Manager, IT & Security Operations

Naperville, IL, US • Posted 1 day ago • Updated 3 hours ago
Full Time
On-site
USD 129,910.00 per year
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • FSA
  • Life Insurance
  • NATURAL
  • Budget
  • Expect
  • System On A Chip
  • MEAN Stack
  • SIEM
  • Email Security
  • Vulnerability Scanning
  • Network
  • Cadence
  • Threat Analysis
  • Security Engineering
  • Inventory
  • Program Development
  • IT Management
  • FOCUS
  • Leadership
  • Reporting
  • SAP GRC
  • Documentation
  • Security Awareness
  • Use Cases
  • Security Operations
  • Vulnerability Management
  • Regulatory Compliance
  • Incident Management
  • Fluency
  • Identity Management
  • Directory Services
  • Multi-factor Authentication
  • Partnership
  • Accountability
  • Mapping
  • Communication
  • Auditing
  • Risk Management
  • Artificial Intelligence
  • Mentorship
  • Collaboration
  • Stakeholder Management
  • Computer Science
  • Information Technology
  • Management
  • Information Security
  • CISSP
  • CISM
  • GCIH
  • GCIA
  • Forms
  • SAP BASIS
  • Military
  • Law
  • Promotions
  • Training
  • Human Resources
  • Recruiting

Summary

Why Work for KeHE?

  • Full-time
  • Pay Range: $129,910.00/Yr. - $190,454.00/Yr.
  • Shift Days: , Shift Time:
  • Benefits on Day 1
    • Health/Rx
    • Dental
    • Vision
    • Flexible and health spending accounts (FSA/HSA)
    • Supplemental life insurance
    • 401(k)
    • Paid time off
    • Paid sick time
    • Short term & long term disability coverage (STD/LTD)
    • Employee stock ownership (ESOP)
    • Holiday pay for company designated holidays

    Overview

    At KeHE, we're obsessed with creating solutions, unboxing potential, and serving others - and it all starts with you. As an employee-owned distributor of natural and organic, specialty, and fresh products, we're committed to making a positive impact and scaling our success together. With a culture that fosters development and opportunity, you'll be embarking on a career that's moving forward. When you join KeHE, you're becoming part of a team that is a force for good.

    Primary Responsibilities

    The Security Operations Manager is a working manager who both leads and actively contributes to the organization's information security operations. This role owns day-to-day security operations and detection, builds and operates the vulnerability management function. The role partners closely with internal teams, and external service partners to reduce risk, respond to incidents, mature security processes, and build a scalable program with direct reports, budget input, and tool ownership consolidating under it. As with all positions at KeHE Distributors, we expect that all actions will be consistent with KeHE's Mission, Vision, and Values.

    Essential Functions

    DUTIES, TASKS AND RESPONSIBILITIES:

    Security Operations Support
    • Own day-to-day security operations, including alert triage standards, escalation paths, incident response coordination, and the operating rhythm of the internal SOC function.
    • Partner with managed security service providers to ensure effective coverage, service quality, and timely response.
    • Support the development and maintenance of incident response processes, playbooks, and escalation procedures.
    • Help coordinate response and investigation activities with internal teams and external partners as needed.
    • Drive detection engineering improvements across SIEM and endpoint tooling, and own operational metrics such as mean time to detect and respond.
    • Manage and continuously improve security technologies across the stack, such as endpoint detection and response (EDR/XDR), SIEM, email security, and vulnerability management, and own the co-managed MDR/MSSP partnership.

    Vulnerability Detection & Threat Response
    • Operate and schedule vulnerability scanning across the environment (infrastructure, endpoint, network, and external/attack-surface), owning scan coverage, cadence, and the health and tuning of the scanning tools.
    • Continuously monitor vulnerability and threat detection outputs, validating and triaging new findings for exploitability and exposure.
    • Lead time-sensitive threat and vulnerability response: track emerging threats and actively-exploited vulnerabilities (threat intelligence, zero-days), assess the organization's exposure, and coordinate urgent response and containment.
    • Partner with Security Engineering and IT teams to align scanning coverage with the asset inventory and close detection gaps.

    Program Development & Leadership
    • Help develop and mature the broader information security program in partnership with IT Leadership, taking on new focus areas as priorities evolve.
    • Recruit, mentor, and develop security staff as the team grows; build repeatable processes so the program is not dependent on any single individual.
    • Define operating procedures, escalation paths, and reporting cadences for the functions this role builds.
    • Demonstrate Company's Core Competencies and values held within.

