> Markdown version of [/jobs/ext/1932347-business-information-security-lead-remote](https://www.wearedevelopers.com/jobs/ext/1932347-business-information-security-lead-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Business Information Security Lead (Remote) - **Company:** US Foods, Inc. - **Location:** Buda, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $100,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing, Cyber Security, Software Vulnerability Management, Software Security, Devsecops, Workday - **Published:** August 5, 2026 - **Apply:** https://dejobs.org/x/x/7439F60ECC504360A005E65669477ABE/job/ ## About the Role ARE YOU A CURRENT US FOODS EMPLOYEE? PLEASE APPLY DIRECTLY THROUGH OUR INTERNAL WORKDAY CAREER SITE (https://www.myworkday.com/usfoods/d/task/2998$47185.htmld), * At least 5+ years of information security experience * Broad foundational knowledge in many information and cyber security domains with priority given to security risk management and application security * Familiarity with compliance requirements (PCI, HIPAA, SOX, etc) and with security frameworks such as NIST CSF, ISO 27001, CIS, etc * Demonstratable experience in building positive working relationships with leaders and associates across multiple areas of the business * Must have the ability to work independently and make decisions that reflect the policies of the Information and Cyber Security Team * Experience measuring and tracking cybersecurity risks, issues, and exceptions * Ability to present complex security topics to a variety of audiences, including senior technical leaders. * Ability to advise, collaborate, and work in a team environment enabling others to trust your input and seek your guidance * Ability to influence without authority to drive desired outcomes * Experience executing security compliance plans, vulnerability management programs, risk management lifecycle, and/or security assessment/governance processes * Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively * Proactive self-development, staying current on evolving threat landscape, security trends/best practices, and dynamic regulatory requirements Education * Bachelor's degree from an accredited college/university OR equivalent professional experience required Related Experience/Requirements: * Experience developing, measuring, and tracking key performance metrics, preferably in a cybersecurity program * Highly organized, efficient, and attention to detail * Demonstrable track record of successful development of resources, mentoring, and career guidance * Strong written and verbal skills enabling effective communication with different levels of leadership Certifications/Training * Preferred but not required: SANS GSEC, GCIA (or related), CISSP ## Description This position is responsible for supporting the Digital and Technology (DigiTech) value stream in the delivery of their initiatives and guiding the value stream through the needed actions to ensure security policies and best practices are met. With support from Information & Cyber Security leadership, this role assesses and validates the assurance of the security program, monitors progress, enforces resolution of outstanding issues, and focuses on strong risk management and corporate resiliency through a deep partnership and understanding of the Value Stream mission., * Consult on key business initiatives ensuring comprehensive end-to-end identification and risk management * Help execute the security program in collaboration with Value Stream partner by identifying and remediating risks in accordance with security policies and standards * Understand business requirements for Value Stream partner and provide security expertise to decision making and road mapping * Help Value Stream partner understand the need for security as it relates to their line of business and potential impacts, whether regulatory or possible cyber-attacks * Act as single point of contact in security for the and provide escalation path for significant security concerns and inquiries * Perform audits, assess risks, and manage/enforce remediation of issues found in security assessments, penetration tests, and internal discovery as related to Value Stream partner * Provide visibility into current security compliance status through defined set of metrics, benchmarking and providing detailed guidance on vulnerabilities * Present monthly to Value Stream Lead, sharing prioritized gap analysis, remediation plans and areas of success * Coach Product Teams to mature their understanding and use of security tools and information * Understand and articulate impacts to value stream partners in strategy and roadmap conversations within the Information and Cyber Security Team, * Internal: Information and Cyber Security Team, DigiTech Value Streams, Internal and external audit, Security Engineering, Security Architecture, Cloud/DevSecOps, Data, IT PMO and Product Teams * External : Technology vendors, including software and service providers; customer risk management representative, relevant managed security services, and professional services vendors, value stream vendors WORK ENVIRONMENT * This role has been segmented as "Remote " meaning works remotely. Can live anywhere in continental US and Alaska. Travel as needed for business. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Destigmatizing the Workplace: Building Real Inclusion](https://www.wearedevelopers.com/videos/1492-destigmatizing-the-workplace-building-real-inclusion) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)