← All rolesVP
Vice President, Information Security
Papa Johns · Retail · 10,000+ employees
Wayne County, MI · Onsite · full_time
CLI Career Level
VP-equivalent
Moderate confidence
Opportunity Score
65/100
Solid
High confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Sep 17, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — VP / Head of Security (US)
CLI Take
Scope matches the title
CLI reads this as a VP-equivalent mandate, consistent with how the employer has titled it. CLI's analysis of the posting describes a strategic build or transformation mandate, and it carries PCI DSS accountability. The reporting line sits below the executive team — the role reports to Technology Leadership. Total compensation and team size are not disclosed and remain the main open questions before pursuing it.
Why this role scores the way it does
65/100 — solid opportunity quality. CLI reads this as a VP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The reporting line sits below the executive team — the role reports to Technology Leadership. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
VP-equivalent — The employer lists this as “Vice President, Information Security”. CLI reads it as VP-equivalent because the role shows 10,000+ employee organization, executive committee exposure.
Moderate confidence
What makes it attractive
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- The role carries more scope than the employer's title suggests.
- Employer profile: 10,000+ employee organization, publicly traded, revenue 1b 10b.
What to probe before applying
- The reporting line sits below the executive team — the role reports to Technology Leadership.
- Scope language covers executive committee exposure.
Scoring components · Solid
Compensation versus comparable rolesNot disclosed · excluded from the score
Compensation is not disclosed and there is no comparable set to place it against.
Reporting level0 · weight 12%
The reporting line sits below the executive team — the role reports to Technology Leadership.
Functional and geographic scope21 · weight 12%
Scope language covers executive committee exposure.
Quality of the mandate100 · weight 12%
CLI's analysis of the posting describes a strategic build or transformation mandate.
Executive and board exposure65 · weight 10%
The posting references executive or committee-level interaction.
Role authority versus title100 · weight 10%
The role carries more scope than the employer's title suggests.
Company scale and trajectory100 · weight 10%
Employer profile: 10,000+ employee organization, publicly traded, revenue 1b 10b.
Team ownershipNot disclosed · excluded from the score
Team size: not disclosed.
Budget ownershipNot disclosed · excluded from the score
Budget ownership: not disclosed.
Risk signals100 · weight 5%
No adverse signals identified in the posting.
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
No compensation disclosed and insufficient comparable data to estimate.
Sample size not yet sufficient for a market comparison
Mandate includes managing cybersecurity operating and capital budgets.
See the full benchmark bands by level and region
The mandate
The VP is tasked with developing and executing a multi-year enterprise cybersecurity strategy and roadmap to protect people, data, and the digital ecosystem. This leader will provide strategic oversight for cyber defense, IAM, vulnerability management, and security architecture while partnering with business units to enable secure operations.
Reporting to technology and business leadership, this role manages the information security organization including the SOC, IAM, and GRC functions. The remit covers the entire enterprise digital ecosystem, including retail applications, APIs, and supply chain security.
Scope
- Reports to Technology Leadership
Domains and regulation
- Enterprise Security
- Cyber Defense
- Application Security
- Identity
- Cloud Security
- Incident Response
- Threat Intelligence
- GRC
- Third-Party Risk
- Privacy
- Infrastructure Security
- PCI DSS
Requirements
Must have
- 10–15+ years of progressive experience in information security or cybersecurity.
- 5+ years of leadership experience managing cybersecurity teams.
- Experience leading enterprise cybersecurity transformation.
- Strong understanding of security operations, IAM, cloud security, application security, vulnerability management, incident response, and cyber risk.
- Experience managing significant budgets and strategic vendors.
Preferred / bonus
- Preferred: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field.
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Leading an enterprise-wide cybersecurity transformation.
- Protecting a complex digital ecosystem including customer-facing digital platforms and APIs.
- Strengthening controls around data protection, encryption, and privacy for sensitive corporate and customer information.
- Developing threat intelligence and response capabilities for specific threats like ransomware, phishing, and DDoS.
Not stated in the posting: Specific reporting line (e.g., CIO or CEO) not explicitly stated.; Compensation range not disclosed.; Specific team size not disclosed..
About Papa Johns
Papa Johns is a global pizza delivery and carryout restaurant chain operating over 5,900 locations in approximately 50 countries. The organization manages a complex digital infrastructure including a high-volume e-commerce platform, mobile applications, and a massive supply chain network. A security leader would oversee data protection for millions of customers and a distributed franchise ecosystem.
- Industry
- Retail
- Headcount
- 10,000+ employees
- Headquarters
- Atlanta, Georgia
- Founded
- 1984
- Ownership
- Public company · NASDAQ:PZZA
- Funding
- Publicly traded
- Revenue
- $1B – $10B
Full company profile for Papa Johns →
View original job description
What’s Unique About You Is What Makes Us Better! Diversity is our strength and competitive advantage. Bring your flavor to the Papa John's team today!Job SummaryThe VP, Information Security & Cybersecurity is responsible for developing and executing the organization's enterprise information security and cybersecurity strategy. This leader will protect the organization's people, data, applications, technology, and digital ecosystem from evolving cyber threats while enabling the business to operate securely and efficiently.The role provides strategic leadership across cyber defense, security operations, identity and access management, vulnerability management, security architecture, incident response, threat intelligence, security governance, and third-party risk.This role partners closely with the technology leadership, business executives, risk, legal, compliance, and audit teams to establish an effective, risk-based security program.Key ResponsibilitiesCybersecurity StrategyDevelop and execute a multi-year enterprise cybersecurity strategy and roadmap.Establish security priorities based on business risk and threat landscape.Define cybersecurity policies, standards, controls, and operating procedures.Provide executive leadership with clear visibility into cyber risk and security posture.Security Operations & Cyber DefenseLead enterprise security operations and cyber defense capabilities.Oversee SOC, SIEM, EDR/XDR, MDR/MSSP, security monitoring, and threat detection.Improve detection, investigation, and response capabilities.Drive security automation and orchestration to improve operational effectiveness.Incident Response & Cyber ResilienceEstablish and maintain the enterprise cyber incident response program.Lead response to significant cybersecurity incidents.Develop and maintain ransomware, phishing, credential compromise, data breach, DDoS, and other incident playbooks.Conduct regular tabletop exercises and cyber simulations.Partner with business continuity and disaster recovery teams to strengthen cyber resilience.Identity & Access SecurityEstablish strong identity and access security practices.Partner with IAM teams on MFA, PAM, SSO, Zero Trust, and least-privilege access.Protect workforce, privileged, third-party, and application identities.Reduce identity-based cyber risk.Vulnerability & Threat ManagementLead enterprise vulnerability and exposure management.Establish risk-based vulnerability prioritization and remediation.Develop threat intelligence capabilities to identify emerging threats.Ensure critical vulnerabilities and exposures receive appropriate executive visibility.Security ArchitectureEstablish enterprise information security architecture and security-by-design principles.Partner with technology and architecture teams to embed security into new products, applications, cloud platforms, and digital experiences.Evaluate emerging cybersecurity technologies and capabilities, including AI-driven security.Application, Data & Digital SecurityEstablish security requirements for applications, APIs, data, and customer-facing digital platforms.Partner with application development teams on secure SDLC and application security.Protect sensitive corporate and customer information.Strengthen controls around data protection, encryption, and privacy.Third-Party & Supply Chain SecurityEstablish cybersecurity requirements for critical vendors and technology partners.Assess and manage third-party cyber risk.Partner with Procurement, Legal, and Risk to ensure appropriate security controls are incorporated into contracts.Governance, Risk & CompliancePartner with Risk, Compliance, Internal Audit, and Legal.Maintain cybersecurity control frameworks and policies.Lead remediation of security assessments and audit findings.Support applicable regulatory, privacy, PCI, and compliance requirements.Leadership & Financial ManagementLead, develop, and retain a high-performing information security organization.Establish clear accountability, KPIs, and operating rhythms.Manage cybersecurity operating and capital budgets.Lead strategic cybersecurity vendors and managed security providers.Build strong partnerships across technology and business organizations.Communicate complex cybersecurity risks in clear business and financial terms.Qualifications10–15+ years of progressive experience in information security or cybersecurity.5+ years of leadership experience managing cybersecurity teams.Experience leading enterprise cybersecurity transformation.Strong understanding of security operations, IAM, cloud security, application security, vulnerability management, incident response, and cyber risk.Experience managing significant budgets and strategic vendors.Strong executive communication and influencing skills.Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field preferred.CISSP, CISM, CRISC, or equivalent certification preferred.Our ValuesEVERYONE BELONGS - We believe connectedness and belonging are the essential ingredients to our successDO THE RIGHT THING - We are relentlessly focused on quality and integrity and make the right choices, even when it's difficultPEOPLE FIRST - To craft positive experiences for our customers, we take care of each other firstINNOVATE TO WIN - We champion and challenge for a better way in all we doHAVE FUN - We find joy, create meaningful impact and celebrate the journey togetherOur Core CompetenciesCUSTOMER CENTRIC - We leverage data and insights to craft a customer experience that builds relationships, cultivates trust, and delivers excellenceRESULTS DRIVEN – We focus on measurable outcomes by remaining optimistic, tenacious, and persistent even in the face of challengesCONTINUOUS IMPROVEMENT - We champion for better through strategic risk taking, experimentation and challenging the status quoBIAS FOR ACTION - We courageously lead, drive towards decisions, and maintain agility to meet the demands of our dynamic industryWINNING TOGETHER - We work together to unlock our full potential by actively collaborating and contributing in a cross-functional capacityPapa Johns is an equal opportunity employer.Papa Johns is a federal contractor that participates in the E-Verify program to confirm employment eligibility for each new team member. We also comply with all Right to Work requirements. Official E-Verify and Right to Work notices are available for applicants to review in both English and Spanish.Everybody loves pizza, which means they also love the people who are behind the scenes working to deliver it. This is complex and challenging work – but let’s face it – it’s also pizza! If you want a fulfilling career with a company that’s always moving forward, we’re the right place.Papa John's is a Federal Contract employer who participates in E-Verify to confirm employment eligibility for each new team member. For more information please view the following PDFs: E-Verify Poster (English) - Right to Work Poster (English) - E-Verify Poster (Spanish) - Right to Work Poster (Spanish) Papa John's is an Affirmative Action and Equal Opportunity Employer. For more information please click on the following PDF. See terms & conditions for site use.
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.