Papa Johns International

Vice President, Information Security

Papa Johns International$160K — $200K *
US-AnywhereRemote in Michigan, US
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10–15+ years in information security or cybersecurity
  • 5+ years in leadership roles managing teams
  • Experience with enterprise cybersecurity transformation
  • Knowledge of security operations, IAM, cloud security, and vulnerability management
  • Proficiency in managing budgets and vendor relationships
  • Strong executive communication and influencing skills
  • Bachelor's degree in Computer Science or related field preferred
  • CISSP, CISM, CRISC, or equivalent certification preferred

Responsibilities

  • Develop and execute a multi-year cybersecurity strategy and roadmap
  • Establish security priorities based on business risk
  • Define cybersecurity policies, standards, and operating procedures
  • Provide clear visibility into cyber risk and security posture to executives
  • Lead enterprise security operations and cyber defense capabilities
  • Oversee security monitoring and threat detection
  • Establish and maintain the enterprise cyber incident response program
  • Develop incident response playbooks and conduct tabletop exercises
  • Establish identity and access security practices
  • Lead enterprise vulnerability and exposure management initiatives
  • Establish cybersecurity requirements for critical vendors
  • Partner with various teams to strengthen security controls and compliance

Benefits

  • Health, Dental, and Vision Insurance
  • 401(K) plan with company match
  • Flexible work arrangements
  • Professional development opportunities
  • Performance bonuses
  • Paid time off and holidays
Full Job Description

Job Summary

The VP, Information Security & Cybersecurity is responsible for developing and executing the organization's enterprise information security and cybersecurity strategy. This leader will protect the organization's people, data, applications, technology, and digital ecosystem from evolving cyber threats while enabling the business to operate securely and efficiently.

The role provides strategic leadership across cyber defense, security operations, identity and access management, vulnerability management, security architecture, incident response, threat intelligence, security governance, and third-party risk.

This role partners closely with the technology leadership, business executives, risk, legal, compliance, and audit teams to establish an effective, risk-based security program.

Key Responsibilities

Cybersecurity Strategy

  • Develop and execute a multi-year enterprise cybersecurity strategy and roadmap.

  • Establish security priorities based on business risk and threat landscape.

  • Define cybersecurity policies, standards, controls, and operating procedures.

  • Provide executive leadership with clear visibility into cyber risk and security posture.

Security Operations & Cyber Defense

  • Lead enterprise security operations and cyber defense capabilities.

  • Oversee SOC, SIEM, EDR/XDR, MDR/MSSP, security monitoring, and threat detection.

  • Improve detection, investigation, and response capabilities.

  • Drive security automation and orchestration to improve operational effectiveness.

Incident Response & Cyber Resilience

  • Establish and maintain the enterprise cyber incident response program.

  • Lead response to significant cybersecurity incidents.

  • Develop and maintain ransomware, phishing, credential compromise, data breach, DDoS, and other incident playbooks.

  • Conduct regular tabletop exercises and cyber simulations.

  • Partner with business continuity and disaster recovery teams to strengthen cyber resilience.

Identity & Access Security

  • Establish strong identity and access security practices.

  • Partner with IAM teams on MFA, PAM, SSO, Zero Trust, and least-privilege access.

  • Protect workforce, privileged, third-party, and application identities.

  • Reduce identity-based cyber risk.

Vulnerability & Threat Management

  • Lead enterprise vulnerability and exposure management.

  • Establish risk-based vulnerability prioritization and remediation.

  • Develop threat intelligence capabilities to identify emerging threats.

  • Ensure critical vulnerabilities and exposures receive appropriate executive visibility.

Security Architecture

  • Establish enterprise information security architecture and security-by-design principles.

  • Partner with technology and architecture teams to embed security into new products, applications, cloud platforms, and digital experiences.

  • Evaluate emerging cybersecurity technologies and capabilities, including AI-driven security.

Application, Data & Digital Security

  • Establish security requirements for applications, APIs, data, and customer-facing digital platforms.

  • Partner with application development teams on secure SDLC and application security.

  • Protect sensitive corporate and customer information.

  • Strengthen controls around data protection, encryption, and privacy.

Third-Party & Supply Chain Security

  • Establish cybersecurity requirements for critical vendors and technology partners.

  • Assess and manage third-party cyber risk.

  • Partner with Procurement, Legal, and Risk to ensure appropriate security controls are incorporated into contracts.

Governance, Risk & Compliance

  • Partner with Risk, Compliance, Internal Audit, and Legal.

  • Maintain cybersecurity control frameworks and policies.

  • Lead remediation of security assessments and audit findings.

  • Support applicable regulatory, privacy, PCI, and compliance requirements.

Leadership & Financial Management

  • Lead, develop, and retain a high-performing information security organization.

  • Establish clear accountability, KPIs, and operating rhythms.

  • Manage cybersecurity operating and capital budgets.

  • Lead strategic cybersecurity vendors and managed security providers.

  • Build strong partnerships across technology and business organizations.

  • Communicate complex cybersecurity risks in clear business and financial terms.

Qualifications

  • 10–15+ years of progressive experience in information security or cybersecurity.

  • 5+ years of leadership experience managing cybersecurity teams.

  • Experience leading enterprise cybersecurity transformation.

  • Strong understanding of security operations, IAM, cloud security, application security, vulnerability management, incident response, and cyber risk.

  • Experience managing significant budgets and strategic vendors.

  • Strong executive communication and influencing skills.

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field preferred.

  • CISSP, CISM, CRISC, or equivalent certification preferred.

About Papa Johns International

Papa John's International, Inc. is an American pizza restaurant franchise company. The company was founded in 1984 and is headquartered in Louisville, Kentucky. Papa John's operates over 5,000 restaurants in 45 countries and territories around the world. The company's menu includes a variety of pizzas, sides, and desserts. Papa John's is known for its commitment to quality ingredients and customer service. The company has faced controversy in recent years due to the behavior of its founder and former CEO, John Schnatter. Papa John's has taken steps to distance itself from Schnatter and improve its corporate culture.
Learn more about Papa Johns International
Size
14,000 employees
Market Cap
$2.9 billion
Industry
Net Income
$57.9 million
Founded
1985
5 Year Trend
+3.8%
Revenue
$1.8 billion
NASDAQ

Similar Jobs

More Jobs at Papa Johns International

More Information Technology Jobs

Find similar Vice President, Information Security jobs: