Senior Director, Cyber Third-Party Risk Management

McDonald’s Corporation

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Chicago, IL
Salary
$237,102–$296,377 / yr
Posted
1 day ago
Freshness
Confirmed live today

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $201k
This role $267k
$144k most similar roles pay here $313k

This role pays more than 86% of similar roles. Most pay $161,250–$240,687 — the shaded band above. At the midpoint, this role pays about $267k versus about $201k for comparable roles.

Based on 240 similar postings.

Employer

About McDonald’s Corporation

McDonald’s Corporation is the world's largest fast-food chain by revenue, operating over 40,000 locations in more than 100 countries.

McDonald’s Corporation currently has 49 open roles on FindRole.

Listed pay typically runs $138,207–$172,758 across 24 roles with salary data.

Most-posted roles

View all roles at McDonald’s Corporation

At a glance

TL;DR · Senior Director, Cyber Third-Party Risk Management

Sr Director, Cyber Third-Party Risk Management leads and modernizes the global third-party cyber risk management capability across a distributed, market-driven technology and supplier ecosystem. This leader is responsible for designing and executing a scalable, intelligence-driven program that moves beyond traditional questionnaire-centric models to incorporate technical validation, automation, and continuous monitoring. The role involves managing the full lifecycle of third-party risk, including onboarding, tiering, due diligence, and offboarding while addressing complex integrations in IDL market segments. Key responsibilities include building a high-performing team, providing executive reporting on risk posture, and collaborating with procurement, legal, and privacy teams to standardize enterprise agreements. The ideal candidate possesses technical fluency in cloud, APIs, identity, and data flows, alongside expertise in NIST CSF, ISO 27001, GDPR, and CCPA to mitigate systemic and concentration risks within the supply chain.

What you'll do

  • Lead and modernize the global third-party cyber risk management program across a distributed technology ecosystem.
  • Transition the TPRM process from questionnaire-based assessments to technical validation, automation, and continuous monitoring.
  • Manage the full third-party risk lifecycle including onboarding, tiering, due diligence, and secure offboarding.
  • Implement automated tools and AI-assisted techniques for evidence collection and risk scoring.
  • Maintain a centralized inventory of third-party engagements and report risk trends to senior leadership.
  • Partner with internal stakeholders to standardize security configurations and contract requirements across different markets.
  • Build and lead a high-performing team of third-party risk professionals and technical reviewers.

What we're looking for

  • 12+ years of experience in cybersecurity, technology risk, or information security with significant ownership of third-party cyber risk management in large enterprises.
  • Proven experience designing and leading a global TPRM program including the full lifecycle from onboarding to offboarding.
  • Demonstrated success modernizing TPRM by moving beyond questionnaire-centric models toward technical validation, automation, and continuous monitoring.
  • Strong technical fluency across cloud, APIs, identity, data flows, and integration architectures.
  • Experience overseeing deep technical assessments for high-risk third parties including architecture reviews and penetration testing results.
  • Ability to operate in distributed environments while translating local solutions into standardized enterprise security requirements.
  • Demonstrated leadership experience building high-performing teams and influencing senior stakeholders across multiple business functions.
  • Strong executive communication skills for reporting third-party cyber risk posture and trends to senior leadership.
  • Familiarity with systemic, concentration, and fourth-party risk (preferred).
  • Working knowledge of NIST CSF, ISO 27001, GDPR, and CCPA (preferred).
  • Relevant certifications such as CISSP, CISM, CRISC, or CISA (preferred).

More like this

Similar roles

Manager, Cyber Security (Third Party Risk)

Capital One Financial

McLean, VA +1 2 days ago $197,300–$225,100
Third Party Risk Management NIST CSF MITRE ATT&CK CMMC FedRAMP Multi-cloud Splunk Crowdstrike Qualys AWS Security Hub Cybersecurity Metrics Threat Intelligence Security Incident Analysis
5+ yrs exp

Director, IT Security Risk

R1 RCM

Remote 6 days ago $122,366–$178,767
Cybersecurity GRC Risk Assessment Automation Compliance Security Governance Workflow Design Reporting Metrics CISM CISSP
10+ yrs exp Remote

Third-Party Cyber Risk Management Engineer II

GEICO

Bethesda, MD +3 13 days ago $60,000–$215,000
TPCRM GRC Archer ServiceNow OneTrust NIST CSF ISO 27001 CIS SQL Power BI Excel AWS GCP Azure AI Automation data-privacy regulations
1+ yrs exp

Senior Staff Cybersecurity Risk

PayPal

Chicago, IL 11 days ago $160,500–$238,700
NIST ISO 27001 COBIT ITIL Power BI SQL KPIs KRIs audit-readiness Automation
8+ yrs exp Hybrid

Principal Cyber Risk & Strategy Advisor

Proofpoint

Remote 38 days ago $200,300–$293,810
DSPM Enterprise DLP CASB Insider Threat Management Incident Response NIST HIPAA PCI-DSS GDPR DORA NIS2 Threat Intelligence Risk Management
6+ yrs exp Remote