Cybersecurity Manager - AppSec
McKinsey & Company · Prague +2 · just now
ManagerOn-siteSecurity
Who you'll work with
You are someone who thrives in a high-performance environment, bringing a growth mindset and entrepreneurial spirit to tackle meaningful challenges that have a real impact.
In return for your drive, determination, and curiosity, we’ll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well-rounded professional, and contribute to work that truly makes a difference.
When you join us, you will have:
- Continuous learning: Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace the fast-paced learning experience, owning your journey.
- A voice that matters: From day one, we value your ideas and contributions. You’ll make a tangible impact by offering innovative ideas and practical solutions, all while upholding our unwavering commitment to ethics and integrity. We not only encourage diverse perspectives, but they are critical in driving us toward the best possible outcomes.
- Global community: With colleagues across 65+ countries and over 100 different nationalities, our firm’s diversity fuels creativity and helps us come up with the best solutions. Plus, you’ll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
- Exceptional benefits: On top of a competitive salary (based on your location, experience, and skills), we provide a comprehensive benefits package to enable holistic well-being for you and your family.
What you'll do
You will act as an application security point of contact for the firm, partnering with engineering and product teams to build security into the software development lifecycle.
You will drive the promotion and adoption of secure coding practices and DevSecOps and Cloud security policies across product and engineering teams. You will conduct application security reviews, including secure code review, static and dynamic analysis (SAST/SCA/DAST), and coordination of penetration testing, and partner with product teams on vulnerability remediation and risk acceptance decisions. You will provide reporting on application security posture, vulnerability trends, and alignment with compliance and regulatory frameworks. You will also contribute to the development and continual improvement of the Tech Ecosystem application security strategy and tooling.
Your work will help secure the products created by the developers and engineers at McKinsey that enable our consulting teams to deliver the value and impact McKinsey is known for.
You will be based in Prague, San Jose, or Sao Paulo.
Your background
- 5+ years of corporate and/or professional services experience
- Hands-on experience identifying and remediating common vulnerability classes (e.g., OWASP Top 10), including practical experience with SAST, DAST, and software composition analysis (SCA) tooling
- Familiarity with cloud security fundamentals and DevSecOps practices in AWS, Azure, or GCP environments, including securing CI/CD pipelines
- Working proficiency in at least one programming language (e.g., Python, Java, JavaScript/TypeScript, Go), with the ability to read and reason about code across multiple languages and frameworks
- Independently manages multiple people and projects simultaneously while participating in best practices and nurturing a trust-based, inclusive, productive environment
- Capable of raising issues, generating solutions, and working effectively under pressure
- Non-hierarchical approach with flexibility and the ability to build consensus among team members.
- Ability to handle multiple tasks, prioritize them, and carry them out independently while being mindful of the big picture
- Sensitivity with confidential information and adherence to the highest professional and process standards
- Strong influencing capabilities, including willingness to push back and deliver tough messages to senior audiences, and demonstrated track record of leadership in high-performing teams
- Ability to engage audiences and create clear, logical, and structured communications across all formats
- Fluent level language skills in English, both written and verbal