Graphic Packaging

VP, Information Security

Graphic Packaging$264K — $352K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity, IT, engineering, or a related field; advanced degree preferred.
  • 15+ years of leadership experience in cybersecurity or technology risk, ideally in a global enterprise setting.
  • Experience securing operational technology (OT), industrial control systems, and IoT environments.
  • Proven ability to build enterprise cybersecurity programs across multiple domains including governance, incident response, and regulatory compliance.
  • Practical experience in managing AI security and associated risks, including generative AI.
  • Strong understanding of global regulatory requirements such as SOX, GDPR, and NIS2.
  • Recognized certifications (CISSP, CISM, CRISC) are preferred.

Responsibilities

  • Define and implement a global cybersecurity and resilience strategy aligned with business goals.
  • Oversee cybersecurity governance, policies, standards, and controls across various systems and environments.
  • Provide comprehensive risk reporting to executive leadership and the Board.
  • Lead and develop a high-performing cybersecurity team, fostering collaboration across various stakeholders.
  • Establish a cyber risk management program that quantifies and prioritizes risks effectively.
  • Maintain incident response and crisis management protocols, including simulations and coordination with external parties.
  • Drive secure technology adoption and integration of AI while ensuring compliance with security principles.

Benefits

  • Competitive pay and performance-based incentive plans.
  • 401(k) plan with employer matching contributions.
  • Comprehensive health and welfare benefits including medical, dental, vision, and prescription coverage.
  • Short and long-term disability and life insurance coverage.
  • Flexible spending and health savings accounts available.
  • Employee assistance program and various voluntary benefits.
  • Tuition assistance and adoption assistance programs.
  • Paid time off along with paid company holidays for work-life balance.
Full Job Description
JOB SUMMARY:

Reporting to the SVP & Chief Information Officer (CIO), the Vice President, Cybersecurity & Chief Information Security Officer (CISO) will lead Graphic Packaging's global cybersecurity, technology risk, and operational resilience agenda. As the company's senior cybersecurity executive, the CISO will protect enterprise information, digital products, cloud platforms, manufacturing operations, operational technology (OT), connected devices, and the extended third-party ecosystem while enabling innovation, growth, and reliable operations.

The CISO will advise executive leadership and the Board on cyber risk, define risk appetite and tolerance with business leaders, and translate technical exposure into business, financial, safety, operational, legal, and reputational impact. This leader will establish an integrated, risk-based program aligned to recognized frameworks and evolving regulatory requirements; strengthen cyber resilience across IT and OT; govern the secure adoption of artificial intelligence, including generative and agentic AI; and embed security, privacy, and resilience by design across technology, procurement, product development, and business transformation.

ESSENTIAL DUTIES & RESPONSIBILITIES:

