
Real job — pulled straight from PepsiCo’s careers page · Verified September 29, 2026 · No reposts.
Job description
PepsiCo is hiring a Senior Information Security Analyst — a full-time, based in Warsaw, Poland role. Apply directly on PepsiCo's careers page below.
Sr. InfoSec Analyst - SAP
Location: Warsaw, Mazowieckie, Poland
Overview Within the Cyber Fusion Center, the Infrastructure Security Team is seeking a Senior Information Security Analyst specializing in SAP Application Security. This role is responsible for identifying, assessing, and tracking security vulnerabilities within SAP ABAP custom code and SAP application environments using Onapsis Assess for Code and Control for Code. The analyst will work closely with SAP development, BASIS, and business application teams to identify insecure coding practices, prioritize security risks, provide remediation recommendations, and integrate findings into Vulnerability Response for tracking and accountability. The ideal candidate will possess strong knowledge of SAP ABAP development, SAP application security, secure software development practices, and vulnerability management processes. Experience with SAP S/4HANA, SAP ECC, SAP BTP, and Onapsis security solutions is highly desirable. Responsibilities SAP Code Security Assessment • Perform security assessments of SAP custom code using Onapsis Assess for Code.• Identify vulnerabilities, insecure coding patterns, authorization weaknesses, and configuration issues within SAP applications.• Analyze ABAP source code for security risks including injection vulnerabilities, authorization bypasses, insecure RFC calls, hardcoded credentials, and data exposure risks.• Validate findings and provide remediation guidance to SAP development teams. SAP Secure Development Governance • Support secure software development lifecycle (SSDLC) practices for SAP applications.• Establish secure coding standards for SAP ABAP development.• Partner with SAP developers to improve code quality and reduce security defects.• Conduct security reviews of SAP transport and application changes prior to production deployment. Control for Code Administration • Administer and maintain Onapsis Control for Code.• Configure automated policy checks and security controls within SAP development workflows.• Develop and maintain security rulesets aligned to corporate standards and compliance requirements.• Monitor code quality and policy compliance across SAP landscapes. Integration and Risk Management • Integrate SAP code security findings into Vulnerability Response.• Ensure findings are accurately mapped, tracked, assigned, and reported through established workflows.• Develop risk-based prioritization methodologies for SAP application vulnerabilities.• Support vulnerability lifecycle management from discovery through remediation validation. Reporting and Metrics • Develop executive and operational reporting for SAP application security risks.• Track remediation progress and risk reduction initiatives.• Produce metrics related to code quality, vulnerability trends, and policy compliance.• Support internal and external audit activities. Security Consulting and Collaboration • Serve as the primary security advisor for SAP development teams.• Conduct developer awareness sessions focused on SAP secure coding practices.• Collaborate with SAP BASIS, architecture, infrastructure, and cybersecurity teams to reduce application risk.• Support threat modeling activities for SAP applications and business-critical processes. Accountability • Improve SAP application security posture through continuous code assessment.• Reduce the number of critical and high-risk SAP code vulnerabilities.• Ensure security findings are tracked and managed through .• Support secure development practices across SAP development teams.• Provide risk-based recommendations and remediation guidance to application owners.• Maintain accurate reporting and metrics related to SAP code security. Qualifications • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Software Engineering, or related field.• 3–5 years of experience in SAP Security, SAP Development, Application Security, or Vulnerability Management.• Experience working within SAP ECC, SAP S/4HANA, or SAP BTP environments. Mandatory Technical Skills • Strong understanding of SAP ABAP programming.• Experience with Onapsis Assess for Code.• Knowledge of SAP authorization concepts and role-based access controls.• Experience integrating security findings into Vulnerability Response.• Understanding of secure coding principles and application security testing methodologies.• Experience analyzing and prioritizing application vulnerabilities.• Strong reporting and data analysis skills. • Experience with SAP S/4HANA transformations• Experience with CI/CD integration and DevSecOps processes.• Knowledge of OWASP Top 10 and secure development frameworks.• Familiarity with SAP BTP security controls. • Experience with threat modeling and secure architecture reviews. Preferred Qualifications Certifications SAP Certified Associate – SAP System Security and Authorizations SAP Certified Technology Associate – SAP S/4HANA System Administration SAP Business Technology Platform (SAP BTP) Security SAP System Security and Authorizations Assess, Control, Assess for Code, Control for Code) Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Non-Technical Skills • Strong analytical and problem-solving capabilities.• Excellent written and verbal communication skills.• Ability to influence development teams and business stakeholders.• Strong project management and organizational skills.• Ability to work independently in a fast-paced global environment. Differentiating Behaviors • Experience leading enterprise-wide SAP application security programs.• Demonstrated success by reducing SAP application security risk through code scanning and governance.• Ability to translate technical findings into business risk.• Experience integrating SAP security findings into enterprise vulnerability management processes. Compensation and Benefits: The expected starting compensation range for this position is 231,000 PLN annually. Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. This role is eligible for an annual bonus of 15% of annual salary, based on performance and eligibility. In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility. #LI-HybridResponsibilities
