VP, Information Security at Graphic Packaging International
At Graphic Packaging International, we produce the paper cup that held your coffee this morning, the basket that transported those bottles of craft beer you enjoyed last weekend, and the microwave tray that heated your gourmet meal last night. We’re one of the largest manufacturers of paperboard and paper-based packaging for some of the world’s most recognized brands of food, beverage, foodservice, household, personal care and pet products. Headquartered in Atlanta, Georgia, we are collaborative, diverse, innovative individuals who create inspired packaging while giving back to our communities.
With over 25,000 employees working in more than 130 locations worldwide, we strive to be environmentally responsible in our industry and in the communities where we operate. We are committed to workplace diversity and offer compensation and benefits programs that are among the industry’s best to reward the talented people who make our company successful.
If this sounds like something you would like to be a part of, we’d love to hear from you.
A World of Difference. Made Possible.
Job Summary
Reporting to the SVP & Chief Information Officer (CIO), the Vice President, Cybersecurity & Chief Information Security Officer (CISO) will lead Graphic Packaging’s global cybersecurity, technology risk, and operational resilience agenda. As the company’s senior cybersecurity executive, the CISO will protect enterprise information, digital products, cloud platforms, manufacturing operations, operational technology (OT), connected devices, and the extended third-party ecosystem while enabling innovation, growth, and reliable operations.
The CISO will advise executive leadership and the Board on cyber risk, define risk appetite and tolerance with business leaders, and translate technical exposure into business, financial, safety, operational, legal, and reputational impact. This leader will establish an integrated, risk-based program aligned to recognized frameworks and evolving regulatory requirements; strengthen cyber resilience across IT and OT; govern the secure adoption of artificial intelligence, including generative and agentic AI; and embed security, privacy, and resilience by design across technology, procurement, product development, and business transformation.
Essential Duties & Responsibilities
Enterprise Cybersecurity Strategy, Governance, and Leadership
- Define and execute a multi-year global cybersecurity and resilience strategy aligned with business priorities, enterprise risk appetite, technology modernization, and recognized frameworks such as NIST Cybersecurity Framework 2.0 and ISO/IEC 27001.
- Own cybersecurity governance, policies, standards, control architecture, exceptions, and assurance across corporate IT, cloud, software, data, OT, industrial control systems, IoT, and digital products.
- Provide clear, decision-oriented reporting to the CIO, executive leadership, Audit Committee, and Board, including quantified risk, material exposures, investment trade-offs, control effectiveness, incident readiness, and remediation progress.
- Lead, develop, and retain a high-performing global cybersecurity organization and establish clear accountability across a federated network of business, IT, engineering, legal, privacy, compliance, internal audit, physical security, and operational stakeholders.
Cyber Risk, Resilience, And Incident Management
- Establish an enterprise cyber risk management program that continuously identifies, quantifies, prioritizes, treats, accepts, and reports risk in business and financial terms.
- Lead continuous threat, attack-surface, exposure, and vulnerability management using intelligence, adversary-informed testing, secure configuration, and risk-based remediation across IT and OT environments.
- Maintain and exercise enterprise incident response, crisis management, cyber recovery, ransomware, data breach, and business continuity playbooks, including executive and Board simulations and coordination with legal counsel, insurers, law enforcement, regulators, customers, and key suppliers.
- Define minimum viable operations, recovery priorities, immutable backup and restoration requirements, and measurable recovery objectives; regularly validate the organization’s ability to restore trusted operations following destructive cyber events.
- Oversee security operations, detection engineering, threat intelligence, digital forensics, incident response, and managed security partners, with automation and AI used responsibly to improve speed, coverage, and analyst effectiveness.
- Set and report key risk, performance, resilience, and control indicators that demonstrate business outcomes, security return on investment, trends, and accountability.
AI, Data, Identity, Cloud, And Secure Technology Enablement
- Co-lead enterprise AI security and risk governance for predictive, generative, and agentic AI, including model and use-case inventory, data protection, human oversight, red-teaming, prompt and model attack defenses, secure AI development, third-party model risk, shadow AI monitoring, and lifecycle assurance.
- Extend identity governance to employees, privileged users, contractors, service accounts, workloads, machines, and AI agents through phishing-resistant authentication, least privilege, just-in-time access, continuous authorization, and strong secrets management.
- Embed secure-by-design and privacy-by-design practices into cloud architecture, applications, APIs, data platforms, DevSecOps, software acquisition, and digital products.
- Partner with enterprise architecture and technology leaders to advance Zero Trust principles, data security, encryption, key management, data loss prevention, cloud security posture, and secure configuration across hybrid and multi-cloud environments.
Essential Duties (Continued)
OT, Product, Third-Party, and Supply Chain Security
- Own the cyber risk strategy for manufacturing sites, OT, industrial control systems, IoT, engineering environments, and cyber-physical operations, balancing safety, availability, quality, and production requirements.
- Establish asset visibility, segmentation, secure remote access, monitoring, vulnerability management, engineering change controls, incident response, and recovery requirements for OT environments, in partnership with plant and engineering leadership.
- Strengthen third-party and fourth-party risk management across suppliers, software, cloud, managed services, logistics, and connected products through tiering, due diligence, contractual controls, continuous monitoring, concentration-risk analysis, and tested exit and recovery plans.
- Set secure procurement and software supply-chain requirements, including secure development evidence, support and patch commitments, vulnerability disclosure, component transparency, and security-by-default expectations.
Regulatory Compliance, Assurance, And Executive Accountability
- Maintain a global cyber regulatory and contractual obligations framework covering applicable privacy, securities, critical-infrastructure, product-security, and breach-notification requirements, including SOX, GDPR, NIS2, and the EU Cyber Resilience Act where applicable.
