Cyber Security Manager – EcliptOS

Company: McKinsey & Company
Apply for the Cyber Security Manager – EcliptOS
Location: London
Job Description:

Overview

In this role you serve as the primary security point of contact across the product lifecycle, translating central security policies into product-specific controls. You own the product’s security posture and ensure compliance with information security standards, from design through operations. You will coordinate risk assessments, threat modelling, and vulnerability management while guiding secure development practices across cross-functional teams. This is an opportunity to shape secure product delivery in a high-performing, diverse, global firm.

Pay / Benefits

  • competitive salary
  • comprehensive benefits package
  • continuous learning and apprenticeship culture
  • mentorship
  • career development
  • well-being support

Responsibilities

  • Act as the primary security owner across the product lifecycle
  • Interpret and cascade security policies into product-specific controls
  • Maintain and prioritize the product security backlog
  • Coordinate risk assessments, threat modelling, and vulnerability assessments
  • Ensure security controls (access, encryption, secure configuration) are implemented and evidenced
  • Monitor security events and support incident response
  • Promote security awareness within the product team and coach teams on secure development
  • Participate in governance forums and define product-level security KPIs and KRIs
  • Collaborate with product managers, engineering leads, SREs, and compliance partners
  • Support client activation discussions and act as the main security contact for internal and external stakeholders

Key requirements

  • Bachelor’s degree or equivalent experience
  • 5+ years of cybersecurity experience in a similar role
  • Strong ability to apply security by design across architectures, decisions, and integrations
  • Experience coordinating product-level risk assessments, threat modelling, and vulnerability assessments
  • Experience interpreting central security policies into product controls and ensuring audit-ready documentation
  • Deep knowledge of access control, logging/monitoring, encryption, and secure configuration
  • Experience monitoring security events, managing configuration drift, and supporting incident response
  • Experience in risk committees, architecture reviews, and defining product KPIs/KRIs
  • Ability to collaborate with cross-functional teams and coach on secure development practices
  • Excellent communication skills with internal and external stakeholders
  • Excellent communication
  • Cross-functional collaboration
  • Proactive security awareness
  • Security by design and by default across architectures
  • Risk assessments and threat modelling
  • Vulnerability assessments

…

Posted: October 1st, 2026