US Foods Logo

US Foods

Lead IT Compliance Analyst (remote)

Reposted 13 Days Ago
In-Office or Remote
Hiring Remotely in Rosemont, IL
95K-155K Annually
Senior level
In-Office or Remote
Hiring Remotely in Rosemont, IL
95K-155K Annually
Senior level
Lead IT compliance efforts to ensure adherence to various standards, manage audits, conduct assessments, and collaborate with cross-functional teams.
The summary above was generated by AI

ARE YOU A CURRENT US FOODS EMPLOYEE? PLEASE APPLY DIRECTLY THROUGH OUR INTERNAL WORKDAY CAREER SITE

Join Our Community of Food People!

At US Foods®, innovation and technology is our superpower. By expanding our digital ecosystem and leading with a customer-first mindset, we’re delivering technology that empowers our customers and simplifies business. As we transform the digital landscape of the foodservice industry, we’re outpacing our competitors faster than ever before.
We believe diversity is the cornerstone of creativity and innovation—and we foster an open, inclusive, flexible work environment that supports our transformation.
This role leads enterprise-wide IT compliance efforts, ensuring alignment with standards like PCI DSS, SOX, HIPAA, CPRA, and CMMC. As a subject matter expert, the candidate will collaborate across IT, Legal, Security, and Audit to maintain regulatory adherence. Responsibilities include managing compliance program lifecycles, conducting assessments, resolving issues, and reporting to senior leadership. This role will also require strategic thinking, independence, and the ability to navigate cross-functional priorities in a dynamic environment.

Flexible Work Policy: The work for the Lead IT Compliance Analyst position is completely remote anywhere in the United States except Hawaii or United States Territories. 

RESPONSIBILITIES

  • Lead and manage the organization’s annual PCI DSS compliance program, including evidence collection, gap remediation, and annual assessment submission.

  • Serve as the primary point of contact for SOX ITGC audits, working closely with Internal Audit and External Audit teams to ensure timely and accurate responses.

  • Support compliance with HIPAA, CPRA, and CMMC by maintaining documentation, tracking regulatory changes, and coordinating with legal and privacy teams.

  • Respond to data privacy and compliance-related inquiries, including customer assessments and regulatory requests.

  • Understand and articulate regulation impacts to IT value streams and help develop efficient/ effective solutions to ensure compliance.

  • Collaborate with IT, Security, and Business stakeholders to ensure compliance controls are embedded in technology processes and projects.

  • Track and report on compliance metrics, issues, and remediation efforts to leadership.

  • Support third-party risk assessments and vendor compliance reviews.

  • Promote a culture of compliance and accountability across the organization.

  • Stay abreast of proposed and new regulatory compliance requirements and changes by engaging in the industry and with internal experts and understanding US Foods products and processes

  • Conduct assessments of technology systems and processes to identify areas of risk and develop remediation plans

  • Participate in internal and external audits and assist with the resolution of any audit findings

  • Provide training and guidance to technology teams on compliance requirements and best practices

RELATIONSHIPS

  • Internal: Information and Cyber Security Team, Digital Commerce, Internal and external audit, Security Engineering, Security Architecture, Cloud/DevSecOps, Data, IT PMO and Product Teams

  • External: Regulatory and compliance organizations and auditors, External Legal Counsel, Technology vendors, including software and service providers; relevant managed security services, and professional services vendors

WORK ENVIRONMENT

  • Remote: This role is fully remote, and the associate is expected to perform assigned responsibilities from a home-based environment.

MINIMUM QUALIFICATIONS

  • At least 5 - 6 years of information security experience in one or more roles in GRC, Compliance, Risk, Third Party Risk Management, or IT Audit.

  • Broad foundational knowledge in many information and cyber security domains with priority given to regulatory compliance.

  • Demonstratable experience in building positive working relationships with leaders and associates across multiple areas of the business.

  • Must have the ability to work independently and make decisions that reflect the policies of the Information and Cyber Security Team.

  • Experience with compliance requirements (PCI, CPRA, HIPAA, SOX, etc.).

  • Familiarity with security frameworks such as NIST-CSF, ISO 27001, and CIS

  • Ability to effectively communicate business risk and information security concepts to audiences of varying technical acumen through multiple communication channels.

  • Experience measuring and tracking cybersecurity risks, issues, and exceptions

  • Ability to advise, collaborate, and work in a team environment enabling others to trust and grow their skills and competencies

  • Ability to influence without authority to drive desired outcomes.

  • Experience executing security compliance plans, vulnerability management programs, risk management lifecycle, and/or security assessment/governance processes

  • Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively

  • Proactive self-development, staying current on evolving threat landscape, security trends/best practices, and dynamic regulatory requirements

  • Experience developing, measuring and tracking key performance metrics, preferably in a cybersecurity program

  • Strong written and verbal skills enabling effective communication with different levels of leadership.

  • Highly organized, efficient, and close attention to detail.

Education
  • Bachelor’s degree from an accredited college/university, Master’s degree preferred

CERTIFICATIONS/TRAINING

  • Preferred but not required: SANS GSEC, GCIA (or related), CISSP, ISACA certifications (e.g., CISA, CISM, CRISC)

This role will also receive annual incentive plan bonus.

Benefits for this role may include health insurance, pre-tax spending accounts, retirement benefits, paid time off, short-term and long-term disability, employee stock purchase plan, and life insurance. 

To review available benefits, please click here: https://www.usfoods.com/careers/benefits.html

Compensation depends on relevant experience and/or education, specific skills, function, geographic location, and other factors as applicable by law (for example: state minimum wage thresholds).  The expected base rate for this role is between

$95,000 - $155,000

***EOE – Race/Color/Religion/Sex/Sexual Orientation/Gender Identity/National Origin/Age/Genetic Information/Protected Veteran/Disability Status***

Top Skills

Cis
Cmmc
Cpra
Hipaa
Iso 27001
Nist-Csf
Pci Dss
Sox

Similar Jobs

26 Minutes Ago
Remote
2 Locations
Senior level
Senior level
Artificial Intelligence • Productivity • Software • Automation
Join Zapier's Integration Quality team to enhance integration features and reliability, debugging systems, and mentoring engineers in a high-impact role.
Top Skills: APIsDatabricksLookerNode.jsTypescript
An Hour Ago
Remote or Hybrid
USA
195K-290K Annually
Expert/Leader
195K-290K Annually
Expert/Leader
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead and develop Agentic AI solutions, mentor team members, collaborate on AI applications, and tackle complex challenges in cybersecurity.
Top Skills: Amazon BedrockGoGoogle Vertex AiJavaMicrosoft Copilot StudioOpen AiPythonScalaServerless Architecture
2 Hours Ago
In-Office or Remote
7 Locations
165K-242K Annually
Senior level
165K-242K Annually
Senior level
Cloud • Information Technology • Machine Learning
The Senior Production Engineer will integrate high-performance storage systems for AI workloads, collaborating with clients and teams to enhance storage solutions and performance metrics.
Top Skills: Distributed FilesystemsGoGpu Direct StorageGrafanaKubernetesLokiPrometheusRdmaSpdk

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account