Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cyber Security Engineer III – Email Security and OS Image Hardening image - Rise Careers
Job details

Cyber Security Engineer III – Email Security and OS Image Hardening

Company Description

McDonald’s growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald’s will accelerate technology innovation so 65M+ customers a day will experience a fast, easy experience, whether at one of our 25,000 and growing Drive thrus, through McDelivery, dine-in or takeaway. 

McDonald’s Global Technology is here to power tomorrow’s feel-good moments.That’s why you’ll find us at the forefront of transformative technology, exploring new and innovative ways to serve our millions of customers and spread happiness one delicious Hot Fudge Sundae-dipped fry at a time. Using AI, robotics and emerging tech, we’re digitizing the Golden Arches. Combine that with our unparalleled global scale, and we’re reshaping all areas of the business, industry and every community that is home to a McDonald’s restaurant. We face complex tech challenges every day. But that’s where our diverse and talented teams come in. They’re made up of the best and brightest from all over the globe, and they thrive in the space where feel-good meets fast-paced.  

Check out the McDonald’s  Global Technology Technical Blog to learn how technology and our global team are directly enabling the Accelerating the Arches strategy. 

Job Description

Are you passionate about cybersecurity and ready to make a significant impact? We're looking for a dynamic Security Engineer to join our Cyber Security Architecture and Engineering team. In this role, you'll be at the forefront of securing endpoints, managing email security, and administering cutting-edge security tools. Your expertise in vulnerability management and cloud security will be crucial as you enhance endpoint security, harden OS images, and optimize email security configurations.

You'll play a key role in planning, designing, developing, and validating robust security solutions. Your collaborative nature will shine as you support risk assessment activities, including threat modeling and vulnerability analysis, and work closely with systems architects and developers to ensure secure solutions.

This position requires a blend of technical skills and organizational savvy. As part of our Global Cyber Security function, you'll report to the Senior Manager of Cyber Security Architecture and Engineering, contributing to our mission of enterprise-wide protection.

Join us and be part of a team that's dedicated to staying ahead of emerging threats and safeguarding our digital assets. If you're ready to take on this exciting challenge, we want to hear from you!

Responsibilities & Accountabilities

  • Partner with End User Computing and cloud infrastructure teams to secure and harden OS images for client and server systems.
  • Ensure compliance with security standards by developing and implementing secure OS hardening processes.
  • Work with other security teams to maintain security standards. Provide reports and recommendations based on threat analysis.
  • Perform vulnerability assessments on endpoint systems and remediate identified risks in gold images across end user devices and servers in multi-cloud environments (AWS, Azure, GCP).
  • Design, deploy, and manage advanced email security solutions, including Proofpoint and O365.
  • Establish and enforce email security policies, controls, and best practices to mitigate phishing and spam threats.
  • Collaborate with the Global Security Operations Center and End User Computing teams to optimize email security settings and configurations.
  • Integrate Microsoft Defender for O365 with Proofpoint to enhance email security posture.
  • Conduct rigorous vulnerability analysis, identifying and remediating security gaps across endpoints and cloud platforms.
  • Collaborate with cross-functional teams to integrate vulnerability findings into remediation plans and security programs.
  • Manage and administrate security tools, including IriusRisk for threat modeling, automation workflows, and system customization.
  • Troubleshoot IriusRisk issues, manage user access, and align tools with organizational security standards.
  • Provide coaching and guidance on effective use of security tools and platforms.
  • Support risk assessment activities such as threat modeling, vulnerability analysis, and mitigation planning.
  • Coordinate with systems architects and developers to ensure secure design and implementation of solutions.
  • · Partner with IT technical teams to foster collaboration and ensure security is incorporated into all processes.
  • Continuously monitor emerging threats and trends to ensure security practices remain proactive and up to date.
  • Craft and implement cybersecurity strategies aligned with industry best practices and company goals.

Benefits eligible: Yes
Bonus eligible: Yes
Long term incentive eligible: Yes
The expected salary range for this role is $129,800 - $165,490/ per year 
The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we may also consider your experience, and other job-related factors.

Qualifications

Basic Qualifications

  • Bachelor's degree in computer science, information technology, or a related field or equivalent experience.
  • 4+ years of experience in a technical role in the cybersecurity field.
  • Strong collaboration skills for working with cross-functional teams, including architects and developers.
  • Proven experience in vulnerability management and analysis in hybrid and cloud environments (AWS, Azure, GCP).
  • Experience with performing vulnerability assessments on endpoint systems and remediating identified risks.
  • Experience with development and implementation of secure OS hardening processes and ensure compliance with security standards.
  • Hands-on experience managing security tools and solutions that enhance enterprise security posture.
  • Excellent communication skills for explaining security to non-technical and technical stakeholders.
  • Experience with Microsoft Defender products implementation.
  • Familiarity with email security policies and solutions like Proofpoint and Microsoft O365.
  • Experienced in cybersecurity processes and strategies within large organizations.

