Cybersecurity Policy and Regulatory Compliance Associate Principal
PepsiCo Plano, Texas, United States · $94K–$156K/yr
Food and Beverage Services · 10,001+ employees
About the role
The associate principal manages the end-to-end lifecycle of global cybersecurity policies and standards while ensuring alignment with regulatory requirements. They facilitate regulatory assessments, perform gap analyses, and collaborate with cross-functional teams to integrate security controls into business processes.
What they look for
Requirements
Candidates must possess in-depth technical knowledge of infrastructure, cloud services, and cybersecurity frameworks such as NIST and ISO 27001. Strong communication, analytical, and stakeholder management skills are required to influence decision-making and drive compliance across the organization.
Benefits
Full description
Overview
The Cybersecurity Policy and Regulatory Compliance Associate Principal will be responsible for the management of the PepsiCo Global Cybersecurity Policy and Standards, including the proactive evaluation of the standards against industry trends, regulatory requirements, and the evolving risk landscape. The role will facilitate the annual review cycle and overall change management of policy and standards. They will be responsible for facilitating the review of change requests from PepsiCo associates, gaining alignment from stakeholders, updating the standards, and managing the review workflow to publishing. They will partner with legal and other relevant teams to review new and changing regulations and perform gap analysis against the current standards, proposing and presenting recommended changes. They will manage the end-to-end policy and standards lifecycle in ServiceNow.
In addition to managing the policy and standards life cycle, the role will include cybersecurity regulatory consulting and compliance to ensure adherence to relevant cybersecurity requirements. They will partner with global cybersecurity, business, and S&T teams to advance the knowledge of security requirements and the use of cybersecurity processes and capabilities. They will lead periodic regulatory engagements to test and report on the compliance of cybersecurity controls.
Responsibilities
- Manage end-to-end PepsiCo Cybersecurity Policies and Standards lifecycle
- Maintain in-depth and up-to-date knowledge of industry cybersecurity trends, policy/control frameworks and regulations; especially the NIST Cybersecurity Framework, CIS, ISO 27001 and other industry frameworks
- Maintain extensive knowledge of PepsiCo Cybersecurity Policy and Standards, including the global applicability and limitations of the standards
- Monitor the external global regulatory landscape for emerging, new or changing cybersecurity regulations that may impact PepsiCo
- Evaluate cybersecurity regulations against PepsICo policies, processes and controls to determine the impact of regulatory changes
- Lead various periodic cybersecurity regulatory assessments and engagements to determine PepsiCo compliance with cybersecurity regulatory requirements.
- Collaborate with Cybersecurity and IT Controls team to ensure updates to standards and regulatory requirements are reflected in updated controls
- Proactively identify and recommend necessary changes to the security policy and standards
- Coordinate with Cybersecurity teams, including Business Information Security Officers, Policy and Standards and others to establish an operating model communicating to/from local teams impacted by new and emerging regulations
- Consult in the design of security solutions, processes, or policies to ensure global regulations are prioritized in the development of requirements
- Develop/Maintain metrics on standards to allow for the identification of risks
- Partner with the Security Exceptions team to identify exception patterns and recommend adjustments to standards as needed to create efficiencies within the process
- Collaborate and align with Cybersecurity and IT teams on changes and additions to standards
- Communicate with PepsiCo Leadership on the interpretation and application of the policies or standards
- Manage workflow in ServiceNow for annual and out-of-cycle review and changes
- Work with the ServiceNow development team to identify opportunities for process/tool improvement
- Provide subject matter expertise on the application of PepsiCo Policy and Standards with IT processes
Compensation and Benefits:
- The expected compensation range for this position is between $93,500 - $156,450.
- Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
- Bonus based on performance and eligibility target payout is 10% of annual salary paid out annually.
- Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
- In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications
- Technical and business expertise to drive Cybersecurity requirement
- In-depth technical experience and knowledge of infrastructure technologies, network, web, computing, cloud services, manufacturing equipment, mobile devices, and information (cyber) security, allowing this role to provide technical leadership and coaching to other members of the organization
- Strong understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business, allowing them to meet their strategic objectives
- Strong verbal and written communication skills that positively impact relationships with key business and third-party stakeholders, and proactively influence the actions taken by these stakeholders
- Comprehensive technical and functional understanding of various Cybersecurity solutions, technologies and industry-leading practices, allowing this role to provide recommendations and support key decisions.
- Proficient in ServiceNow IRM, Microsoft Excel, Word, and PowerPoint skills to develop ad hoc reports to manage the reports and the metrics.
- Knowledgeable of Security controls and requirements for broad IT system types (e.g., Cloud, Database, Network, etc.)
- Independent thinker and strong self-motivator, with the ability to collaborate with virtual teams and influence decision-making
- Strong understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business, allowing them to meet their strategic objectives.
- Strong verbal and written communication skills that positively impact relationships with key business and third-party stakeholders, and proactively influence the actions taken by these stakeholders.
- Excellent prioritization capabilities, with an aptitude for breaking down complex work into manageable parts, effectively assessing the priority and time required to complete each part
- An ability to work on several tasks simultaneously
- Strong decision-making capabilities, with a proven ability and common sense to weigh the relative costs and benefits of potential actions and identify the most appropriate one
- Strong ability to effectively influence others and lead peers and superiors to modify their opinions, plans, or behaviors, with an emphasis on collaborating across multiple teams and ensuring program needs are satisfied through interpersonal and trusted communication
- Effective ability to identify and assess the severity and potential impact of risks, and communicate risk assessment findings to risk owners outside Cybersecurity. Communication should consistently drive objectives, relying on fact-based decisions about risk that optimize the trade-off between risk mitigation and business performance.
>
Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status. PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy. Please view our Pay Transparency Statement.
Similar roles
-
Senior IT Manager-Cloud, Cybersecurity & AI
New Wave Design Eden Prairie, Minnesota, United States · $130K–$183K/yr
-
Automotive Cybersecurity Architect
NXP Semiconductors Barcelona, Catalonia, Spain
-
Senior Information Security Engineer - Incident Response
LinkedIn United States · $129K–$212K/yr
-
Cyber Security Engineer – Product & OT Security
Knightec Group Sweden Solna, Sweden
-
Security Engineer
Sundt Tempe, Arizona, United States
-
Sr. Information Security Engineer - AppSec
EverBank Jacksonville, Florida, United States