Sr Manager, Penetration Testing
Listed on 2026-02-23
-
IT/Tech
Cybersecurity, IT Project Manager, IT Consultant
Job Description:
Company
Description:
McDonald’s is proud to be one of the most recognized brands in the world, with restaurants in over 100 countries that serve 70 million customers daily. We continue to operate from a position of strength. Our updated growth strategy is focused on staying ahead of what our customers want and realizing further growth potential. Our relentless ambition is why McDonald’s remains one of the world’s leading corporations after almost 70 years.
Joining McDonald’s means thinking big and preparing for a career that can have influence around the world.
At McDonald’s, we see every day as a chance to create positive impact. We lead through our values centered on inclusivity, service, integrity, community and family. From support of Ronald McDonald House Charities to our Youth Opportunity project and sustainability initiatives, our values keep us dedicated to using our scale for good: good for our customers, people, industry and planet. We also offer a broad range of outstanding benefits including a sabbatical program, tuition assistance and flexible work arrangements.
Duties- Conduct Penetration testing (50-75% of the role) to identify and mitigate security vulnerabilities.
- Assist in executing annual risk assessment activities for technology, digital, and related areas, and developing the technology and digital audit plan.
- Lead the Security & Privacy portion of our technology and digital audit plan, ensuring that assessment activities are successfully completed on-time and on-budget.
- Lead technology assessments including penetration testing, red teaming, and technical assessments related to data privacy, cloud infrastructure, data protection, network security, secure coding, mobile and web applications, and Internet of Things (IoT).
- Manage and guide the Technology & Digital Audit team in conducting all aspects of our projects including, but not limited to, the development of assessment scope and objectives, development of risk and control matrix, testing approach, handling key communications, audit deliverables, and monitoring issue remediation efforts.
- Assist with setting and executing the department's Security & Privacy Assessment strategy.
- Assist in the successful execution of Sarbanes-Oxley (SOX) IT controls testing, including providing support and assistance to our offshore third-party testing partner.
- Contribute during periodic leadership meetings on the department's strategy, processes, and approaches, demonstrating strong security, privacy, and audit domain knowledge.
- You will work with IT leadership on topics including technology and digital strategies, privacy and related regulations, customer loyalty program, and cybersecurity. Partner with management to improve effective identify risks and improve the control environment.
- Earn trust with leadership by effectively managing sensitive risk and audit discussions, communications, and deliverables.
- Demonstrate thought leadership for current and emerging technology topics including cybersecurity, Dev Ops, privacy compliance, and data governance.
- Provide meaningful hands‑on guidance during assessments of areas including privacy and data protection, data governance, information security, third parties, and digital operations. Whenever necessary, directly execute audit work.
- Ensure that all team deliverables are of high-quality through high‑engagement, detailed oversight, direct involvement, and thought leadership.
- Lead internal infrastructure projects, increasing the department's capabilities and contributing to the continuous improvement of the audit function.
- Develop, coach, and mentor a high‑performing audit team through hiring, oversight, training, and timely and candid performance feedback.
- Bachelor's degree in Engineering, Computer Science, Information Technology, or related field; master's degree preferred.
- 6+ years of related work experience.
- Experience in delivering and leading penetration testing activities, red teaming, mobile and web application assessments, technical assessments, information technology audits, financial compliance (Sarbanes‑Oxley) audits, program and system implementation reviews, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).