Talent.com
Senior Information Security Analyst
Senior Information Security AnalystPepsiCo • Purchase, New York, US
Senior Information Security Analyst

Senior Information Security Analyst

PepsiCo • Purchase, New York, US
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Overview

We are looking for an experienced and highly technical Senior Security Engineer with 6 to 7 years of expertise in Vulnerability Management, Security Automation, and Enterprise Security Operations. This role demands advanced coding skills (Python, PowerShell, Bash, or equivalent) to develop automation frameworks, integrate security tools, and optimize vulnerability remediation workflows.

The ideal candidate will have a deep understanding of SAP security, Onapsis, and Tenable, along with hands-on experience in ServiceNow Vulnerability Response (VR) module, Configuration Compliance, and third-party security platforms (Okta, Salesforce, M365, SAP, etc.). This role will focus on enterprise vulnerability management, integrating security findings into ServiceNow, automating compliance reporting, and enhancing risk visibility across on-prem and cloud environments.

As a seasoned professional, you will lead strategic security automation initiatives, design scalable security architectures, drive SAP vulnerability remediation, and mentor junior analysts.

Responsibilities

  • Advanced Security Automation & API Development
  • Develop, optimize, and scale automation scripts (Python, PowerShell, Bash) to improve vulnerability detection, tracking, and remediation.
  • Design custom API integrations between Tenable, Onapsis, ServiceNow VR, and ITSM platforms to automate security workflows.
  • Implement security automation playbooks that reduce manual efforts and accelerate response times.
  • Engineer custom security solutions to streamline vulnerability scanning and compliance reporting.
  • Enterprise Vulnerability Management & Risk Prioritization
  • Lead enterprise-wide vulnerability assessments using Tenable, Onapsis, Qualys, or Nexpose.
  • Implement automated risk-based prioritization models, leveraging AI / ML-driven insights where applicable.
  • Oversee and optimize the ServiceNow VR module for scalable vulnerability tracking, exception management, and automated ticketing.
  • Work closely with IT and business stakeholders to define remediation SLAs, risk thresholds, and compliance requirements.
  • SAP Security & Onapsis Integration
  • Lead the security assessment of SAP environments, ensuring compliance with industry standards and best practices.
  • Automate the ingestion of Onapsis vulnerability findings into ServiceNow VR for enhanced tracking and resolution.
  • Work with SAP teams to remediate misconfigurations, unauthorized access risks, and compliance gaps.
  • Develop automation frameworks to monitor SAP security posture and streamline remediation workflows.
  • Security Platform & ServiceNow Integration
  • Manage the full integration of Tenable, Onapsis, and Configuration Compliance findings into ServiceNow VR.
  • Enhance Configuration Compliance monitoring by automating the processing of audit findings and risk exceptions.
  • Ensure that security data is accurate, actionable, and seamlessly integrated with ITSM and GRC platforms.
  • Deep Network & Security Protocols Expertise
  • Apply expert-level knowledge of networking and security protocols (, TCP / IP, HTTP / S, SSH, FTP, DNS, SSL / TLS, VPNs, RDP).
  • Assess security implications of common ports (, 443 (HTTPS), 22 (SSH), 3389 (RDP), 53 (DNS), 445 (SMB)) and automate network security controls.
  • Work on firewall rule reviews, segmentation strategies, and security policy enforcement.
  • Compliance Automation & Security Governance
  • Design automation workflows for PCI-DSS, NIST, ISO 27001, and CIS benchmarks compliance.
  • Develop tools to generate real-time compliance reports, track remediation progress, and reduce audit preparation time.
  • Stay ahead of emerging threats, regulatory changes, and vulnerability trends, continuously refining security automation strategies.
  • Strategic Leadership & Mentorship
  • Provide technical leadership in vulnerability management, SAP security, and security automation.
  • Drive strategic discussions with IT, business, and leadership teams to align security initiatives with organizational goals.
  • Mentor junior and mid-level security analysts, sharing best practices in automation, API development, and risk prioritization.
  • Develop comprehensive security documentation, playbooks, and process improvements.

