Director, Global Security Operations Center (GSOC)

Company Description

Job Description

Job Description:

Company Description: 

McDonald’s growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald’s will accelerate technology innovation so 65M+ customers a day will experience a fast, easy experience, whether at one of our 25,000 and growing Drive thrus, through McDelivery, dine-in or takeaway.  

McDonald’s Global Technology is here to power tomorrow’s feel-good moments.   

That’s why you’ll find us at the forefront of transformative technology, exploring new and innovative ways to serve our millions of customers and spread happiness one delicious Hot Fudge Sundae-dipped fry at a time. Using AI, robotics and emerging tech, we’re digitizing the Golden Arches. Combine that with our unparalleled global scale, and we’re reshaping all areas of the business, industry and every community that is home to a McDonald’s restaurant. We face complex tech challenges every day. But that’s where our diverse and talented teams come in. They’re made up of the best and brightest from all over the globe, and they thrive in the space where feel-good meets fast-paced.   

Check out the McDonald’s  Global Technology Technical Blog to learn how technology and our global team are directly enabling the Accelerating the Arches strategy.  

Department Overview

The Director, Global Security Operations Center (GSOC) is responsible for leading McDonald’s 24/7/365 security monitoring, detection, and triage operations across three global locations spanning the United States, United Kingdom, and India. This role operates a follow-the-sun model that ensures continuous protection of McDonald’s global systems, data, and brand. 

Reporting to the Sr. Director, Cyber Defense, you are a peer to the Director of Threat Operations & Offensive Security, Director of Incident Response (CIRT), and Detection Engineering leadership. Together, this leadership team forms the Cyber Defense pillar within Global Cyber Security (GCS), delivering integrated detection, response, threat intelligence, and adversary validation services to McDonald’s markets worldwide. 

This role demands a technical leader who can operate at the intersection of hands-on security operations and executive-level program delivery. You must be comfortable with the demands of a 24/7 operation, including extended and non-standard working hours during major incidents and escalations. You will be responsible for building and developing a world-class defense team, maturing operational capabilities, driving measurable outcomes, and ensuring McDonald’s SOC operates as a best-in-class global capability. 

Responsibilities

24/7 Security Operations and Service Delivery

  • Own and lead 24/7/365 global security monitoring, alert triage, investigation, and escalation across regional SOC locations (US, UK, India) operating in a follow-the-sun model.
  • Ensure consistent, high-quality event handling across all tiers (L1, L2, L3), maintaining adherence to service-level objectives, KPIs, and operational agreements.
  • Manage the end-to-end lifecycle of security events from detection through triage, investigation, escalation to CIRT, and closure.
  • Serve as the operational authority for GSOC service delivery, including onboarding new markets, log integration, and adoption of centralized monitoring services.
  • Oversee and optimize the GSOC technology stack, including SIEM, SOAR, EDR and XDR, case management, and orchestration platforms.

Detection and Response Operations

  • Drive continuous improvement in detection coverage, alert quality, triage accuracy, and response times (MTTD, MTTR) across the global SOC.
  • Partner with Detection Engineering to operationalize detection content, validate alerts, reduce false positives, and align with the threat landscape.
  • Coordinate with Incident Response (CIRT) to ensure seamless escalation and shared awareness during active incidents.
  • Collaborate with Threat Operations and Offensive Security teams to integrate threat intelligence and validate defense coverage against adversary tactics.

Executive Communication and Metrics

  • Develop and report GSOC metrics, KPIs, and SLOs to demonstrate performance, risk reduction, and business impact.
  • Deliver program updates, business reviews, and risk briefings to technical and executive audiences, including CIO and CISO.
  • Translate complex security events and trends into actionable insights and executive-level narratives.
  • Maintain dashboards, reporting frameworks, and service performance documentation.

People Leadership and Team Development

  • Lead and develop a global team of managers, senior analysts, and analysts across multiple regions.
  • Recruit and retain cybersecurity talent while fostering technical excellence and accountability.
  • Manage workforce planning, scheduling, and performance across a 24/7 operation.
  • Provide hands-on mentorship to strengthen investigation, analysis, and response capabilities.
  • Drive career development, training, and certification programs across all analyst levels.

