The Hershey Company is a 130-year-old snacks and confectionery giant with a portfolio of more than 70 brands - HERSHEY'S, REESE'S, TWIZZLERS, ICE BREAKERS, SKINNYPOP, PIRATES BOOTY among them - spanning manufacturing, distribution, and retail operations across the United States and globally. That footprint means the threat surface is wide: OT environments on factory floors, massive supply-chain integrations, e-commerce platforms, and the usual corporate IT stack. The attack model for a food manufacturer of this scale isn't hypothetical - ransomware targeting production lines, credential compromise across sprawling vendor ecosystems, and data theft from consumer-facing digital properties are all in play.
Cybersecurity teams here aren't protecting a single software product; they're defending a complex, physical-and-digital operation where downtime on a production line has immediate, tangible cost. The work spans industrial control system security, cloud infrastructure, application security for direct-to-consumer platforms, and enterprise identity management. Expect to engage with a mix of legacy manufacturing technology and modern cloud-native tooling - meaning interoperability and segmentation strategies matter as much as any single detection stack.
Hershey operates under stated values of integrity, fairness, and ethical conduct, with a public commitment to sustainability and responsible business practices. The company's Shared Goodness Promise signals a corporate posture where security and risk functions are part of a broader operational discipline rather than siloed IT afterthoughts. For practitioners who want to work at the intersection of physical operations and digital defense - where the consequences of getting it wrong show up in shipping manifests, not just in logs - this is that kind of environment.






