信息安全副总裁
Vice President, Information Security
我们看重你与众不同的特质,这正是让我们变得更好的原因!多样性是我们最强大的力量和竞争优势。今天就将你的独特之处带入Papa John's团队吧!
职位概述
信息安全部副总裁负责制定并执行组织的企业信息安全和网络安全战略。这位领导者将保护组织的人员、数据、应用程序、技术和数字生态系统免受不断演变的网络威胁,同时使业务能够安全高效地运行。
该职位在网络安全防御、安全运营、身份与访问管理、漏洞管理、安全架构、事件响应、威胁情报、安全治理和第三方风险等方面提供战略领导。
该职位与技术领导、业务高管、风险、法律、合规和审计团队紧密合作,建立有效的基于风险的安全计划。
主要职责
网络安全战略
- 制定并执行多年的企业网络安全战略和路线图。
- 根据业务风险和威胁环境确定安全优先级。
- 制定网络安全政策、标准、控制措施和操作流程。
- 向高管层提供清晰的网络风险和安全状况视图。
安全运营与网络安全防御
- 领导企业安全运营和网络安全防御能力。
- 监督SOC、SIEM、EDR/XDR、MDR/MSSP、安全监控和威胁检测。
- 提高检测、调查和响应能力。
- 推动安全自动化和编排以提高运营效率。
事件响应与网络安全韧性
- 建立并维护企业网络安全事件响应计划。
- 领导重大网络安全事件的响应。
- 制定和维护勒索软件、钓鱼攻击、凭证泄露、数据泄露、DDoS等事件的预案。
- 定期进行桌面演练和网络模拟。
- 与业务连续性和灾难恢复团队合作,加强网络安全韧性。
身份与访问安全
- 建立强有力的身份与访问安全实践。
- 与IAM团队合作,实施多因素认证(MFA)、特权访问管理(PAM)、单点登录(SSO)、零信任(Zero Trust)和最小权限访问。
- 保护员工、特权用户、第三方和应用的身份。
- 降低基于身份的网络安全风险。
漏洞与威胁管理
- 领导企业漏洞和暴露面管理。
查看英文原文
What’s Unique About You Is What Makes Us Better! Diversity is our strength and competitive advantage. Bring your flavor to the Papa John's team today!
Job Summary
The VP, Information Security & Cybersecurity is responsible for developing and executing the organization's enterprise information security and cybersecurity strategy. This leader will protect the organization's people, data, applications, technology, and digital ecosystem from evolving cyber threats while enabling the business to operate securely and efficiently.
The role provides strategic leadership across cyber defense, security operations, identity and access management, vulnerability management, security architecture, incident response, threat intelligence, security governance, and third-party risk.
This role partners closely with the technology leadership, business executives, risk, legal, compliance, and audit teams to establish an effective, risk-based security program.
Key Responsibilities
Cybersecurity Strategy
- Develop and execute a multi-year enterprise cybersecurity strategy and roadmap.
- Establish security priorities based on business risk and threat landscape.
- Define cybersecurity policies, standards, controls, and operating procedures.
- Provide executive leadership with clear visibility into cyber risk and security posture.
Security Operations & Cyber Defense
- Lead enterprise security operations and cyber defense capabilities.
- Oversee SOC, SIEM, EDR/XDR, MDR/MSSP, security monitoring, and threat detection.
- Improve detection, investigation, and response capabilities.
- Drive security automation and orchestration to improve operational effectiveness.
Incident Response & Cyber Resilience
- Establish and maintain the enterprise cyber incident response program.
- Lead response to significant cybersecurity incidents.
- Develop and maintain ransomware, phishing, credential compromise, data breach, DDoS, and other incident playbooks.
- Conduct regular tabletop exercises and cyber simulations.
- Partner with business continuity and disaster recovery teams to strengthen cyber resilience.
Identity & Access Security
- Establish strong identity and access security practices.
- Partner with IAM teams on MFA, PAM, SSO, Zero Trust, and least-privilege access.
- Protect workforce, privileged, third-party, and application identities.
- Reduce identity-based cyber risk.