Strategy, Program Maturity, and Cross-Functional Partnership

  • Define and execute the GSOC strategic roadmap, including process improvements, automation, and AI-driven capabilities.
  • Own the GSOC operating model and service playbook, ensuring clarity on roles and service boundaries globally.
  • Partner with GRC, Cyber Market Engagement, and Legal or Privacy teams to ensure compliance across regions.
  • Drive continuous improvement through lessons learned, incident reviews, and operational refinements.
  • Evaluate and recommend new technologies and service models to enhance scalability and effectiveness.

Vendor and Partner Management

  • Manage relationships with third-party providers, MSSPs, and technology partners supporting GSOC operations.
  • Oversee vendor performance against SLAs and service expectations.
  • Support onboarding and readiness of new security services across global markets.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent professional experience 
  • 10+ years of progressive experience in cybersecurity operations, security monitoring, detection and response, or SOC leadership 
  • 5+ years of direct people leadership experience managing cybersecurity teams, including people managers (Senior Managers or Managers) 
  • 5+ years of experience leading 24/7 security operations in a global, multi-regional, follow-the-sun operating model 
  • Deep technical understanding of SIEM platforms, SOAR orchestration, EDR/XDR solutions, log management, and security event investigation workflows 
  • Demonstrated ability to build, scale, and mature security operations teams and capabilities in complex, multinational enterprise environments 
  • Expert-level understanding of security monitoring, alert triage methodologies, incident escalation frameworks, and the cyber kill chain 
  • Strong executive communication and stakeholder management skills with the ability to translate operational data and security events into business risk language for CIO/CISO audiences 
  • Proven ability to operate under pressure, manage competing priorities, and lead teams through high-stress incident response situations with extended working hours 
  • History of leading large-scale cross-functional initiatives to success, on time, and within budget 
  • Experience with AI-augmented SOC operations, automated triage, and intelligent alert enrichment platforms 
  • Outstanding technical writing skills and the ability to produce executive-ready reports, service playbooks, and operational documentation 
  • Experience developing and managing SOC metrics frameworks, including MTTD, MTTR, MTTC, SLOs, KPIs, and operational dashboards 
  • Experience with Google SecOps/Azure Sentinel, Defender/SentinelOne/CrowdStrike, or comparable SIEM/EDR platforms at enterprise scale 
  • Willingness and ability to work non-standard hours, including nights, weekends, and holidays, in support of active incident response operations and global SOC coverage requirements  
  • Experience operating in high-pressure, ambiguous environments where rapid decision-making with incomplete information is required to contain threats and minimize business impact  
  • Resilience and composure under stress, with a proven ability to prioritize competing demands across simultaneous incidents, operational obligations, and strategic initiatives without degradation in quality or judgment 

Compensation

Bonus Eligible: YES

Long - Term Incentive: YES

Benefits Eligible: YES

Salary Range

The expected salary range for this role is $195,371.00 - $244,214.00 per year
 
The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we may also consider your experience, and other job-related factors.

Additional Information: 

Benefits eligible: This position offers health and welfare benefits, including but not limited to comprehensive health insurance, which includes medical, prescription drug, mental health, dental and vision coverage, as well as, life insurance.

Bonus eligible: This position is eligible for a bonus, calculated based on individual and company performance. 

Long term Incentive eligible: This position is eligible for stock or other equity grants pursuant to McDonald’s long-term incentive plan. 

McDonald’s is an equal opportunity employer committed to the diversity of our workforce. We promote an inclusive work environment that creates feel-good moments for everyone. McDonald’s provides reasonable accommodations to qualified individuals with disabilities as part of the application or hiring process or to perform the essential functions of their job. If you need assistance accessing or reading this job posting or otherwise feel you need an accommodation during the application or hiring process, please contact mcdhrbenefits@us.mcd.com. Reasonable accommodations will be determined on a case-by-case basis. 

McDonald’s provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training. 

Nothing in this job posting or description should be construed as an offer or guarantee of employment. 

Qualifications

Additional Information