Sr Manager - Vulnerability Management

Date: Nov 17, 2025

Location: Chicago, IL, US, 60607

Company: McDonald's Corporation

Company Description: 

McDonald’s growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald’s will accelerate technology innovation so 65M+ customers a day will experience a fast, easy experience, whether at one of our 25,000 and growing Drive thrus, through McDelivery, dine-in or takeaway.  

McDonald’s Global Technology is here to power tomorrow’s feel-good moments.   

That’s why you’ll find us at the forefront of transformative technology, exploring new and innovative ways to serve our millions of customers and spread happiness one delicious Hot Fudge Sundae-dipped fry at a time. Using AI, robotics and emerging tech, we’re digitizing the Golden Arches. Combine that with our unparalleled global scale, and we’re reshaping all areas of the business, industry and every community that is home to a McDonald’s restaurant. We face complex tech challenges every day. But that’s where our diverse and talented teams come in. They’re made up of the best and brightest from all over the globe, and they thrive in the space where feel-good meets fast-paced.   

Check out the McDonald’s  Global Technology Technical Blog to learn how technology and our global team are directly enabling the Accelerating the Arches strategy.  

Department Overview

McDonald’s Global Cyber Security is looking for a highly motivated, diligent, and skilled candidate to join the Vulnerability Management team. The Lead Analyst - Vulnerability Management is a key member of the Vulnerability Management team and works with internal and external groups globally to identify and drive remediation of security risks. Develop new Cybersecurity services and improve existing ones to meet growing demand for user, device, network, application, and data protection. The ideal candidate will have prior experience developing vulnerability management programs, analyzing vulnerabilities to determine applicability and impact, reporting vulnerability and risk to senior leadership, and leading prioritization and remediation strategies in an enterprise environment.

Accountability & Responsibilities

  • Establish strategic relationships with key McDonald’s stakeholders ensuring vulnerability and threat management principles are incorporated into their processes, applications, and products across the enterprise to develop a culture of security.
  • Support the rapid response of high-profile vulnerabilities and exposure across the system. Lead the publication advisories providing targeted technical guidance, prioritizing asset lists, and deadlines that are commensurate with the level of risk to the business. Identify mitigating controls where full remediation is not feasible.
  • Oversee vulnerabilities and threats, determine their impact on McDonald’s, collaborate with Threat Intelligence, and coordinate responses based on risk levels.
  • Apply vulnerability assessment tools and process outputs to develop and implement methods for detecting and assessing security weaknesses. Incorporate the use of industry standards and frameworks such as CVSS, EPSS, KEV, CPE & CWE to prioritize remediation activities.
  • Elevate the understanding of key vulnerabilities and their prominent presence throughout the company to effectively convey and encourage the vital steps to address or minimize risk.
  • Develop strategies and tools for producing reports and metrics to automate demonstrating the efficiency and strength of the vulnerability management initiative. This includes using a variety of tools such as Python, PowerShell, Power Automate, SQL, different database technologies, Power BI, Tableau, as well as ServiceNow or O365 tools.
  • Develop standards, and procedures that support the global vulnerability management program. Lead vulnerability and risk assessments to evaluate severity, exploitability and potential business impact. Collaborate with technical and business stakeholders to validate assessment results, recommend mitigation strategies, and communicate actionable insights.

Qualifications

  • 5+ years of experience in information security technologies and processes, vulnerability management, security operations, security engineering, program development or similar experience. Experience with vulnerability detection and prioritization tools, such as Tenable, Qualys, Wiz, Tanium, Avalor, Nucleus, Service Now VR, etc. (Required)
  • Bachelor’s degree in Cybersecurity, Information Security, or a related field. Expert knowledge of cybersecurity vulnerability management techniques, as applied to infrastructure, cloud, data, applications, platforms, operating systems and networks.
  • Demonstrate outstanding leadership, and interpersonal verbal and written communication skills. Is process-oriented and able to manage multiple concurrent work streams. Ensure timely communication and updates through designated work management tools and remote productivity platforms. Participate in virtual meetings and contribute to discussions using remote productivity tools (e.g., Slack, Microsoft Teams, WebEx) Ability to support 24 x 7 x 365 stakeholders and work as part of a cohesive team.
  • Ability to work within tight timeframes and a fast-paced environment with changing priorities. Ability to manage people and vendors to deliver a successful Vulnerability Management program
  • Information security certifications such as Security+, Network+, CISSP, CCNA, GSEC, GCIA, GPEN, CEH. Proficiency in security regulations including NIST and PCI-DSS is a must. Knowledge of laws, regulations, and standards relevant to Cybersecurity / privacy.

Compensation

Bonus Eligible: Yes

Long - Term Incentive: Yes

Benefits Eligible: Yes

Salary Range

The expected salary range for this role is $167,366.00 - $209,207.00 per year
 
The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we may also consider your experience, and other job-related factors.

Additional Information: 

Benefits eligible: This position offers health and welfare benefits, a 401(k) plan, adoption assistance program, educational assistance program, flexible ways of working, and time off policies (including sick leave, parental leave, and vacation/PTO). Eligibility requirements apply to some benefits and may depend on job classification and length of employment.  

Bonus eligible: This position is eligible for a bonus, calculated based on individual and company performance. 

Long term Incentive eligible: This position is eligible for stock or other equity grants pursuant to McDonald’s long-term incentive plan. 

McDonald’s is an equal opportunity employer committed to the diversity of our workforce. We promote an inclusive work environment that creates feel-good moments for everyone. McDonald’s provides reasonable accommodations to qualified individuals with disabilities as part of the application or hiring process or to perform the essential functions of their job. If you need assistance accessing or reading this job posting or otherwise feel you need an accommodation during the application or hiring process, please contact mcdhrbenefits@us.mcd.com. Reasonable accommodations will be determined on a case-by-case basis. 

McDonald’s provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training. 

Nothing in this job posting or description should be construed as an offer or guarantee of employment. 


Nearest Major Market: Chicago