Enterprise Cybersecurity Strategy, Governance, and Leadership:
  • Define and execute a multi-year global cybersecurity and resilience strategy aligned with business priorities, enterprise risk appetite, technology modernization, and recognized frameworks such as NIST Cybersecurity Framework 2.0 and ISO/IEC 27001.
  • Own cybersecurity governance, policies, standards, control architecture, exceptions, and assurance across corporate IT, cloud, software, data, OT, industrial control systems, IoT, and digital products.
  • Provide clear, decision-oriented reporting to the CIO, executive leadership, Audit Committee, and Board, including quantified risk, material exposures, investment trade-offs, control effectiveness, incident readiness, and remediation progress.
  • Lead, develop, and retain a high-performing global cybersecurity organization and establish clear accountability across a federated network of business, IT, engineering, legal, privacy, compliance, internal audit, physical security, and operational stakeholders.
Cyber Risk, Resilience, and Incident Management:
  • Establish an enterprise cyber risk management program that continuously identifies, quantifies, prioritizes, treats, accepts, and reports risk in business and financial terms.
  • Lead continuous threat, attack-surface, exposure, and vulnerability management using intelligence, adversary-informed testing, secure configuration, and risk-based remediation across IT and OT environments.
  • Maintain and exercise enterprise incident response, crisis management, cyber recovery, ransomware, data breach, and business continuity playbooks, including executive and Board simulations and coordination with legal counsel, insurers, law enforcement, regulators, customers, and key suppliers.
  • Define minimum viable operations, recovery priorities, immutable backup and restoration requirements, and measurable recovery objectives; regularly validate the organization's ability to restore trusted operations following destructive cyber events.
  • Oversee security operations, detection engineering, threat intelligence, digital forensics, incident response, and managed security partners, with automation and AI used responsibly to improve speed, coverage, and analyst effectiveness.
  • Set and report key risk, performance, resilience, and control indicators that demonstrate business outcomes, security return on investment, trends, and accountability.
AI, Data, Identity, Cloud, and Secure Technology Enablement:
  • Co-lead enterprise AI security and risk governance for predictive, generative, and agentic AI, including model and use-case inventory, data protection, human oversight, red-teaming, prompt and model attack defenses, secure AI development, third-party model risk, shadow AI monitoring, and lifecycle assurance.
  • Extend identity governance to employees, privileged users, contractors, service accounts, workloads, machines, and AI agents through phishing-resistant authentication, least privilege, just-in-time access, continuous authorization, and strong secrets management.
  • Embed secure-by-design and privacy-by-design practices into cloud architecture, applications, APIs, data platforms, DevSecOps, software acquisition, and digital products.
  • Partner with enterprise architecture and technology leaders to advance Zero Trust principles, data security, encryption, key management, data loss prevention, cloud security posture, and secure configuration across hybrid and multi-cloud environments.
Essential Duties (Continued):

OT, Product, Third-Party, and Supply Chain Security:
  • Own the cyber risk strategy for manufacturing sites, OT, industrial control systems, IoT, engineering environments, and cyber-physical operations, balancing safety, availability, quality, and production requirements.
  • Establish asset visibility, segmentation, secure remote access, monitoring, vulnerability management, engineering change controls, incident response, and recovery requirements for OT environments, in partnership with plant and engineering leadership.
  • Strengthen third-party and fourth-party risk management across suppliers, software, cloud, managed services, logistics, and connected products through tiering, due diligence, contractual controls, continuous monitoring, concentration-risk analysis, and tested exit and recovery plans.
  • Set secure procurement and software supply-chain requirements, including secure development evidence, support and patch commitments, vulnerability disclosure, component transparency, and security-by-default expectations.
Regulatory Compliance, Assurance, and Executive Accountability:
  • Maintain a global cyber regulatory and contractual obligations framework covering applicable privacy, securities, critical-infrastructure, product-security, and breach-notification requirements, including SOX, GDPR, NIS2, and the EU Cyber Resilience Act where applicable.
  • Partner with Legal, Privacy, Compliance, Finance, Internal Audit, and Disclosure Committees to support timely escalation, materiality assessment, regulatory reporting, customer notification, litigation readiness, and defensible evidence.
  • Oversee independent assessments, penetration testing, red and purple teaming, control testing, audits, certifications, and remediation governance; ensure systemic issues and overdue risks are transparently escalated.
  • Develop the enterprise's cryptographic inventory and risk-based transition roadmap for post-quantum readiness, prioritizing long-lived sensitive data, critical trust services, and high-impact systems.
  • Manage the global cybersecurity operating and capital budgets, workforce, sourcing strategy, cyber insurance support, and partner portfolio; prioritize investments using risk reduction, resilience, business value, and total cost of ownership.
  • Build a measurable security culture through role-based education, executive and Board engagement, phishing-resistant practices, insider-risk coordination, and positive reinforcement of secure behaviors.
  • Drive simplification, automation, platform rationalization, skills development, succession planning, and continuous improvement across the cybersecurity program.
  • This position will be located at the company's headquarters in Sandy Springs, Georgia.
Candidate Profile:

