Jobs and Careers
TH

Senior Analyst Cybersecurity Risk Management

The Campbell's Company
United Statesfull_timeVerifiedPosted 24 Jun 2025
💰 $141,900/yr($98,700/yr$141,900/yr)

About the role

Since 1869 we've connected people through food they love. We’re proud to be stewards of amazing brands that people trust. Our portfolio includes the iconic Campbell’s brand, as well as Michael Angelo’s, Pace, Pacific Foods, Prego, Rao’s Homemade, Swanson, and V8. In our Snacks division, we have brands like Cape Cod, Goldfish, Kettle Brand, Lance, Late July, Pepperidge Farm, Snack Factory, and Snyder’s of Hanover. 

Here, you will make a difference every day. You will be supported to build a rewarding career with opportunities to grow, innovate and inspire. Make history with us.

Why Campbell’s…

  • Benefits begin on day one and include medical, dental, short and long-term disability, AD&D, and life insurance (for individual, families, and domestic partners).
  • Employees are eligible for our matching 401(k) plan and can enroll on the first day of employment with immediate vesting.
  • Campbell’s offers unlimited sick time along with paid time off and holiday pay.
  • If in WHQ – free access to the fitness center. Access to on-site day care (operated by Bright Horizons) and company store.
  • Giving back to the communities where our employees work and live is very important to Campbell’s.   Our “Campbell’s Cares” program matches employee donations and/or volunteer activity up to $1,500 annually.
  • Campbell’s has a variety of Employee Resource Groups (ERGs) to support employees.

How you will make history here…

The Senior Analyst, Cybersecurity Risk Management will be part of a cross-functional team to ensure information security and business alignment. This role will work closely with the lines of business to understand their strategic and operational needs, identify and evaluate the associated risk, and determine policy and/or technical controls that will mitigate overall risk to the Company and drive business value. 
 

What you will do…

  • Partner with the IT Service Manager and the line of business to develop an understanding of organization’s business operations and strategic vision.
  • Evaluate the operations and strategic plan to identify potential security and privacy requirements, challenges and concerns in order to proactively advise on security and privacy risks to be considered as part of planning.
  • Partner with Information Security Architects, Information Assurance and Compliance, Incident Management and other IT Stakeholders to ensure that security controls are designed and implemented effectively. This may include ensuring appropriate testing of applications prior to launch, including SecDevOPS and pentesting.
  • Partner with business teams to identify, document, assess and mitigate existing and emerging cyber security risks based on the sensitivity level of data in use, control of the data internally and externally, and unique needs of the business unit.
  • Conduct periodic assessments of data protection controls and security measures to validate their effectiveness and identify areas for improvement.
  • Collaborate with business units and data owners to identify and document data flows, usage patterns, and access controls as per Campbell’s data classification requirements. This entails categorizing data based on its sensitivity, criticality, and regulatory requirements.

  • Establish the organizational tolerance for risk and communicate the risk tolerance throughout the organization including guidance on how risk tolerance impacts ongoing decision-making activities.
  • Identify and partner with Information Security Policy/Awareness analyst to identify role based training including educating business unit teams on identifying cyber security risks in day-to-day operations.
  • Remain current about current security threats, events and breaches in the industry specific to the line of business in order to ensure that control frameworks are future-proofed as best as possible.
  • Analyze business requirements that could require unique/specific security controls such as those related to Internet of Things (IoT), Big Data etc.
  • Partner with Information Security Compliance, Chief Privacy Officer and others to identify compliance requirements such as PCI, GDPR/CCPA, SOX etc.
  • Perform documented risk assessments of business projects that include review of functionality, architecture, data mapping, third party assessment, policy and operations controls. Obtain executive sign off as appropriate.
  • Review audit and other independent assessments to ensure that recommended controls are appropriate based on risk tolerance/acceptance procedures.

What you bring to the table…

  • Recommended Security certifications CISA, CISM, CISSP, SANS, etc
  • Bachelor's degree required.
  • 5+ years of experience required in the following areas:

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

The Campbell's Company

View company profile →