Market Information Security Officer
Yum! · United States
About The Role
As Market Information Security Officer (ISO) supporting Yum! Brands, and as part of the Yum! Global Cybersecurity team, you will serve as the primary security leader for one or more markets, acting as a strategic liaison between the business and the enterprise cybersecurity function.
As Market ISO, you are responsible for ensuring that security policies, standards, and practices align with business objectives while effectively managing cyber risks. This role will drive security awareness, risk mitigation and compliance efforts within the business unit, partnering with stakeholders to embed security into processes, products and services.
Key Responsibilities
- Act as the primary security advisor for assigned market(s), ensuring alignment between business priorities and enterprise security goals.
- Proactively and regularly engage with market cross functional teams to stay abreast of business initiatives and identify and lead opportunities for security intervention.
- Create and lead a security strategy tailored to the markets’ specific needs, risks, and regulatory requirements.
- Act as a consultant to the business by providing expert guidance to market business leaders on security risks, controls, and best practices.
- Track market compliance and risk remediation efforts.
- Advise market teams in preparation for security audits, assessments and other compliance efforts.
- Advocate for security by design in business processes, projects, and product development
- Drive the development and testing of business unit-specific incident response and disaster recovery plans.
- Act as the primary security point of contact during security incidents affecting the business unit.
- Report security metrics and risk insights to market leadership and/or other governance stakeholders.
- Successfully build franchisee relationships and influence franchisee’s to adopt security initiatives.
Skills/Knowledge Requirements
- 10+ years of progressive experience in cybersecurity, risk management or related discipline, with at least 2 years in a leadership role.
- Excellent communication and stakeholder management skills with the ability to convey complex security concepts to non-technical audiences, including business executives.
- Strong collaboration skills with a history of building cross-functional relationships between business, IT, and security teams.
- Deep understanding of ecommerce platform technologies and architectures (e.g., web applications, APIs, payment systems, mobile apps, content delivery networks).
- Strong knowledge of security threats, attack vectors, and mitigation strategies specific to ecommerce and other digital environments, including DDoS mitigation, secure payment processing, and data privacy.
- Strong expertise in securing cloud environments, including Identity and Access Management, cloud-native security tools, data protection, logging/monitoring, and compliance frameworks (CIS Benchmarks, ISO 27017)
- Experience securing restaurant networks and other restaurant technologies preferred.
- Familiar with incident response processes and incident response table-top exercises.
- Experience with common security metrics, security reporting, and management dashboards.
- Good understanding of security frameworks, compliance requirements, and industry best practices (PCI Controls, SANS 20 Security Controls, NIST 800-53, SOC 2 Type II, ISO 27001/02 etc.)
Education/Certifications
- Bachelor’s degree in Information Security, Computer Science or a related field
- Relevant certifications such as – CISM, CISA, CISSP are a plus
Salary Range: $157,100 to $203,300 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we’ll consider the successful candidate’s location, experience, and other job-related factors.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
