Skip to content

Open nowPosted 30 days ago

Principal IT Security Consultant

Yum!6 open roles

Pay
$157,100 – $203,300 a year
Where
Irvine, CA, United States
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal IT Security ConsultantYum! · Irvine, CA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Yum!'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Yum! postings stay open a median of 4 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 30 days ago

Yum! median: 4 days open

The posting

Job Description

Job Description:

As Principal IT Security Consultant supporting Yum! Brands, and as part of the Yum! Global Cybersecurity team, you will serve as the primary security leader for one or more markets, acting as a strategic liaison between the business and the enterprise cybersecurity function.

As Principal IT Security Consultant, you are responsible for ensuring that security policies, standards, and practices align with business objectives while effectively managing cyber risks. This role will drive security awareness, risk mitigation and compliance efforts within the business unit, partnering with stakeholders to embed security into processes, products and services.

Responsibilities

Key Responsibilities:

  • Act as the primary security advisor for assigned market(s), ensuring alignment between business priorities and enterprise security goals.
  • Proactively and regularly engage with market cross functional teams to stay abreast of business initiatives and identify and lead opportunities for security intervention.
  • Create and lead a security strategy tailored to the markets’ specific needs, risks, and regulatory requirements.
  • Act as a consultant to the business by providing expert guidance to market business leaders on security risks, controls, and best practices.
  • Track market compliance and risk remediation efforts.
  • Advise market teams in preparation for security audits, assessments and other compliance efforts.
  • Advocate for security by design in business processes, projects, and product development
  • Drive the development and testing of business unit-specific incident response and disaster recovery plans.
  • Act as the primary security point of contact during security incidents affecting the business unit.
  • Report security metrics and risk insights to market leadership and/or other governance stakeholders.
  • Successfully build franchisee relationships and influence franchisee’s to adopt security initiatives.

Qualifications

Skills/Knowledge Requirements

  • 10+ years of progressive experience in cybersecurity, risk management or related discipline, with at least 2 years in a leadership role.
  • Excellent communication and stakeholder management skills with the ability to convey complex security concepts to non-technical audiences, including business executives.
  • Strong collaboration skills with a history of building cross-functional relationships between business, IT, and security teams.
  • Deep understanding of ecommerce platform technologies and architectures (e.g., web applications, APIs, payment systems, mobile apps, content delivery networks).
  • Strong knowledge of security threats, attack vectors, and mitigation strategies specific to ecommerce and other digital environments, including DDoS mitigation, secure payment processing, and data privacy.
  • Strong expertise in securing cloud environments, including Identity and Access Management, cloud-native security tools, data protection, logging/monitoring, and compliance frameworks (CIS Benchmarks, ISO 27017)
  • Experience securing restaurant networks and other restaurant technologies preferred.
  • Familiar with incident response processes and incident response table-top exercises.
  • Experience with common security metrics, security reporting, and management dashboards.
  • Good understanding of security frameworks, compliance requirements, and industry best practices (PCI Controls, SANS 20 Security Controls, NIST 800-53, SOC 2 Type II, ISO 27001/02 etc.)

Education/Certifications:

  • Bachelor’s degree in Information Security, Computer Science or a related field
  • Relevant certifications such as – CISM, CISA, CISSP are a plus

Salary Range: $157,100 to $203,300 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we’ll consider the successful candidate’s location, experience, and other job-related factors.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Yum!'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Yum!'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Yum!'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.