Cyber Risk Program Manager

Reposted 6 Days Ago
2 Locations
In-Office or Remote
115K-154K Annually
Senior level
Food
The Role
The Cyber Risk Program Manager leads cyber risk management initiatives, ensuring risks are identified and managed, while promoting risk governance across the organization.
Summary Generated by Built In

The Cyber Risk Program Manager leads the operationalization of Yum!’s enterprise cyber risk management initiatives, including the Crown Jewels Program — ensuring risks are identified, assessed, and managed in alignment with NIST CSF 2.0CIS Controls, and FAIR principles. This role embeds risk governance practices across brands and markets, overseeing the cyber risk lifecycleexception management, and continuous improvement of the risk operating model.  The Program Manager acts as a coach and mentor to Cyber Risk team members and stakeholders, strengthening Yum!’s risk culture through leadership, data-driven insight, and effective cross-functional engagement. 

Responsibilities

Cyber Risk Program Operationalization 
•    Lead the operationalization of Yum!’s enterprise cyber risk management framework across brands, enabling measurable, repeatable, and scalable processes. 
•    Maintain and continuously refine the enterprise risk register, ensuring risks are consistently assessed, updated, and tracked through mitigation or acceptance. 
•    Translate risk appetite and tolerance thresholds into actionable decision criteria and embed these into enterprise processes. 
•    Develop and report Key Risk Indicators (KRIs), leveraging automation and data analytics for timely insights. 
•    Partner with IT, Security Engineering, and ERM to ensure risk data quality and alignment with enterprise priorities. 


Governance, Risk, and Compliance (GRC) Operations 
•    Manage daily operations within the GRC platform, ensuring data integrity and accurate reporting. 
•    Oversee risk assessments, remediation tracking, and control validation across cybersecurity domains. 
•    Enhance automation and reporting pipelines in collaboration with BI and data teams, leveraging prompt engineering to improve risk insight generation and dashboarding. 


Control Framework and Exception Management 
•    Oversee the operationalization of Yum!’s control alignment model across CIS, PCI DSS, ISO 27001, and SOC 2 frameworks as applicable.  
•    Lead exception management, ensuring exceptions are risk-assessed, approved, tracked, and reviewed according to enterprise policy. 
•    Manage the lifecycle of risk issues — classification, remediation, and closure validation — ensuring proper documentation and leadership visibility. 

Stakeholder Engagement and Communication 
•    Serve as a key liaison between Cyber Risk, ERM, and Compliance teams to align methodologies and governance reporting. 
•    Communicate risk insights to senior leaders, translating technical data into business impact. 
•    Promote a risk-aware culture through targeted engagement, education, and communication initiatives. 

Leadership and Coaching 
•    Lead and coach a team of Cyber Risk Analysts, fostering professional development and technical growth. 
•    Provide leadership oversight on prioritization, performance management, and delivery alignment. 
•    Actively mentor team members and peer leaders on effective risk communication, analysis methods, and GRC tool utilization. 
•    Represent the Cyber Risk function on steering committees and cross-functional governance councils. 

 
Key Performance Indicators (KPIs) 
 

Functional Areas 
•    Technical Delivery: Effective use of automation and prompt-engineering-driven analytics for GRC insights. 
•    People Management: Demonstrated team skill growth and engagement improvement (measured via feedback and performance outcomes). 
•    Operational Efficiency: Improved exception turnaround time and policy compliance adherence. 
•    Product Impact: Clear linkage of cyber risk insights to business outcomes and investment decisions. 
 


Qualifications

Required Skills 
•    Expertise in cyber risk governance, risk assessment methodology, and risk analytics. 
•    Proficiency in GRC platforms (Auditboard, ServiceNow, or similar). 
•    Advanced prompt engineering skills for generative AI use cases in data analysis, reporting, and communication. 
•    Strong stakeholder engagement, coaching, and cross-functional collaboration skills. 
•    Analytical mindset with ability to operationalize frameworks into measurable outcomes. 
 
Qualifications 
•    Bachelor’s degree in Cybersecurity, Risk Management, or related discipline. 
•    8+ years of experience in cybersecurity risk or governance functions. 
•    Deep understanding of NIST CSF 2.0, CIS Controls, FAIR, and enterprise risk governance principles. 
•    Proven success in program operationalization (not just implementation) and leading cross-functional teams. 
•    Excellent written and verbal communication skills. 
•    Proficient in written and spoken English. 
Salary Range: $114,900 - $154,185 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate’s location, experience, and other job-related factors.


Skills Required

  • Expertise in cyber risk governance, risk assessment methodology, and risk analytics.
  • Proficiency in GRC platforms (Auditboard, ServiceNow, or similar).
  • Advanced prompt engineering skills for generative AI in data analysis, reporting, and communication.
  • Strong stakeholder engagement, coaching, and cross-functional collaboration skills.
  • Bachelor's degree in Cybersecurity, Risk Management, or related discipline.
  • 8+ years of experience in cybersecurity risk or governance functions.
  • Deep understanding of NIST CSF 2.0, CIS Controls, FAIR, and enterprise risk governance principles.
  • Proven success in program operationalization and leading cross-functional teams.

Yum! Brands Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Yum! Brands and has not been reviewed or approved by Yum! Brands.

  • Leave & Time Off Breadth Corporate roles include four weeks of vacation, year‑round half‑day Fridays, company holidays, dedicated “Live Well” days, and paid volunteer days. These policies contribute meaningfully to overall compensation value for corporate employees.
  • Wellbeing & Lifestyle Benefits Offerings include free access to mental‑health counselors, onsite/virtual wellness tools, onsite gyms in select offices, and wellbeing discounts. Smoking‑cessation and weight‑management programs further bolster lifestyle support.
  • Parental & Family Support Benefits span family‑planning coverage such as adoption, fertility, and baby‑bonding leave. Corporate materials also note enhanced parental leave for U.S. corporate employees.

Yum! Brands Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Louisville, KY
6,056 Employees
Year Founded: 1997

What We Do

Yum! Brands, Inc., based in Louisville, Kentucky, and its subsidiaries franchise or operate a system of over 55,000 restaurants in more than 155 countries and territories under the Company’s concepts – KFC, Taco Bell, Pizza Hut and the Habit Burger Grill. The Company's KFC, Taco Bell and Pizza Hut brands are global leaders of the chicken, Mexican-style food, and pizza categories, respectively. The Habit Burger Grill is a fast casual restaurant concept specializing in made-to-order chargrilled burgers, sandwiches and more. What makes Yum! a great place to work? It's our people. As the world's largest restaurant company, we invest in people capability so that our global workforce can make the most of their careers. With ongoing opportunities for personal and professional success, we've built a culture that rewards and recognizes great effort while providing the flexibility that is so important to all of us.

Similar Jobs

UL Solutions Logo UL Solutions

Senior Sales Executive

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
2 Locations
15000 Employees
95K-193K Annually

UL Solutions Logo UL Solutions

Senior Sales Executive

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
2 Locations
15000 Employees
95K-193K Annually

Wipfli Logo Wipfli

Transaction Advisory Services Manager

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
3000 Employees
117K-158K Annually

Wipfli Logo Wipfli

Director - Transaction Advisory Services

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
3000 Employees
142K-191K Annually

Similar Companies Hiring

McCain Foods Thumbnail
Food • Retail • Agriculture • Manufacturing
Florenceville-Bristol, NB
20000 Employees
Munchkin, Inc. Thumbnail
Consumer Web • eCommerce • Food • Kids + Family • Design • Manufacturing
Milton, Ontario
325 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account