職務内容/Job duties Position Summary
McDonald’s Japan is one of the company’s largest and most successful international markets, operating and franchising McDonald’s restaurants nationwide under McDonald’s Holdings Company (Japan), Ltd. Established in 1971 and headquartered in Tokyo, the business combines strong global brand standards with localized menu innovation and operational excellence to serve millions of customers across Japan.
The Director, Head of Cyber Security for McDonald’s Japan is responsible for providing strategic leadership, governance, and oversight of cyber security and information risk management across the Japan market. This role ensures the protection of customer, employee, franchisee, and corporate information assets while enabling business growth, digital transformation, and operational resilience. A critical aspect of this role is close partnership with McDonald’s global cyber security teams and alignment with global security strategies, standards, and operating models, while addressing local regulatory, business, and cultural requirements.
Key Responsibilities
・Develop, lead, and execute the cyber security strategy for McDonald’s Japan in alignment with local and global cyber security vision, policies, and roadmaps.
・Serve as the senior cyber security leader for Japan, providing risk-based security guidance to local executive leadership and business stakeholders.
・Manage, develop and lead the local cyber security team
・Partner closely with McDonald’s global cyber security, technology, and risk teams to ensure consistent implementation of global security controls and processes.
・Ensure compliance with global McDonald’s cyber security standards and Japan-specific regulatory and privacy requirements.
・Oversee cyber risk management activities including assessments, vulnerability management, penetration testing, and risk acceptance.
・Lead cyber incident response and crisis management for Japan in coordination with global incident response teams.
・Embed security-by-design principles across restaurant systems, digital platforms, cloud services, and third-party integrations.
・Manage security expectations and performance of vendors, service providers, and franchise partners.
・Drive security awareness and training programs across corporate and franchise environments.
・Provide transparent reporting of cyber risk, incidents, and remediation progress to local and global leadership.
・Act as the accountable owner of Japan cyber security outcomes, balancing global standardization with effective local execution.
・Drive continuous improvement of cyber security maturity, operating model, and capabilities.
・Translate cyber and information security risks into business, financial, operational, and reputational impacts for executive and officer-level discussions.
・Support enterprise risk management (ERM), audit, and assurance activities related to cyber risk.
Global Collaboration and Partnership
・Act as the primary cyber security liaison between McDonald’s Japan and global cyber security leadership.
・Participate in global cyber security governance forums, steering committees, and working groups.
・Adopt and operationalize global security processes, metrics, and reporting frameworks.
・Collaborate with global teams on major initiatives, platform rollouts, and global incident response.
・Balance global standardization with effective local execution.
応募資格/Qualifications Qualifications and Experience
・10+ years of experience in cyber security, information security, or technology risk management.
・At least 5 years in a senior leadership role within a large or complex organization including working with senior management groups
・Experience working in a global or multinational environment.
・Strong knowledge of cyber security frameworks such as NIST, ISO 27001, or CIS.
・Experience managing cyber incidents and executive-level communications.
・Understanding of Japan data protection and privacy regulations.
・Fluency in both Japanese and English.
・Experience leading governance, risk, and compliance (GRC) programs in regulated or consumer-facing industries.
・Experience in large-scale consumer, retail, hospitality, or digital platform environments.
・Professional certifications such as CISSP, CISM, CRISC (preferred).
・Executive-level security certification such as CCISO or equivalent (preferred).
・Experience owning or influencing cyber security investment and budget decisions.
Leadership Competencies
・Strategic, risk-based mindset
・Strong collaboration across local and global teams
・Decisive and calm leadership during incidents
・Ability to influence in a matrixed organization
・Commitment to continuous improvement and security culture
・Strong written and verbal communication skills
・Strong executive communication and stakeholder management skills
待遇/Salary \& Benefits - 雇用形態
正社員 ※試用期間あり(6ヶ月、同条件)
フレックスタイム制
通常の勤務時間は9時〜18時としていますが、月間所定労働時間(※)の範囲内であれば、深夜時間(22:00\~5:00)と公休日を除き、柔軟に勤務時間を決めて働くことができます。
※月間所定労働時間=8時間×1か月の勤務日数
土日祝日、年末年始休暇(12月31日および翌年1月2日、3日) 年次有給休暇(初年度10日を基準として入社時期に応じて付与) 慶弔特別有給休暇 出産、育児休暇 育児休業 育児短時間勤務制度(小学校卒業まで最大3時間短縮) 看護勤務・看護休暇(取得規定あり) 介護休暇・介護休業(取得規定あり) 育児目的休暇(取得規定あり) 永年勤続休暇(5年で5日、10年で10日、20年で20日、30年で30日の連続した特別有給休暇を付与) 誕生日休暇(1日)
給与改定/年1回、賞与/年1回
※賞与は職位ごとに定められた基準にしたがい、会社業績および個人評価を加味して支給額を決定します
※賞与の支給要件として最低3ヶ月間の勤務が必要です
勤務地/Location 日本マクドナルド株式会社本社(東京都新宿区)