- Partner with Legal, Privacy, Compliance, Finance, Internal Audit, and Disclosure Committees to support timely escalation, materiality assessment, regulatory reporting, customer notification, litigation readiness, and defensible evidence.
- Oversee independent assessments, penetration testing, red and purple teaming, control testing, audits, certifications, and remediation governance; ensure systemic issues and overdue risks are transparently escalated.
- Develop the enterprise’s cryptographic inventory and risk-based transition roadmap for post-quantum readiness, prioritizing long-lived sensitive data, critical trust services, and high-impact systems.
- Manage the global cybersecurity operating and capital budgets, workforce, sourcing strategy, cyber insurance support, and partner portfolio; prioritize investments using risk reduction, resilience, business value, and total cost of ownership.
- Build a measurable security culture through role-based education, executive and Board engagement, phishing-resistant practices, insider-risk coordination, and positive reinforcement of secure behaviors.
- Drive simplification, automation, platform rationalization, skills development, succession planning, and continuous improvement across the cybersecurity program.
- This position will be located at the company’s headquarters in Sandy Springs, Georgia.
Candidate Profile
The successful candidate will bring the following experience and expertise:
- Bachelor’s degree in cybersecurity, information technology, engineering, computer science, risk management, or a related discipline; advanced degree preferred.
- At least 15 years of progressive cybersecurity, technology risk, or related leadership experience, including significant tenure leading a complex global enterprise security function; public-company and manufacturing experience strongly preferred.
- Demonstrated experience securing OT, industrial control systems, manufacturing assets, IoT, and cyber-physical environments without compromising safety or operational continuity.
- Proven ability to build and transform enterprise cybersecurity programs across strategy, governance, security operations, incident response, identity, cloud, applications, data, third parties, resilience, and regulatory compliance.
- Practical experience governing AI risk and securing generative and agentic AI, including data flows, models, agents, non-human identities, AI-enabled software development, and AI-supported security operations.
- Deep knowledge of relevant frameworks and practices, Zero Trust, secure software development, and business continuity and disaster recovery.
- Strong understanding of applicable global requirements such as SOX, GDPR, SEC cybersecurity disclosure expectations, NIS2, the EU Cyber Resilience Act, and other sector- or geography-specific obligations.
- Demonstrated success quantifying cyber risk, presenting to executive leadership and Boards, leading through major incidents, influencing without direct authority, and making balanced decisions in ambiguous, high-pressure environments.
- Recognized cybersecurity or risk certifications such as CISSP, CISM, CRISC, or equivalent are preferred.
Disclaimer
The candidate must be able to perform the essential functions of the position satisfactorily, with or without a reasonable accommodation. Graphic Packaging retains the right to change or assign other duties to this position.
Competencies
The successful candidate will bring the following experience and expertise:
- Bachelor’s degree in cybersecurity, information technology, engineering, computer science, risk management, or a related discipline; advanced degree preferred.
- At least 15 years of progressive cybersecurity, technology risk, or related leadership experience, including significant tenure leading a complex global enterprise security function; public-company and manufacturing experience strongly preferred.
- Demonstrated experience securing OT, industrial control systems, manufacturing assets, IoT, and cyber-physical environments without compromising safety or operational continuity.
- Proven ability to build and transform enterprise cybersecurity programs across strategy, governance, security operations, incident response, identity, cloud, applications, data, third parties, resilience, and regulatory compliance.
- Practical experience governing AI risk and securing generative and agentic AI, including data flows, models, agents, non-human identities, AI-enabled software development, and AI-supported security operations.
- Deep knowledge of relevant frameworks and practices, Zero Trust, secure software development, and business continuity and disaster recovery.
- Strong understanding of applicable global requirements such as SOX, GDPR, SEC cybersecurity disclosure expectations, NIS2, the EU Cyber Resilience Act, and other sector- or geography-specific obligations.
- Demonstrated success quantifying cyber risk, presenting to executive leadership and Boards, leading through major incidents, influencing without direct authority, and making balanced decisions in ambiguous, high-pressure environments.
- Recognized cybersecurity or risk certifications such as CISSP, CISM, CRISC, or equivalent are preferred.
Pay Range
$264,100.00 - $352,100.00
Pay Range: $264,100.00 - $352,100.00
GPI’s Benefit Program
- Competitive Pay
- 401(k) w/employer matching
- Health & Welfare Benefits
- Medical, dental, vision, and prescription drug coverage
- Short and Long-Term Disability
- Life Insurance
- Accidental Death & Dismemberment (AD&D) Insurance
- Flexible Spending and Health Savings Accounts
- Various Voluntary benefits
- Adoption Assistance Program
- Employee Discount Programs
- Employee Assistance Program
- Tuition Assistance Program
- Paid Time Off + paid company holidays each year
Applicants will be accepted on an ongoing basis and there is no deadline.
This role is incentive plan eligible. Additional information will be shared during the hiring process. Each candidate’s compensation offer will be based on multiple factors including, but not limited to, knowledge, skills, past experience, job duties, geography, and business need, among other things.
Graphic Packaging is an equal opportunity employer and abides by all applicable federal, state provincial and local laws with respect to the recruitment and hiring process. We are committed to an inclusive, barrier-free recruitment and hiring process free from discrimination or harassment based upon race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. Should you require an accommodation for a disability, please contact your Human Resources representative or email [email protected].
Requisition: 16061
Browse All Jobs in This State
Explore full job listings for the area:: Jobs in Atlanta | Jobs in Georgia
You May Also Be Interested In
Find other job listings similar to this one: