×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Analyst (Risk & Compliance

Job in Richmond, Henrico County, Virginia, 23214, USA
Listing for: Performance Food Group
Full Time position
Listed on 2026-08-22
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 70000 - 100000 USD Yearly USD 70000.00 100000.00 YEAR
Job Description & How to Apply Below
Position: Information Security Analyst (Risk & Compliance)
  • Competitive pay and benefits, including Day 1 Health & Wellness Benefits, Employee Stock Purchase Plan, 401K Employer Matching, Education Assistance, Paid Time Off, and much more
  • Growth opportunities performing essential work to support America’s food distribution system
  • Safe and inclusive working environment, including culture of rewards, recognition, and respect
We Deliver the Goods
  • Competitive pay and benefits, including Day 1 Health & Wellness Benefits, Employee Stock Purchase Plan, 401K Employer Matching, Education Assistance, Paid Time Off, and much more
  • Growth opportunities performing essential work to support America’s food distribution system
  • Safe and inclusive working environment, including culture of rewards, recognition, and respect
Position Summary

Performance Food Group is looking for a talented Information Security Analyst to play a key role in supporting Information and Privacy Risk Management aspects of the company as a member of the Information Security Department. PFG is in the midst of establishing a Risk Management function that focuses on identifying, quantifying, communicating, and tracking risks associated with information assets. Reporting to the Manager of Information Security Risk Management and working with IT and line of business stakeholders, the analyst will have a heavy focus on compliance with internal/external policies/statutes, IT Risk Management, and Third Party Risk.

Position

Responsibilities
  • Conduct risk assessments and maintain risk register. Perform assessments of IT controls processes, and systems, identifying gaps and opportunities to enhance design perational effectiveness while reducing the cost of compliance. Conduct periodic readouts and risk reviews with IT teams and segment/line of business stakeholders to convey risk and influence decision making
  • Assist in maintaining security exception lifecycle, including qualfiying associated risk, determining compensating controls, communicating with IT and LOB stakeholders.
  • Assist in development of evaluative risk frameworks for new and emerging technologies, including but not limited to Artificial Intelligence
  • Maintain Business Impact Analysis. Work with IT and LOB teams to maintain Business Impact Analysis, establishing risk categorizations for applications and infrastructure based on mission criticality and sensitivity of hosted data.
  • Assist in development and implementation of Enterprise Crown Jewels program. Work with IT, LOB teams, and security control owners to define and govern control parameters for critical applications and technologies.
  • KPI/KRI Development and Reporting. Assist in development of control-based Key Risk Indicators and Key Performance Indicators across business segments. Assist in developing associated governance model and metric tiers for consumption by various levels of stakeholders, up to and including the Board of Directors.
  • Support IT Risk and exception management governance forums across business segments with varying operational models and business context.
  • Support PFG’s Third Party Risk Management Program, assessing third parties for inherent and residual risk based on the nature of their services and their ability to appropriately secure PFG data and provide dependent services.
  • Negotiate the inclusion of security requirements into third party contract agreements.
  • Develop and Maintain IT Audit and Control documentation.
  • Support necessary governance forums (committees, working groups) to ensure sound decision-making and stakeholder communications.
  • Identify and report on non-compliance with regulatory mandates (i.e. Sarbanes Oxley section 404 PCI DSS, HIPAA, GDPR, CCPA).
  • Support operational audits as necessary.
  • Performs other related duties as assigned.
Required Qualifications
  • Bachelors Degree
  • 1 - 3 Years of experience
  • Experience in developing, communicating, and presenting security or risk concepts to varying audiences
  • Experience with evaluating AI initiatives through a security risk lens
  • Knowledge of regulatory requirements and frameworks
  • Development and implementation of security policies
  • Experience conducting security maturity assessments
  • Development and implementation of security controls
  • Strong…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary