At a Glance
- Tasks: Lead Cyber Security and Data initiatives, ensuring compliance and managing security operations.
- Company: Join McDonald's, a leading employer in the UK with over 1500 restaurants and a commitment to community.
- Benefits: Enjoy hybrid working, a supportive culture, and opportunities for career growth.
- Why this job: Be part of a high-performing team that values diversity and innovation in a dynamic environment.
- Qualifications: Requires extensive experience in information security management and relevant IT qualifications.
- Other info: Contribute to a vision of building a better McDonald's while fostering an inclusive workplace.
The predicted salary is between 48000 - 84000 ÂŁ per year.
McDonald’s has operated in the UK since 1974, with over 1500 restaurants across the UK and Ireland, serving nearly four million customers daily. It is one of the UK’s largest private sector employers, employing over 170,000 people.
Hybrid Working: This role is based in our East Finchley office, working 3 days in the office and 2 days remotely.
The Opportunity: This role will join the Leadership Team of the Technology Function to lead the Cyber Security and Data capability. The role acts as a strategic leader within Running Great Restaurant Technology (RGRT), responsible for:
- Managing a broad range of technical and process security controls and leading a program of continuous improvement in response to evolving security threats.
- Implementing a UK&I market and globally aligned Cyber Security and Data Strategy and operating model.
- Providing advice and direction to the McDonald’s Technology senior leadership and broader organization, integrating security practices into strategic and operational processes.
This is a highly visible role across the UK&I business, interacting with functional leadership, franchisees, and contributing to leadership initiatives, plans, and roadmaps.
Accountabilities:
- Leading within RGRT and broader Technology teams to foster a high-performing culture aligned with company values.
- Developing and maintaining a business-aligned Information and Cyber Security strategy and operating model.
- Ensuring GDPR compliance and escalation in collaboration with the UK&I Legal team.
- Collaborating with other McDonald’s markets and the Global Risk function to embed policies and frameworks.
- Providing coaching and mentoring to team members, supporting their development and career progression.
- Offering consultancy during major security incidents.
- Managing a 24/7 offshore Cyber Security Operations Centre (SOC).
- Managing budgets for cyber and data TFA accounts and G&A compliance.
- Ensuring compliance with IT SOX and PCI DSS audits for the UK&I market.
- Sponsoring key cyber, data, and risk projects.
- Maintaining project governance and building vendor relationships to explore innovation and manage third-party risks.
- Representing McDonald’s UK&I in external groups and staying updated on legislation and security challenges.
- Aligning with McDonald’s Global Technology and Cyber Security standards.
- Supporting data enablement projects and providing data consultancy for enterprise projects.
- Assisting the Director of Technology in developing strategies and roadmaps.
- Driving team culture, prioritization, and leading town halls.
Team and Stakeholders: This role is part of the RGRT Leadership team and the UK&I Technology Leadership team, reporting to the Director of Technology. It interacts with Department Heads, Global & Segment Risk, Legal, Cyber and Data teams, and franchisees as needed.
Qualifications:
- Extensive experience in enterprise information security management.
- Bachelor’s degree in IT, cyber, or related fields.
- Relevant certifications (e.g., CISA, CISSP, CISM, CRISC).
- Experience managing budgets and securing approvals for enterprise-level business cases.
- Strong leadership, strategic, and problem-solving skills, with the ability to motivate teams.
- Proven stakeholder engagement and management skills, including with executives.
- Excellent communication skills, capable of simplifying complex technical issues.
Company Vision and Culture: Our vision is to build a better McDonald’s, aiming to be the UK & Ireland’s best-loved restaurant company. Our culture is driven by our values: Serve, Inclusion, Integrity, Community, and Family. We embrace diversity, promote inclusivity, and are committed to creating an environment where everyone can be their authentic selves. We do not tolerate inequality or discrimination and recognize our role in community development and skills enhancement.
Cyber Security and Data Manager employer: Help Me Settle Ltd
Contact Detail:
Help Me Settle Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security and Data Manager
✨Tip Number 1
Familiarise yourself with McDonald's corporate culture and values, especially their focus on inclusion and community. This will help you align your approach during interviews and discussions, showcasing how your personal values resonate with theirs.
✨Tip Number 2
Stay updated on the latest trends and challenges in cyber security and data management. Being able to discuss current threats and innovative solutions during your conversations will demonstrate your expertise and proactive mindset.
✨Tip Number 3
Network with professionals in the cyber security field, particularly those who have experience in large organisations or the food service industry. This can provide valuable insights and potentially lead to referrals that could strengthen your application.
✨Tip Number 4
Prepare to discuss your leadership style and how you've successfully motivated teams in the past. Given the emphasis on fostering a high-performing culture, sharing specific examples will help illustrate your capability to lead effectively.
We think you need these skills to ace Cyber Security and Data Manager
Some tips for your application 🫡
Understand the Role: Thoroughly read the job description for the Cyber Security and Data Manager position at McDonald's. Make sure you understand the key responsibilities and qualifications required, as this will help you tailor your application.
Highlight Relevant Experience: In your CV and cover letter, emphasise your extensive experience in enterprise information security management. Include specific examples of how you've managed budgets, led teams, and implemented security strategies that align with the role's requirements.
Showcase Leadership Skills: Since this role involves leading a team and interacting with senior leadership, be sure to highlight your leadership and strategic skills. Provide examples of how you've motivated teams and engaged stakeholders effectively in previous roles.
Tailor Your Application: Customise your CV and cover letter to reflect McDonald's values and culture. Use keywords from the job description and demonstrate how your personal values align with their vision of serving the community and promoting inclusivity.
How to prepare for a job interview at Help Me Settle Ltd
✨Understand the Role and Responsibilities
Make sure you thoroughly understand the job description and the specific responsibilities of the Cyber Security and Data Manager role. Familiarise yourself with McDonald's approach to cyber security and data management, as well as their company values.
✨Showcase Your Leadership Skills
As this role involves leading teams and fostering a high-performing culture, be prepared to discuss your leadership style and provide examples of how you've motivated teams in the past. Highlight any experience you have in mentoring or coaching team members.
✨Prepare for Technical Questions
Expect to answer technical questions related to enterprise information security management, GDPR compliance, and risk management. Brush up on relevant certifications like CISA, CISSP, or CISM, and be ready to explain how you've applied these principles in previous roles.
✨Demonstrate Strong Communication Skills
Since the role requires simplifying complex technical issues for various stakeholders, practice articulating your thoughts clearly and concisely. Be prepared to discuss how you've effectively communicated with executives and other non-technical audiences in the past.