Director, Technology Risk & Digital Enablement
McCormick & Company · Hunt Valley, MD · 5 days ago
Hybrid$141k–$253k/yrFull-time
Responsibilities
- Lead and own all GRAM workstreams related to global Technology Risk Universe, ensuring comprehensive coverage of IT, cyber, data, cloud, AI, and third-party technology risks.
- Lead the planning, execution, and reporting of all technology advisory and assurance initiatives across infrastructure, applications, cybersecurity, data governance, and emerging technology.
- Serve as GRAM function’s primary interface with the Technology leadership team incl. CTO, CISO, and others.
- Act as the in-house expert on all Technology matters related to Sarbanes-Oxley (SOX), corporate governance and enterprise risks and provide expert opinion on technology risk matters to the CARO, Audit Committee, and senior management, translating complex technical risks into clear business language.
- Collaborate closely with other members of GRAM leadership team to ensure that risk management activities are well-defined, coordinated, risk-based, and executed.
- Stay current with the evolving technology risk landscape (e.g., cloud, AI/ML risk, ransomware, third-party digital risk) and ensure risk mitigation and audit plans remain relevant and forward-looking.
- Oversee quality assurance on technology audit engagements, ensuring findings are well-evidenced, rated consistently, and linked to business impact.
- Champion the adoption of digital tools and capabilities within Internal Audit, including data analytics, automation/AI-assisted audit techniques, and continuous monitoring.
- Define and execute a multi-year Digital Enablement Roadmap for the GRAM function, with measurable milestones and efficiency outcomes.
- Partner with Data & Analytics, IT, and external vendors to build and sustain function-specific data pipelines, dashboards, and automated testing capabilities.
- Identify and pilot emerging technologies (e.g., natural language processing for document review, anomaly detection, GRC platform enhancements).
- Embed data-driven risk management techniques into engagements, helping teams move from sample-based testing to population-level analysis.
- Track and report on digital enablement ROI — efficiency gains, risk coverage expansion, and quality improvements.
Qualifications
- Bachelor’s degree in Information Systems or related field.
- Required: CISA, CISM, CISSP certification or quivalent.
- PREFERRED: CIA, CPA or equivalent.
- 10+ years of progressive experience in technology audit, IT risk management, or information security, with at least 4 years in a leadership role, including interaction with senior management.
- Experience managing cross-regional or multi-country audit programs, with specific exposure to emerging markets with regions.
- Strong track record of leading high-performing audit teams and developing talent at all levels.
- Exceptional communication, influencing, and executive presence skills — ability to present complex risk and audit topics to C-suite and Board audiences.
- Proficiency with audit management and GRC technology platforms (e.g., Optro, Workiva, Archer, or equivalent).
- Large, multi-brand, global, public company experience preferred.
- M&A experience preferred.
- Thorough knowledge of IT Operational Functions including IAM, Asset Management, Cybersecurity, Data Privacy.
- Demonstrated experience leading or materially contributing to a digital transformation or data analytics program within an audit or risk function.
- Robust understanding of internal auditing standards, PCAOB auditing standards, COSO, SOX, US GAAP and risk assessment practice.
- Thorough understanding of regulatory and external requirements as they relate to IT, privacy and cybersecurity for regulations such as GDPR, NERC-CIP and SOX.
- Proven track-record of implementing technology enablers such as data analytics, AI, etc. to modernize risk & audit capabilities.
- Proven ability to handle scale, change agenda, pace and overall complexity.
- Experience implementing and managing change within an organization, taking steps to remove barriers or to accelerate its pace.
- Track record of working alongside business leaders, positioning internal audit as a strategic partner, identifying and helping mitigate risk.
- Broad understanding of the inter-dependency between operational, technological, strategic and reputational risks as well as general compliance standards.
- Professional, self-starter, solution-minded, results oriented and approachable.
- Strong analytical and problem-solving skills with attention to detail and customer focus.
- Excellent organizational, time management and prioritization skills.
- Commitment to maintaining a high degree of discretion and confidentiality.