The successful candidate will bring the following experience and expertise:
  • Bachelor's degree in cybersecurity, information technology, engineering, computer science, risk management, or a related discipline; advanced degree preferred.
  • At least 15 years of progressive cybersecurity, technology risk, or related leadership experience, including significant tenure leading a complex global enterprise security function; public-company and manufacturing experience strongly preferred.
  • Demonstrated experience securing OT, industrial control systems, manufacturing assets, IoT, and cyber-physical environments without compromising safety or operational continuity.
  • Proven ability to build and transform enterprise cybersecurity programs across strategy, governance, security operations, incident response, identity, cloud, applications, data, third parties, resilience, and regulatory compliance.
  • Practical experience governing AI risk and securing generative and agentic AI, including data flows, models, agents, non-human identities, AI-enabled software development, and AI-supported security operations.
  • Deep knowledge of relevant frameworks and practices, Zero Trust, secure software development, and business continuity and disaster recovery.
  • Strong understanding of applicable global requirements such as SOX, GDPR, SEC cybersecurity disclosure expectations, NIS2, the EU Cyber Resilience Act, and other sector- or geography-specific obligations.
  • Demonstrated success quantifying cyber risk, presenting to executive leadership and Boards, leading through major incidents, influencing without direct authority, and making balanced decisions in ambiguous, high-pressure environments.
  • Recognized cybersecurity or risk certifications such as CISSP, CISM, CRISC, or equivalent are preferred.
Disclaimer

The candidate must be able to perform the essential functions of the position satisfactorily, with or without a reasonable accommodation. Graphic Packaging retains the right to change or assign other duties to this position.

Competencies:

The successful candidate will bring the following experience and expertise:
  • Bachelor's degree in cybersecurity, information technology, engineering, computer science, risk management, or a related discipline; advanced degree preferred.
  • At least 15 years of progressive cybersecurity, technology risk, or related leadership experience, including significant tenure leading a complex global enterprise security function; public-company and manufacturing experience strongly preferred.
  • Demonstrated experience securing OT, industrial control systems, manufacturing assets, IoT, and cyber-physical environments without compromising safety or operational continuity.
  • Proven ability to build and transform enterprise cybersecurity programs across strategy, governance, security operations, incident response, identity, cloud, applications, data, third parties, resilience, and regulatory compliance.
  • Practical experience governing AI risk and securing generative and agentic AI, including data flows, models, agents, non-human identities, AI-enabled software development, and AI-supported security operations.
  • Deep knowledge of relevant frameworks and practices, Zero Trust, secure software development, and business continuity and disaster recovery.
  • Strong understanding of applicable global requirements such as SOX, GDPR, SEC cybersecurity disclosure expectations, NIS2, the EU Cyber Resilience Act, and other sector- or geography-specific obligations.
  • Demonstrated success quantifying cyber risk, presenting to executive leadership and Boards, leading through major incidents, influencing without direct authority, and making balanced decisions in ambiguous, high-pressure environments.
  • Recognized cybersecurity or risk certifications such as CISSP, CISM, CRISC, or equivalent are preferred.
Pay Range

$264,100.00 - $352,100.00

Pay Range: $264,100.00 - $352,100.00

GPI's Benefit Program
  • Competitive Pay
  • 401(k) w/employer matching
  • Health & Welfare Benefits
    • Medical, dental, vision, and prescription drug coverage
    • Short and Long-Term Disability
    • Life Insurance
    • Accidental Death & Dismemberment (AD&D) Insurance
    • Flexible Spending and Health Savings Accounts
  • Various Voluntary benefits
  • Adoption Assistance Program
  • Employee Discount Programs
  • Employee Assistance Program
  • Tuition Assistance Program
  • Paid Time Off + paid company holidays each year
Applicants will be accepted on an ongoing basis and there is no deadline.

This role is incentive plan eligible. Additional information will be shared during the hiring process. Each candidate's compensation offer will be based on multiple factors including, but not limited to, knowledge, skills, past experience, job duties, geography, and business need, among other things.

About Graphic Packaging

Graphic Packaging is committed to providing consumer packaging that makes a world of difference. The Company is a provider of sustainable fiber-based packaging solutions for a wide variety of products to food, beverage, foodservice, and other consumer products companies. The Company operates on a global basis, is one of the largest producers of folding cartons and paper-based foodservice products in the United States, and holds strong market positions in coated recycled paperboard, coated unbleached kraft paperboard, and solid bleached sulfate paperboard. The Company's customers include many of the world's most widely recognized companies and brands.

