Cybersecurity IAM Senior Principal Engineer

PepsiCo Deutschland GmbH

Plano (TX)

On-site

USD 124,000 - 207,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual bonus 15%
Paid time off
Benefits package

Job summary

PepsiCo Deutschland GmbH seeks an IAM Principal Cybersecurity Architect to lead strategy, design, and governance of IAM services including AI, LLMs, and autonomous AI agents. This senior role sets enterprise AI identity standards, secures AI platforms, and enables safe Agentic AI adoption across the organization.

You will partner with AI Engineering, Cloud, Enterprise Architecture, and Security teams to design scalable, secure AI solutions and govern non-human identities with Zero Trust

Qualifications

  • Bachelor’s degree in computer science, cybersecurity, information technology, or a related field.
  • 15+ years of experience in Cybersecurity with significant IAM expertise.
  • 7+ years in a Principal, Lead, or Senior Architecture role supporting enterprise or cloud-native environments.
  • Expert knowledge of IAM technologies including AWS IAM, AWS Identity Center, Entra ID, OAuth 2.0, OIDC, SAML, and Zero Trust Architecture.
  • Experience securing AI platforms, LLMs, Agentic AI applications, or autonomous AI agents.
  • Strong understanding of cloud security, workload identities, and non-human identity management.
  • Excellent communication and stakeholder management skills.

Responsibilities

  • Lead solution architecture across IAM services for cross functional programs.
  • Lead modernization of IAM capabilities supporting AI and cloud-native applications.
  • Design secure identity architectures leveraging AWS IAM, AWS Identity Center, Microsoft Entra ID, and cloud-native identity services.
  • Integrate AI platforms with enterprise IAM, Identity Governance (IGA), and Privileged Access Management (PAM) solutions.
  • Define the enterprise architecture and security strategy for AI systems, LLMs, and Agentic AI platforms.
  • Develop architecture standards, reference designs, and best practices for securing AI workloads.
  • Partner with AI Engineering and platform teams to embed security-by-design into AI solutions.
  • Drive adoption of Zero Trust principles across AI and cloud environments.
  • Design and govern the complete identity lifecycle for AI agents, including onboarding, authentication, authorization, certification, monitoring, and decommissioning.
  • Establish governance standards for AI identities, non-human identities, and machine identities.
  • Implement least privilege, Just-in-Time, and Just-Enough-Access models for AI workloads.
  • Ensure AI systems meet enterprise security, compliance, privacy, and regulatory requirements.
  • Serve as the technical authority for AI identity security across the enterprise.
  • Partner with Cybersecurity, Enterprise Architecture, AI Engineering, Cloud, GRC, Privacy, and business teams to deliver secure AI capabilities.
  • Mentor architects and engineers on AI security, IAM, and cloud identity best practices.
  • Communicate architecture decisions and security risks effectively to executive leadership and technical stakeholders.

Skills

IAM expertise
Cloud security
Secure AI platforms
Zero Trust
Leadership

Education

Bachelor’s degree in CS/Cybersecurity/IT

Tools

AWS IAM
AWS Identity Center
Microsoft Entra ID
OAuth 2.0
OIDC
SAML
Zero Trust Architecture
Saviynt
SailPoint
AWS Bedrock
Amazon AgentCore
Azure AI

Job description

Overview

IAM Principal Cybersecurity Architect will lead the strategy, solution design, and governance of Identity and Access Management (IAM) services including AI, Large Language Models (LLMs), and autonomous AI agents and security.

This is a senior technical leadership role responsible for defining enterprise standards for AI identity, securing AI platforms, and enabling the safe adoption of Agentic AI across the organization. The role will partner closely with AI Engineering, Cloud, Enterprise Architecture, and Security teams to design scalable, secure, and compliant AI solutions.

The ideal candidate has deep expertise in IAM, cloud security, Zero Trust architecture, and AI security, with experience building governance models for AI agents and non-human identities.

