Please mention DailyRemote when applying
ARE YOU A CURRENT US FOODS EMPLOYEE? PLEASE APPLY DIRECTLY THROUGH OUR INTERNAL WORKDAY CAREER SITE
Join Our Community of Food People!
At US Foods®, innovation and technology is our superpower. By expanding our digital ecosystem and leading with a customer-first mindset, we’re delivering technology that empowers our customers and simplifies business. As we transform the digital landscape of the foodservice industry, we’re outpacing our competitors faster than ever before.The work for the Business Information Security Lead position is completely remote anywhere in the United States except Hawaii or United States Territories.
RESPONSIBILITIES
Consult on key business initiatives ensuring comprehensive end-to-end identification and risk management
Help execute the security program in collaboration with Value Stream partner by identifying and remediating risks in accordance with security policies and standards
Understand business requirements for Value Stream partner and provide security expertise to decision making and road mapping
Help Value Stream partner understand the need for security as it relates to their line of business and potential impacts, whether regulatory or possible cyber-attacks
Act as single point of contact in security for the and provide escalation path for significant security concerns and inquiries
Perform audits, assess risks, and manage/enforce remediation of issues found in security assessments, penetration tests, and internal discovery as related to Value Stream partner
Provide visibility into current security compliance status through defined set of metrics, benchmarking and providing detailed guidance on vulnerabilities
Present monthly to Value Stream Lead, sharing prioritized gap analysis, remediation plans and areas of success
Coach Product Teams to mature their understanding and use of security tools and information
Understand and articulate impacts to value stream partners in strategy and roadmap conversations within the Information and Cyber Security Team
SUPERVISION:
N/A
RELATIONSHIPS
Internal: Information and Cyber Security Team, DigiTech Value Streams, Internal and external audit, Security Engineering, Security Architecture, Cloud/DevSecOps, Data, IT PMO and Product Teams
External: Technology vendors, including software and service providers; customer risk management representative, relevant managed security services, and professional services vendors, value stream vendors
WORK ENVIRONMENT
This role has been segmented as "Remote " meaning works remotely. Can live anywhere in continental US and Alaska. Travel as needed for business.
MINIMUM QUALIFICATIONS
At least 5+ years of information security experience
Broad foundational knowledge in many information and cyber security domains with priority given to security risk management and application security
Familiarity with compliance requirements (PCI, HIPAA, SOX, etc) and with security frameworks such as NIST CSF, ISO 27001, CIS, etc
Demonstratable experience in building positive working relationships with leaders and associates across multiple areas of the business
Must have the ability to work independently and make decisions that reflect the policies of the Information and Cyber Security Team
Experience measuring and tracking cybersecurity risks, issues, and exceptions
Ability to present complex security topics to a variety of audiences, including senior technical leaders.
Ability to advise, collaborate, and work in a team environment enabling others to trust your input and seek your guidance
Ability to influence without authority to drive desired outcomes
Experience executing security compliance plans, vulnerability management programs, risk management lifecycle, and/or security assessment/governance processes
Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively
Proactive self-development, staying current on evolving threat landscape, security trends/best practices, and dynamic regulatory requirements
Education
Bachelor’s degree from an accredited college/university OR equivalent professional experience required
Related Experience/Requirements:
Experience developing, measuring, and tracking key performance metrics, preferably in a cybersecurity program
Highly organized, efficient, and attention to detail
Demonstrable track record of successful development of resources, mentoring, and career guidance
Strong written and verbal skills enabling effective communication with different levels of leadership
Certifications/Training
Preferred but not required: SANS GSEC, GCIA (or related), CISSP
This role may also receive annual incentive plan bonus.
Benefits for this role may include health insurance, pre-tax spending accounts, retirement benefits, paid time off, short-term and long-term disability, employee stock purchase plan, and life insurance. To review available benefits, please click here: https://www.usfoods.com/careers/benefits.html.
Compensation depends on relevant experience and/or education, specific skills, function, geographic location, and other factors as applicable by law (for example: state or local minimum wage thresholds). The expected base rate for this role is between
$100,000 - $155,000***EOE – Race/Color/Religion/Sex/Sexual Orientation/Gender Identity/National Origin/Age/Genetic Information/Protected Veteran/Disability Status***
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Software Development
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“ I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!