Graphic Packaging Careers

Join the vibrant team at Graphic Packaging, a leader in the packaging industry, where innovation meets sustainability to transform the packaging landscape. As one of the most forward-thinking companies, Graphic Packaging offers a plethora of job opportunities that promise not only professional growth but also a commitment to diversity and leadership development.

Work You’ll Do

At Graphic Packaging, you’ll be part of a culture that values innovation and leadership. Our team is dedicated to mastering the art of high-quality packaging solutions, ensuring that every team member is involved in making a significant impact. Whether you're looking for a position in design, production, sales, or management, Graphic Packaging provides an environment where your skills will be honed and your professional aspirations met.

Explore Career Paths

Graphic Packaging is keen on nurturing talent through comprehensive career paths that include both employment and internship opportunities. Our internship programs are designed to transform academic knowledge into professional real-world experience, providing a robust foundation for a flourishing career in the packaging industry.

Innovate and Lead

Join a team where innovation is at the core of everything we do. Graphic Packaging is home to over 17,000 employees who are encouraged to think big and create smarter packaging solutions. With a focus on sustainable practices and cutting-edge technology, our leadership fosters a workspace where every idea is valued and every individual can thrive.

Diversity and Professional Growth

We believe that a diverse workforce fuels innovation and creates a stronger team. Graphic Packaging is committed to diversity training and leadership development, ensuring that all employees have the opportunity for career advancement and personal growth. Our leadership programs are tailored to nurture your potential and propel you to new heights in your career.

Benefits and Culture

At Graphic Packaging, we understand that job satisfaction extends beyond the office. That’s why we offer competitive benefits that cover health, finance, and family. Be part of a company that supports your well-being and provides the tools you need to achieve your best both professionally and personally.

Join Our Team

Ready to advance your career at Graphic Packaging? Explore the various job opportunities on our careers page. We are continuously hiring and looking for individuals who are passionate, curious, and eager to drive change in the packaging industry.

Stay Connected

Keep up to date with the latest at Graphic Packaging by joining our networking events, reading our careers blog, and subscribing to job alert emails. Tailor your experience and stay ahead in your career with insider tips, industry news, and exclusive looks into life at Graphic Packaging.

Apply Now

Your future at Graphic Packaging is just an interview away. Polish your resume, prepare your skills, and apply for the position that will set you on the path to success. We look forward to seeing how you can contribute to our team and help shape the future of packaging.

Graphic Packaging Jobs

Discover the exciting and rewarding opportunities that await at Graphic Packaging. Whether you’re seeking an internship or a full-time position, our doors are open to those ready to make a significant impact in the industry. Join us and be part of a company that’s leading the way in innovative and sustainable packaging solutions.
Learn more about Graphic Packaging
Size
25,000 employees
Market Cap
$6.8 billion
Industry
Net Income
$167.3 million
Founded
1978
5 Year Trend
+10.7%
Revenue
$6.5 billion
NASDAQ

Similar Jobs

More Jobs at Graphic Packaging

  • Graphic Packaging
    VP, Information Security
    $264K — $352K *
    Atlanta, GA 30349 (Fulton County)
    Information Technology
    In-Person
  • Graphic Packaging
    Finishing Associate Manager
    $72K — $96K *
    Sioux Falls, SD 57106 (Minnehaha County)
    Food & Beverages
    In-Person
  • Graphic Packaging
    Finishing Manager
    $92K — $123K *
    Solon, OH 44139 (Cuyahoga County)
    Manufacturing & Automotive
    In-Person
  • Graphic Packaging
    Plant Controller
    $110K — $145K *
    Staunton, VA 24401 (Staunton City County)
    Manufacturing & Automotive
    In-Person
  • Graphic Packaging
    Finishing Manager
    $92K — $123K *
    Pacific, MO 63069 (Franklin County)
    Manufacturing & Automotive
    In-Person

More Information Technology Jobs

Find similar VP, Information Security jobs: