Sr Director, Cyber Third-Party Risk Management
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Company
Description:
McDonald’s is proud to be one of the most recognized brands in the world, with restaurants in over 100 countries that serve 70 million customers daily.
We continue to operate from a position of strength. Our updated growth strategy is focused on staying ahead of what our customers want and realizing further growth potential. Our relentless ambition is why McDonald’s remains one of the world’s leading corporations after almost 70 years. Joining McDonald's means thinking big and preparing for a career that can have influence around the world.
At McDonald’s, we see every day as a chance to create positive impact. We lead through our values centered on inclusivity, service, integrity, community and family. From support of Ronald McDonald House to our Youth Opportunity project and sustainability initiatives, our values keep us dedicated to using our scale for good: good for our customers, people, industry and planet. We also offer a broad rangeofoutstanding benefits including a sabbatical program, tuition assistance and flexible work arrangements.
DepartmentOverview
The Senior Director of Cyber Third-Party Risk Management (TPRM) is accountable for leading and modernizing McDonald’s global third-party cyber risk management capability across a highly distributed, market-driven technology and supplier ecosystem. This role owns the design and execution of a scalable, intelligence-driven TPRM program that moves beyond traditional, questionnaire-centric approaches and delivers meaningful, defensible assurance over third-party cyber risk.
The role places particular emphasis on third-party providers operating within IDL market segments, where complex technology integrations, data flows, and operational dependencies introduce elevated cyber and business risk. The Senior Director develops deep understanding of these integrations, works closely with security architecture and technical SMEs to validate control effectiveness, and ensures that third-party solutions supporting markets do not introduce unacceptable systemic or concentration risk.
This leader partners closely with Global Supply Chain, Indirect Procurement, Legal, Privacy, ERM, and IDL Market CTOs to reduce fragmentation across markets by translating market-specific solution sets into standardized enterprise agreements, security configurations, and control expectations. A core mandate of the role is innovation: designing new, differentiated approaches to third-party assurance that leverage automation, technical validation, and continuous monitoring rather than relying solely on static questionnaires.
Program Leadership & Modernization
- Own and evolve McDonald’s global TPRM strategy and operating model, ensuring it is scalable, risk-based, and aligned to enterprise cyber risk governance expectations.
- Transform TPRM from a primarily questionnaire-driven process into a modern program that blends survey efficiency with technical validation, continuous monitoring, and risk quantification.
- Establish and operate the full third-party risk lifecycle, including onboarding, inherent risk tiering, due diligence, technical assessment, ongoing monitoring, reassessment, and secure offboarding.
Continuous Monitoring, Automation & Innovation
- Implement continuous monitoring capabilities to provide near real-time visibility into third-party cyber posture, control degradation, and emerging risk signals.
- Explore and deploy innovative approaches, including automation and AI-assisted techniques, for evidence collection, risk scoring, and exception management.
- Continuously evaluate emerging tools, data sources, and assurance models to improve coverage, reduce friction, and increase signal quality beyond traditional questionnaires.
Governance, Reporting & Escalation
- Maintain a centralized inventory of third-party engagements, risk tiers, and risk treatment decisions across the enterprise.
- Provide clear, concise reporting on third-party cyber risk posture, trends, and concentration risk to the Vice President, Cyber GRC and senior leadership.
Leadership & Collaboration
- Build and lead a high-performing team of third-party risk professionals and technical…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).