- Salary
- $124k – $207k
- Location
- Plano, TX, US
- Type
- Full-time
- Department
- IT
- Closing date
- Today
- Source
- iCIMS
Description
Overview
The Transformation BISO is a proven leader in the Business Information Security Office responsible for guiding and driving information security risk management priorities, issues and mitigation as an embed in PepsiCo’s Global Functions & Products team. Part of a team focused on non-Cybersecurity stakeholders, this role will serve as the trusted security advisor to digital teams that are transforming functions such as Agriculture, Sustainability, Environmental Health & Safety, R&D and Legal. The role will partner closely to ensure appropriate organizational awareness and risk management as business processes and digital capabilities evolve. Adopting multi-faceted security approaches considering vendor, data, AI, and access management risk, the role requires creativity, resourcefulness and proactive engagement with stakeholders across Cybersecurity, business and technical capability teams to identify and mitigate risk.
The role also continuously strives to shift security left with key technology vendors and platforms, minimize barriers to security compliance and attain new efficiencies in risk management processes.
Responsibilities
- Act as Security Coach and advisor to global transformation teams in all aspects of security risk management, from issue identification, stakeholder alignment, development of mitigating controls, and execution of remediation plans
- Identify, assess, and report on security gaps within global transformation and product teams; develop action plans to address opportunity areas
- Provide feedback and coaching to delivery teams to drive defense-in-depth security requirements from initiative planning cycles
- Engage with key stakeholders and partners as trusted advisor on Information Security strategy, services and processes
- Develop tailored content and present on Information Security programs, initiatives, incidents, threats and risk topics
- Identify and overcome stakeholder resistance and barriers, tightening the cohesion between Business, Technology and Cybersecurity
- Monitor and facilitate post-incident recovery activities in collaboration with stakeholders, incident management teams and other key partners
- Continuously advance and deepen knowledge of PepsiCo’s business, technology and security ecosystem, along with associated best practices and emerging threats
Compensation & Benefits:
- The expected compensation range for this position is between $123,500 - $206,750.
- Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
- Bonus based on performance and eligibility target payout is 15% of annual salary paid out annually.
- Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
- In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications
Required Education/Experience:
- Bachelor’s or Advanced degree (Information Security, Cybersecurity, or Business with a a digital focus preferred)
- 10+ years of digital experience, including leadership roles (Consumer and Packaged Goods preferred, with domain knowledge in one or more of Agriculture, Environmental Health & Safety, Sustainability, R&D, Legal, HR)
- 5+ years Information Security experience (technical experience as a BISO, security architect or engineer preferred)
- CISM, CISSP, CRISC, GIAC/GSEC certifications (preferred)
- Well-versed in NIST Cybersecurity Framework and AI RMF, GDPR, and CCPA, CIS Top 20 Critical Controls, OWASP Top 20 and LLM Top 10
- Knowledge of Project Management and Agile methodologies
- Written/spoken English proficiency
Skills:
- Ability to translate technology risk into business language
- Commercial acumen – understanding cost/benefit of security investments
- Strong interpersonal, oral and written communication skills
- Innovative and collaborative problem solver
- Highly self-motivated and directed
- Strong organizational, project management and presentation skills
- Technical knowledge in cloud security architecture (AWS, Azure, GCP), Zero Trust security frameworks, IAM, AI/ML security considerations and governance)
- Dedicated and resourceful life-long learner
- Excellent attention to detail
- Ability to analyze and automate processes for effectiveness and efficiency
- Ability to manage multiple priorities and work across multiple organizations and teams
- Willing “can do” attitude
- Ability to effectively prioritize and execute tasks in a high-pressure environment
>
Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status. PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy. Please view our Pay Transparency Statement.