Preferred Qualifications

  • Familiarity with administering and optimizing threat modeling tools like IriusRisk or similar tools.
  • Experience with threat modeling, risk assessment, and mitigation planning.
  • Provide guidance and coaching on effective threat modeling methodologies.
  • Experience with security policy and controls, particularly with CSPM tools like Wiz or Prisma Cloud
  • Proficient in developing and executing mitigation strategies to prevent security breaches and minimize potential damage.

Certifications

  • Must have one or more of the certifications.
  • CompTIA Security+
  • CISSP
  • CCSP
  • GIAC
  • CEH
  • Or related security certification

Additional Information

Benefits eligible: This position offers health and welfare benefits, a 401(k) plan, adoption assistance program, educational assistance program, flexible ways of working, and time off policies (including sick leave, parental leave, and vacation/PTO). Eligibility requirements apply to some benefits and may depend on job classification and length of employment. 

Bonus eligible: This position is eligible for a bonus, calculated based on individual and company performance.

Long term Incentive eligible: This position is eligible for stock or other equity grants pursuant to McDonald’s long-term incentive plan.

McDonald’s is an equal opportunity employer committed to the diversity of our workforce. We promote an inclusive work environment that creates feel-good moments for everyone. McDonald’s provides reasonable accommodations to qualified individuals with disabilities as part of the application or hiring process or to perform the essential functions of their job. If you need assistance accessing or reading this job posting or otherwise feel you need an accommodation during the application or hiring process, please contact [email protected]. Reasonable accommodations will be determined on a case-by-case basis.

McDonald’s provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Nothing in this job posting or description should be construed as an offer or guarantee of employment.

Average salary estimate

$147645 / YEARLY (est.)
min
max
$129800K
$165490K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cyber Security Engineer III – Email Security and OS Image Hardening, McDonald's Corporation

Are you excited about cybersecurity and want to impact a global brand? Join McDonald's as a Cyber Security Engineer III, specializing in Email Security and OS Image Hardening. In this pivotal role within our Cyber Security Architecture and Engineering team, you'll dive deep into securing endpoints and managing sophisticated email security systems. Your daily adventures will include enhancing endpoint security, hardening OS images, and optimizing email configurations to fend off cyber threats. Your collaborative spirit will shine as you partner with various teams to conduct risk assessments and vulnerability analyses, designing robust security solutions alongside systems architects and developers. We value innovation, so anticipate engaging with the latest in cloud security and vulnerability management while making recommendations based on threat analysis. You will have the chance to shape our security posture and ensure compliance with the highest standards, while also refining your skills in tools like IriusRisk for threat modeling. If you're passionate about keeping our digital landscapes safe and enjoy tackling complex challenges in a fast-paced environment, McDonald's is your next great adventure. We embrace diverse perspectives, and we're excited to hear how you can contribute to our mission of safeguarding our digital assets every day!

Frequently Asked Questions (FAQs) for Cyber Security Engineer III – Email Security and OS Image Hardening Role at McDonald's Corporation
What are the responsibilities of a Cyber Security Engineer III at McDonald's?

As a Cyber Security Engineer III at McDonald's, you'll be responsible for securing endpoints, managing email security systems like Proofpoint and Microsoft O365, and hardening OS images for client and server systems. You'll also conduct vulnerability assessments, collaborate with various teams to execute security strategies, and perform threat modeling and vulnerability analysis to strengthen our security initiatives.

Join Rise to see the full answer
What qualifications are required for the Cyber Security Engineer III position at McDonald's?

To qualify for the Cyber Security Engineer III role at McDonald's, candidates should possess a Bachelor's degree in computer science or a related field, along with at least four years of experience in cybersecurity. Proven expertise in vulnerability management, familiarity with cloud environments like AWS, Azure, and GCP, and hands-on experience with security tools are crucial. Additionally, relevant certifications such as CompTIA Security+, CISSP, or CEH are preferred.

Join Rise to see the full answer
What tools will I work with as a Cyber Security Engineer III at McDonald's?

In the role of Cyber Security Engineer III at McDonald's, you'll engage with various advanced security tools and platforms. For email security, you’ll manage tools like Proofpoint and Microsoft O365. You’ll also work with IriusRisk for threat modeling and automation, alongside tools for vulnerability assessments and remediation processes across multi-cloud environments.

