Yum! Brands is seeking a Principal-level Senior Security Architect to shape enterprise security architecture across our global ecosystem (KFC, Taco Bell, The Habit Burger Grill). In this role, you tackle unique, enterprise-wide problem spaces, anticipating future risks and setting strategic recommendations that guide multi-year roadmaps. You will operate with limited oversight, aligning outcomes through consultation with your coach and stakeholders. Your decisions will influence multiple functions and cross-brand programs. You will establish secure-by-design guardrails that accelerate delivery while reducing risk, and mentor Staff/Principal architects and senior engineers to raise the bar across the organization.
Key Responsibilities
Security Architecture & Design
Author reusable reference architectures, patterns, blueprints, and decision frameworks. Lead end-to-end reviews and threat modeling for complex, cross-brand initiatives; resolve novel challenges with broad business impact and drive clarity amid uncertainty.
Establish pragmatic architecture governance (principles, patterns, review mechanisms) that balances innovation with risk reduction; translate strategy into roadmaps and measurable outcomes (OKRs/KPIs).
Translate strategy into actionable roadmaps and multi-year control adoption plans; measure outcomes with meaningful KPIs.
Cloud Security & DevSecOps
Define enterprise guardrails for AWS/Azure/GCP (landing zones, identity boundaries, network baselines, encryption, logging) and guide adoption at scale.
Integrate security into CI/CD (SAST, DAST, IaC scanning, policy-as-code, artifact signing, SBOMs); influence platform roadmaps for secure delivery velocity.
Advance container/Kubernetes security (runtime controls, supply-chain security, secrets management) and coach platform/product teams on cloud-native practices.
Serve as principal consultant for complex cloud decisions; decisions typically span multiple departments/functions.
Identity, Access & Zero Trust
Architect Zero Trust across workforce, workloads, and data; mature segmentation, continuous verification, and strong authentication.
Guide enterprise IAM patterns (SSO, MFA, RBAC/ABAC, PAM) and standardize access models for least privilege at scale.
Partner with platform and identity teams to modernize federation and entitlement lifecycle.
Data, Network & Detection
Define enterprise data protection strategy (classification, end-to-end encryption, tokenization, key management, data residency) with cross-functional impact.
Lead segmentation and secure access patterns aligned to Zero Trust; evolve secure edge and private access.
Raise the quality of telemetry and detection engineering (logging standards, SIEM/XDR) with detections mapped to MITRE ATT&CK.
Risk, Compliance & Vendor/SaaS
Align architectures to PCI, SOX, GDPR, and internal risk frameworks; recommend practical compensating controls when constraints exist.
Lead security assessments for emerging technology and third-party platforms; negotiate security outcomes with vendors.
Communicate tradeoffs and risks to senior technical and business leaders; influence investment decisions and sequencing.
Leadership, Autonomy & Influence
Serve as a primary representative for Security Architecture in enterprise forums and technical councils; decisions typically affect multiple functions.
Operate with limited supervision, using judgment in ambiguous situations; outcomes are reviewed via consultation and alignment.
Mentor Staff/Principal architects and senior engineers; lead communities of practice; drive continuous improvement with metrics, threat intelligence, and post-implementation reviews.
Required Qualifications
Bachelor’s in Cybersecurity, Information Systems, Computer Science, or related field (or equivalent experience).
10+ years in security architecture/engineering or related function.
Deep expertise in two or more major clouds and cloud-native security controls.
Advanced knowledge of IAM/Zero Trust, data protection, secure networking, and DevSecOps toolchains.
Familiarity with NIST (800-53/207), ISO 27001, PCI, and architecture methods (TOGAF, SABSA).
Preferred Qualifications
CISSP, CCSP, CISM, AWS/Azure/GCP Security Specialty, TOGAF, or SABSA certifications.
Experience in regulated or high-scale environments (retail/QSR, payments, consumer data).
Demonstrated impact establishing enterprise guardrails, control libraries, and architecture governance.
Salary Range: $169,900 to $233,100 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate’s location, experience, and other job-related factors.

Yum! Brands, Inc., based in Louisville, Kentucky, and its subsidiaries franchise or operate a system of over 60,000 restaurants in more than 155 countries and territories under the Company’s concepts – KFC, Taco Bell, Pizza Hut and the Habit Burger Grill. The Company's KFC, Taco Bell and Pizza Hut brands are global leaders of the chicken, Mexican-style food, and pizza categories, respectively. The Habit Burger Grill is a fast casual restaurant concept specializing in made-to-order chargrilled burgers, sandwiches and more.
What makes Yum! a great place to work? It's our people. As the world's largest restaurant company, we invest in people capability so that our global workforce can make the most of their careers. With ongoing opportunities for personal and professional success, we've built a culture that rewards and recognizes great effort while providing the flexibility that is so important to all of us.