About this role
<h1 style="margin:0.0in;font-size:12.0pt;font-family:Arial, sans-serif;font-weight:normal"> </h1> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif">You may know McCormick as a leader in herbs, spices, seasonings, and condiments – and we’re only getting started. At McCormick, we’re always looking for new people to bring their unique flavor to our team.</p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif">McCormick employees – all 14,000 of us across the world – are what makes this company a great place to work.</p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif">We are looking to hire an <strong>Cybersecurity Strategy & Program Sr. Manager </strong>immediately in a Hybrid (50/50) capacity at our Global Headquarters in Hunt Valley, Maryland. </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><strong>What We Bring To The Table:</strong></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif">The best people deserve the best rewards. In addition to the benefits you’d expect from a global leader (401k, health insurance, paid time off, etc.) we also offer:</p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif">• Competitive compensation</p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif">• Career growth opportunities</p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif">• Flexibility and Support for Diverse Life Stages and Choices</p> <p><span style="font-size:12.0pt;line-height:115%;font-family:Aptos, sans-serif">• Wellbeing programs including </span></p><table class="MsoNormalTable" style="width:100%;border:none" border="1" cellspacing="0" cellpadding="0"> <tbody> <tr> <td style="width:7.5in;border:none;padding:0.0in 5.0pt 1.0pt 5.0pt" valign="top"> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><strong><span style="font-family:Arial, sans-serif">Position Overview</span></strong></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> </td> </tr> <tr> <td style="width:7.5in;border:none;padding:0.0in 5.0pt 1.0pt 5.0pt" valign="top"> <table class="MsoNormalTable" style="width:100%;border:none" border="1" cellspacing="0" cellpadding="0"> <tbody> <tr> <td style="width:100%;border:none;padding:0.0in 5.4pt 0.0in 5.4pt" valign="top"> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">The Cybersecurity Strategy & Program Sr. Manager serves as the connective tissue between security leadership, technical teams, and the broader business, ensuring that security is embedded into every decision we make. We believe in proactive protection, transparent communication, and empowering every employee to be a guardian of our data and systems.</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">The role is a critical component of the cybersecurity leadership team—turning vision into action. Orchestrates high-impact security initiatives, streamline governance processes, and ensures the security strategy is not only understood but embraced across the organization. The role directly influences how we protect our customers, our brand, and our future.</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">• Partner with the CISO to define, track, and communicate the company’s cybersecurity strategy, priorities, and progress.</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">• Lead cross-functional security programs—such as enterprise risk & program assessments, compliance readiness, and data protection improvements.</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">• Develop and maintain executive-level dashboards, metrics, and reports that translate complex security metrics into clear business insights.</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">• Coordinate security governance forums, steering committees, and leadership briefings.</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">• Ensure alignment between security initiatives and business objectives, working closely with IT, EA, corporate security, strategic risk, legal, and cybersecurity teams.</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">• Provide decision-making support through analysis and recommendations and escalation of cyber risk decisions to appropriate committees. </span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">• Manage stakeholder relationships, serving as a proxy or gatekeeper for the CISO, and synthesizing information for executive decisions.</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">• Drive continuous improvement in security processes, documentation, and communication.</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">Key Responsibilities</span></strong></span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Strategy Development Support:</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Assists CISO in developing and implementing a comprehensive cybersecurity strategy that aligns business objectives and industry standards. Gains industry data and trends, business priority and strategy, stakeholder input and analysis of key data inputs to help CISO monitor and adjust cybersecurity strategy to changing trends while maintaining alignment to business strategy. Ensuring that the organization's strategies are clearly defined, operationally feasible, and aligned across teams</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Team Alignment to Strategy: Collaborating with other departments to ensure a cohesive approach to cybersecurity across the organization.</span></span></li> </ul> <p style="margin-top:0.0in;margin-right:0.0in;margin-bottom:0.0in;margin-left:0.0px;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Cybersecurity Program Initiatives Oversight: </span></p> <ul> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Supporting strategic business initiatives, from business plan development through successful execution. Holding PMs accountable for delivery. Provides reporting of status to CISO and Cybersecurity Governance Committees. This includes initiatives outside of CISO responsibility such as BCP, Physical Security, and IT projects that have cybersecurity impact (Tech Modernization). Overseeing special projects and managing cross-functional teams to anticipate risks through data analysis and planning.