Vice President, Information Security

🏢 Papa Johns · all 3 jobs
📍 United States
📅 Posted Sep 19, 2026 · via Himalayas
🏷 Infosec, Cybersecurity, Security Operations, It Risk Management, Security Leadership, Vice President Of Information Security +4 more
Apply on original site ↗

What’s Unique About You Is What Makes Us Better! Diversity is our strength and competitive advantage. Bring your flavor to the Papa John's team today!
Job Summary

The VP, Information Security & Cybersecurity is responsible for developing and executing the organization's enterprise information security and cybersecurity strategy. This leader will protect the organization's people, data, applications, technology, and digital ecosystem from evolving cyber threats while enabling the business to operate securely and efficiently.

The role provides strategic leadership across cyber defense, security operations, identity and access management, vulnerability management, security architecture, incident response, threat intelligence, security governance, and third-party risk .

This role partners closely with the technology leadership, business executives, risk, legal, compliance, and audit teams to establish an effective, risk-based security program.

Key Responsibilities
Cybersecurity Strategy

-
Develop and execute a multi-year enterprise cybersecurity strategy and roadmap.

-
Establish security priorities based on business risk and threat landscape.

-
Define cybersecurity policies, standards, controls, and operating procedures.

-
Provide executive leadership with clear visibility into cyber risk and security posture.

Security Operations & Cyber Defense

-
Lead enterprise security operations and cyber defense capabilities.

-
Oversee SOC, SIEM, EDR/XDR, MDR/MSSP, security monitoring, and threat detection.

-
Improve detection, investigation, and response capabilities.

-
Drive security automation and orchestration to improve operational effectiveness.

Incident Response & Cyber Resilience

-
Establish and maintain the enterprise cyber incident response program.

-
Lead response to significant cybersecurity incidents.

-
Develop and maintain ransomware, phishing, credential compromise, data breach, DDoS, and other incident playbooks.

-
Conduct regular tabletop exercises and cyber simulations.

-
Partner with business continuity and disaster recovery teams to strengthen cyber resilience.

Identity & Access Security

-
Establish strong identity and access security practices.

-
Partner with IAM teams on MFA, PAM, SSO, Zero Trust, and least-privilege access .

-
Protect workforce, privileged, third-party, and application identities.

- Reduce identity-based cyber risk.

Vulnerability & Threat Management

-
Lead enterprise vulnerability and exposure management.

-
Establish risk-based vulnerability prioritization and remediation.

-
Develop threat intelligence capabilities to identify emerging threats.

-
Ensure critical vulnerabilities and exposures receive appropriate executive visibility.

Security Architecture

-
Establish enterprise information security architecture and security-by-design principles.

-
Partner with technology and architecture teams to embed security into new products, applications, cloud platforms, and digital experiences.

-
Evaluate emerging cybersecurity technologies and capabilities, including AI-driven security.

Application, Data & Digital Security

-
Establish security requirements for applications, APIs, data, and customer-facing digital platforms.

-
Partner with application development teams on secure SDLC and application security.

-
Protect sensitive corporate and customer information.

-
Strengthen controls around data protection, encryption, and privacy.

Third-Party & Supply Chain Security

-
Establish cybersecurity requirements for critical vendors and technology partners.

-
Assess and manage third-party cyber risk.

-
Partner with Procurement, Legal, and Risk to ensure appropriate security controls are incorporated into contracts.

Governance, Risk & Compliance

-
Partner with Risk, Compliance, Internal Audit, and Legal.

-
Maintain cybersecurity control frameworks and policies.

-
Lead remediation of security assessments and audit findings.

-
Sup

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Get new remote jobs like this by email
Daily email, only when there's something new. One click to stop.

Get remote jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you