Party IT Risk Manager is responsible for leading and modernizing Wolters Kluwer’s global third‑party cyber risk management capability across a highly distributed, market‑driven technology and supplier landscape. This role ensures third-party engagements align with... 
    Cyber
    Full time
    Contract work
    Work at office
    Shift work

    Wolters Kluwer

    Chicago, IL
    2 days ago
  • $95k - $143.6k

     ...performing information security reviews of third parties that provide services to the bank. Key...  ...a third parties information security risk with a holistic lens to determine if they...  ...with third parties and Enterprise Vendor Managers Must be able to travel up to 10-15% (i.e... 
    Cyber
    Full time
    Work at office
    Flexible hours
    Day shift

    Bank of America

    Chicago, IL
    4 days ago
  • $125k - $225k

    The RoleAs a Senior Cyber Broker within Willis’ FINEX practice, you will serve as a trusted...  ...delivering strategic advice on cyber risk transfer solutions.The successful candidate...  ...optimal coverage and achieve their risk management objectives. This role requires strong technical... 
    Cyber
    Senior
    Temporary work
    Local area
    Visa sponsorship
    Work visa
    Flexible hours

    Willis Towers Watson

    Chicago, IL
    3 days ago
  • Moody’s is seeking an Industry Practice Lead for Corporate Compliance and Third-Party Risk Management in Chicago. You will drive client engagement, market leadership, and strategic growth across multinational clients, aligning solutions to compliance and risk management... 
    Senior

    PassFort

    Chicago, IL
    2 days ago
  •  ...basis. You'll integrate security into CI/CD pipelines and help evaluate third-party libraries, components, and dependencies. Candidates must have a strong background in software development, cyber security, and previous experience with Application Security/DevSecOps. Required... 
    Cyber
    Senior
    Full time

    Motion Recruitment

    Chicago, IL
    4 days ago
  •  ...delivering end-to-end cybersecurity services across strategy, risk management, digital identity, cyber defense, and managed security. With security...  ...or IT stakeholders, Accenture domain experts and other third-party teams as needed. You will lead others on your projects... 
    Cyber
    Senior
    Full time
    Work experience placement
    Live in
    Work at office
    Local area
    Remote work

    Accenture

    Chicago, IL
    5 days ago
  • Crowe is seeking a Manager - Third Party Risk to oversee TPRM engagements, ensuring quality assessment and risk mitigation. The successful candidate will lead teams, manage client relationships, and guide project execution while supporting career development among team... 
    Senior
    Remote work

    Crowe

    Chicago, IL
    5 days ago
  • Old National Bank is seeking a Third-Party Risk Management Senior Analyst responsible for overseeing third-party risk management activities and ensuring compliance with regulatory standards. This role involves managing vendor relationships and supporting internal stakeholders... 
    Senior
    Work at office

    Old National Bank

    Chicago, IL
    1 day ago
  • $83k - $95k

     ....com The Senior Analyst, US Operational Risk Management, supports the execution, reporting, and continuous...  ...control testing, reporting and analytics, third party risk management, business continuity, operational resilience, cyber risk, data risk, fraud risk, and physical... 
    Cyber
    Senior
    Full time
    Remote work
    3 days per week

    CIBC

    Chicago, IL
    3 days ago
  • $131k - $164k

     ...HR Business Partner (Sr. HRBP) to join our Global...  ...Change Management: Lead cross-functional...  ...diagnose organizational risk, and deliver proactive...  ...Engineering VPs, Product Directors, and UX leaders regarding...  ...will not pay fees to any third-party agency or company that... 
    Senior
    Work at office
    Local area
    Remote work
    Flexible hours
    Shift work

    New Relic

    Chicago, IL
    4 days ago
  • $70k - $120k

     ...Compliance Testing And Third-Party Risk ProfessionalAbove Lending is a next-generation financial services company helping everyday Americans...  ...with hands-on experience in compliance testing, vendor management, or risk testing functions in the financial services industry... 
    Senior
    3 days per week

    Above Lending

    Chicago, IL
    2 days ago
  • $159k - $242k

     ...looking for a visionary corporate cyber defense leader to architect...  ...trust, privileged access management, joiner-mover-leaver controls...  ...management, including OAuth and third-party app governance, shadow SaaS...  ....Data protection and insider-risk tooling across endpoint, email... 
    Cyber
    Senior
    Work at office
    Remote work
    Work from home
    Flexible hours

    Gong.io

    Chicago, IL
    2 days ago
  • $96k - $181k

     ...the Job Reporting to the Director of Cybersecurity Risk Oversight, the Sr. Cybersecurity Risk...  ...nd Line of Defense risk management position that provides...  ...access management, and cyber defenses - along with emerging...  ...or services including third parties. Assist with... 
    Cyber
    Senior
    Work at office
    Flexible hours
    Night shift

    KeyBank

    Chicago, IL
    2 days ago
  • $97k - $189k

     ...their fullest potential. The Consulting Director, Attack Surface Management defines strategy, adoption, and...  ...remediation of external attack surface risk through advanced automation, analytics...  ...AI initiatives that realize value to Cyber Defense, Global Enterprise Security,... 
    Cyber
    Full time
    Work experience placement