    Reporting & Stakeholder Management
    • Produce regular security metrics and program updates for leadership reporting.
    • Maintain visibility into open risks and remediation progress, escalating blockers as appropriate.
    • Represent the security program in cross-functional meetings and collaborate with internal teams and external partners.

    Other Responsibilities
    • Support GRC activities, including policy maintenance, control tracking, and risk register upkeep.
    • Assist audit and certification readiness efforts, contributing to evidence collection and control documentation across stakeholders.
    • Support the vendor and third-party risk management process, participating in security posture assessments and helping track findings.
    • Contribute to security awareness efforts, helping ensure training and communications reach all parts of the organization.
    • Participate in evaluating security practices for emerging AI and agentic tools as adoption expands across the organization.
    • Provide input into governance, guardrails, and acceptable-use guidance for new technologies, balancing enablement with risk.
    • Stay current on the evolving threat landscape and help the security program adapt as new risks and use cases emerge.
    • The position responsibilities outlined above are in no way to be construed as all encompassing. Other duties, responsibilities, and qualifications may be required and/or assigned as necessary.
    • Other duties and projects as assigned.

    SKILLS, KNOWLEDGE AND ABILITIES:
    • Broad understanding of information security domains, including security operations, vulnerability management, governance, risk, and compliance.
    • Experience with incident response, including investigation, coordination, and post-incident improvement.
    • Working fluency in identity and access management - directory services, conditional access, MFA, and privileged access concepts - sufficient to own IAM run-state issues before a dedicated IAM team exists.
    • Demonstrated hands-on capability: able to write or tune a detection, work an incident end to end, and interpret log and endpoint telemetry directly.
    • Experience managing managed detection and response or MSSP partnerships, including holding a provider accountable to coverage and service outcomes.
    • Experience developing security policies, standards, and risk management processes.
    • Familiarity with common security and risk frameworks and control mapping.
    • Ability to prioritize work using risk context and business impact.
    • Strong written and verbal communication skills; ability to translate security concepts for both technical and non-technical audiences.
    • Experience supporting audit or certification programs, preferred
    • Experience building vendor or third-party risk management processes, preferred
    • Awareness of emerging security risks, including those related to AI and agentic tool adoption, and interest in helping shape AI security practices as the program matures, preferred
    • Experience mentoring or managing security staff, preferred
    • Player-coach mindset; comfortable performing hands-on work while building processes and leading others.
    • Strong collaboration and stakeholder management skills; ability to influence without authority.
    • Ability to manage multiple priorities and adapt to shifting organizational needs.
    • High integrity and ability to maintain confidentiality of sensitive information.

    Minimum Requirements, Qualifications, Additional Skills, Aptitude

    EDUCATION AND EXPERIENCE:
    • Bachelor's degree in Information Security, Computer Science, Information Technology, or related field; or equivalent practical experience.
    • Minimum of 8 years progressive experience in information security, with minimum of 3 years' experience in a lead or management capacity.
    • Demonstrated experience building or maturing security functions, rather than solely operating within established programs.
    • Experience in a regulated or multi-entity environment.
    • Relevant information security certification (e.g., CISSP, CISM, GCIH, GCIA, or comparable), or equivalent demonstrated experience (or ability to obtain within 12 months).

    PHYSICAL REQUIREMENTS:
    • This position operates in a hybrid working environment, with in-person presence Tuesday, Wednesday, and Thursday (remote work available Monday and Friday, as business needs allow).
    • Ability to work in a standard office environment which requires sitting and viewing monitor(s) for extended periods of time, operating standard office equipment such as, but not limited to, a keyboard, copier and telephone.
    • Limited travel as needed to Company locations and third-party locations within the US.

    Requisition ID

    2026-29801

    Equal Employer Opportunity Statement

    KeHE Distributors provides equal employment opportunities to all employees and applicants for employment and prohibits all forms of discrimination and harassment on the basis of race, color, religion or faith, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training as well as the administration of all Human Resources and Talent Acquisition processes.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: RTX153802
  • Position Id: e49c3c819b514ccc5bc19da9bdab405e
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Naperville, Illinois

•

24d ago

Easy Apply

Full-time

Depends on Experience

Homewood, Illinois

•

Today

Full-time

Hybrid in Chicago, Illinois

•

30+d ago

Easy Apply

Full-time

$120,000 - $140,000

Chicago, Illinois

•

Today

Easy Apply

Full-time

USD 116000-144000

Search all similar jobs