Vice President, Information Security

Papa John's USA, Inc.

Michigan

Hybrid

USD 180,000 - 240,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Papa John's USA, Inc. seeks a strategic VP, Information Security & Cybersecurity to lead the organization’s security program.

This executive will shape the enterprise security strategy, align it with business goals, and drive risk-based decisions across technology, data, and operations. The role requires crafting policies, leading cyber defense, incident response, IAM, vulnerability management, and security architecture while partnering with risk, legal, compliance, and audit teams to enable

Qualifications

  • 10–15+ years of progressive information security or cybersecurity experience.

Responsibilities

  • Develop and execute a multi-year enterprise cybersecurity strategy and roadmap.
  • Lead enterprise security operations, SOC, SIEM, EDR/XDR, MDR/MSSP.
  • Establish and maintain incident response programs and playbooks.
  • Set identity and access security practices including MFA, PAM, SSO, and Zero Trust.
  • Oversee vulnerability and threat management and risk-based prioritization.
  • Lead security architecture and secure-by-design principles across products and platforms.
  • Ensure governance, risk, compliance, and third-party risk management.

Skills

Leadership
Executive communication
Cybersecurity strategy
Security operations
IAM & Zero Trust
Vulnerability management
Incident response
Security architecture
Risk & governance
Budget & vendor management

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field
CISSP, CISM, CRISC, or equivalent certification preferred

Job description

Job Summary

What's Unique About You Is What Makes Us Better! Diversity is our strength and competitive advantage. Bring your flavor to the Papa John's team today! The VP, Information Security & Cybersecurity is responsible for developing and executing the organization's enterprise information security and cybersecurity strategy. This leader will protect the organization's people, data, applications, technology, and digital ecosystem from evolving cyber threats while enabling the business to operate securely and efficiently. The role provides strategic leadership across cyber defense, security operations, identity and access management, vulnerability management, security architecture, incident response, threat intelligence, security governance, and third-party risk. This role partners closely with the technology leadership, business executives, risk, legal, compliance, and audit teams to establish an effective, risk-based security program.

Key Responsibilities
  • Cybersecurity Strategy: Develop and execute a multi-year enterprise cybersecurity strategy and roadmap. Establish security priorities based on business risk and threat landscape. Define cybersecurity policies, standards, controls, and operating procedures. Provide executive leadership with clear visibility into cyber risk and security posture.
  • Security Operations & Cyber Defense: Lead enterprise security operations and cyber defense capabilities. Oversee SOC, SIEM, EDR/XDR, MDR/MSSP, security monitoring, and threat detection. Improve detection, investigation, and response capabilities. Drive security automation and orchestration to improve operational effectiveness.
  • Incident Response & Cyber Resilience: Establish and maintain the enterprise cyber incident response program. Lead response to significant cybersecurity incidents. Develop and maintain ransomware, phishing, credential compromise, data breach, DDoS, and other incident playbooks. Conduct regular tabletop exercises and cyber simulations. Partner with business continuity and disaster recovery teams to strengthen cyber resilience.
  • Identity & Access Security: Establish strong identity and access security practices. Partner with IAM teams on MFA, PAM, SSO, Zero Trust, and least-privilege access. Protect workforce, privileged, third-party, and application identities. Reduce identity-based cyber risk.
  • Vulnerability & Threat Management: Lead enterprise vulnerability and exposure management. Establish risk-based vulnerability prioritization and remediation. Develop threat intelligence capabilities to identify emerging threats. Ensure critical vulnerabilities and exposures receive appropriate executive visibility.
  • Security Architecture: Establish enterprise information security architecture and security-by-design principles. Partner with technology and architecture teams to embed security into new products, applications, cloud platforms, and digital experiences. Evaluate emerging cybersecurity technologies and capabilities, including AI-driven security.
  • Application, Data & Digital Security: Establish security requirements for applications, APIs, data, and customer-facing digital platforms. Partner with application development teams on secure SDLC and application security. Protect sensitive corporate and customer information. Strengthen controls around data protection, encryption, and privacy.
  • Third-Party & Supply Chain Security: Establish cybersecurity requirements for critical vendors and technology partners. Assess and manage third-party cyber risk. Partner with Procurement, Legal, and Risk to ensure appropriate security controls are incorporated into contracts.
  • Governance, Risk & Compliance: Partner with Risk, Compliance, Internal Audit, and Legal. Maintain cybersecurity control frameworks and policies. Lead remediation of security assessments and audit findings. Support applicable regulatory, privacy, PCI, and compliance requirements.
  • Leadership & Financial Management: Lead, develop, and retain a high-performing information security organization. Establish clear accountability, KPIs, and operating rhythms. Manage cybersecurity operating and capital budgets. Lead strategic cybersecurity vendors and managed security providers. Build strong partnerships across technology and business organizations. Communicate complex cybersecurity risks in clear business and financial terms.
Qualifications
  • 10–15+ years of progressive experience in information security or cybersecurity.
  • 5+ years of leadership experience managing cybersecurity teams.
  • Experience leading enterprise cybersecurity transformation.
  • Strong understanding of security operations, IAM, cloud security, application security, vulnerability management, incident response, and cyber risk.
  • Experience managing significant budgets and strategic vendors.
  • Strong executive communication and influencing skills.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field preferred.
  • CISSP, CISM, CRISC, or equivalent certification preferred.
Our Values
  • EVERYONE BELONGS - We believe connectedness and belonging are the essential ingredients to our success
  • DO THE RIGHT THING - We are relentlessly focused on quality and integrity and make the right choices, even when it's difficult
  • PEOPLE FIRST - To craft positive experiences for our customers, we take care of each other first
  • INNOVATE TO WIN - We champion and challenge for a better way in all we do
  • HAVE FUN - We find joy, create meaningful impact and celebrate the journey together
Our Core Competencies
  • CUSTOMER CENTRIC - We leverage data and insights to craft a customer experience that builds relationships, cultivates trust, and delivers excellence
  • RESULTS DRIVEN – We focus on measurable outcomes by remaining optimistic, tenacious, and persistent even in the face of challenges
  • CONTINUOUS IMPROVEMENT - We champion for better through strategic risk taking, experimentation and challenging the status quo
  • BIAS FOR ACTION - We courageously lead, drive towards decisions, and maintain agility to meet the demands of our dynamic industry
  • WINNING TOGETHER - We work together to unlock our full potential by actively collaborating and contributing in a cross-functional capacity
Equal Opportunity

