Job Description
We are seeking a highly experienced Non-Human Identity (NHI) Lead to define and drive the strategic vision, architecture, governance, and implementation of PepsiCo's enterprise Non-Human Identity (NHI) program. The role is responsible for establishing enterprise-wide visibility, lifecycle governance, security controls, policy standards, and risk management for all machine identities, including service accounts, service principals, workloads, API credentials, keys, secrets, certificates, managed identities, bots, and emerging AI Agents.
The individual will lead the enterprise NHI roadmap, governance model, platform strategy, and onboarding programs while partnering with Security, Cloud, Infrastructure, Application Development, DevOps, Platform Engineering, Architecture, Risk & Compliance, and Business teams.
This role requires deep expertise in Identity Security, Cloud Security, Secrets Management, Machine Identity Management, Zero Trust Architecture, and AI Agent Identity Security. The successful candidate will combine strategic leadership with strong technical architecture skills to enable secure, scalable, and automated management of NHI’s across PepsiCo.
Responsibilities
Enterprise NHI Implementation
- Define and own the enterprise-wide NHI vision, strategy, roadmap, and multi-year maturity plan.
- Establish enterprise standards, policies, and governance frameworks for NHI management.
- Build and drive program across Cybersecurity, S&T, Cloud, Infrastructure, and Engineering teams.
- Lead global NHI transformation initiatives and drive adoption across all sectors and business units.
- Develop KPI/KRI metrics and provide executive reporting to IAM leadership, CISO, and governance boards.
- Establish NHI operating models, ownership models, and accountability frameworks.
Architecture & Platform Leadership
- Define target-state architecture for:
- NHI Discovery, NHI Lifecycle Management, NHI Identity Governance, Secrets Management, Certificate Management, AI Agent Identity Management
- Lead architecture reviews for NHI designs across cloud and enterprise platforms.
- Develop enterprise integration patterns for:
- AWS, Azure, GCP, SaaS platforms, DevOps platforms, Containerized workloads, AI Platforms
- Establish architecture standards for:
- Workload identities, Service principals, Managed identities, Kubernetes identities, Secrets, Certificates, Machine-to-machine authentication
NHI Discovery & Governance
- Lead implementation and adoption of enterprise NHI discovery capabilities.
- Establish a centralized inventory of:
- Service Accounts, Secrets, API Keys, Certificates, Service Principals, Managed Identities, Bot Identities, AI Agent Identities
- Define enterprise ownership attribution strategy.
- Establish risk scoring and classification models.
- Drive remediation of:
- Orphaned NHIs, Dormant Accounts, Excessive Privilege, Long-Lived Credentials, Unmanaged Secrets, Policy Violations
- Govern enterprise-wide access review and certification processes for NHI populations.
NHI Lifecycle Management
- Define and implement enterprise lifecycle processes for machine identities:
- Creation, Modification, Rotation, Recertification, Decommissioning
- Drive automation of NHI onboarding and provisioning workflows.
- Integrate lifecycle processes into:
- IGA Platforms, PAM Platforms, CMDB, DevOps Toolchains, ServiceNow
- Establish NHI access governance and least-privilege controls.
Secrets & Machine Identity Security
- Define enterprise secrets management strategy.
- Establish governance for:
- Encryption Keys, API Credentials, Certificates, Managed Secrets, OAuth Clients
- Drive adoption of automated credential rotation.
- Lead migration from static credentials toward workload identity-based authentication.
- Define policies for secrets lifecycle management and compliance monitoring.
Risk, Compliance & Governance
- Partner with Security, Audit, Risk, and Compliance teams.
- Establish policy frameworks, dashboards aligned with:
- NIST, ISO 27001, CIS Controls, CSA AI Controls Matrix, Zero Trust Architecture
- Lead audit readiness activities.
- Ensure compliance with regulatory and internal security requirements.
- Develop measurable compliance and remediation programs.
Compensation and Benefits:
- The expected compensation range for this position is between $93,500 - $156,450.
- Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
- Bonus based on performance and eligibility target payout is 10% of annual salary paid out annually.
- Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
- In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications
Experience
- 12+ years in Identity & Access Management or Cybersecurity.
- 5+ years leading enterprise-scale IAM programs.
- Demonstrated leadership experience managing global projects and strategic initiatives.
- Proven experience implementing enterprise identity strategies and roadmaps.
NHI Expertise
- Strong expertise in:
- Non-Human Identity Security, Machine Identity Management, Secrets Management, Certificate Management, Workload Identity Security, Cloud Identity Governance, Privileged Access Management, Identity Governance & Administration
- Hands-on experience with platforms such as:
- Veza, Astrix, Akeyless, HashiCorp Vault, CyberArk, Thales CTM, BeyondTrust, SailPoint, Saviynt
Cloud & Architecture
- Deep hands-on expertise in:
- AWS, Azure, GCP, Kubernetes, Service Mesh, CI/CD Security, Zero Trust Architecture
Technical Skills
- Strong SQL and database experience (queries, joins, analysis)
- Hands-on experience with AWS, Azure, Google Cloud Platform (GCP)
- Working Knowledge of IAM Roles, Managed Identities, Service Accounts, Key Management Services, Cloud-native security controls
- Experience integrating with SAAS and Enterprise platforms like Entra ID, Sales force, ServiceNow, GitHub, OKTA etc.
- Strong experience in API & Integration Skills like REST APIs, JSON, OAuth etc.
- Directory services (LDAP / AD/cloud directories)
Reporting & Analytics
- Experience building dashboards and operational reports
- Ability to translate raw IAM data into actionable insights
- Experience in working with large datasets and identity relationships
>
Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance.
All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.
PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity
If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy.
Please view our Pay Transparency Statement