Compensation & Benefits :

  • The expected compensation range for this position is between $89,000 - $149,000.
  • Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
  • Bonus based on performance and eligibility target payout is 10% of annual salary paid out annually.
  • Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
  • In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility : Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
  • Qualifications

  • Strong programming skills in Python, PowerShell, Bash, or equivalent languages for security automation.
  • Deep expertise in SAP security and Onapsis vulnerability management.
  • Advanced API development skills, integrating security platforms (Tenable, Onapsis, ServiceNow, ITSM).
  • Strong experience with ServiceNow VR module, including automation, custom workflows, and integrations.
  • Hands-on experience with Tenable, Qualys, or Nexpose for enterprise vulnerability scanning.
  • Expert-level understanding of network security protocols and common port numbers.
  • Experience securing third-party platforms (Okta, SAP, ServiceNow, Salesforce, M365).
  • Proven ability to lead security automation initiatives and mentor junior analysts.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Preferred Qualifications :

  • Experience with cloud security automation (AWS, Azure, GCP).
  • Infrastructure-as-Code (Terraform, Ansible) for security automation.
  • Familiarity with SAP Basis, HANA security, and GRC compliance.
  • Experience with machine learning-driven security automation.
  • Security certifications (CISSP, OSCP, GIAC, AWS Security Certs, Onapsis Certified Expert) are a plus.
  • EEO Statement

    Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance.

    All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

    PepsiCo is an Equal Opportunity Employer : Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity

    If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy.

    Please view our Pay Transparency Statement

    serp_jobs.job_alerts.create_a_job

    Information Security Analyst • Purchase, New York, US

    Job_description.internal_linking.related_jobs
    Senior Director Analyst - Cloud Security

    Senior Director Analyst - Cloud Security

    Gartner • Stamford, CT, United States
    serp_jobs.job_card.full_time
    Senior Director Analyst - Cloud Security.Gartner Analysts are industry thought leaders who create must-have research, market predictions and best practices for a broad range of world-leading organi...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Director of Cyber Security

    Director of Cyber Security

    Atlas Air • City of White Plains, NY, United States
    serp_jobs.job_card.full_time
    Atlas Air is currently seeking a.Director of Cybersecurity Operations.Hybrid role – White Plains, NY.Relocation assistance is available. Leads a team of highly experienced individual contributors an...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior IT Analyst

    Senior IT Analyst

    Medfar • Great Neck, New York, USA
    serp_jobs.job_card.full_time
    We are seeking a highly skilled and experienced Senior IT Analyst with strong expertise in Microsoft system administration virtualization technologies and IT security. The successful candidate will ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Travel Ultrasonographer - $2862 / Week

    Travel Ultrasonographer - $2862 / Week

    LRS Healthcare - Allied • Mount Kisco, NY, US
    serp_jobs.job_card.full_time
    LRS Healthcare - Allied is seeking an experienced Ultrasonographer for an exciting Travel Allied job in Mount Kisco, NY.Shift : Inquire Start Date : ASAP Duration : 13 weeks Pay : $2862 / Week.Ready to...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Head of Information Security (Greenwich)

    Head of Information Security (Greenwich)

    Confidential • Greenwich, CT, US
    serp_jobs.job_card.part_time
    Accomplished investment management firm.The Company is in search of a Head of Information Security to join their team.This hands-on role is pivotal in the protection of the company's network and pr...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Senior Compliance Analyst

    Senior Compliance Analyst

    Franklin Templeton • Stamford, Connecticut, USA
    serp_jobs.job_card.full_time
    At Franklin Templeton were advancing our industry forward by developing new and innovative ways to help our clients achieve their investment goals. Our dynamic firm spans asset management wealth man...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Analyst MA Integration

