Yum! Brands Logo

Yum! Brands

Cyber Risk Program Manager

Reposted 12 Days Ago
In-Office or Remote
Hiring Remotely in United States
115K-154K Annually
Senior level
In-Office or Remote
Hiring Remotely in United States
115K-154K Annually
Senior level
The Cyber Risk Program Manager leads cyber risk management initiatives, ensuring risks are identified and managed, while promoting risk governance across the organization.
The summary above was generated by AI

The Cyber Risk Program Manager leads the operationalization of Yum!’s enterprise cyber risk management initiatives, including the Crown Jewels Program — ensuring risks are identified, assessed, and managed in alignment with NIST CSF 2.0CIS Controls, and FAIR principles. This role embeds risk governance practices across brands and markets, overseeing the cyber risk lifecycleexception management, and continuous improvement of the risk operating model.  The Program Manager acts as a coach and mentor to Cyber Risk team members and stakeholders, strengthening Yum!’s risk culture through leadership, data-driven insight, and effective cross-functional engagement. 

Responsibilities

Cyber Risk Program Operationalization 
•    Lead the operationalization of Yum!’s enterprise cyber risk management framework across brands, enabling measurable, repeatable, and scalable processes. 
•    Maintain and continuously refine the enterprise risk register, ensuring risks are consistently assessed, updated, and tracked through mitigation or acceptance. 
•    Translate risk appetite and tolerance thresholds into actionable decision criteria and embed these into enterprise processes. 
•    Develop and report Key Risk Indicators (KRIs), leveraging automation and data analytics for timely insights. 
•    Partner with IT, Security Engineering, and ERM to ensure risk data quality and alignment with enterprise priorities. 


Governance, Risk, and Compliance (GRC) Operations 
•    Manage daily operations within the GRC platform, ensuring data integrity and accurate reporting. 
•    Oversee risk assessments, remediation tracking, and control validation across cybersecurity domains. 
•    Enhance automation and reporting pipelines in collaboration with BI and data teams, leveraging prompt engineering to improve risk insight generation and dashboarding. 


Control Framework and Exception Management 
•    Oversee the operationalization of Yum!’s control alignment model across CIS, PCI DSS, ISO 27001, and SOC 2 frameworks as applicable.  
•    Lead exception management, ensuring exceptions are risk-assessed, approved, tracked, and reviewed according to enterprise policy. 
•    Manage the lifecycle of risk issues — classification, remediation, and closure validation — ensuring proper documentation and leadership visibility. 

Stakeholder Engagement and Communication 
•    Serve as a key liaison between Cyber Risk, ERM, and Compliance teams to align methodologies and governance reporting. 
•    Communicate risk insights to senior leaders, translating technical data into business impact. 
•    Promote a risk-aware culture through targeted engagement, education, and communication initiatives. 

Leadership and Coaching 
•    Lead and coach a team of Cyber Risk Analysts, fostering professional development and technical growth. 
•    Provide leadership oversight on prioritization, performance management, and delivery alignment. 
•    Actively mentor team members and peer leaders on effective risk communication, analysis methods, and GRC tool utilization. 
•    Represent the Cyber Risk function on steering committees and cross-functional governance councils. 

 
Key Performance Indicators (KPIs) 
 

Functional Areas 
•    Technical Delivery: Effective use of automation and prompt-engineering-driven analytics for GRC insights. 
•    People Management: Demonstrated team skill growth and engagement improvement (measured via feedback and performance outcomes). 
•    Operational Efficiency: Improved exception turnaround time and policy compliance adherence. 
•    Product Impact: Clear linkage of cyber risk insights to business outcomes and investment decisions. 
 


Qualifications

Required Skills 
•    Expertise in cyber risk governance, risk assessment methodology, and risk analytics. 
•    Proficiency in GRC platforms (Auditboard, ServiceNow, or similar). 
•    Advanced prompt engineering skills for generative AI use cases in data analysis, reporting, and communication. 
•    Strong stakeholder engagement, coaching, and cross-functional collaboration skills. 
•    Analytical mindset with ability to operationalize frameworks into measurable outcomes. 
 
Qualifications 
•    Bachelor’s degree in Cybersecurity, Risk Management, or related discipline. 
•    8+ years of experience in cybersecurity risk or governance functions. 
•    Deep understanding of NIST CSF 2.0, CIS Controls, FAIR, and enterprise risk governance principles. 
•    Proven success in program operationalization (not just implementation) and leading cross-functional teams. 
•    Excellent written and verbal communication skills. 
•    Proficient in written and spoken English. 
Salary Range: $114,900 - $154,185 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate’s location, experience, and other job-related factors.


Similar Jobs

A Minute Ago
Remote
United States
110K-144K Annually
Senior level
110K-144K Annually
Senior level
Artificial Intelligence • HR Tech • Information Technology • Software • Business Intelligence
Own the VA account: prospect, demo, negotiate contracts, respond to RFx, drive new logo acquisition and account expansion, meet sales targets, and partner with internal teams to increase Qualtrics adoption across VA administrations.
Top Skills: Experience Management (Xm)FedrampHipaaMeddiccQualtrics
25 Minutes Ago
Remote or Hybrid
US
100K-130K Annually
Senior level
100K-130K Annually
Senior level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Lead UX research and design for B2B/SaaS insurance products: create wireframes, mockups, and prototypes; run user research and usability tests; use analytics to measure outcomes; collaborate with product and engineering to implement consistent, validated UX solutions.
Top Skills: BalsamiqFigmaMiroWhiteboards
25 Minutes Ago
Remote or Hybrid
US
100K-160K Annually
Senior level
100K-160K Annually
Senior level
Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Design, build, and operate enterprise-scale multi-cloud infrastructure (Azure primary, GCP, AWS exposure). Own landing zones, Terraform modules, production AKS/GKE Kubernetes, Vault secrets, hybrid networking, CI/CD pipelines, monitoring, DR, and automation (Ansible, Python/Bash). Mentor engineers, document runbooks, and collaborate with security, application teams, and leadership to ensure secure, reliable, cost-optimized cloud platforms.
Top Skills: AksAnsibleApp GatewayArtifact RegistryAWSAwxAzureAzure DevopsAzure MonitorAzure StorageBashBgpBigQueryCloud BuildCloud LoggingCloud RunCloud SqlCloudboltDatadogDnsEc2EksGitlab CiGkeGoogle Cloud MonitoringGoogle Cloud Platform (Gcp)Hashicorp VaultHelmIamJenkinsKubernetesLoad BalancingManaged IdentityNsgPowershellPrivate EndpointsPythonS3SignozTerraformVertex AiVpcVpc Service ControlsVpnWorkload Identity

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account