Papa Johns is an equal opportunity employer. Papa Johns is a federal contractor that participates in the E-Verify program to confirm employment eligibility for each new team member. We also comply with all Right to Work requirements. Official E-Verify and Right to Work notices are available for applicants to review in both English and Spanish. Everybody loves pizza, which means they also love the people who are behind the scenes working to deliver it. This is complex and challenging work – but let’s face it – it’s also pizza! If you want a fulfilling career with a company that’s always moving forward, we’re the right place. Papa John's is a Federal Contract employer who participates in E-Verify to confirm employment eligibility for each new team member. For more information please view the following PDFs: E-Verify Poster (English) - Right to Work Poster (English) - E-Verify Poster (Spanish) - Right to Work Poster (Spanish) Papa Johns is an affirm…
For more information please click on the following PDF. See terms & conditions for site use. At Papa John's, we LOVE pizza. It brings people together and brings out the best in all of us. Just like our ingredients and toppings, we combine in unique ways to deliver a truly tantalizing result. Here, you're a valued team member right from the start. We want you to contribute your best ideas, collaborate and keep building your skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vice President, Information Security
Vice President, Information Security

Papa Johns • Michigan

On-site
USD 180,000 - 280,000
Director, Tech Enablement
Director, Tech Enablement

Papa Johns • Michigan

On-site
USD 140,000 - 230,000
Senior Product Business Analyst
Senior Product Business Analyst

Papa John's USA, Inc. • Atlanta (GA)

On-site
USD 90,000 - 125,000
Staff Engineer- Web (Remote)
Staff Engineer- Web (Remote)

Papa John's International , Inc. • Atlanta (GA)

Hybrid
USD 150,000 - 200,000
Shift Leader
Shift Leader

Papa John's USA, Inc. • Topeka (KS)

On-site
USD 18,000 - 23,000
Shift Leader
Shift Leader

Papa John's USA, Inc. • Zionsville (IN)

On-site
USD 17,000 - 25,000
Shift Leader
Shift Leader

Papa John's USA, Inc. • Belton (MO)

On-site
USD 19,000 - 25,000
General Manager
General Manager

Papa John's USA, Inc. • New Albany (IN)

On-site
USD 60,000 - 80,000
Shift Leader
Shift Leader

Papa John's USA, Inc. • Springfield (TN)

On-site
USD 17,000 - 21,000
Shift Leader
Shift Leader

Papa John's USA, Inc. • Concord (NC)

On-site
USD 17,000 - 21,000