Security & Cyber Incident Response Engineer
Yum! Louisville, Kentucky, United States · $131K–$164K/yr
Restaurants · 10,001+ employees
About the role
The role involves leading technical investigations and coordinating incident response activities across global enterprise systems, including cloud and network environments. You will also drive continuous improvements to security playbooks and mentor team members while communicating risks to executive leadership.
What they look for
Requirements
Candidates must have a bachelor's degree in computer science or a related field and at least 5 years of cybersecurity experience. Proficiency in incident response processes, cloud environments like Azure/AWS, and relevant industry certifications such as GCIH or Security+ is required.
Full description
Yum! Brands has a new opportunity for an Information Security & Cyber Incident Response Engineer. This role gives a successful candidate the opportunity to influence Yum’s business at a global level by working to drive the Global Cybersecurity strategy by further progressing the incident response program. The position partners with various Information Technology teams, business functions, and other key stakeholders to gain commitment and alignment to identify and manage risk. In this role, you will have the opportunity to learn our business from the ground up while working on cutting edge technologies. The ideal candidate will be protecting enterprise systems and information by responding to security threats and incidents, working autonomously or as part of a geographically diverse team to detect, examine and resolve cybersecurity incidents globally.
For this role, the ideal candidate will need to have the ability to work extended hours including nights, weekends, and holidays with little notice to facilitate incident response. This role also requires participation in after-hours on-call rotation, including the ability to investigate reported incidents within 30 minutes of notice.
Responsibilities
Responsibilities
- Lead technical investigation activities across endpoints, servers, networks, cloud environments, identities, applications, and other enterprise platforms to identify affected assets, accounts, data, indicators of compromise, attack vectors, and root cause.
- Coordinate and execute technical containment, eradication, and remediation activities, including endpoint isolation, account disablement, access revocation, IOC blocking, credential resets, malware removal, vulnerability remediation, system reconfiguration, and other corrective actions as appropriate.
- Maintain a comprehensive incident timeline and document investigative findings, technical decisions, response actions, approvals, communications, and evidence references throughout the incident lifecycle.
- Partner with Security Operations, Cyber Threat Intelligence, Digital Forensics, Security Engineering, Vulnerability Management, Threat Hunting, Architecture, infrastructure teams, and other technical stakeholders to coordinate investigation and response activities.
- Serve as Incident Response Lead for complex and high-severity cybersecurity incidents, independently coordinating technical workstreams, establishing investigative priorities, driving technical decisions, managing dependencies, and escalating material risks and decisions to cybersecurity leadership.
- Apply threat intelligence and adversary behavior analysis during active investigations to reconstruct attack paths, identify attacker objectives, assess potential additional compromise, and inform containment and remediation strategies.
- Lead and participate in incident response exercises, tabletop simulations, and post-incident reviews; identify capability gaps and own or drive continuous improvements to incident response playbooks, procedures, investigation methodologies, automation, tooling, monitoring, and technical controls.
- Independently develop and coordinate technical response strategies for complex incidents, including situations where established playbooks, procedures, or precedent may not fully address the circumstances, exercising judgment based on incident type, severity, business impact, operational risk, evidence-preservation requirements, and business continuity considerations.
- Validate the effectiveness of containment and remediation actions, confirm that residual indicators of compromise or attacker persistence have been removed, and ensure corrective actions address identified root causes and reduce the likelihood of recurrence.
- Coordinate secure recovery of affected systems and services with infrastructure, application, cloud, and business teams, including validation of rebuilt systems, restored data, security configurations, and enhanced controls before returning systems to normal operation.
- Coordinate technical response activities with third-party vendors, service providers, cloud providers, and external incident response partners in accordance with established incident response procedures and contractual requirements.
- Maintain accurate, timely, and auditable Security Incident Records (SIRs) within ServiceNow, including incident scope, severity, investigation findings, actions taken, decisions, status updates, evidence references, and closure documentation.
- Communicate technical findings, risks, incident impact, response options, dependencies, and implications of technical decisions to cybersecurity leadership, business stakeholders, executive leadership, and other technical and non-technical audiences as appropriate.
- Identify systemic security control, monitoring, architecture, and operational gaps discovered through investigations and influence partner teams to implement corrective actions that reduce enterprise cybersecurity risk and the likelihood of recurrence.
- Serve as a technical resource and mentor for less-experienced security engineers and analysts, providing guidance on investigation methodology, technical analysis, incident response decisions, and complex escalations.
Qualifications
Minimum Requirements
- Bachelor’s degree in computer science, information security or related field
- Industry certifications such as CompTIA Security+, CompTIA CySA+, GIAC Certified Incident Handler (GCIH)
- 5+ years of cybersecurity experience, including significant hands-on experience in security incident response, security operations, or equivalent relevant experience
- Knowledge of incident response processes (detection, triage, incident research, remediation, and reporting)
- Knowledge of administration and use of Linux, Mac, and Windows systems
- Knowledge of complex cloud environments, specifically providers such as Azure and Amazon AWS
- Ability to communicate complex technical findings, risks, and recommendations effectively to technical and non-technical audiences
- Proficient in written and spoken English
Preferred Requirements
- Experience with leading Incident Response in a global organization with Cloud and Software as a Service exposure
- Experience with large scale and complex incidents of all types to include Advanced Threats, DDoS, insider, web and mobile applications, data ex-filtration etc.
- Knowledge of Cybersecurity practices, operations, risk management processes, methods, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies
- Thorough knowledge of networking and security architecture
- Experience with ServiceNow Ticket Management and managing the SIR module
Key Performance Indicators (KPIs)
Short-Term Outcomes (3-6 months)
- Demonstrate consistent compliance with critical-incident engagement and on-call response requirements, including investigation initiation within required response timeframes.
- Maintain at least 95% timely and complete Security Incident Record documentation for assigned incidents, including scope, decisions, evidence references, response actions, and closure details.
- Complete or materially improve priority incident response playbooks, procedures, or investigation workflows based on identified operational gaps and lessons learned.
Long-Term Outcomes (6-12+ months)
- Drive corrective actions from significant incidents and post-incident reviews to completion within agreed timelines, with measurable reduction in repeat issues attributable to previously identified root causes.
- Deliver measurable improvements to incident response capability through enhanced playbooks, automation, tooling, monitoring, or investigation methodologies.
- Demonstrate sustained technical leadership on complex and high-severity incidents, including effective coordination, decision-making, escalation, and recovery.
Functional Areas
- Technical Delivery: Produce accurate, defensible investigations and validate containment, eradication, remediation, and secure recovery before incident closure.
- Operational Efficiency: Improve response consistency and reduce avoidable investigation or remediation delays through reusable processes, automation, and technical standards.
- Technical Leadership & Influence: Mentor less-experienced team members, provide guidance on complex escalations, and influence partner teams to address systemic security gaps.
- Stakeholder Impact: Communicate incident risk, impact, response options, dependencies, and technical decisions clearly to cybersecurity leadership, business stakeholders, and executive audiences.
Salary Range: $131,100 to $164,300 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we’ll consider the successful candidate’s location, experience, and other job-related factors.