Search Jobs

Search by job, company or skills

Deputy Director - Information Security Lead

Deputy Director - Information Security Lead

PepsiCo
  • Posted 3 hours ago
  • Be among the first 10 applicants

Job Description

Overview

The Information Security Lead is a key member of the Business Information Security Office, serving as a trusted security advisor and change agent, enabling secure digital transformation across multiple enterprise business domains (e.g., Supply Chain & Operations, Consumer & Commercial, Finance, HR, Enterprise Platforms). This role partners closely with business, strategy & transformation leads, capability teams, IT, OT, and Cybersecurity stakeholders to embed security-by-design into large-scale transformation initiatives (e.g., AI adoption, automation, cloud, data platforms), while advancing BISO operating maturity, scalable security capabilities, and consistent risk outcomes.

The role focuses on forward-looking initiatives, operating model evolution, and systematic risk reduction-complementing run-the-business BISO activities with a strong emphasis on transformation programs, pattern-based security solutions, and continuous improvement.


Responsibilities

Transformation & Strategy

  • Act as the security transformation lead for major business and technology transformation initiatives, ensuring security requirements are integrated early across strategy, planning, design, and execution phases.
  • Partner with business and technology leaders to translate transformation objectives into actionable security strategies, roadmaps, and measurable outcomes.
  • Shape and operationalize secure-by-design patterns for AI/ML, cloud, automation, data platforms, and domain-specific technologies.
  • Drive alignment of transformation programs with enterprise security strategy, architecture standards, and risk appetite.

Risk Management & Advisory

  • Serve as a security coach and trusted advisor to global capability and transformation teams on risk identification, assessment, mitigation planning, and risk acceptance.
  • Identify, assess, and report on systemic and transformational security gaps develop prioritized remediation and maturity-improvement plans.
  • Guide teams in adopting defense-in-depth controls and resilience principles within transformation delivery cycles.
  • Advise leaders on emerging risks (e.g., AI risk, third-party risk, cloud concentration risk, data protection risk) relevant to the supported business domain.

Operating Model & Enablement

  • Advance the BISO operating model by developing repeatable processes, playbooks, metrics, and automation to scale security engagement across transformations.
  • Create and deliver tailored security enablement content (briefings, playbooks, patterns, guardrails) for business, transformation, and engineering audiences.
  • Identify and remove organizational friction, strengthening collaboration across Business, IT, Architecture, Risk, Privacy, and Cybersecurity teams.
  • Support the adoption of Agile and product-centric delivery models while ensuring appropriate security governance.

Stakeholder Engagement & Leadership

  • Build strong, trusted relationships with senior stakeholders and transformation leaders as a single point of security accountability for major initiatives.
  • Influence decision-making by clearly articulating risk trade-offs in business terms, enabling informed and timely decisions.
  • Present on Information Security programs, initiatives, incidents, threat trends, and risk posture as it relates to transformation.

Incident Readiness & Learning

  • Partner with incident management and recovery teams to support post-incident recovery and lessons learned, feeding insights back into transformation patterns and controls.
  • Continuously deepen understanding of the business, technology, and threat landscape relevant to supported enterprise domains.

Qualifications

  • Bachelor's or Advanced degree (Information Security, Engineering, Computer Science, or IT-related studies preferred).
  • 6+ years of IT experience supporting enterprise business functions or platforms, with exposure to Supply Chain, ERP, CRM, cloud platforms, data/analytics, AI, automation, or domain-specific systems.
  • 3+ years of Information Security experience (BISO, security architect, engineer, or risk leader experience strongly preferred).
  • Demonstrated experience supporting large-scale digital or business transformations.
  • Strong working knowledge of:
    • NIST Cybersecurity Framework and NIST AI RMF
    • CIS Critical Security Controls
    • OWASP Top 10 and LLM/GenAI security risks
  • Experience with Agile, product-centric delivery models, and modern program management practices.
  • Professional security certifications (CISSP, CISM, CRISC, GIAC/GSEC) preferred.
  • Written and spoken English proficiency.

Skills & Core Competencies

  • Strong interpersonal, oral, and written communication skills with executive presence.
  • Ability to translate complex technical and security concepts into clear business language.
  • Strategic, systems-oriented thinker with a transformation mindset.
  • Innovative, collaborative problem solver with a strong bias for action.
  • Ability to analyze, simplify, and automate processes for effectiveness and efficiency.
  • Proven capability to manage multiple priorities across diverse organizations and geographies.
  • High resilience and effectiveness in fast-paced, high-pressure transformation environments.
  • Highly self-motivated, well-organized, and detail oriented.
  • Dedicated, curious, and resourceful lifelong learner with a continuous-improvement mindset.

More Info

Job Type:
Function:
Employment Type:

Key Skills

modern program management practices

NIST AI RMF

LLM GenAI security risks

Agile product-centric delivery models

CIS Critical Security Controls

NIST Cybersecurity Framework

About Company