Sr. Director, Data Protection
- Full-time
- McDonald's Office Location: MHQ
- Global Grade: G7
Company Description
McDonald’s new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald’s will accelerate technology innovation so 65M+ customers a day will experience a fast, easy experience, whether at one of our 25,000 and growing Drive Thrus, through McDelivery, dine-in or takeaway.
Leading this tech revolution is McDonald’s Global Technology organization made up of intrapreneurs who get to build really cool tech with scary smart people using the latest innovations like AI, IOT, and edge computing. We do this working along diverse, global teams who are always hungry for a challenge. It’s bonus points when you get to see your family and friends use the tech you build at their favorite McD restaurant.
As we have matured as an engineering organization and seen the demands for technology grow exponentially, we’re gearing up to deliver on the next set of opportunities for the business. We are building up an engineering team in house accountable for our strategic products. We’ll have diverse squads made up of engineers with traditional and specialized skillsets, both from internal engineers coupled with our partners, to help us flex with demand and solve technology innovation challenges done at an incredible scale.
Check out the Global Technology Technical Blog to learn how technology is directly enabling the Accelerating the Arches strategy.
Job Description
We are seeking a Sr. Director of Data Protection to oversee the security and integrity of our company, employee, and customer data and sensitive information. As the Sr. Director of Data Protection, protecting the information required to support these platforms and strategies is essential to maintain customer trust and loyalty and will be your number one priority. You will lead both strategic and tactical elements of our global data protection program and will partner closely with various critical collaborators in Global Technology and the Law Department, among others.
You will help lead continuous improvement of the team's data protection effort through automation and process maturity. The ideal candidate will have a solid understanding of data protection laws and regulations, experience building a data protection program from the ground up, and experience developing and implementing data protection policies and procedures.
The Sr. Director of Data Protection must have the ability to cultivate a collaborative working relationship with cybersecurity and privacy customers across the global McDonald’s environment. Demonstrated success in building and implementing a data protection program. A leader in this space will have experience developing a strategic vision for data protection, and familiarity with various privacy and data laws and regulations.
Responsibilities
- Develop and implement a comprehensive data protection strategy to ensure compliance with all relevant laws and regulations.
- Be responsible for the development and implementation of data protection policies and procedures.
- Review and evaluate the effectiveness of data protection controls and drive recommendations for improvement.
- Develop and deliver employee training to promote awareness and understanding of data protection policies and procedures.
- Coordinate with our Incident Response team in the event of a data breach or other security incident involving data.
- Collaborate with internal and external partners to ensure data protection requirements are met globally.
- Stay up to date with changes in data protection laws and regulations and make recommendations for essential changes to policies and procedures.
- Mentor, manage, and motivate a successful team of directors, senior managers/analysts, and/or senior professionals and set clear priorities to achieve team goals.
- Conduct risk assessments to identify potential threats and vulnerabilities to the company's data and infrastructure.
- Develop and maintain a data inventory and classification system to protect critical data appropriately.
- Collaborate with IT and business teams to ensure data protection requirements are integrated into new systems and applications.
- Stay updated with emerging threats and vulnerabilities and adjust data protection strategies and tactics accordingly.
- Develop and maintain relationships with external partners, such as regulators and industry groups, to stay informed of data protection laws and regulations changes.
- Develop and lead a data breach response plan, including roles and responsibilities, communication protocols, and incident reporting procedures.
- Develop and deliver regular reports on data protection risks, incidents, and compliance status to executive management.
Qualifications
Minimum Requirements
- Bachelor’s degree in Systems, Engineering, Computer Science, or other related fields.
- Experience building a data protection program, running as a program, and a proven record of delivering on critical milestones.
Desired Skills
- Familiarity with complex multinational companies and distributed business models
- Professional certifications such as CISSP
- Proficient in technical writing and demonstrating various creative mechanisms to communicate to diverse audiences
- Capability to identify gaps in technological capabilities and submit requirements to meet identified gaps – perform impact/risk assessments
Additional Information
McDonald’s is committed to providing qualified individuals with reasonable accommodations to perform the essential functions of their jobs. Additionally, if you (or another applicant of whom you are aware) require assistance accessing or reading this job posting or otherwise seek assistance in the application process, please contact [email protected]
McDonald’s provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Nothing in this job posting or description should be construed as an offer or guarantee of employment.