About this role
<p><span style="font-family:georgia, palatino, serif;color:black">You may know McCormick as a leader in herbs, spices, seasonings, and condiments – and we’re only getting started. At McCormick, we’re always looking for new people to bring their unique flavor to our team.</span><br><span style="font-family:georgia, palatino, serif;color:black">McCormick employees – all 14,000 of us across the world – are what makes this company a great place to work.</span></p><p><span style="font-family:georgia, palatino, serif;color:black"><strong>Position Overview: </strong></span></p> <p><span style="font-family:georgia, palatino, serif;color:black">The Security Risk Team Lead is a key member of the Cybersecurity Governance, Risk, and Compliance team and will report to the Senior Manager, Cybersecurity Governance, Risk & Compliance. This position will be responsible for leading assessments of security risk, establishing security standards, and ensuring compliance against those standards across all disciplines of the information security domain that support McCormick’s global brands and subsidiaries. The ideal candidate has a strong work ethic along with strong organizational, project management, superlative communication skills and problem-solving skills. Additional key qualities include the ability to work with others to drive results. This position requires excellent verbal and written communication skills spanning across all levels of management. Candidates must thrive in a demanding, fast-paced work environment that is energetic, driven, and team-oriented. This role will also work with SMEs across the organization to mature/design security controls & mitigate risk.</span></p> <p> </p> <p><span style="font-family:georgia, palatino, serif;color:black"><strong>Key Responsibilities: </strong></span></p> <ul> <li style="font-family:georgia, palatino, serif;color:black"><span style="font-family:georgia, palatino, serif;color:black">Identify and manage IT-related risks to ensure the security, integrity, and efficiency of the organization's IT infrastructure.</span></li> <li style="font-family:georgia, palatino, serif;color:black"><span style="font-family:georgia, palatino, serif;color:black">Regularly report to IT and business leadership teams on risk management activities and potential impact.</span></li> <li style="font-family:georgia, palatino, serif;color:black"><span style="font-family:georgia, palatino, serif;color:black">Work with GRC tool to develop and improve workflows and processes related to management of risk.</span></li> <li style="font-family:georgia, palatino, serif;color:black"><span style="font-family:georgia, palatino, serif;color:black">Oversee risks identified and managed related to third-party vendor risk assessment program.</span></li> <li style="font-family:georgia, palatino, serif;color:black"><span style="font-family:georgia, palatino, serif;color:black">Demonstrate effective teaming skills with the ability to work independently as needed; leading initiation, execution, and completion to finalization and reporting for key work tasks.</span></li> </ul> <p><span style="font-family:georgia, palatino, serif;color:black"><strong>Desired Candidate Profile: </strong></span></p> <ul> <li style="font-family:georgia, palatino, serif;color:black"><span style="font-family:georgia, palatino, serif;color:black">Bachelor’s degree in Information Technology, Information Systems, Risk Management, Accounting or similar.</span></li> <li style="font-family:georgia, palatino, serif;color:black"><span style="font-family:georgia, palatino, serif;color:black">12+ years of experience related to internal/external audit, information technology, or internal controls.</span></li> <li style="font-family:georgia, palatino, serif;color:black"><span style="font-family:georgia, palatino, serif;color:black">Internal/External Audit, Sarbanes-Oxley, or other internal control (IT or operational) project experiences. Strong verbal and written communication skills, with the ability to effectively communicate complex cybersecurity and IT issues and concepts to non-technical stakeholders. </span></li> </ul><p><span style="font-family:georgia, palatino, serif;color:black">Agencies: McCormick as needed will work with external recruitment vendors through our Agency Portal. Unless previously contacted, McCormick does not accept unsolicited resumes from external recruiting agencies.</span><br><span style="font-family:georgia, palatino, serif;color:black"> </span><br><span style="font-family:georgia, palatino, serif;color:black">McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, colour, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.</span><br><span style="font-family:georgia, palatino, serif;color:black"> </span><br><span style="font-family:georgia, palatino, serif;color:black">As users of the disability confident scheme, we guarantee to interview all disabled applicants who meet the minimum criteria for the vacancy/ies.</span></p>