Responsibilities
IAM & Cloud Security
  • Lead solution architecture across IAM services for critical cross functional programs
  • Lead modernization of IAM capabilities supporting AI and cloud-native applications.
  • Design secure identity architectures leveraging AWS IAM, AWS Identity Center, Microsoft Entra ID, and cloud-native identity services.
  • Integrate AI platforms with enterprise IAM, Identity Governance (IGA), and Privileged Access Management (PAM) solutions.
AI Agent Security Strategy & Architecture
  • Define the enterprise architecture and security strategy for AI systems, LLMs, and Agentic AI platforms.
  • Develop architecture standards, reference designs, and best practices for securing AI workloads.
  • Partner with AI Engineering and platform teams to embed security-by-design into AI solutions.
  • Drive adoption of Zero Trust principles across AI and cloud environments.
AI Agent Identity & Governance
  • Design and govern the complete identity lifecycle for AI agents, including onboarding, authentication, authorization, certification, monitoring, and decommissioning.
  • Establish governance standards for AI identities, non-human identities (NHI), and machine identities.
  • Implement least privilege, Just-in-Time (JIT), and Just-Enough-Access (JEA) access models for AI workloads.
  • Ensure AI systems meet enterprise security, compliance, privacy, and regulatory requirements.
Leadership & Collaboration
  • Serve as the technical authority for AI identity security across the enterprise.
  • Partner with Cybersecurity, Enterprise Architecture, AI Engineering, Cloud, GRC, Privacy, and business teams to deliver secure AI capabilities.
  • Mentor architects and engineers on AI security, IAM, and cloud identity best practices.
  • Communicate architecture decisions and security risks effectively to executive leadership and technical stakeholders.
Compensation and Benefits:
  • The expected compensation range for this position is between $123,500 - $206,750.
  • Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
  • Bonus based on performance and eligibility target payout is 15% of annual salary paid out annually.
  • Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
  • In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications
Required Qualifications
  • Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related field.
  • 15+ years of experience in Cybersecurity, with significant expertise in Identity and Access Management (IAM).
  • 7+ years in a Principal, Lead, or Senior Architecture role supporting enterprise or cloud-native environments.
  • Expert knowledge of IAM technologies, including AWS IAM, AWS Identity Center, Microsoft Entra ID, OAuth 2.0, OpenID Connect (OIDC), SAML, and Zero Trust Architecture.
  • Experience securing AI platforms, LLMs, Agentic AI applications, or autonomous AI agents.
  • Strong understanding of cloud security, workload identities, and non-human identity (NHI) management.
  • Excellent communication and stakeholder management skills.
Preferred Qualifications
  • Experience with AWS Bedrock, Amazon AgentCore, Azure AI, or similar enterprise AI platforms.
  • Experience with Identity Governance (IGA) platforms such as Saviynt, SailPoint, or equivalent.
  • Knowledge of OWASP Top 10 for LLM Applications, prompt injection defenses, and AI security best practices.
  • Experience with SPIFFE/SPIRE, workload identity frameworks, or service identity management.
  • Familiarity with AI governance, AI risk management, and responsible AI frameworks.
  • Professional certifications such as CISSP, CISM, CCSP, AWS Certified Security – Specialty, TOGAF, or cloud architecture certifications.
EEO Statement

Our Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance.

All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.

PepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age

If you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy.

Please view our Pay Transparency Statement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity IAM Senior Principal Engineer
Cybersecurity IAM Senior Principal Engineer

PepsiCo • Plano (TX)

On-site
USD 124,000 - 207,000
Medical
Dental
Vision
+2
Associate Principal – Non-Human Identity (NHI) Lead
Associate Principal – Non-Human Identity (NHI) Lead

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 94,000 - 156,000
Bonus 10% of annual salary
Comprehensive benefits
Paid time off
Associate Principal – Non-Human Identity (NHI) Lead
Associate Principal – Non-Human Identity (NHI) Lead

PepsiCo • Plano (TX)

On-site
USD 94,000 - 156,000
Bonus eligibility
Comprehensive benefits package
Paid time off
Senior Identity & Access Management (CIAM) Engineer
Senior Identity & Access Management (CIAM) Engineer

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 80,000 - 134,000
Medical, Dental, Vision
Paid time off
Equal Opportunity Employer
Senior AI Engineer
Senior AI Engineer

PepsiCo • Plano (TX)

On-site
USD 93,000 - 157,000
Bonus based on performance
Comprehensive benefits package
Paid time off including parental leave
AI Solutions Architect
AI Solutions Architect

PepsiCo • Plano (TX)

On-site
USD 110,700 - 185,250
Paid time off including parental leave, vacation, and sick leave
Comprehensive benefits package including medical, dental, vision
Bonus based on performance, target payout 12%
AI Engineer
AI Engineer

PepsiCo Deutschland GmbH • Town of Texas (WI)

Hybrid
USD 106,000 - 179,000
Comprehensive benefits package
Paid time off including parental leave
Senior AI Engineer
Senior AI Engineer

PepsiCo • Chicago (IL)

On-site
USD 110,000 - 186,000
Comprehensive benefits package
Paid time off including parental leave
Performance bonus
Senior Authentication, SSO/MFA & CIAM SME Lead
Senior Authentication, SSO/MFA & CIAM SME Lead

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 111,000 - 185,000
Medical
Dental
Vision
+5
Senior AI Engineer
Senior AI Engineer

PepsiCo • Purchase (NY)

On-site
USD 93,000 - 157,000
Bonus program based on performance
Comprehensive benefits package including medical, dental, and vision
Paid time off and parental leave