Cybersecurity Policy and Regulatory Compliance Associate Principal
www.pepsicojobs.com
Overview The Cybersecurity Policy and Regulatory Compliance Associate Principal will be responsible for the management of the PepsiCo Global Cybersecurity Policy and Standards, including the proactive evaluation of the standards against industry trends, regulatory requirements, and the evolving risk landscape. The role will facilitate the annual review cycle and overall change management of policy and standards.
They will be responsible for facilitating the review of change requests from PepsiCo associates, gaining alignment from stakeholders, updating the standards, and managing the review workflow to publishing. They will partner with legal and other relevant teams to review new and changing regulations and perform gap analysis against the current standards, proposing and presenting recommended changes.
They will manage the end-to-end policy and standards lifecycle in ServiceNow. In addition to managing the policy and standards life cycle, the role will include cybersecurity regulatory consulting and compliance to ensure adherence to relevant cybersecurity requirements. They will partner with global cybersecurity, business, and S&T teams to advance the knowledge of security requirements and the use of cybersecurity processes and capabilities.
They will lead periodic regulatory engagements to test and report on the compliance of cybersecurity controls. Responsibilities Manage end-to-end PepsiCo Cybersecurity Policies and Standards lifecycle Maintain in-depth and up-to-date knowledge of industry cybersecurity trends, policy/control frameworks and regulations; especially the NIST Cybersecurity Framework, CIS, ISO 27001 and other industry frameworks Maintain extensive knowledge of PepsiCo Cybersecurity Policy and Standards, including the global applicability and limitations of the standards Monitor the external global regulatory landscape for emerging, new or changing cybersecurity regulations that may impact PepsiCo Evaluate cybersecurity regulations against PepsICo policies, processes and controls to determine the impact of regulatory changes Lead various periodic cybersecurity regulatory assessments and engagements to determine PepsiCo compliance with cybersecurity regulatory requirements.
Collaborate with Cybersecurity and IT Controls team to ensure updates to standards and regulatory requirements are reflected in updated controls Proactively identify and recommend necessary changes to the security policy and standards Coordinate with Cybersecurity teams, including Business Information Security Officers, Policy and Standards and others to establish an operating model communicating to/from local teams impacted by new and emerging regulations Consult in the design of security solutions, processes, or policies to ensure global regulations are prioritized in the development of requirements Develop/Maintain metrics on standards to allow for the identification of risks Partner with the Security Exceptions team to identify exception patterns and recommend adjustments to standards as needed to create efficiencies within the process Collaborate and align with Cybersecurity and IT teams on changes and additions to standards Communicate with PepsiCo Leadership on the interpretation and application of the policies or standards Manage workflow in ServiceNow for annual and out-of-cycle review and changes Work with the ServiceNow development team to identify opportunities for process/tool improvement Provide subject matter expertise on the application of PepsiCo Policy and Standards with IT processes Compensation and Benefits: The expected compensation range for this position is between $93,500 - $156,450.
Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process. Bonus based on performance and eligibility target payout is 10% of annual salary paid out annually. Paid time off subject to eligi