Security Manager II – Digital Risk

Company: McKinsey & Company
Apply for the Security Manager II – Digital Risk
Location: Greater London
Job Description:

Who You’ll Work With

We’re looking for someone who thrives in a high‑performance environment, bringing a growth mindset and entrepreneurial spirit to tackle meaningful challenges that have a real impact.

In return for your drive, determination, and curiosity, we’ll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well‑rounded professional, and contribute to work that truly makes a difference.

When you join us, you will have:

  • Continuous learning: Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace a fast‑paced learning experience, owning your journey.
  • A voice that matters: From day one, we value your ideas and contributions. You’ll make a tangible impact by offering innovative ideas and practical solutions, all while upholding our unwavering commitment to ethics and integrity. We not only encourage diverse perspectives, they are critical in driving us toward the best possible outcomes.
  • Global community: With colleagues across 65+ countries and over 100 different nationalities, our firm’s diversity fuels creativity and helps us come up with the best solutions. Plus, you’ll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
  • Exceptional benefits: On top of a competitive salary (based on your location, experience, and skills), we provide a comprehensive benefits package to enable holistic well‑being for you and your family.

Your Impact

As a Security Manager II, you will act as the digital risk lead embedded within ClienTech’s product, data, and engineering ecosystem, ensuring that secure‑by‑design principles, firm cybersecurity standards, and ClienTech‑specific delivery patterns are consistently applied across digital assets, accelerators, and client deployments.

You will embed cybersecurity controls and secure design practices into ClienTech pipelines, reusable assets, accelerator builds, and delivery environments across AWS, Azure, and GCP. Working closely with engineering squads, you will support the implementation of secure SDLC and DevSecOps practices, including static analysis, dependency scanning, container hardening, threat modeling, and secure design reviews. You will also support the governance and security uplift of ClienTech internal platforms, development environments, and shared services, conduct technical assessments for emerging capabilities (including GenAI tools), track adherence to secure engineering guardrails, and highlight areas requiring uplift. During client delivery, you will work directly with client service teams to select secure runtime environments and define compliant data‑handling workflows.

Your work supports ClienTech’s mission to deliver high‑quality, high‑velocity digital solutions by operationalizing security controls, enabling engineering teams, and effectively managing cyber risk across the build‑and‑deploy lifecycle.

You will be based in one of our core locations as part of the ClienTech technology and engineering ecosystem, partnering closely with product, data, engineering, and client service teams.

Your Qualifications and Skills

  • Bachelor’s degree or master’s degree equivalent of work experience required; background in Cybersecurity, Computer Science, Engineering, or equivalent experience preferred.
  • 5+ years of cybersecurity experience with strong exposure to digital product engineering, cloud workloads, or security architecture.
  • Working knowledge of securing cloud solutions in AWS, Azure, or GCP, including IAM, networking, containerization, and Kubernetes.
  • Hands‑on experience with DevSecOps toolchains such as SAST, DAST, dependency scanning, container image scanning, and infrastructure‑as‑code security scanning.
  • Experience conducting threat modeling, secure design reviews, and engineering‑focused risk assessments.
  • Familiarity with industry standards and frameworks such as ISO 27001, SOC 2, OWASP, and NIST CSF.
  • Strong communication and stakeholder‑management skills, with the ability to partner effectively with engineering teams in fast‑paced delivery environments.
  • Experience supporting digital product teams or client‑facing technology delivery units; knowledge of privacy and data protection regulations (e.g., GDPR, CCPA); and relevant professional certifications such as CISSP, CISM, CCSK, or cloud security specialty certifications are preferred.

#J-18808-Ljbffr…

Posted: April 18th, 2026