SAP Code Security Assessment • Perform security assessments of SAP custom code using Onapsis Assess for Code.• Identify vulnerabilities, insecure coding patterns, authorization weaknesses, and configuration issues within SAP applications.• Analyze ABAP source code for security risks including injection vulnerabilities, authorization bypasses, insecure RFC calls, hardcoded credentials, and data exposure risks.• Validate findings and provide remediation guidance to SAP development teams. SAP Secure Development Governance • Support secure software development lifecycle (SSDLC) practices for SAP applications.• Establish secure coding standards for SAP ABAP development.• Partner with SAP developers to improve code quality and reduce security defects.• Conduct security reviews of SAP transport and application changes prior to production deployment. Control for Code Administration • Administer and maintain Onapsis Control for Code.• Configure automated policy checks and security controls within SAP development workflows.• Develop and maintain security rulesets aligned to corporate standards and compliance requirements.• Monitor code quality and policy compliance across SAP landscapes. Integration and Risk Management • Integrate SAP code security findings into Vulnerability Response.• Ensure findings are accurately mapped, tracked, assigned, and reported through established workflows.• Develop risk-based prioritization methodologies for SAP application vulnerabilities.• Support vulnerability lifecycle management from discovery through remediation validation. Reporting and Metrics • Develop executive and operational reporting for SAP application security risks.• Track remediation progress and risk reduction initiatives.• Produce metrics related to code quality, vulnerability trends, and policy compliance.• Support internal and external audit activities. Security Consulting and Collaboration • Serve as the primary security advisor for SAP development teams.• Conduct developer awareness sessions focused on SAP secure coding practices.• Collaborate with SAP BASIS, architecture, infrastructure, and cybersecurity teams to reduce application risk.• Support threat modeling activities for SAP applications and business-critical processes. Accountability • Improve SAP application security posture through continuous code assessment.• Reduce the number of critical and high-risk SAP code vulnerabilities.• Ensure security findings are tracked and managed through .• Support secure development practices across SAP development teams.• Provide risk-based recommendations and remediation guidance to application owners.• Maintain accurate reporting and metrics related to SAP code security.Qualifications
• Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Software Engineering, or related field.• 3–5 years of experience in SAP Security, SAP Development, Application Security, or Vulnerability Management.• Experience working within SAP ECC, SAP S/4HANA, or SAP BTP environments. Mandatory Technical Skills • Strong understanding of SAP ABAP programming.• Experience with Onapsis Assess for Code.• Knowledge of SAP authorization concepts and role-based access controls.• Experience integrating security findings into Vulnerability Response.• Understanding of secure coding principles and application security testing methodologies.• Experience analyzing and prioritizing application vulnerabilities.• Strong reporting and data analysis skills. • Experience with SAP S/4HANA transformations• Experience with CI/CD integration and DevSecOps processes.• Knowledge of OWASP Top 10 and secure development frameworks.• Familiarity with SAP BTP security controls. • Experience with threat modeling and secure architecture reviews. Preferred Qualifications Certifications SAP Certified Associate – SAP System Security and Authorizations SAP Certified Technology Associate – SAP S/4HANA System Administration SAP Business Technology Platform (SAP BTP) Security SAP System Security and Authorizations Assess, Control, Assess for Code, Control for Code) Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) Non-Technical Skills • Strong analytical and problem-solving capabilities.• Excellent written and verbal communication skills.• Ability to influence development teams and business stakeholders.• Strong project management and organizational skills.• Ability to work independently in a fast-paced global environment. Differentiating Behaviors • Experience leading enterprise-wide SAP application security programs.• Demonstrated success by reducing SAP application security risk through code scanning and governance.• Ability to translate technical findings into business risk.• Experience integrating SAP security findings into enterprise vulnerability management processes. Compensation and Benefits: The expected starting compensation range for this position is 231,000 PLN annually. Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. This role is eligible for an annual bonus of 15% of annual salary, based on performance and eligibility. In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility. #LI-HybridGet Security Analyst jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs

Data Security Governance Manager (Remote)



Frequently asked questions
What skills are required for Senior Information Security Analyst at PepsiCo?
The required skills for Senior Information Security Analyst at PepsiCo include: CISSP, CISM.
What is the seniority level for Senior Information Security Analyst at PepsiCo?
Senior Information Security Analyst at PepsiCo is a Senior level position.
How do I apply for Senior Information Security Analyst at PepsiCo?
You can view the full description and apply for Senior Information Security Analyst at PepsiCo on EchoJobs: https://echojobs.io/job/pepsico-sr-infosec-analyst-sap-t0hpq.