Overview:
You have the opportunity to coordinate and lead PepsiCo’s response to high-impact cybersecurity incidents. This role is responsible for maintaining and evolving PepsiCo’s cybersecurity incident response plan, conducting tabletop exercises, managing third-party incidents, and providing timely awareness and communication to executive leadership during significant cyber incidents and emerging threats.
The Cybersecurity Enterprise Incident Commander partners closely with Cybersecurity teams, Infrastructure, Platform, Legal, Communications, and business stakeholders to ensure effective response, recovery, and business continuity throughout the incident lifecycle. This position drives continuous improvement through lessons learned and alignment with industry frameworks and best practices.
Responsibilities:
Coordinate communications and response efforts among Cybersecurity, Infrastructure, Compute, Platform, Legal, Communications, and business teams to ensure effective incident response and business continuity
Develop, maintain, test, and continuously improve incident management methodologies, playbooks, runbooks, and escalation processes to address current and emerging cyber threats and ensure consistent and effective enterprise response capabilities
Develop, facilitate, and document technical, business, and executive tabletop exercises to validate preparedness, improve resilience, and strengthen organizational readiness
Conduct after-action reviews and lessons-learned activities following incidents and exercises, providing insights and driving continuous improvement initiatives to strengthen PepsiCo’s security posture, operational resilience, and business continuity capabilities
Coordinate the response to third-party and supply chain cybersecurity incidents, working closely with internal stakeholders, external partners, and service providers
Manage multiple concurrent cybersecurity incidents and investigations, prioritizing activities based on business impact, organizational risk, and operational requirements
Ensure incident management processes, plans, and activities align with established cybersecurity frameworks, enterprise policies, and industry best practices
Compensation and Benefits:
The expected compensation range for this position is between $110,700 - $185,250.
-
Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
-
Bonus based on performance and eligibility target payout is 12% of annual salary paid out annually.
-
Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
-
-
In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications:
Required
7+ years of experience in Information Security, Cybersecurity Operations, Incident Response, Threat Management, or a related discipline, including at least 5 years focused on cybersecurity incident response or investigations
Demonstrated experience managing complex cybersecurity incidents throughout the full incident lifecycle, from initial detection through containment, eradication, recovery, and post-incident review
Experience managing incidents involving ransomware, advanced persistent threats (APT), DDoS, third-party compromise, intrusion activity, vulnerability exploitation, and data exfiltration
Strong leadership, decision-making, and risk management capabilities, with the ability to maintain a professional presence in high-pressure and high-visibility environments
Strong understanding of networking, operating systems, identity and access management technologies, cloud platforms, and cybersecurity concepts
Familiarity with cybersecurity frameworks and standards, including NIST Cybersecurity Framework (CSF), NIST Incident Response guidance, and related industry best practices
Exceptional organizational and prioritization skills, with the ability to manage multiple concurrent incidents, investigations, and competing priorities
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related discipline
Experience coordinating cyber incidents and investigations with legal counsel, incident response vendors, internal stakeholders, cyber insurance providers, law enforcement, and third-party vendors or partners
-
Knowledge of security, privacy, legal, and regulatory considerations associated with cybersecurity incidents
-
Relevant certifications such as CISSP, CISM, GCIH, or equivalent industry certifications
>:
Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance.
All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.
PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age
If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy.
Please view our Pay Transparency Statement.