</span></span></li> </ul> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Cybersecurity Governance Structure:</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Manages agenda, membership, reporting, tracking of actions, presentation materials development, and facilitates meetings as necessary and escalation of cybersecurity risk decisions </span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Decision Support: Providing decision-making support through analysis and recommendations and escalation of cyber risk decisions to appropriate committees. Managing stakeholder relationships, serving as a proxy or gatekeeper for the CISO, and synthesizing information for executive decisions.</span></span></li> </ul> <p style="margin-top:0.0in;margin-right:0.0in;margin-bottom:0.0in;margin-left:0.0px;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Reports & Communication:</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Research & develop content for communications needed by CISO for cybersecurity governance committees, audit committee and board reports, C-suite executives, and various stakeholders. Provides regular reporting on current security landscape, cyber trends, threats, and effectiveness of security program.</span></li> <li style="margin:0.0in 0.0in 0.0in 0.0px;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Metrics: Oversees and executes the development, review, and regular stakeholder reporting of cybersecurity dashboards and metrics. Collaborates across cybersecurity team to assure metrics are appropriate and relevant. Provides reports to appropriate stakeholders including explanations for variations within reporting.</span></span></li> </ul> <p style="margin-top:0.0in;margin-right:0.0in;margin-bottom:0.0in;margin-left:0.0px;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Program Maturity & Risk Assessments:</span></p> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <ul> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Facilitates External Program & Cybersecurity Risk Assessments at an enterprise level. Analyzes output from assessments, identifies gaps, works with stakeholders on prioritization and adjusts cybersecurity strategy and roadmaps accordingly to changing risks.</span></span></li> </ul> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif"><strong>Required Qualifications</strong></span></span></p> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <ul> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Bachelor’s degree in computer science, information security, engineering, Business Management or related field</span></span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Certifications such as Certified in Governance of Enterprise IT (CGEIT), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), or similar are strongly preferred</span></span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">10-12 years of experience in cybersecurity program management, governance, risk, and compliance (GRC), or a related field.</span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Experience conducting or facilitating assessment or audits, coordinating with auditors, and implementing audit recommendations.</span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Broad and comprehensive knowledge of cybersecurity domains is required.</span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Strong understanding of security frameworks (e.g., NIST CSF, ISO 27001, CIS Controls) and regulatory requirements (e.g., GDPR, HIPAA, SOX).</span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Exceptional written & verbal communication skills—able to translate complex technical security concepts into business language for executives and stakeholders.</span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">Proven ability to manage multiple high-priority initiatives in a fast-paced environment.</span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Experience with tools such as project management and collaboration tools, GRC platforms, and data visualization tools like Power BI or Tableau.</span></span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">A collaborative mindset with the ability to influence without direct authority.</span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif">High ethical standards and a commitment to confidentiality and integrity.</span></li> <li style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Ability to work effectively individually in a leadership role. Ability to work effectively with all levels of the organization</span></span></li> </ul> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"> </p> <p style="font-size:11.0pt;font-family:'Times New Roman', serif"><span style="font-family:Arial, sans-serif"><span style="font-size:11.0pt;font-family:Arial, sans-serif">#LI-NP2 </span></span></p> </td> </tr> </tbody> </table> <p style="margin:0.0in;font-size:11.0pt;font-family:'Times New Roman', serif"> </p> </td> </tr> </tbody> </table> <p> </p><div id="tor__fextJobDescFooter_readOnlyDiv"> <div id="tor__fextJobDescFooter_content"> <p> </p> <p> </p> <p>McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.</p> <p>As a general policy, McCormick does not offer employment visa sponsorships upon hire or in the future. </p> <p> </p> <p>Base Salary: $121,900-$219,410</p> <p><br>Base salary compensation will be determined based on factors such as geographic location, skills, education, experience for this role, and/or internal equity of our current employees as part of any final offer. This position is also eligible to participate in McCormick’s Incentive Bonus (MIB) Plan. In addition to a competitive compensation package, permanent employees of McCormick are eligible for our extensive Total Rewards programs that include:<br>- Comprehensive health plans covering medical, vision, dental, life and disability benefits - Family-friendly benefits such as paid parental leave, fertility benefits, Employee Assistance Program, and caregiver support - Retirement and investment programs including 401(k) and profit-sharing plans</p> </div> </div> <table width="100%"> <tbody> <tr> <td style="height:36.0px"> </td> </tr> </tbody> </table> <p> </p>