Do you want to work on complex and pressing challenges—the kind that bring together curious, ambitious, and determined leaders who strive to become better every day? If this sounds like you, you’ve come to the right place.
As Senior Security Manager II, you will lead practice product and cloud security across AWS or Azure or GCP, including planning and implementation of the firm's security standards in support of the strategic business plan, implement Shift left strategies, tooling and processes across software development life cycle, and provide direct support to CSTs to ensure cybersecurity is addressed throughout the engagement delivery lifecycle, from infrastructure and tooling choices to the secure development of products, processing and deletion of client data.
You will also help win client business by providing cybersecurity assurance to Practice-specific RFIs, RFPs, proposals, contract drafting, security questionnaires, workshops and other client due diligence processes. This involves implementing and managing the ongoing independent third party attestations of industry cybersecurity standards and certifications, such as ISO 27001, SOC 2 for Practice-specific solutions and products.
Lastly, you will act as a single point of contact and escalation for the SOC, Threat Intel and Crisis Response Teams for practice related cybersecurity incidents, ensuring timely identification, remediation and lessons learned, while providing practice-level cybersecurity reporting, metrics and forecasting to practice and firm Leadership.
The Senior Security Manager acts as the interface between firm-wide Cybersecurity Leadership and the Practice, driving the implementation of Firm-wide strategy - and, in turn, ensuring client and Practice requirements are fed back into the continual improvement of Firm-wide strategy.
Day-to-day the Senior Security Manager drives the implementation of firm cybersecurity, data protection, and privacy policies, standards and processes within the Practice. They work to continually improve the security posture of asset development and engagement delivery through proactive risk management and the establishment of a broad range of cybersecurity controls.
The role will proactively work on initiatives around Platform McKinsey and have an exposure to our firms CTO and the team.
You are someone who thrives in a high-performance environment, bringing a growth mindset and entrepreneurial spirit to tackle meaningful challenges that have a real impact.
In return for your drive, determination, and curiosity, we’ll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well-rounded professional, and contribute to work that truly makes a difference.
When you join us, you will have:
Please review the additional requirements regarding essential job functions of McKinsey colleagues.
FOR U.S. APPLICANTS: McKinsey & Company is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by applicable law.
FOR NON-U.S. APPLICANTS: McKinsey & Company is an Equal Opportunity employer. For additional details regarding our global EEO policy and diversity initiatives, please visit our McKinsey Careers and Diversity & Inclusion sites.
Read Full Description