Business Information Security Lead
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Business Information Security Lead securing US Foods’ digital foodservice technology ecosystem. Managing cybersecurity risks, compliance, assessments, and remediation across DigiTech value streams.
Responsibilities:
- Consult on key business initiatives, ensuring end-to-end identification and risk management
- Execute the security program with Value Stream partners by identifying and remediating risks according to security policies and standards
- Understand business requirements and provide security expertise for decision-making and roadmaps
- Explain the business need for security and potential regulatory or cyber-attack impacts
- Act as the single security point of contact for the Value Stream and provide escalation for significant concerns
- Perform audits, assess risks, and manage or enforce remediation of issues from security assessments, penetration tests, and internal discovery
- Provide security compliance visibility through metrics, benchmarking, and vulnerability guidance
- Present monthly prioritized gap analyses, remediation plans, and successes to the Value Stream Lead
- Coach Product Teams on the maturity and use of security tools and information
- Articulate impacts to Value Stream partners during strategy and roadmap discussions with the Information and Cyber Security Team
- Collaborate with internal teams, auditors, vendors, managed security services, and professional services providers
- Travel as needed for business
Requirements:
- At least 5+ years of information security experience
- Broad foundational knowledge across information and cybersecurity domains, especially security risk management and application security
- Familiarity with PCI, HIPAA, SOX, NIST CSF, ISO 27001, CIS, and similar frameworks
- Experience building positive relationships across multiple business areas
- Ability to work independently and make policy-aligned decisions
- Experience measuring and tracking cybersecurity risks, issues, and exceptions
- Ability to present complex security topics to varied audiences, including senior technical leaders
- Ability to advise, collaborate, and work in a team environment
- Ability to influence without authority
- Experience executing security compliance plans, vulnerability management programs, risk management lifecycles, and/or security assessment/governance processes
- Bachelor’s degree from an accredited college/university or equivalent professional experience required
- Experience developing, measuring, and tracking key performance metrics, preferably in cybersecurity
- Highly organized, efficient, and detail-oriented
- Track record of developing resources, mentoring, and providing career guidance
- Strong written and verbal communication skills
- Proactive self-development and awareness of evolving threats, security trends, best practices, and regulatory requirements
- Preferred but not required: SANS GSEC, GCIA or related certification, CISSP
Benefits:
- Annual incentive plan bonus may apply
- Health insurance
- Pre-tax spending accounts
- Retirement benefits
- Paid time off
- Short-term disability
- Long-term disability
- Employee stock purchase plan
- Life insurance
- Remote work arrangement




