Vulnerability & Threat Management
- Lead enterprise vulnerability and exposure management.
- Establish risk-based vulnerability prioritization and remediation.
- Develop threat intelligence capabilities to identify emerging threats.
- Ensure critical vulnerabilities and exposures receive appropriate executive visibility.
Security Architecture
- Establish enterprise information security architecture and security-by-design principles.
- Partner with technology and architecture teams to embed security into new products, applications, cloud platforms, and digital experiences.
- Evaluate emerging cybersecurity technologies and capabilities, including AI-driven security.
Application, Data & Digital Security
- Establish security requirements for applications, APIs, data, and customer-facing digital platforms.
- Partner with application development teams on secure SDLC and application security.
- Protect sensitive corporate and customer information.
- Strengthen controls around data protection, encryption, and privacy.
Third-Party & Supply Chain Security
- Establish cybersecurity requirements for critical vendors and technology partners.
- Assess and manage third-party cyber risk.
- Partner with Procurement, Legal, and Risk to ensure appropriate security controls are incorporated into contracts.
Governance, Risk & Compliance
- Partner with Risk, Compliance, Internal Audit, and Legal.
- Maintain cybersecurity control frameworks and policies.
- Lead remediation of security assessments and audit findings.
- Support applicable regulatory, privacy, PCI, and compliance requirements.
Leadership & Financial Management
- Lead, develop, and retain a high-performing information security organization.
- Establish clear accountability, KPIs, and operating rhythms.
- Manage cybersecurity operating and capital budgets.
- Lead strategic cybersecurity vendors and managed security providers.
- Build strong partnerships across technology and business organizations.
- Communicate complex cybersecurity risks in clear business and financial terms.
Qualifications
- 10–15+ years of progressive experience in information security or cybersecurity.
- 5+ years of leadership experience managing cybersecurity teams.
- Experience leading enterprise cybersecurity transformation.
- Strong understanding of security operations, IAM, cloud security, application security, vulnerability management, incident response, and cyber risk.
- Experience managing significant budgets and strategic vendors.
- Strong executive communication and influencing skills.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field preferred.
- CISSP, CISM, CRISC, or equivalent certification preferred.
Our Values
- EVERYONE BELONGS - We believe connectedness and belonging are the essential ingredients to our success
- DO THE RIGHT THING - We are relentlessly focused on quality and integrity and make the right choices, even when it's difficult
- PEOPLE FIRST - To craft positive experiences for our customers, we take care of each other first
- INNOVATE TO WIN - We champion and challenge for a better way in all we do
- HAVE FUN - We find joy, create meaningful impact and celebrate the journey together
Our Core Competencies
- CUSTOMER CENTRIC - We leverage data and insights to craft a customer experience that builds relationships, cultivates trust, and delivers excellence
- RESULTS DRIVEN – We focus on measurable outcomes by remaining optimistic, tenacious, and persistent even in the face of challenges
- CONTINUOUS IMPROVEMENT - We champion for better through strategic risk taking, experimentation and challenging the status quo
- BIAS FOR ACTION - We courageously lead, drive towards decisions, and maintain agility to meet the demands of our dynamic industry
- WINNING TOGETHER - We work together to unlock our full potential by actively collaborating and contributing in a cross-functional capacity
Papa Johns is an equal opportunity employer.
Papa Johns is a federal contractor that participates in the E-Verify program to confirm employment eligibility for each new team member. We also comply with all Right to Work requirements. Official E-Verify and Right to Work notices are available for applicants to review in both English and Spanish.
Everybody loves pizza, which means they also love the people who are behind the scenes working to deliver it. This is complex and challenging work – but let’s face it – it’s also pizza! If you want a fulfilling career with a company that’s always moving forward, we’re the right place.
Papa John's is a Federal Contract employer who participates in E-Verify to confirm employment eligibility for each new team member. For more information please view the following PDFs: E-Verify Poster (English) - Right to Work Poster (English) - E-Verify Poster (Spanish) - Right to Work Poster (Spanish) Papa John's is an Affirmative Action and Equal Opportunity Employer. For more information please click on the following PDF. See terms & conditions for site use.
Originally posted on Himalayas