Sr. Manager of Detection Engineering at McDonald's Global Technology (Chicago, IL)
McDonald's new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald's will accelerate technology innovation so 65M+ customers a day will experience a fast, easy experience, whether at one of our 25,000 and growing Drive Thrus, through McDelivery, dine-in or takeaway.
Leading this tech revolution is McDonald's Global Technology organization made up of intrapreneurs who get to build really cool tech with scary smart people using the latest innovations like AI, IOT, and edge computing. We do this working along diverse, global teams who are always hungry for a challenge. It's bonus points when you get to see your family and friends use the tech you build at their favorite McD restaurant.
As we have matured as an engineering organization and seen the demands for technology grow exponentially, we're gearing up to deliver on the next set of opportunities for the business. We are building up an engineering team in house accountable for our strategic products. We'll have diverse squads made up of engineers with traditional and specialized skillsets, both from internal engineers coupled with our partners, to help us flex with demand and solve technology innovation challenges done at an incredible scale.
We are seeking a Sr Manager for a Detection Engineering role that will build out and improve our ability to effectively detect and respond to threats. You will collaborate closely with cybersecurity experts, Global Technology teams, service partners, and business leaders to assess detection gaps across McDonald's. drive the development, deployment, and maintenance of our global policies and standards. This role will have a direct impact on building capabilities for a new program through influence and technical contributions. The Operations team is expanding and looking to bring in a Detection Engineer with a strong foundation and understanding related to various security solutions and technologies. If disruption of the threat actors across the environment sounds exciting, then this opportunity is a perfect fit for you.
- Write detection logic/rules to discover malicious activity
- Build automation and detection models to support the identification of anomalous activity and response activities to mitigate threats at scale
- Hunt for threats in our corporate and market environments to proactively identify anomalous activity and determine if there are gaps in coverage
- Work side by side with our engineering teams to help them tune advanced detection rules to help keep systems safe and secure
- Identify and consult on the design of security measures to reduce threats in our global environment
- Keep up to date with current trends, tactics, and vulnerabilities to understand the Threat Landscape as it applies to McDonald's
- Work with the Cyber Threat Intelligence, Incident Response, and Endpoint teams to discover gaps, and submit tuning requirements to platform owners based on relevant signatures for monitoring and alerting purposes
- Research network-based Tactics, Techniques, and Procedures (TTPs) and develop high-fidelity detections in various tools/languages including Endpoint Detection and Response platform and SIEM
- Document internal team policies and procedures for completing core functions and engineering lifecycle
- Develop relationships with external security organizations to maintain awareness of security issues and trends
Must be fully vaccinated (i.e., at least 2 weeks after last dose) for COVID-19 and, if hired, present proof of vaccination by start date.
The Sr Manager of Detection Engineering must be familiar with the use of frameworks such as MITRE ATT&CK and D3fend, as well as the Cyber Kill Chain, to map current detection coverage and identify opportunities for developing new threat detection use cases. Be able to identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection. Experienced with cybersecurity technologies such as Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), email security, and SOAR. This position will have the ability to take lead in creating high-fidelity detections from logs, alerts, and anomalous behavior.
- Bachelor's degree in a related technical field or equivalent practical experience.
- 5+ years of hands-on in-depth knowledge and technical experience in security operations including detection engineering, threat hunting, incident response, digital forensics, and/or threat intelligence.
- Exposure to data science and analytics solutions applicable to cybersecurity
- Knowledge and familiarity of the Cyber Kill Chain Framework and MITRE ATT&CK Framework and how these apply to the insider threat landscape.
- Experience automating security detection and response
- Self-starter and creative problem-solver able to work independently with minimal guidance
- Outstanding organizational, prioritization, communication, and multitasking skills
- Excellent written and verbal communication skills to describe security event details and technical analysis
- Professional certifications such as CPA, CA, CIA, CISA, CISSP, and PMP
McDonald's is committed to providing qualified individuals with reasonable accommodations to perform the essential functions of their jobs. Additionally, if you (or another applicant of whom you are aware) require assistance accessing or reading this job posting or otherwise seek assistance in the application process, please contact [email protected]
McDonald's provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Nothing in this job posting or description should be construed as an offer or guarantee of employment.