Senior Security Risk Analyst (HYBRID)
McCormick & CompanyRole Overview
McCormick & Company is hiring a Senior Security Risk Analyst (HYBRID). This is a full-time hybrid role, based in Cockeysville. Part of McCormick & Company's Risk hiring. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Sign up free to auto-tailor your resume with all these keywords and get a higher ATS score
Job Description
You may know McCormick as a leader in herbs, spices, seasonings, and condiments – and we’re only getting started. At McCormick, we’re always looking for new people to bring their unique flavor to our team.
McCormick employees – all 14,000 of us across the world – are what makes this company a great place to work.
We are looking to hire an Senior Security Risk Analyst immediately in a Hybrid (50/50) capacity at our Global Headquarters in Hunt Valley, Maryland.
What We Bring To The Table:
The best people deserve the best rewards. In addition to the benefits you’d expect from a global leader (401k, health insurance, paid time off, etc.) we also offer:
- Competitive compensation
- Career growth opportunities
- Flexibility and Support for Diverse Life Stages and Choices
- Wellbeing programs including
Position Overview
The Senior Security Risk Analyst is a key member of the Cybersecurity Governance, Risk, and Compliance team and will report to the Senior Manager, Cybersecurity Governance, Risk & Compliance. This position will be responsible for leading assessments of security risk, establishing security standards, and ensuring compliance against those standards across all disciplines of the information security domain that support McCormick’s global brands and subsidiaries. The ideal candidate has a strong work ethic along with strong organizational, project management, and problem-solving skills. Additional key qualities include the ability to work with others to drive results. This position requires excellent verbal and written communication skills spanning across all levels of management. Candidates must thrive in a demanding, fast-paced work environment that is energetic, driven, and team-oriented. This role will also work with SMEs across the organization to mature/design security controls & mitigate risk.
Key Responsibilities
- Intake and analysis of identified risks from a variety of sources including audits, compliance checks, automated vulnerability systems, and other internally or externally reported risks. Process risk acceptance requests and provide necessary information and analysis to allow business leaders to determine which risks are appropriate
- Complete analyses and reports and work with the Senior Manager, Cybersecurity GRC to develop a comprehensive view of risk across the company.
- Work with GRC tool to develop and improve workflows and processes related to management of risk
- Process policy exception requests as needed or ad-hoc risk analysis as assigned as well as execute a detailed audit plan and identify risk areas, develop action plans, and monitor completion.
- Draft clear, concise audit reports that communicate key insights and observations to functional/business personnel and executive leadership.
- Demonstrate effective teaming skills with the ability to work independently as needed; leading initiation, execution, and completion to finalization and reporting for key work tasks
Required Qualifications
- Bachelor’s degree in Information Technology, Information Systems, Risk Management, Accounting or similar
- 5-8 years of experience related to internal/external audit, information technology, or internal controls
- Internal/External Audit, Sarbanes-Oxley, or other internal control (IT or operational) project experiences. Strong verbal and written communication skills, with the ability to effectively communicate complex cybersecurity and IT issues and concepts to non-technical stakeholders
- Experience using GRC tool for managing risk and compliance workflows
#LI-NP2
McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.
As a general policy, McCormick does not offer employment visa sponsorships upon hire or in the future.
Base Salary: $87,910-$153,870
Base salary compensation will be determined based on factors such as geographic location, skills, education, experience for this role, and/or internal equity of our current employees as part of any final offer. This position is also eligible to participate in McCormick’s Incentive Bonus (MIB) Plan. In addition to a competitive compensation package, permanent employees of McCormick are eligible for our extensive Total Rewards programs that include:
- Comprehensive health plans covering medical, vision, dental, life and disability benefits - Family-friendly benefits such as paid parental leave, fertility benefits, Employee Assistance Program, and caregiver support - Retirement and investment programs including 401(k) and profit-sharing plans
Frequently Asked Questions
How do I apply for the Senior Security Risk Analyst (HYBRID) position at McCormick & Company?
Use the Apply button above to submit your application directly to McCormick & Company. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Is the Senior Security Risk Analyst (HYBRID) role at McCormick & Company remote or in-office?
This is a hybrid role based in Cockeysville. Expect a mix of in-office and remote days, with the specific cadence set by the hiring manager.
What does a Senior Security Risk Analyst (HYBRID) at McCormick & Company earn?
McCormick & Company has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Senior Security Risk Analyst (HYBRID) role at McCormick & Company posted?
This role was posted on April 22, 2026 (48 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
How much experience does the Senior Security Risk Analyst (HYBRID) role at McCormick & Company require?
This is a senior-level position. Most senior roles call for 5+ years of directly relevant experience. McCormick & Company lists their specific requirements in the description below, so review the must-have qualifications closely before applying.
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get Started FreeNo credit card to start