Point your AI agent at freehire and let it find you a job.

Get the CLI →

PepsiCo

NewBe an early applicant

Sr. InfoSec Analyst

Posted
Discussion

Summary

A senior information security analyst in PepsiCo's Cyber Fusion Center specializing in SAP application security. Day to day they assess SAP ABAP custom code with Onapsis Assess/Control for Code, prioritize and track vulnerabilities in ServiceNow Vulnerability Response, advise SAP development teams on secure coding, and produce security reporting and metrics.

Overview Within the Cyber Fusion Center, the Infrastructure Security Team is seeking a Senior Information Security Analyst specializing in SAP Application Security. This role is responsible for identifying, assessing, and tracking security vulnerabilities within SAP ABAP custom code and SAP application environments using Onapsis Assess for Code and Control for Code. The analyst will work closely with SAP development, BASIS, and business application teams to identify insecure coding practices, prioritize security risks, provide remediation recommendations, and integrate findings into ServiceNow Vulnerability Response for tracking and accountability. The ideal candidate will possess strong knowledge of SAP ABAP development, SAP application security, secure software development practices, and vulnerability management processes. Experience with SAP S/4HANA, SAP ECC, SAP BTP, and Onapsis security solutions is highly desirable. Responsibilities SAP Code Security Assessment • Perform security assessments of SAP custom code using Onapsis Assess for Code.• Identify vulnerabilities, insecure coding patterns, authorization weaknesses, and configuration issues within SAP applications.• Analyze ABAP source code for security risks including injection vulnerabilities, authorization bypasses, insecure RFC calls, hardcoded credentials, and data exposure risks.• Validate findings and provide remediation guidance to SAP development teams. SAP Secure Development Governance • Support secure software development lifecycle (SSDLC) practices for SAP applications.• Establish secure coding standards for SAP ABAP development.• Partner with SAP developers to improve code quality and reduce security defects.• Conduct security reviews of SAP transport and application changes prior to production deployment. Control for Code Administration • Administer and maintain Onapsis Control for Code.• Configure automated policy checks and security controls within SAP development workflows.• Develop and maintain security rulesets aligned to corporate standards and compliance requirements.• Monitor code quality and policy compliance across SAP landscapes. ServiceNow Integration and Risk Management • Integrate SAP code security findings into ServiceNow Vulnerability Response.• Ensure findings are accurately mapped, tracked, assigned, and reported through established workflows.• Develop risk-based prioritization methodologies for SAP application vulnerabilities.• Support vulnerability lifecycle management from discovery through remediation validation. Reporting and Metrics • Develop executive and operational reporting for SAP application security risks.• Track remediation progress and risk reduction initiatives.• Produce metrics related to code quality, vulnerability trends, and policy compliance.• Support internal and external audit activities. Security Consulting and Collaboration • Serve as the primary security advisor for SAP development teams.• Conduct developer awareness sessions focused on SAP secure coding practices.• Collaborate with SAP BASIS, architecture, infrastructure, and cybersecurity teams to reduce application risk.• Support threat modeling activities for SAP applications and business-critical processes. Accountability • Improve SAP application security posture through continuous code assessment.• Reduce the number of critical and high-risk SAP code vulnerabilities.• Ensure security findings are tracked and managed through ServiceNow.• Support secure development practices across SAP development teams.• Provide risk-based recommendations and remediation guidance to application owners.• Maintain accurate reporting and metrics related to SAP code security. Qualifications • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Software Engineering, or related field.• 3–5 years of experience in SAP Security, SAP Development, Application Security, or Vulnerability Management.• Experience working within SAP ECC, SAP S/4HANA, or SAP BTP environments. Mandatory Technical Skills • Strong understanding of SAP ABAP programming.• Experience with Onapsis Assess for Code.• Knowledge of SAP authorization concepts and role-based access controls.• Experience integrating security findings into ServiceNow Vulnerability Response.• Understanding of secure coding principles and application security testing methodologies.• Experience analyzing and prioritizing application vulnerabilities.• Strong reporting and data analysis skills. • Experience with SAP S/4HANA transformations• Experience with CI/CD integration and DevSecOps processes.• Knowledge of OWASP Top 10 and secure development frameworks.• Familiarity with SAP BTP security controls. • Experience with threat modeling and secure architecture reviews. Preferred Qualifications Certifications SAP Certified Associate – SAP System Security and Authorizations SAP Certified Technology Associate – SAP S/4HANA System Administration SAP Business Technology Platform (SAP BTP) Security SAP System Security and Authorizations Assess, Control, Assess for Code, Control for Code) Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Non-Technical Skills • Strong analytical and problem-solving capabilities.• Excellent written and verbal communication skills.• Ability to influence development teams and business stakeholders.• Strong project management and organizational skills.• Ability to work independently in a fast-paced global environment. Differentiating Behaviors • Experience leading enterprise-wide SAP application security programs.• Demonstrated success by reducing SAP application security risk through code scanning and governance.• Ability to translate technical findings into business risk.• Experience integrating SAP security findings into enterprise vulnerability management processes. Compensation and Benefits: The expected starting compensation range for this position is 231,000 PLN annually. Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. This role is eligible for an annual bonus of 15% of annual salary, based on performance and eligibility. In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility. #LI-Hybrid

Skills

What Senior Security jobs ask for — and how much of it you have →

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available