Market Information Security Officer

Yum! Brands, Inc.
  • Louisville, KY
    15 days ago

    Job Description

    Job Description:

    As Market Information Security Officer (ISO) supporting Yum! Brands, and as part of the Yum! Global Cybersecurity team, you will serve as the primary security leader for one or more markets, acting as a strategic liaison between the business and the enterprise cybersecurity function.

    As Market ISO, you are responsible for ensuring that security policies, standards, and practices align with business objectives while effectively managing cyber risks. This role will drive security awareness, risk mitigation and compliance efforts within the business unit, partnering with stakeholders to embed security into processes, products and services.

    Skills/Knowledge Requirements

    • 10+ years of progressive experience in cybersecurity, risk management or related discipline, with at least 2 years in a leadership role.

    • Excellent communication and stakeholder management skills with the ability to convey complex security concepts to non-technical audiences, including business executives.

    • Strong collaboration skills with a history of building cross-functional relationships between business, IT, and security teams.

    • Deep understanding of ecommerce platform technologies and architectures (e.g., web applications, APIs, payment systems, mobile apps, content delivery networks).

    • Strong knowledge of security threats, attack vectors, and mitigation strategies specific to ecommerce and other digital environments, including DDoS mitigation, secure payment processing, and data privacy.

    • Strong expertise in securing cloud environments, including Identity and Access Management, cloud-native security tools, data protection, logging/monitoring, and compliance frameworks (CIS Benchmarks, ISO 27017)

    • Experience securing restaurant networks and other restaurant technologies preferred.

    • Familiar with incident response processes and incident response table-top exercises.

    • Experience with common security metrics, security reporting, and management dashboards.

    • Good understanding of security frameworks, compliance requirements, and industry best practices (PCI Controls, SANS 20 Security Controls, NIST 800-53, SOC 2 Type II, ISO 27001/02 etc.)

    Education/Certifications:

    • Bachelor's degree in Information Security, Computer Science or a related field

    • Relevant certifications such as - CISM, CISA, CISSP are a plus

    Salary Range: $157,100 to $203,300 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate's location, experience, and other job-related factors.

    Key Responsibilities:

    • Act as the primary security advisor for assigned market(s), ensuring alignment between business priorities and enterprise security goals.

    • Proactively and regularly engage with market cross functional teams to stay abreast of business initiatives and identify and lead opportunities for security intervention.

    • Create and lead a security strategy tailored to the markets' specific needs, risks, and regulatory requirements.

    • Act as a consultant to the business by providing expert guidance to market business leaders on security risks, controls, and best practices.

    • Track market compliance and risk remediation efforts.

    • Advise market teams in preparation for security audits, assessments and other compliance efforts.

    • Advocate for security by design in business processes, projects, and product development

    • Drive the development and testing of business unit-specific incident response and disaster recovery plans.

    • Act as the primary security point of contact during security incidents affecting the business unit.

    • Report security metrics and risk insights to market leadership and/or other governance stakeholders.

    • Successfully build franchisee relationships and influence franchisee's to adopt security initiatives.

    Key Responsibilities:

    • Act as the primary security advisor for assigned market(s), ensuring alignment between business priorities and enterprise security goals.

    • Proactively and regularly engage with market cross functional teams to stay abreast of business initiatives and identify and lead opportunities for security intervention.

    • Create and lead a security strategy tailored to the markets' specific needs, risks, and regulatory requirements.

    • Act as a consultant to the business by providing expert guidance to market business leaders on security risks, controls, and best practices.

    • Track market compliance and risk remediation efforts.

    • Advise market teams in preparation for security audits, assessments and other compliance efforts.

    • Advocate for security by design in business processes, projects, and product development

    • Drive the development and testing of business unit-specific incident response and disaster recovery plans.

    • Act as the primary security point of contact during security incidents affecting the business unit.

    • Report security metrics and risk insights to market leadership and/or other governance stakeholders.

    • Successfully build franchisee relationships and influence franchisee's to adopt security initiatives.

    Numbers & Facts

    LocationLouisville, KY

    Skills

    • Application Programming Interface (API)unmatched
    • Benchmarkingunmatched
    • Best Practicesunmatched
    • Business Developmentunmatched
    • Business Processesunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Consultingunmatched
    • Content Delivery Network (CDN)unmatched
    • Cross-Functionalunmatched
    • Data Processingunmatched
    • Denial of Service (DoS)unmatched
    • Disaster Recoveryunmatched
    • Enterprise Protectionunmatched
    • ISO (International Organization for Standardization)unmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Applicationunmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Maintain Complianceunmatched
    • Metricsunmatched
    • Mobile Applicationsunmatched
    • Mobile Paymentsunmatched
    • PCIunmatched
    • Payment Processingunmatched
    • Product Developmentunmatched
    • Regulatory Complianceunmatched
    • Regulatory Requirementsunmatched
    • Reporting Dashboardsunmatched
    • Risk Managementunmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Auditingunmatched
    • Security Designunmatched
    • Team Playerunmatched
    • Test Plan/Scheduleunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • Unit Testunmatched
    • eCommerceunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder