McKinsey & Company

Senior Security Manager II

Company
Location
London, England, United Kingdom
Posted At
7/3/2025
Advertise with us by contacting: [email protected]
Description
Who You'll Work With

You are someone who thrives in a high-performance environment, bringing a growth mindset and entrepreneurial spirit to tackle meaningful challenges that have a real impact.

In return for your drive, determination, and curiosity, we’ll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well-rounded professional, and contribute to work that truly makes a difference.

When you join us, you will have:

  • Continuous learning: Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace the fast-paced learning experience, owning your journey.
  • A voice that matters: From day one, we value your ideas and contributions. You’ll make a tangible impact by offering innovative ideas and practical solutions. We not only encourage diverse perspectives, but they are critical in driving us toward the best possible outcomes.
  • Global community: With colleagues across 65+ countries and over 100 different nationalities, our firm’s diversity fuels creativity and helps us come up with the best solutions. Plus, you’ll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
  • Exceptional benefits: In addition to a competitive salary (based on your location, experience, and skills), we offer a comprehensive benefits package, including medical, dental, mental health, and vision coverage for you, your spouse/partner, and children.

Your Impact

As Senior Security Manager II, you will lead practice product and cloud security across AWS or Azure or GCP, including planning and implementation of the firm's security standards in support of the strategic business plan, implement Shift left strategies, tooling and processes across software development life cycle, and provide direct support to CSTs to ensure cybersecurity is addressed throughout the engagement delivery lifecycle, from infrastructure and tooling choices to the secure development of products, processing and deletion of client data.

You will also help win client business by providing cybersecurity assurance to Practice-specific RFIs, RFPs, proposals, contract drafting, security questionnaires, workshops and other client due diligence processes. This involves implementing and managing the ongoing independent third party attestations of industry cybersecurity standards and certifications, such as ISO 27001, SOC 2 for Practice-specific solutions and products.

Lastly, you will act as a single point of contact and escalation for the SOC, Threat Intel and Crisis Response Teams for practice related cybersecurity incidents, ensuring timely identification, remediation and lessons learned, while providing practice-level cybersecurity reporting, metrics and forecasting to practice and firm Leadership.

The Senior Security Manager acts as the interface between firm-wide Cybersecurity Leadership and the Practice, driving the implementation of Firm-wide strategy - and, in turn, ensuring client and Practice requirements are fed back into the continual improvement of Firm-wide strategy.

Day-to-day the Senior Security Manager drives the implementation of firm cybersecurity, data protection, and privacy policies, standards and processes within the Practice. They work to continually improve the security posture of asset development and engagement delivery through proactive risk management and the establishment of a broad range of cybersecurity controls.

The role will proactively work on initiatives around Platform McKinsey and have an exposure to our firms CTO and the team.

Your Qualifications and Skills

  • Knowledge of Secure Software Development Lifecycle and DevSecOps
  • 8+ years of experience in information security management, IT security and data protection
  • Technical understanding of a range of enterprise IT and cloud-based architectures and technologies (AWS, Azure, GCP), networking, server infrastructure, operating systems, web applications, databases, containerisation, mobile
  • Working knowledge of common information security controls, guidelines and standards, such as ISO27001, OWASP, SOC 2, NIST
  • Experience of conducting risk assessments threat modeling and information security reviews, and audits
  • Experience with security technologies and tooling, e.g. vulnerability scanners, firewalls, network monitors, IAM, SIEM, IDS/IPS
  • Excellent problem solving, organizational skills, and attention to detail
  • Strong analytical and organizational skills and the ability to work independently, as well as part of a wider team, with minimal supervision
  • Strong written and verbal communication with the ability to converse effectively at all levels of seniority, both internally and externally
Advertise with us by contacting: [email protected]
logo
Hunt UK Visa Sponsors

Copyright © 2025

About us

How does it workContact UsBlog

Stay up to date

TwitterTelegram
Senior Security Manager II | McKinsey & Company | Hunt UK Visa Sponsors