KeHE Distributors

Manager, Security Operations

KeHE Distributors$129K — $190K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or related field.
  • 5+ years in information security, with 2+ years in a management role.
  • Proven experience in building or maturing security functions.
  • Hands-on incident response experience with a focus on improvement post-incident.
  • Familiarity with managed detection and response partnerships.
  • Relevant information security certification (e.g., CISSP, CISM) preferred.

Responsibilities

  • Lead day-to-day SOC operations and manage a team of security engineers.
  • Develop and maintain incident response processes and playbooks.
  • Manage the MDR/MSSP partnership for optimal service delivery.
  • Drive detection improvements across security tools like SIEM and EDR.
  • Build and own the end-to-end vulnerability management program.
  • Define risk-based remediation timelines and priorities for teams.
  • Monitor and report on program effectiveness and security metrics.

Benefits

  • Comprehensive health, dental, and vision plans available from day one.
  • Flexible spending and health savings accounts (FSA/HSA) offered.
  • Employee stock ownership plan (ESOP) included.
  • Paid time off and sick leave provided.
  • Short and long-term disability coverage available.
Full Job Description
  • Full-time
  • Pay Range: $129,910.00/Yr. - $190,454.00/Yr.
  • Shift Days: , Shift Time:
  • Benefits on Day 1
    • Health/Rx
    • Dental
    • Vision
    • Flexible and health spending accounts (FSA/HSA)
    • Supplemental life insurance
    • 401(k)
    • Paid time off
    • Paid sick time
    • Short term & long term disability coverage (STD/LTD)
    • Employee stock ownership (ESOP)
    • Holiday pay for company designated holidays
    Overview

    At KeHE, we’re obsessed with creating solutions, unboxing potential, and serving others – and it all starts with you. As an employee-owned distributor of natural and organic, specialty, and fresh products, we’re committed to making a positive impact and scaling our success together. With a culture that fosters development and opportunity, you’ll be embarking on a career that’s moving forward. When you join KeHE, you’re becoming part of a team that is a force for good.

    Primary Responsibilities

    The Security Operations Manager leads and actively contributes to the organization’s information security operations. This role owns day-to-day security operations and detection, builds and operates the vulnerability management function. The role partners closely with internal teams, and external service partners to reduce risk, respond to incidents, mature security processes, and build a scalable program with direct reports, budget input, and tool ownership consolidating under it. As with all positions at KeHE Distributors, we expect that all actions will be consistent with KeHE’s Mission, Vision, and Values.

    Essential Functions

    DUTIES, TASKS AND RESPONSIBILITIES:

    • Own day-to-day SOC operations, including alert triage standards, escalation paths, and incident response coordination and manage a team of security engineers.
    • Develop and maintain incident response processes, playbooks, and escalation procedures; coordinate investigations with internal teams and external partners.
    • Manage the MDR/MSSP partnership, ensuring coverage, service quality, and timely response.
    • Drive detection engineering improvements across SIEM/EDR/XDR and other security tooling; own operational metrics (MTTD/MTTR).
    • Build and own the end-to-end vulnerability management program, from identification through remediation and reporting.
    • Define risk-based remediation timelines and priorities; coordinate with technical teams to drive resolution.
    • Track and report on remediation progress and program effectiveness.
    • Embed vulnerability management into operational processes with IT partners.
    • Partner with IT Leadership to develop and mature the information security program, expanding scope as priorities evolve.
    • Recruit, mentor, and develop security staff; build repeatable, documented processes so the program isn't dependent on any one person.
    • Define operating procedures, escalation paths, and reporting cadences for owned functions.
    • Produce security metrics and program updates for leadership; maintain visibility into open risks and escalate blockers.
    • Represent the security program in cross-functional meetings and with external partners.
    • Support policy maintenance, control tracking, risk register upkeep, vendor/third-party risk management, including posture assessments and findings tracking.
    • Contribute to audit/certification readiness, including evidence collection and control documentation.
    • Contribute to security awareness training and organization-wide communications.
    • Evaluate security practices for AI/agentic tools; provide input on governance, guardrails, and acceptable-use guidance.
    • Stay current on the threat landscape and help the program adapt to new risks and use cases.
    • Other duties and projects as assigned.

    SKILLS, KNOWLEDGE AND ABILITIES:

    • Broad understanding of information security domains, including security operations, vulnerability management, governance, risk, and compliance.
    • Working fluency in identity and access management - directory services, conditional access, MFA, and privileged access concepts - sufficient to own IAM run-state issues before a dedicated IAM team exists.
    • Demonstrated hands-on capability: able to write or tune a detection, work an incident end to end, and interpret log and endpoint telemetry directly.
    • Familiarity with common security and risk frameworks and control mapping.
    • Strong written and verbal communication skills; ability to translate security concepts for both technical and non-technical audiences.
    • Awareness of emerging security risks, including those related to AI and agentic tool adoption, and interest in helping shape AI security practices as the program matures.
    • Player-coach mindset; comfortable performing hands-on work while building processes and leading others.
    • Strong collaboration and stakeholder management skills; ability to influence without authority.
    • Ability to manage, guide, and train a team of engineers to achieve the business goals outlined.
    • Ability to manage multiple priorities and adapt to shifting organizational needs and prioritize work using risk context and business impact.
    • High integrity and ability to maintain confidentiality of sensitive information.
    Minimum Requirements, Qualifications, Additional Skills, Aptitude

    EDUCATION AND EXPERIENCE:

    • Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field; or equivalent practical experience.
    • Minimum of 5+ years experience in information security, with minimum of 2 years’ experience in a lead or management capacity.
    • Experience building or maturing security functions, rather than solely operating within established programs.
    • Experience with incident response, including investigation, coordination, and post-incident improvement.
    • Experience managing managed detection and response or MSSP partnerships, including holding a provider accountable to coverage and service outcomes.
    • Experience developing security policies, standards, and risk management processes, supporting audit or certification programs, building vendor or third-part risk management processed, or mentoring/managing security staff preferred..
    • Relevant information security certification (e.g., CISSP, CISM, GCIH, GCIA, or comparable), or equivalent demonstrated experience (or ability to obtain within 12 months).

    PHYSICAL REQUIREMENTS:

    • This position operates in a hybrid working environment, with in-person presence Tuesday, Wednesday, and Thursday (remote work available Monday and Friday, as business needs allow).
    • Ability to work in a standard office environment which requires sitting and viewing monitor(s) for extended periods of time, operating standard office equipment such as, but not limited to, a keyboard, copier and telephone.
    • Limited travel as needed to Company locations and third-party locations within the US.
    Requisition ID2026-29801

About KeHE Distributors

KeHE Distributors is a food distribution company that provides natural and organic, specialty and fresh products to grocery and natural food stores. The company was founded in 1953 and is headquartered in Romeoville, Illinois. KeHE Distributors has over 16,000 products and serves over 30,000 customers.
Learn more about KeHE Distributors
Size
5,000 employees
Industry
Founded
1952

Similar Jobs

More Jobs at KeHE Distributors

More Information Technology Jobs

Find similar Manager, Security Operations jobs: