Job Description
Summary
McKinsey & Company is seeking a Security Manager I to join its GM&S (Growth, Marketing & Sales) technology practice in Bengaluru or Gurugram. This role is ideal for experienced information security professionals with expertise in cloud security (AWS, Azure), secure software development, DevSecOps, and risk management. As a Security Manager at McKinsey, you will ensure the security and compliance of enterprise applications, client engagements, and cloud-based solutions, helping the firm uphold its cybersecurity standards while driving innovative and secure product development.
Job Details at a Glance
| Job Title | Security Manager I – Technology & Digital |
|---|---|
| Company | McKinsey & Company |
| Location | Bengaluru / Gurugram, India |
| Department | Technology & Digital / GM&S |
| Experience Required | 5+ years in information security or cybersecurity management |
| Education | Bachelor’s degree in CS, IT, Cybersecurity, or related field |
| Key Skills/Tools | Cloud Security (AWS, Azure), DevSecOps, ISO 27001, SOC 2, NIST CSF, GDPR, SIEM, IAM, IDS/IPS, Vulnerability Scanners, Databricks |
| Shift/Work Mode | Full-time |
| Industry | Technology / Cybersecurity / Consulting |
Responsibilities
- Ensure practice product and cloud security across AWS and Azure, aligning with McKinsey’s security standards.
- Embed Shift Left strategies and security tools throughout the software development lifecycle.
- Support client engagements by providing cybersecurity assurance, responding to security questionnaires, and participating in workshops.
- Assist in compliance efforts by implementing and managing third-party attestations like ISO 27001 and SOC 2.
- Act as the point of contact for the SOC, Threat Intelligence, and Crisis Response Teams for cybersecurity incidents.
- Identify, remediate, and document cybersecurity incidents, ensuring lessons learned are captured.
- Prepare practice-level cybersecurity reports, metrics, and forecasts for leadership.
- Support proactive risk management efforts and establish cybersecurity controls to enhance security posture.
Skills and Qualifications
Required:
- 5+ years of experience in a similar information security role.
- Strong knowledge of Secure Software Development Lifecycle (SDLC) and DevSecOps.
- Technical expertise across enterprise IT, cloud architectures (AWS, Azure, Databricks), networking, servers, operating systems, databases, containerization.
- Familiarity with information security controls, guidelines, and standards: ISO 27001, SOC 2, NIST CSF, NIST SP800-53, GDPR.
- Experience in risk assessments, threat modeling, security reviews, and audits.
- Hands-on experience with security tools: vulnerability scanners, firewalls, network monitors, IAM, SIEM, IDS/IPS.
- Strong analytical, organizational, and communication skills, able to work independently and collaboratively.
Preferred:
- Experience in consulting environments supporting cloud and enterprise applications.
- Exposure to compliance and regulatory frameworks for international clients.
Benefits
- Competitive salary and comprehensive benefits for you and your family.
- Opportunities for continuous learning, mentorship, and career growth in a high-performance, global environment.
- Exposure to a diverse, multinational technology and cybersecurity community.
Apply Now
Take the next step in your cybersecurity career with McKinsey & Company as a Security Manager I and help drive secure product development and cloud security initiatives across the GM&S practice.