Overview
Our Information Security Group at PepsiCo is looking for a cyber security
thought leader, influencer, security advocate, and driver of change, to join
our very exciting journey to manage cyber security risks for PepsiCo and all
our partners around the world. The Third-Party Information Security Senior
Specialist will be responsible for supporting and influencing the information
security efforts and team that determine functional and technical risks
related to the use, processing, storage and transmission of information to and
from those third-party entities engaged by PepsiCo globally.
As a Third-Party Information Security Risk Management senior specialist, you
will work with a global team to evolve and implement a full life-cycle
governance risk and compliance framework related to PepsiCo 's global third
parties. This includes tasks such as providing strategic oversight and
direction of the third-party security assessment program to adapt it to the
changing threat landscape and always keep it relevant, continuously advocating
for the success of our business by partnering with multiple organizations,
influencing a team of global assessors responsible for executing risk-based
information security risk assessments of PepsiCo's third parties,
collaborating with global procurement and legal teams to facilitate the
inclusion of Information Security Requirements in third-party contracts,
developing and tracking key performance indicators and operational/ executive
metrics, communicating third-party assessment issue and results to both IT and
Business executives, and advocating for the importance of third-party
information security risk management as it pertains to the various services
provided by third parties to PepsiCo.
Responsibilities
Responsibilities for this position include:
Qualifications
Preferred Skills:
Candidates will be evaluated based on their ability to perform the duties
listed above while demonstrating the functional and technical skills and
competencies necessary to be highly-effective in the role. These skills and
competencies include:
* Strong third-party information security risk assessment skills to evaluate functional and technical capabilities across all information security domains.
* Technical and business expertise to drive information security requirements/clauses in third-party contracts, together with people skills to negotiate requirements with third-party representatives.
* Strong understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business, allowing them to meet their strategic objectives.
* In depth technical experience and knowledge of infrastructure technologies, network, web, computing, cloud services, manufacturing equipment, mobile devices, and information (cyber) security, allowing this role to provide technical leadership and coaching to other members of the organization.
* Comprehensive technical and functional understanding of various information security solutions, technologies and industry-leading practices, allowing this role to provide recommendations and support key decisions.
* Strong and very articulate verbal and written communication skills in English that positively impact relationships with key businesses' and third parties' stakeholders, and proactively influence the actions taken by these stakeholders.
* Excellent prioritization capabilities, with an aptitude for breaking down complex work into manageable parts, effectively assessing the priority and time required to complete each part.
* An ability to work on several tasks simultaneously across multiple organizations.
* Strong decision-making capabilities, with a proven ability and common-sense to weigh the relative costs and benefits of potential actions, identify the most appropriate one, and influence other teams to adopt recommendation and guidance.
* Strong ability to effectively influence others (including executives and peers) around the world to modify their opinions, plans, or behaviors, with an emphasis on collaborating across multiple teams and ensuring program needs are satisfied through interpersonal and trusted communication.
* Effective ability to identify and assess the severity and potential impact of risks and communicate risk assessment findings to risk owners outside Information Security. Communication should consistently drive objectives, relying on fact-based decisions about risk that optimize the trade-off between risk mitigation and business performance.
* Strong presentation creation and presentation delivery skills in English
* Strong ability to be a team-lead supporting global functions
Minimum Requirements:
* Bachelor degree or higher.
* 10+ years of experience in third-party information security risk/ compliance/ governance, IT audit, and/or Enterprise Risk Management.
* 10+ years of technical or project management experience across various technologies and architectures including web, networks, infrastructure, applications, and/or information security.
Desired Qualifications:
* One certification of the following highly desirable: Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified in the Governance of Enterprise IT (CGEIT), Certified Information Security Manager (CISM).
* 5+ years of experience with regulatory compliance and information security management frameworks (e.g., IS0 27000/27001, COBIT, NIST 800, NISCT CSF, etc.).
* 2+ years direct technical experience with one or more security-related regulatory or industry standards (HIPAA/HITECH, SOX, PCI-DSS, GDPR, CCPA, etc.).
* ServiceNow Vendor Risk Management (VRM) and Governance Risk and Compliance (GRC) experience
* Strong Microsoft Excel and PowerPoint skills to analyze metrics and create executive-level presentations
**ROLE PURPOSE:** Manage all related cyber security compliance programs Manage cyber security related risk Responsible for the implementation and effectiveness of Cyber Prevent Controls. Identify risk triggers, and corresponding risk responses strategy. Governance of all inherit…
Job Role / Function **Operations/Expansion** Years of Experience **Unspecified** Career Level **Manager** Gender **Unspecified** Expiry date **22 Feb 2023** Job Description * Fluent in English * At least 10 years of experience * Strong communication skills * High level of problem-solving s…
* Responsible for overseeing and contributing to the development and implementation of an effective Ethics, Risk & Compliance Program within the respective country or cluster in alignment with the Company, Divisions, Organizational Units or Function strategy. * Drive robust implementation of the…
Cairo Risk Senior Specialist Legal Departement **Job Purpose:** To introduce and maintain smooth operation to the Enterprise Risk Management (ERM) function to ACT business operation. **Responsibilities:** * Conduct assessments to define and analyze possible risks . * Review and audit the cur…
Responsibilities: * Working closely with the Quality Assurance department and higher management to enforce the penalty system across different departments based on Schedule, COC, and COE violations. * Identifying, and reporting compliance issues, irregularities, and violations of employees …
Why Patients Need You Everything we do, every day, is in line with an unwavering commitment to the quality and the delivery of safe and effective products to patients. Our science and risk-based compliant quality culture is flexible, innovative, and customer oriented. Whether you are involved in de…
Johnson & Johnson is recruiting for **Business Compliance Specialist** to be located in Cairo, Egypt. Caring for the world, one person at a time has inspired and united the people of Johnson & Johnson for over 125 years. We embrace research and science - bringing innovative ideas, products and serv…
Caring for the world, one person at a time has inspired and united the people of Johnson & Johnson for over 125 years. We embrace research and science - bringing innovative ideas, products and services to advance the health and well-being of people. Employees of the Johnson & Johnson Family of Comp…
## **Role Purpose** As a Partnerships Sr. Specialist you will be handling the content department 's day to day operations, starting with contractual agreements, alignment with legal and regulatory departments and managing partner and vendor payment across all verticals, in addition to Leading on Pa…
**This is where you save and sustain lives** At Baxter, we are deeply connected by our mission. No matter your role at Baxter, your work makes a positive impact on people around the world. You'll feel a sense of purpose throughout the organization, as we know our work improves outcomes for millions…