Sr Cybersecurity Lead, Offensive Security
GURGAON, IN, 122001
You may know McCormick as a leader in herbs, spices, seasonings, and condiments – and we’re only getting started. At McCormick, we’re always looking for new people to bring their unique flavor to our team.
McCormick employees – all 14,000 of us across the world – are what makes this company a great place to work.
We are looking to hire an Offensive Security Lead immediately in a Hybrid (50/50) capacity at our Global Headquarters in Hunt Valley, Maryland.
What We Bring To The Table:
The best people deserve the best rewards. In addition to the benefits you’d expect from a global leader (401k, health insurance, paid time off, etc.) we also offer:
• Competitive compensation
• Career growth opportunities
• Flexibility and Support for Diverse Life Stages and Choices
About the job
You may know McCormick as a leader in herbs, spices, seasonings, and condiments – and we’re only getting started on our journey to create flavors for the globe. At McCormick, we’re always looking for new people to bring their unique perspective to our team.
McCormick employees – all 14,000 of us across the world – are what makes this company a great place to work.
We are looking to hire an Offensive Security Lead immediately in a Hybrid (50/50) capacity at our Gurgaon office.
What We Bring To The Table
The best people deserve the best rewards. In addition to the benefits you’d expect from a global leader (401k, health insurance, paid time off, etc.) we also offer:
- Competitive compensation
- Career growth opportunities
- Flexibility and Support for Diverse Life Stages and Choices
Responsibilities
- Own the offensive security product strategy, roadmap, service model, and continuous improvement plan.
- Lead authorized penetration tests, red team engagements, purple team exercises, and AI security assessments across IT, cloud, and OT environments.
- Serve as technical lead for complex assessments, including attack-path analysis and adversary simulation.
- Partner with Threat Detection and Response teams to validate controls and improve detection, prevention, and response coverage.
- Establish testing standards, rules of engagement, reporting requirements, quality controls, and safety practices.
- Translate findings into prioritized, actionable remediation plans with product, platform, and business owners.
- Evaluate and introduce relevant offensive security tools, methods, and automation capabilities.
- Define program metrics and communicate exposure, remediation progress, and strategic risk to technical and executive stakeholders.
Required Qualifications
- Bachelor’s degree in computer science, information security, related discipline, or equivalent demonstrated experience.
- Relevant certifications such as OSCP, OSEP, OSWE, GPEN, CISSP, cloud security certifications, or equivalent demonstrated expertise.
- Five to eight years of cybersecurity experience, including hands-on penetration testing, red teaming, adversary simulation, or security assessment experience.
- Demonstrated expertise in at least two areas: application security, cloud security, identity security, network security, OT security, red teaming, or AI security.
- Strong knowledge of operating systems, networking, enterprise identity, cloud platforms, application architectures, and common attack techniques.
- Experience leading authorized assessments across complex enterprise environments and coordinating stakeholders through remediation.
- Experience assessing security risks in cloud-hosted applications, AI-enabled solutions, or AI models and supporting infrastructure.
- Understanding of OT security considerations, including the need for operational safety, business coordination, and controlled testing approaches.
As a general policy, McCormick does not offer employment visa sponsorships upon hire or in the future.
McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.