- Salary
- $94k – $156k
- Location
- Plano, TX, US
- Type
- Full-time
- Department
- IT
- Seniority
- Lead
- Experience
- 5+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- iCIMS
Description
Overview
The GRC Associate Principal supports the execution and operational management of PepsiCo's Global Information Security Requirements (GISR) program and governance of PepsiCo's third-party cybersecurity obligations. This role partners with Cybersecurity, Legal, Procurement, and business stakeholders to ensure cybersecurity requirements are incorporated into third-party agreements, monitor compliance with contractual cybersecurity obligations, and provide metrics and reporting that support risk management, regulatory compliance, and program effectiveness. The position also helps drive alignment between cybersecurity policies, contractual requirements, and third-party governance processes.
Responsibilities
- Manage the execution of PepsiCo's GISR contract governance program, including contract reviews, cybersecurity requirement assessments, and negotiation support.
- Maintain governance processes, controls, reporting, and compliance activities to ensure consistent adoption of cybersecurity contractual requirements
- Partner with Cybersecurity, Legal, Procurement, and business stakeholders to support policy alignment, regulatory initiatives, training, and continuous program improvement.
Compensation and Benefits:
- The expected compensation range for this position is between $93,500 - $156,450.
- Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
- Bonus based on performance and eligibility target payout is 10% of annual salary paid out annually.
- Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
- In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications
- 5-8 years of experience in Cybersecurity Governance, GRC, Information Security, Contract Governance, or a related field, with the ability to translate cybersecurity requirements into business and contractual obligations.
- Strong knowledge of cybersecurity governance frameworks, contractual risk management, and stakeholder engagement across Legal, Procurement, and business functions.
- Bachelor's degree in a related discipline required; advanced degree, cybersecurity certifications, experience with governance platforms (e.g., ServiceNow, Icertis), and proficiency with Microsoft 365 applications and Copilot preferred.
>
Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status. PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy. Please view our Pay Transparency Statement.