Vice President, Information Security

Papa John's International , Inc.

Lansing (MI)

On-site

USD 180,000 - 280,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Papa John's International, Inc. invites a senior cybersecurity executive to lead the enterprise information security program in the United States. The VP will shape strategy, risk posture, policy, and alignment with business objectives.

You will direct security operations, identity and access management, threat intelligence, and incident response while partnering with technology, risk, legal, and audit to build a resilient digital ecosystem.

Qualifications

  • 10–15+ years of progressive experience in information security or cybersecurity.
  • 5+ years of leadership experience managing cybersecurity teams.
  • Experience leading enterprise cybersecurity transformation.
  • Strong understanding of security operations, IAM, cloud security, application security, vulnerability management, incident response, and cyber risk.
  • Experience managing significant budgets and strategic vendors.
  • Strong executive communication and influencing skills.

Responsibilities

  • Develop a multi-year enterprise cybersecurity strategy and roadmap.
  • Lead enterprise security operations and cyber defense capabilities.
  • Lead incident response and cyber resilience programs.
  • Establish strong identity and access security practices and Zero Trust implementation.
  • Oversee vulnerability and threat management and security architecture.
  • Partner with risk, compliance, legal, and audit to ensure regulatory alignment.

Skills

Executive leadership
Cybersecurity strategy
Risk management
Security operations
Executive communication

Education

Bachelor's degree in Computer Science or related field
CISSP / CISM / CRISC or equivalent

Tools

IAM / Zero Trust concepts
Cloud security architectures

Job description

Job Summary

The VP, Information Security & Cybersecurity is responsible for developing and executing the organization's enterprise information security and cybersecurity strategy. This leader will protect the organization's people, data, applications, technology, and digital ecosystem from evolving cyber threats while enabling the business to operate securely and efficiently.

The role provides strategic leadership across cyber defense, security operations, identity and access management, vulnerability management, security architecture, incident response, threat intelligence, security governance, and third-party risk.

This role partners closely with the technology leadership, business executives, risk, legal, compliance, and audit teams to establish an effective, risk-based security program.