    CNA Financial

    Chicago, IL
    4 days ago
  • $75k - $103k

     ...Overview The Analyst II, Information and Cyber Security supports the execution and...  ...of enterprise cybersecurity governance, risk, and compliance (GRC) programs. This role...  ...initiatives including risk management, third-party assessments, audit support, and security... 
    Cyber
    Contract work

    Invenergy LLC

    Chicago, IL
    1 day ago
  • $138.4k - $212.1k

     ...exceptional underwriting, claims, and risk management expertise to our partners...  ...on both in‑house and third‑party administered property claims...  ...Professional Liability/E&O, Directors & Officers, Lawyers Professional...  ..., Fiduciary, Crime, Cyber, and Transactional Risk. Key... 
    Cyber
    Senior
    Temporary work

    Munich Re Specialty - North America

    Chicago, IL
    1 day ago
  • $95.6k - $162.4k

     ...TrustAs a global leader in innovative wealth management, asset servicing, asset management and...  ...the institution’s central owner for the third party across all engagements and business...  ...view of the third party’s performance, risk posture, and concentration of exposure to... 
    Senior
    Full time
    H1b
    Worldwide
    Flexible hours

    Northern Trust

    Chicago, IL
    1 day ago
  •  ...automation workflow automation enterprise risk management control management risk management audit third party risk management information security risk...  ...ai governance policy management esg cyber risk management third-party risk... 
    Cyber

    Confidential

    Chicago, IL
    3 days ago
  • $190k - $220k

     ...resiliency including testing resilience. Business Incident/Crisis Management focuses on the handling and communication of active incidents....  ...identification, assessment, and management of operational risks, including critical business services and processes.Lead scenario... 
    Senior
    Full time

    CIBC Bank

    Chicago, IL
    5 days ago
  • $83.1k - $141.3k

    Senior Consultant, Third Party Risk Management Relationship Management Work Location can be Tempe, Arizona or Chicago, Illinois. Major Duties Serve as the institution's central owner for the third party across all engagements and business units. Maintain a holistic view... 
    Senior
    Flexible hours

    Northern Trust

    Chicago, IL
    5 days ago
  • $155.6k - $306.8k

     ...The mission of Quality and Risk Management (QRM) is to manage the risk...  .... Work you’ll do Deloitte’s Cyber QRM team is seeking a Quality...  ...Partners, Principals, Managing Directors, and engagement teams on...  ...vendor contracts (buy-side) for third-party software providers,... 
    Cyber
    Senior
    Contract work
    For subcontractor
    Work at office
    Local area

    Deloitte

    Chicago, IL
    1 day ago
  • $132.6k - $195k

     ...marketplace of consumers, merchants, and drivers.About the RoleThe Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced... 
    Senior
    Hourly pay
    Contract work
    Work at office
    Local area
    Remote work
    Flexible hours

    Doordash

    Chicago, IL
    1 day ago
  • The Senior Manager, Application Development is a senior technology leader responsible for...  ..., cybersecurity, infrastructure, data, risk, compliance, and IT leadership to deliver...  ...initiatives. Manage vendor and third-party relationships to ensure quality, performance... 
    Senior

    Tier4 Group

    Chicago, IL
    5 days ago
  • The Executive Vice President of Risk and Intelligence is a strategic leader reporting directly...  ...assets, novel algorithmic trading, cyber threats, and novel fraud schemesFoster a...  ..., and retain top-tier talent across risk management, intelligence analysis, data science, and... 
    Cyber
    Full time
    Temporary work
    For contractors
    For subcontractor
    Local area
    Immediate start

    Financial Industry Regulatory Authority

    Chicago, IL
    5 days ago
  • $150k - $337.5k

     ...responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunity The Cyber & Investigative Services (CIS) Senior...  ..., management, vendors, and external parties Establish, foster, and maintain... 
    Cyber
    Full time
    Summer holiday
    Local area
    Remote work
    Flexible hours

    EY

    Chicago, IL
    1 day ago
  • $76.6k - $157k

     ...and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative...  ....Coordinating with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams -... 
    Cyber
    Work at office
    Local area
    Visa sponsorship
    Shift work

    Deloitte

    Chicago, IL
    5 days ago
  • $157.6k - $228.55k

     ...support evolving and maintaining the cyber risk management program. Work across the BCBSA organization...  ...program. -Assess internal and third-party supplier risks, realistically...  ...and works with team-leads and other directors to enhance relationships and influence... 
    Cyber
    Senior
    Full time
    Work experience placement
    Shift work

    Blue Cross Blue Shield Association

    Chicago, IL
    1 day ago
  • $115k - $190k

     ...Portfolio Quality & Operations (PQ&O) within Cyber Security Technology (CST) as a Senior...  ...processes that improve efficiency, reduce risk, and enhance delivery consistency....  ...efficiency, consistency, governance, and risk management. • Facilitate stakeholder workshops, process... 
    Cyber
    Senior
    Full time
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America

    Chicago, IL
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr Director, Cyber Third-Party Risk Management. Be the first to apply!