Information Security Analyst (Risk & Compliance)

Performance Food Group

Richmond (VA)

On-site

USD 70,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Day 1 health benefits
Employee stock purchase plan
401K employer matching
Education assistance
Paid time off

Job summary

Performance Food Group is seeking an Information Security Analyst to support information and privacy risk management within the Information Security Department. The role focuses on identifying, quantifying, communicating, and tracking risks to information assets and ensuring compliance with internal/external policies.

Reporting to the Manager of Information Security Risk Management, you will collaborate with IT and business stakeholders on IT risk management, third-party risk, and evolving AI

Qualifications

  • Bachelor's degree required.
  • 1-3 years of information security/risk experience.
  • Ability to communicate security concepts to diverse audiences.
  • Experience evaluating AI initiatives through a security risk lens.
  • Knowledge of regulatory requirements and frameworks (SOX, CobIT, PCI DSS, GDPR, CCPA).

Responsibilities

  • Conduct risk assessments and maintain risk register.
  • Assess IT controls, identify gaps, and optimize design for cost-effective compliance.
  • Maintain risk management governance across IT and LOB stakeholders.
  • Support development of evaluative risk frameworks for new technologies (AI).
  • Maintain Business Impact Analysis and classify risk for applications/infrastructure.
  • Support third-party risk management and contract security requirements.

Skills

Risk management
Regulatory knowledge
IT security risk assessments
AI risk evaluation
Stakeholder communication

Education

Bachelor's Degree

Tools

Azure Information Protection

Job description

  • Competitive pay and benefits, including Day 1 Health & Wellness Benefits, Employee Stock Purchase Plan, 401K Employer Matching, Education Assistance, Paid Time Off, and much more
  • Growth opportunities performing essential work to support America’s food distribution system
  • Safe and inclusive working environment, including culture of rewards, recognition, and respect
We Deliver the Goods
  • Competitive pay and benefits, including Day 1 Health & Wellness Benefits, Employee Stock Purchase Plan, 401K Employer Matching, Education Assistance, Paid Time Off, and much more
  • Growth opportunities performing essential work to support America’s food distribution system
  • Safe and inclusive working environment, including culture of rewards, recognition, and respect
Position Summary

Performance Food Group is looking for a talented Information Security Analyst to play a key role in supporting Information and Privacy Risk Management aspects of the company as a member of the Information Security Department. PFG is in the midst of establishing a Risk Management function that focuses on identifying, quantifying, communicating, and tracking risks associated with information assets. Reporting to the Manager of Information Security Risk Management and working with IT and line of business stakeholders, the analyst will have a heavy focus on compliance with internal/external policies/statutes, IT Risk Management, and Third Party Risk.

Position Responsibilities
  • Conduct risk assessments and maintain risk register. Perform assessments of IT controls processes, and systems, identifying gaps and opportunities to enhance design\operational effectiveness while reducing the cost of compliance. Conduct periodic readouts and risk reviews with IT teams and segment/line of business stakeholders to convey risk and influence decision making
  • Assist in maintaining security exception lifecycle, including qualfiying associated risk, determining compensating controls, communicating with IT and LOB stakeholders.
  • Assist in development of evaluative risk frameworks for new and emerging technologies, including but not limited to Artificial Intelligence
  • Maintain Business Impact Analysis. Work with IT and LOB teams to maintain Business Impact Analysis, establishing risk categorizations for applications and infrastructure based on mission criticality and sensitivity of hosted data.
  • Assist in development and implementation of Enterprise Crown Jewels program. Work with IT, LOB teams, and security control owners to define and govern control parameters for critical applications and technologies.
  • KPI/KRI Development and Reporting. Assist in development of control-based Key Risk Indicators and Key Performance Indicators across business segments. Assist in developing associated governance model and metric tiers for consumption by various levels of stakeholders, up to and including the Board of Directors.
  • Support IT Risk and exception management governance forums across business segments with varying operational models and business context.
  • Support PFG’s Third Party Risk Management Program, assessing third parties for inherent and residual risk based on the nature of their services and their ability to appropriately secure PFG data and provide dependent services.
  • Negotiate the inclusion of security requirements into third party contract agreements.
  • Develop and Maintain IT Audit and Control documentation.
  • Support necessary governance forums (committees, working groups) to ensure sound decision-making and stakeholder communications.
  • Identify and report on non-compliance with regulatory mandates (i.e. Sarbanes Oxley section 404 PCI DSS, HIPAA, GDPR, CCPA).
  • Support operational audits as necessary.
  • Performs other related duties as assigned.
Required Qualifications
  • Bachelors Degree
  • 1 - 3 Years of experience
  • Experience in developing, communicating, and presenting security or risk concepts to varying audiences
  • Experience with evaluating AI initiatives through a security risk lens
  • Knowledge of regulatory requirements and frameworks
  • Development and implementation of security policies
  • Experience conducting security maturity assessments
  • Development and implementation of security controls
  • Strong teamwork and interpersonal skills
  • Experience in assisting with process improvement initiatives
  • Hold relevant security certifications or willingness to pursue additional certifications
  • Continuous learning mindset
  • Experience performing IT and security risk assessments, using both qualitative and quantitative methods to identify, quantify, and communicate risk
  • Working knowledge of privacy statutes including the European Union General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA)
  • Experience with Data Classification, Data Security, and Data Loss Prevention methods and tools, specifically Microsoft Azure Information Protection
  • Strong MS Office skills (specifically PowerPoint, Word, Excel, Project, Visio)
  • Strong process analysis and engineering skills
  • Experience conducting and documenting business impact analysis, designing and implementing Business Continuity/Disaster Recovery plans
  • Experience with IT assurance mandates/frameworks such as Sarbanes-Oxley, CobIT
  • Demonstrated leadership skills
  • Demonstrated high level of analytical and problem-solving skills
  • Excellent written and verbal communication skills
  • Ability to influence cross functional and highly matrixes business and IT stakeholders
Compensation

70,000-100,000 + 15% Bonus Opportunity

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst (Risk & Compliance)
Information Security Analyst (Risk & Compliance)

Core-Mark • Richmond (VA)

On-site
USD 85,000 - 120,000
Information Security Analyst (Risk & Compliance)
Information Security Analyst (Risk & Compliance)

Performance Food Group (New) • Richmond (VA)

On-site
USD 90,000 - 130,000
Day 1 Health & Wellness Benefits
Employee Stock Purchase Plan
401K Employer Matching
+2
Information Security Risk & Compliance Specialist
Information Security Risk & Compliance Specialist

Performance Food Group • Richmond (VA)

On-site
USD 70,000 - 100,000
Day 1 health benefits
Employee stock purchase plan
401K employer matching
+2
Information Security Risk & Compliance Analyst
Information Security Risk & Compliance Analyst

Core-Mark • Richmond (VA)

On-site
USD 85,000 - 120,000
Compliance and Risk Analyst - PCC
Compliance and Risk Analyst - PCC

ViziRecruiter,LLC. • Merrimack (NH)

On-site
USD 70,000 - 90,000
401k plans
Medical insurance
Mental health resources
+1
Senior Risk and Compliance Analyst
Senior Risk and Compliance Analyst

cbrands • United States

On-site
USD 97,000 - 148,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 54,000 - 90,000
Hybrid work model
Relocation assistance
Certifications support
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

Socket.dev • McHenry (IL)

Hybrid
USD 15,000 - 120,000
Information Security GRC Analyst
Information Security GRC Analyst

Paymentus • Charlotte (NC)

On-site
USD 85,000 - 120,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000