Job ID: 112087
- London
Do you want to do work that matters, alongside supportive leaders who will help you grow faster than you ever thought possible? Are you a creative problem-solver who is energized by challenges? You’ve come to the right place.
YOUR IMPACT
Acting as the primary security point of contact throughout the product lifecycle, you will interpret and cascade central security policies, standards, and regulatory requirements into product-specific requirements, patterns, and controls.
You will be responsible for ensuring that a product complies with the firm’s central information and security policies and standards. You will own the product’s security posture across design, build, test, release, and operations, ensuring “security by design and by default” is applied to architectures, technical decisions, and third-party integrations.
Your work will involve maintaining and prioritizing the product’s security backlog, coordinating risk assessments, threat modelling, and vulnerability assessments, and ensuring that required security controls (e.g., access control, encryption, secure configuration) are implemented and evidenced. You will monitor security-relevant events, support incident response efforts, and act as the primary point of contact for all product-related security queries. Additionally, you will promote security awareness within the product team, provide best practice guidance to Forward Deployed Engineers, participate in governance forums, and define product-level security KPIs and KRIs.
YOUR GROWTH
You are someone who thrives in a high-performance environment, bringing a growth mindset and entrepreneurial spirit to tackle meaningful challenges that have a real impact.
In return for your drive, determination, and curiosity, we’ll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well-rounded professional, and contribute to work that truly makes a difference.
When you join us, you will have:
- Continuous learning: Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace the fast-paced learning experience, owning your journey.
- A voice that matters: From day one, we value your ideas and contributions. You’ll make a tangible impact by offering innovative ideas and practical solutions, all while upholding our unwavering commitment to ethics and integrity. We not only encourage diverse perspectives, but they are critical in driving us toward the best possible outcomes.
- Global community: With colleagues across 65+ countries and over 100 different nationalities, our firm’s diversity fuels creativity and helps us come up with the best solutions. Plus, you’ll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
- Exceptional benefits: On top of a competitive salary (based on your location, experience, and skills), we provide a comprehensive benefits package to enable holistic well-being for you and your family.
YOUR QUALIFICATIONS AND SKILLS
- Bachelor’s degree in related field or equivalent working experience
- 5+ Years of Cyber Security experience in a similar role
- Strong ability to ensure “security by design and by default” across architectures, user stories, technical decisions, and third-party integrations
- Proficiency in coordinating product-level security risk assessments, threat modelling, and vulnerability assessments, as well as maintaining a prioritized security backlog
- Experience interpreting and cascading central security policies, standards, and regulatory requirements into product-specific controls, and ensuring documentation is audit-ready
- Deep knowledge of required security controls, including access control, logging and monitoring, encryption, and secure configuration
- Experience monitoring security-relevant events, managing configuration drift, and supporting incident response efforts (triage, containment, lessons learned)
- Experience participating in risk committees, architecture reviews, and defining/maintaining product-level security KPIs and KRIs
- Ability to collaborate closely with product managers, engineering leads, SREs, and compliance partners, while promoting security awareness and coaching teams on secure development practices
- Excellent communication skills to act as the primary contact for internal stakeholders (architecture, legal, privacy, risk, audit) and external parties, as well as supporting client activation discussions
Please review the additional requirements regarding essential job functions of McKinsey colleagues.
Our unwavering commitment to integrity drives everything we do, guiding us to always act in the best interests of our clients, our people, and the communities we serve.