    Senior Analyst MA Integration

    MasterCard • Purchase, NY, United States
    serp_jobs.job_card.full_time
    Senior Analyst M&A Integration.The Senior Analyst, M&A Integration is an integral member of the team supporting all phases acquisition integration. The qualified candidate will be a member of a high...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Information Services Assistant

    Information Services Assistant

    Vanguard Group Staffing, Inc. • West Harrison, NY, US
    serp_jobs.job_card.permanent +1
    Temporary opportunity, with potential for direct hire, at firm in convenient Westchester County location.Analyze sales and depletion reports, resolve data inquiries, analyze statistical reports, an...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    IT Business Analyst for Major Japanese Bank NY

    IT Business Analyst for Major Japanese Bank NY

    NSD International, Inc • White Plains, NY, US
    serp_jobs.job_card.full_time
    Summary : As a bilingual (Japanese–English) IT Business Analyst, the role involves bridging the U.Japan teams while defining technical standards and design specifications in the specialized field of...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Maximo Analyst

    Maximo Analyst

    Ampcus Inc • City of White Plains, NY, United States
    serp_jobs.job_card.full_time
    Maximo Analyst – Location : White Plains, NY.This role will support stakeholders’ use of IBM Maximo system.Responsibilities will range from administrator to analysis documentation with technical tea...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Information Security Manager

    Information Security Manager

    Mitchell Martin • Greenwich, CT, United States
    serp_jobs.job_card.full_time
    Northeastern United States (Hybrid).Collaborate with technology and risk management teams to enhance security performance. Maintain a formal information security controls framework.Represent cyberse...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Information Security Controls Manager

    Information Security Controls Manager

    The Right Click, Inc. • Greenwich, CT, United States
    serp_jobs.job_card.full_time
    Our client is looking for an experienced.Information Security Controls Manager.This role is ideal for someone with a strong background in information security, excellent communication skills, and t...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    SAP Security Analyst (IT 1179)

    SAP Security Analyst (IT 1179)

    Amicis Global • White Plains, New York, USA
    serp_jobs.job_card.full_time
    The SAP GRC Analyst is responsible for supporting SAP GRC Access and Process Control and S / 4 Hana security management in a diverse SAP Enterprise Application environment. The analyst also provides t...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Manager of Cybersecurity Detection Engineering

    Senior Manager of Cybersecurity Detection Engineering

    Cox • North Hills, NY, United States
    serp_jobs.job_card.full_time
    The Senior Manager of Cybersecurity Detection Engineering will lead a team of Detection Engineers in designing, implementing, and maintaining advanced detection capabilities to safeguard the organi...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Analyst M&A Integration

    Senior Analyst M&A Integration

    MasterCard • Harrison, NY, United States
    serp_jobs.job_card.full_time +1
    Mastercard powers economies and empowers people in 200+ countries and territories worldwide.Together with our customers, we’re helping build a sustainable economy where everyone can prosper.We supp...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Network Security Analyst

    Network Security Analyst

    Skadden • White Plains, New York, USA
    serp_jobs.job_card.full_time
    We invite you to review our current business services professionals openings to learn about the opportunities available across the firm. Skadden Arps Slate Meagher & Flom LLP has forged a reputa...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Security Architect

    Senior Security Architect

    TradeJobsWorkForce • 10709 Eastchester, NY, US
    serp_jobs.job_card.full_time
    Senior Security Architect Job Duties : Enhances security team accomplishments and competence by planning deliver...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Chief Information Security Officer (CISO) - US Government & Public Sector

    Chief Information Security Officer (CISO) - US Government & Public Sector

    Ernst & Young Oman • Stamford, CT, United States
    serp_jobs.job_card.full_time
    EY is seeking a Chief Information Security officer (CISO) for the US Government & Public Sector (GPS).The CISO is the senior executive responsible for enterprise cybersecurity strategy, governance,...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_less • serp_jobs.job_card.promoted • serp_jobs.job_card.new