Join Rise to see the full answer
How does the Cyber Security Engineer III role contribute to McDonald's overall security strategy?

The Cyber Security Engineer III at McDonald's plays a vital role in the company's overall security strategy by designing, implementing, and maintaining robust cybersecurity measures. This includes optimizing email security settings, hardening OS images, conducting thorough vulnerability assessments, and collaborating with cross-functional teams to ensure that security protocols are effectively integrated into all processes.

Join Rise to see the full answer
What kind of work environment can I expect as a Cyber Security Engineer III at McDonald's?

As a Cyber Security Engineer III at McDonald's, you can expect a dynamic and collaborative work environment. Our team thrives on innovation and teamwork, where your contributions will be valued as we tackle sophisticated cybersecurity challenges together. With a commitment to fostering diversity and inclusion, we ensure that all team members feel empowered and encouraged to share their ideas and insights.

Join Rise to see the full answer
Common Interview Questions for Cyber Security Engineer III – Email Security and OS Image Hardening
Can you describe your experience with vulnerability management in cloud environments?

To effectively answer this question, describe specific projects where you performed vulnerability assessments in AWS, Azure, or GCP. Highlight tools you've used for scanning and remediation and explain your overall approach to maintaining security in multi-cloud setups.

Join Rise to see the full answer
How do you ensure compliance with security standards when hardening OS images?

Emphasize your methodology for developing and implementing hardening processes, including the specific compliance frameworks you’ve worked with, how you integrate best practices into your workflow, and your approach to documenting changes and policies.

Join Rise to see the full answer
What strategies do you employ for email security and threat mitigation?

Discuss your hands-on experience with email security solutions such as Proofpoint or Microsoft O365. Explain your approach to setting security policies, handling phishing attempts, and integrating threat intelligence into email security measures.

Join Rise to see the full answer
How do you tackle cross-functional collaboration in cybersecurity projects?

Share examples of past collaborations with IT, developers, or compliance teams. Focus on how you effectively communicate technical information to non-technical stakeholders and the strategies you use to ensure everyone is aligned with security objectives.

Join Rise to see the full answer
Can you explain how you conduct threat modeling?

Provide a detailed explanation of your threat modeling process, including frameworks you use, such as STRIDE or PASTA, and how you prioritize vulnerabilities based on risk assessments. Include examples of how threat models influenced decision-making in previous roles.

Join Rise to see the full answer
Describe a challenging security incident you navigated. What did you learn?

Pick a specific incident where you played a key role in managing a security breach. Outline your involvement, the steps taken to resolve the issue, and any lessons learned that improved your approach to cybersecurity.

Join Rise to see the full answer
What is your approach to continuous monitoring of cybersecurity threats?

Discuss the tools and techniques you use for continuous monitoring, such as SIEM solutions, regular vulnerability scanning, and staying updated on industry trends. Leave the interviewer with insight into how you leverage data and reports to inform security strategies.

Join Rise to see the full answer
How do you ensure security tools are used effectively across teams?

Explain your experience in training and coaching team members on security tools. Talk about developing user guides, holding workshops, and how you monitor tool usage and provide feedback to enhance efficiency.

Join Rise to see the full answer
What methods do you use for effective risk assessment?

Outline your risk assessment process, highlighting how you identify threats, analyze vulnerabilities, and assess potential impacts. Cite any frameworks or methodologies you apply, ensuring that your answer showcases your strategic approach to risk management.

Join Rise to see the full answer
What emerging cybersecurity trends do you think are important for McDonald's to focus on?

Demonstrate your knowledge of current trends in cybersecurity, such as the rise of AI in threat detection, the significance of zero trust architecture, or advancements in endpoint security. Articulate how these trends could impact the strategy of a global leader like McDonald's.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
McDonald's Corporation Hybrid 110 N Carpenter St, Chicago, IL 60607, USA
Posted 10 days ago
Photo of the Rise User
Posted 4 days ago
Knowhirematch Remote No location specified
Posted 3 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Servus Credit Union Remote No location specified
Posted 10 days ago
Photo of the Rise User
NBCUniversal Remote 4100 E Dry Creek Road, Centennial, COLORADO
Posted 4 days ago
Photo of the Rise User
Posted 2 days ago

McDonald's Corporation is a chain of fast food restaurants. Headquartered in Oak Brook, Illinois, the company's famous menu items include the Big Mac, Chicken McNuggets and Egg McMuffin. McDonald's is a publicly owned company and operates a Canadi...

125 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
January 5, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!