Deputy Director - Information Security Lead
PepsiCo · Hyderabad
- Experience6–7 yrs
- SalaryNot disclosed
- Work modeonsite
- Posted25 Sept 2026
About PepsiCo
PepsiCo is hiring in Hyderabad in consumer goods. This role looks for around 6+ years of experience.
Skills
- AI
- cloud
- data platforms
- automation
- NIST Cybersecurity Framework
- NIST AI Risk Management Framework
- CIS Critical Security Controls
- OWASP Top 10
- LLM/GenAI security
- Agile
- enterprise security architecture
- risk management
- digital transformation
The role
A security architect at a consumer goods company designs secure-by-design transformation strategies across AI, cloud, data platforms, automation, and enterprise technology, applying NIST Cybersecurity Framework and OWASP Top 10 while advising business and technology leaders on risk.
Full job description
Overview
The Information Security Lead is a key member of the Business Information Security Office, serving as a trusted security advisor and change agent, enabling secure digital transformation across multiple enterprise business domains (e.g., Supply Chain & Operations, Consumer & Commercial, Finance, HR, Enterprise Platforms). This role partners closely with business, strategy & transformation leads, capability teams, IT, OT, and Cybersecurity stakeholders to embed security-by-design into large-scale transformation initiatives (e.g., AI adoption, automation, cloud, data platforms), while advancing BISO operating maturity, scalable security capabilities, and consistent risk outcomes.
The role focuses on forward-looking initiatives, operating model evolution, and systematic risk reduction—complementing run-the-business BISO activities with a strong emphasis on transformation programs, pattern-based security solutions, and continuous improvement.
Responsibilities
Transformation & Strategy
Act as the security transformation lead for major business and technology transformation initiatives, ensuring security requirements are integrated early across strategy, planning, design, and execution phases.Partner with business and technology leaders to translate transformation objectives into actionable security strategies, roadmaps, and measurable outcomes.Shape and operationalize secure-by-design patterns for AI/ML, cloud, automation, data platforms, and domain-specific technologies.Drive alignment of transformation programs with enterprise security strategy, architecture standards, and risk appetite.
Risk Management & Advisory
Serve as a security coach and trusted advisor to global capability and transformation teams on risk identification, assessment, mitigation planning, and risk acceptance.Identify, assess, and report on systemic and transformational security gaps; develop prioritized remediation and maturity-improvement plans.Guide teams in adopting defense-in-depth controls and resilience principles within transformation delivery cycles.Advise leaders on emerging risks (e.g., AI risk, third-party risk, cloud concentration risk, data protection risk) relevant to the supported business domain.
Operating Model & Enablement
Advance the BISO operating model by developing repeatable processes, playbooks, metrics, and automation to scale security engagement across transformations.Create and deliver tailored security enablement content (briefings, playbooks, patterns, guardrails) for business, transformation, and engineering audiences.Identify and remove organizational friction, strengthening collaboration across Business, IT, Architecture, Risk, Privacy, and Cybersecurity teams.Support the adoption of Agile and product-centric delivery models while ensuring appropriate security governance.
Stakeholder Engagement & Leadership
Build strong, trusted relationships with senior stakeholders and transformation leaders as a single point of security accountability for major initiatives.Influence decision-making by clearly articulating risk trade-offs in business terms, enabling informed and timely decisions.Present on Information Security programs, initiatives, incidents, threat trends, and risk posture as it relates to transformation.
Incident Readiness & Learning
Partner with incident management and recovery teams to support post-incident recovery and lessons learned, feeding insights back into transformation patterns and controls.Continuously deepen understanding of the business, technology, and threat landscape relevant to supported enterprise domains.
Qualifications
Bachelor’s or Advanced degree (Information Security, Engineering, Computer Science, or IT-related studies preferred).6+ years of IT experience supporting enterprise business functions or platforms, with exposure to Supply Chain, ERP, CRM, cloud platforms, data/analytics, AI, automation, or domain-specific systems.3+ years of Information Security experience (BISO, security architect, engineer, or risk leader experience strongly preferred).Demonstrated experience supporting large-scale digital or business transformations.Strong working knowledge of:NIST Cybersecurity Framework and NIST AI RMFCIS Critical Security ControlsOWASP Top 10 and LLM/GenAI security risksExperience with Agile, product-centric delivery models, and modern program management practices.Professional security certifications (CISSP, CISM, CRISC, GIAC/GSEC) preferred.Written and spoken English proficiency.
Skills & Core Competencies
Strong interpersonal, oral, and written communication skills with executive presence.Ability to translate complex technical and security concepts into clear business language.Strategic, systems-oriented thinker with a transformation mindset.Innovative, collaborative problem solver with a strong bias for action.Ability to analyze, simplify, and automate processes for effectiveness and efficiency.Proven capability to manage multiple priorities across diverse organizations and geographies.High resilience and effectiveness in fast-paced, high-pressure transformation environments.Highly self-motivated, well-organized, and detail oriented.Dedicated, curious, and resourceful lifelong learner with a continuous-improvement mindset.