
Sr. Lead Cybersecurity Analyst, Cybersecurity
Chick-fil-A Restaurants
Job description
How We Work At Chick-fil-A
Chick-fil-A, Inc. ('Chick-fil-A' or 'the Company') Staff members play a vital role in achieving our strategic goals by developing their skills, fostering inclusive teamwork, and embracing innovation. All Staff are expected to contribute to a compelling future by inspiring and motivating those around them. Growth and development are essential at Chick-fil-A. We want Staff to seek new perspectives and adopt new methods to drive continuous improvement and adaptation to evolving business needs. Lastly, we ask Staff to seek wisdom, expect the best, accept responsibility, respond with courage, and think others first.
Our Flexible Futures Model offers a healthy mix of working in person (currently a minimum of 8-10 days per month) and virtually, strengthening key elements of the Chick-fil-A culture by fostering collaboration and community.
Overview
Join a small family of cybersecurity advisors who aid their colleagues across the company to become more aware of cybersecurity best practices in each user's role and projects while coordinating response to emergent system vulnerabilities. As part of Cybersecurity Consulting within the Digital Transformation and Technology (DTT) department’s cybersecurity team, you will serve as a trusted advisor to other teams by applying cybersecurity expertise across multiple domains. You will exercise initiative and influence while working independently with product, engineering, architecture, privacy, legal, and business teams. The role will advise on cybersecurity requirements for complex systems and initiatives, especially those involving mobile applications, cloud-hosted workloads, APIs, sensitive data, third-party integrations, and modern software delivery practices. You will help teams identify risks early, translate cybersecurity and privacy requirements into practical implementation guidance, and support secure-by-design decisions throughout the lifecycle of digital products and platforms. The role will also contribute to the continuous improvement of cybersecurity standards, secure development expectations, assessment methods, governance practices, and architecture patterns that help protect Chick-fil-A digital resources and information. You will be responsible to advise your colleagues on best practices to establish security in multiple business areas and remediate security gaps in existing projects that span all current and imagined technologies, especially in mobile and cloud environments. Your team's work encompasses the traditional functional cybersecurity practices of awareness training, information systems security management, risk assessments, and vulnerability management, so you will get to influence security strategies across all business areas of the company.
Responsibilities
-
Know and independently apply broad comprehensive knowledge of cybersecurity best practices to the completion of highly complex assignments
-
Own and manage responsibility for information systems security management as the primary cybersecurity consultant to one or more major DTT sub-departments. Learn, advise, and collaborate on the security issues of that team’s technical projects, working independently on complex projects with support and mentoring by the team leader as needed.
-
Provide cybersecurity guidance for mobile application security, secure authentication and authorization, API integrations, secure architectures, data protection, and vulnerability management.
-
Advise department leadership on cybersecurity posture, develop and execute plans to ensure timely risk mitigation, oversee and coordinate security assessments and penetration testing engagements for the organization.
-
Provide guidance on data protection concepts such as data classification, sensitive data handling, data minimization, encryption, tokenization, retention, disposal, and privacy-aware system design.
-
Partner with product teams to ensure secure software development and engineering practices, including CI/CD security, code review, vulnerability scanning, secrets management, and remediation tracking.
-
Leverage experience to interpret cybersecurity policies, standards, frameworks, and risk findings into practical implementation guidance for product and engineering teams.
-
Possess a strong ability to cross-reference business and operational requirements against cybersecurity, privacy, architecture, and engineering best practices.
-
Evaluate technical designs, architecture diagrams, data flows, integration patterns, and operational processes to identify cybersecurity and privacy risks.
-
Partner with senior cybersecurity team members to coordinate and advise on iterative improvements in security posture to remediate identified security vulnerabilities.
-
Take ownership and a lead role among colleagues in creating and improving security policies, standards, and advisories based on consulting and industry trends.
-
Respond independently in a timely manner to ad hoc requests for security consulting.
-
Communicate and collaborate regularly with colleagues in security consulting and across the department via a variety of online and in-person means, showing initiative and discernment for sharing appropriate insights, job aids, and updates on progress for mutual benefit and team awareness wherever appropriate.
Required Qualifications (Knowledge, Skills, & Abilities)
-
Direct experience in information security management for complex projects in an agile development environment
-
Experience providing security consulting services to individuals and teams in a complex networked environment
-
Familiarity with administering security awareness programs
Preferred Qualifications (Knowledge, Skills, & Abilities)
-
Skilled in cross-referencing operational business requirements to technical cybersecurity best practices
-
Experience advising on mobile application security for iOS and/or Android applications, including secure storage, platform security controls, authentication flows, mobile API consumption, and sensitive data protection
-
Experience advising on cloud security in AWS or other approved enterprise cloud environments, including IAM, network design, account structure, workload isolation, encryption, logging, monitoring, and infrastructure as code
-
Experience in reviewing and acting on results of automated risk vulnerability scanning tools
-
Experience conducting application security, architecture, or design reviews for systems that process sensitive, confidential, payment, or regulated data
-
Experience in DevSecOps
-
Familiarity with SaaS integrations
-
Experience in incident response
Required Years Of Experience
4
Preferred Years Of Experience
7
Travel Requirements
10%
Required Level Of Education
Bachelor's degree or equivalent experience
Preferred Level Of Education
Bachelor's Degree
Required Major/Concentration
Technical field of study or equivalent applicable technical experience/training
Preferred Major/Concentration
Cybersecurity, Computer Science, Management Information Systems, Information Technology, Software Engineering, or a related technical field
Relocation Assistance Provided
No