Key Responsibilities
Cybersecurity Strategy
  • Develop and execute a multi-year enterprise cybersecurity strategy and roadmap.
  • Establish security priorities based on business risk and threat landscape.
  • Define cybersecurity policies, standards, controls, and operating procedures.
  • Provide executive leadership with clear visibility into cyber risk and security posture.
Security Operations & Cyber Defense
  • Lead enterprise security operations and cyber defense capabilities.
  • Oversee SOC, SIEM, EDR/XDR, MDR/MSSP, security monitoring, and threat detection.
  • Improve detection, investigation, and response capabilities.
  • Drive security automation and orchestration to improve operational effectiveness.
Incident Response & Cyber Resilience
  • Establish and maintain the enterprise cyber incident response program.
  • Lead response to significant cybersecurity incidents.
  • Develop and maintain ransomware, phishing, credential compromise, data breach, DDoS, and other incident playbooks.
  • Conduct regular tabletop exercises and cyber simulations.
  • Partner with business continuity and disaster recovery teams to strengthen cyber resilience.
Identity & Access Security
  • Establish strong identity and access security practices.
  • Partner with IAM teams on MFA, PAM, SSO, Zero Trust, and least-privilege access.
  • Protect workforce, privileged, third-party, and application identities.
  • Reduce identity-based cyber risk.
Vulnerability & Threat Management
  • Lead enterprise vulnerability and exposure management.
  • Establish risk-based vulnerability prioritization and remediation.
  • Develop threat intelligence capabilities to identify emerging threats.
  • Ensure critical vulnerabilities and exposures receive appropriate executive visibility.
Security Architecture
  • Establish enterprise information security architecture and security-by-design principles.
  • Partner with technology and architecture teams to embed security into new products, applications, cloud platforms, and digital experiences.
  • Evaluate emerging cybersecurity technologies and capabilities, including AI-driven security.
Application, Data & Digital Security
  • Establish security requirements for applications, APIs, data, and customer-facing digital platforms.
  • Partner with application development teams on secure SDLC and application security.
  • Protect sensitive corporate and customer information.
  • Strengthen controls around data protection, encryption, and privacy.
Third-Party & Supply Chain Security
  • Establish cybersecurity requirements for critical vendors and technology partners.
  • Assess and manage third-party cyber risk.
  • Partner with Procurement, Legal, and Risk to ensure appropriate security controls are incorporated into contracts.
Governance, Risk & Compliance
  • Partner with Risk, Compliance, Internal Audit, and Legal.
  • Maintain cybersecurity control frameworks and policies.
  • Lead remediation of security assessments and audit findings.
  • Support applicable regulatory, privacy, PCI, and compliance requirements.
Leadership & Financial Management
  • Lead, develop, and retain a high-performing information security organization.
  • Establish clear accountability, KPIs, and operating rhythms.
  • Manage cybersecurity operating and capital budgets.
  • Lead strategic cybersecurity vendors and managed security providers.
  • Build strong partnerships across technology and business organizations.
  • Communicate complex cybersecurity risks in clear business and financial terms.
Qualifications
  • 10–15+ years of progressive experience in information security or cybersecurity.
  • 5+ years of leadership experience managing cybersecurity teams.
  • Experience leading enterprise cybersecurity transformation.
  • Strong understanding of security operations, IAM, cloud security, application security, vulnerability management, incident response, and cyber risk.
  • Experience managing significant budgets and strategic vendors.
  • Strong executive communication and influencing skills.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field preferred.
  • CISSP, CISM, CRISC, or equivalent certification preferred.
Our Values
  • EVERYONE BELONGS - We believe connectedness and belonging are the essential ingredients to our success
  • DO THE RIGHT THING - We are relentlessly focused on quality and integrity and make the right choices, even when it's difficult
  • PEOPLE FIRST - To craft positive experiences for our customers, we take care of each other first
  • INNOVATE TO WIN - We champion and challenge for a better way in all we do
  • HAVE FUN - We find joy, create meaningful impact and celebrate the journey together
Our Core Competencies
  • CUSTOMER CENTRIC - We leverage data and insights to craft a customer experience that builds relationships, cultivates trust, and delivers excellence
  • RESULTS DRIVEN – We focus on measurable outcomes by remaining optimistic, tenacious, and persistent even in the face of challenges
  • CONTINUOUS IMPROVEMENT - We champion for better through strategic risk taking, experimentation and challenging the status quo
  • BIAS FOR ACTION - We courageously lead, drive towards decisions, and maintain agility to meet the demands of our dynamic industry
  • WINNING TOGETHER - We work together to unlock our full potential by actively collaborating and contributing in a cross-functional capacity

Papa Johns is an equal opportunity employer.

Papa Johns is a federal contractor that participates in the E-Verify program to confirm employment eligibility for each new team member. We also comply with all Right to Work requirements. Official E-Verify and Right to Work notices are available for applicants to review in both English and Spanish.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vice President, Information Security
Vice President, Information Security

Papa Johns • Michigan

On-site
USD 180,000 - 280,000
Vice President, Information Security
Vice President, Information Security

Papa John's USA, Inc. • Michigan

Hybrid
USD 180,000 - 240,000
Vice President, Information Security
Vice President, Information Security

papajohns • United States

On-site
USD 250,000 - 360,000
Director, Global Risk Management
Director, Global Risk Management

Papa John's International • Louisville (KY)

On-site
USD 140,000 - 210,000
Senior Manager, Technical Delivery Management
Senior Manager, Technical Delivery Management

Papa Johns • Atlanta (GA)

On-site
USD 130,000 - 190,000
Staff Engineer- Web (Remote)
Staff Engineer- Web (Remote)

Papa Johns • Atlanta (GA)

On-site
USD 140,000 - 190,000
Director, Global Risk Management
Director, Global Risk Management

Papa John's International , Inc. • Louisville (KY)

On-site
USD 120,000 - 190,000
VP, Information Security & Cyber Defense
VP, Information Security & Cyber Defense

papajohns • United States

On-site
USD 250,000 - 360,000
Senior Manager, Technical Delivery Management
Senior Manager, Technical Delivery Management

Papa John's International , Inc. • Atlanta (GA)

On-site
USD 140,000 - 190,000
Senior Product Business Analyst
Senior Product Business Analyst

Papa Johns • Atlanta (GA)

On-site
USD 110,000 - 150,000