Cybersecurity Engineer II
GURGAON, IN, 122001
At McCormick, we bring our passion for flavor to work each day. We encourage growth, respect everyone's contributions and do what's right for our business, our people, our communities and our planet. Join us on our quest to make every meal and moment better.
Founded in Baltimore, MD in 1889 in a room and a cellar by 25-year-old Willoughby McCormick with three employees, McCormick is a global leader in flavour. With over 14,000 employees around the world and more than $6 Billion in annual sales, the Company manufactures, markets, and distributes spices, seasoning mixes, condiments and other flavourful products to the entire food industry, retail outlets, food manufactures, food service businesses and consumers.
While our global headquarters are in the Baltimore, Maryland, USA area, McCormick operates and serves customers from nearly 60 locations in 25 countries and 170 markets in Asia-Pacific, China, Europe, Middle East and Africa, and the Americas, including North, South and Central America
McCormick & Company, Inc., a world leader in the spice, flavor and seasonings industry, is seeking a full time Cybersecurity Engineer– Technology and Engineering. This position will report to the Sr. Manager Cybersecurity - Technology and Engineering.
Position Overview:
The Security Engineer – Secure Access owns the administration, optimization, and automation of McCormick’s internet proxy and secure remote access platforms, ensuring secure internet and private application access across our global enterprise. This role is central to enforcing Zero Trust principles through secure traffic forwarding, client connector deployments, segmentation strategies, and strong policy governance across on-prem, hybrid, and cloud environments.
Partnering closely with extended cybersecurity, network, and cloud teams, the engineer supports new application deployments, migrations, and infrastructure initiatives while troubleshooting complex connectivity and policy issues. The role also contributes to compliance monitoring, incident response, and lifecycle management activities including upgrades, certificate renewals, and capacity planning.
Why this role: This is a high-visibility, high-impact position shaping the future of secure access in a global organization. It offers hands-on ownership of leading-edge Zero Trust technologies while directly influencing enterprise architecture, resilience, and secure business growth.
Key Responsibilities:
• Administer, optimize, and automate the full Zscaler suite (ZIA, ZPA), ensuring secure internet access, private application access, and continuous validation of Zero Trust access posture across global environments.
• Design and maintain secure traffic forwarding architectures (GRE/IPSec), client connector deployments, segmentation strategies, and policy enforcement standards aligned to enterprise Zero Trust principles.
• Partner with infrastructure, cloud, and application teams to integrate secure access solutions into new deployments, cloud migrations, and modernization initiatives.
• Troubleshoot and resolve connectivity, performance, and policy-related issues across on-prem, hybrid, and cloud environments, ensuring minimal business disruption.
• Monitor and analyze operational events and traffic logs; support investigations, compliance requirements, and remediation of network and access-related incidents.
• Provide on-call support for secure remote access and related security platforms, responding to high-priority or business-impacting incidents in a timely manner.
• Manage solution lifecycle activities including platform upgrades, certificate renewals, policy optimization, capacity planning, and continuous improvement of enterprise security capabilities.
• Maintain architectural and operational documentation, conduct peer reviews, and contribute to the development of standards, procedures, and best practices.
• Collaborate cross-functionally with cybersecurity, network, and cloud engineering teams to enhance secure access architecture and drive ongoing platform maturity.
• Work with IT, cloud, and other infrastructure teams to integrate security controls into deployments and services.
• Maintain documentation like SOPs, configuration guides, and exception logs to support operational continuity.
• Provide on call and/or after-hours support occasionally as needed.
• Participate in tool evaluations, new security projects, and ongoing improvements to our tech stack.
• Share insights and updates with management—on tool performance, incidents, risks, and opportunities for improvement.
Preferred Qualifications:
- Bachelor’s degree in Computer Science, Information Technology, Information Security, or a related field (equivalent experience will be considered in lieu of degree).
- One or more relevant industry certifications such as GIAC, CCSK, OCSP, CISSP, AWS/GCP/Azure Cloud certifications, CEH, ITIL, CCNS, CISC, CPFA, RHCE,
- Microsoft Certification, Security+, or other related security credentials.
- 3–6 years of hands-on experience in endpoint security, cybersecurity engineering, or systems administration within enterprise environments, with a strong understanding of endpoint threats, controls, and operational requirements.
- Strong experience deploying and managing core endpoint security technologies, including EDR, antivirus, encryption, patch management, and posture/compliance tools across Windows platforms; Linux experience is an asset.
- Proficiency in scripting and automation (e.g., PowerShell, Python) to streamline operational tasks, enforce configuration standards, and support compliance monitoring.
- Working knowledge of security control frameworks such as NIST CSF, CIS Benchmarks, and ISO 27001, with practical experience supporting compliance and audit initiatives.
- Proven ability to collaborate cross-functionally with IT, cloud, compliance, and infrastructure teams to implement secure configurations, remediate vulnerabilities, and support incident response activities.
- Demonstrated commitment to continuous learning and professional development, staying current on evolving endpoint threats, emerging technologies, and industry best practices.
Other skills and competencies:
- Must be able to multi-task and set priorities
- Must have experience leading and working in a collaborative, multi-disciplined, globally diverse team environment.
- Effective communication skills and the ability to communicate appropriately at all levels of the organization; this includes written and verbal communications as well as visualizations
- Are hands-on and take ownership of tools and processes
- Positive approach to customer service with demonstrated ability to handle high pressure support needs in a calm, respectful, and efficient manner
- Conflict resolution skills.
- Attention to detail and follow through.
- Demonstrated ability to manage both technical and business relationships and liaise on the information needs of the business to IT and system constraints back to the business.
- Ability to maintain confidential and personal information.
- Demonstrated leader of continuous improvement ideas and implementations
- Ability to operate a multi-cultural and multi-lingual environment both with team members and internal customers (critical)
- Ability to discuss technical information with non-technical individuals across multiple cultures in multiple countries. (critical)
- English fluency (critical)
McCormick & Company is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law.
As a general policy, McCormick does not offer employment visa sponsorships upon hire or in the future.