Manager, Security Operations

KeHE Distributors, LLCNaperville, IL
Hybrid

About The Position

At KeHE, we’re obsessed with creating solutions, unboxing potential, and serving others – and it all starts with you. As an employee-owned distributor of natural and organic, specialty, and fresh products, we’re committed to making a positive impact and scaling our success together. With a culture that fosters development and opportunity, you’ll be embarking on a career that’s moving forward. When you join KeHE, you’re becoming part of a team that is a force for good.

Requirements

  • Broad understanding of information security domains, including security operations, vulnerability management, governance, risk, and compliance.
  • Working fluency in identity and access management - directory services, conditional access, MFA, and privileged access concepts - sufficient to own IAM run-state issues before a dedicated IAM team exists.
  • Demonstrated hands-on capability: able to write or tune a detection, work an incident end to end, and interpret log and endpoint telemetry directly.
  • Familiarity with common security and risk frameworks and control mapping.
  • Strong written and verbal communication skills; ability to translate security concepts for both technical and non-technical audiences.
  • Awareness of emerging security risks, including those related to AI and agentic tool adoption, and interest in helping shape AI security practices as the program matures.
  • Player-coach mindset; comfortable performing hands-on work while building processes and leading others.
  • Strong collaboration and stakeholder management skills; ability to influence without authority.
  • Ability to manage, guide, and train a team of engineers to achieve the business goals outlined.
  • Ability to manage multiple priorities and adapt to shifting organizational needs and prioritize work using risk context and business impact.
  • High integrity and ability to maintain confidentiality of sensitive information.
  • Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field; or equivalent practical experience.
  • Minimum of 5+ years experience in information security, with minimum of 2 years’ experience in a lead or management capacity.
  • Experience building or maturing security functions, rather than solely operating within established programs.
  • Experience with incident response, including investigation, coordination, and post-incident improvement.
  • Experience managing managed detection and response or MSSP partnerships, including holding a provider accountable to coverage and service outcomes.
  • Experience developing security policies, standards, and risk management processes, supporting audit or certification programs, building vendor or third-part risk management processed, or mentoring/managing security staff preferred..
  • Relevant information security certification (e.g., CISSP, CISM, GCIH, GCIA, or comparable), or equivalent demonstrated experience (or ability to obtain within 12 months).

Nice To Haves

  • Experience developing security policies, standards, and risk management processes, supporting audit or certification programs, building vendor or third-part risk management processed, or mentoring/managing security staff preferred.

Responsibilities

  • Own day-to-day SOC operations, including alert triage standards, escalation paths, and incident response coordination and manage a team of security engineers.
  • Develop and maintain incident response processes, playbooks, and escalation procedures; coordinate investigations with internal teams and external partners.
  • Manage the MDR/MSSP partnership, ensuring coverage, service quality, and timely response.
  • Drive detection engineering improvements across SIEM/EDR/XDR and other security tooling; own operational metrics (MTTD/MTTR).
  • Build and own the end-to-end vulnerability management program, from identification through remediation and reporting.
  • Define risk-based remediation timelines and priorities; coordinate with technical teams to drive resolution.
  • Track and report on remediation progress and program effectiveness.
  • Embed vulnerability management into operational processes with IT partners.
  • Partner with IT Leadership to develop and mature the information security program, expanding scope as priorities evolve.
  • Recruit, mentor, and develop security staff; build repeatable, documented processes so the program isn't dependent on any one person.
  • Define operating procedures, escalation paths, and reporting cadences for owned functions.
  • Produce security metrics and program updates for leadership; maintain visibility into open risks and escalate blockers.
  • Represent the security program in cross-functional meetings and with external partners.
  • Support policy maintenance, control tracking, risk register upkeep, vendor/third-party risk management, including posture assessments and findings tracking.
  • Contribute to audit/certification readiness, including evidence collection and control documentation.
  • Contribute to security awareness training and organization-wide communications.
  • Evaluate security practices for AI/agentic tools; provide input on governance, guardrails, and acceptable-use guidance.
  • Stay current on the threat landscape and help the program adapt to new risks and use cases.
  • Other duties and projects as assigned.

Benefits

  • Health/Rx
  • Dental
  • Vision
  • Flexible and health spending accounts (FSA/HSA)
  • Supplemental life insurance
  • 401(k)
  • Paid time off
  • Paid sick time
  • Short term & long term disability coverage (STD/LTD)
  • Employee stock ownership (ESOP)
  • Holiday pay for company designated holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service