Advance Stores - Raleigh, NC

posted 3 months ago

Full-time - Senior
Raleigh, NC
10,001+ employees
Motor Vehicle and Parts Dealers

About the position

The Vice President and Chief Information Security Officer (CISO) at Advance Auto Parts will be tasked with developing and implementing a comprehensive information security strategy aimed at safeguarding the company's digital assets, customer information, and IT infrastructure. This executive role is pivotal in overseeing all aspects of information security, which includes risk management, compliance, incident response, and cybersecurity operations. The CISO will work closely with senior leadership to ensure that security initiatives are aligned with business goals, thereby providing the highest level of protection against cyber threats. This position is part of a hybrid work arrangement based in Raleigh, NC, and reports directly to the EVP and Chief Technology Officer. In terms of leadership and strategy, the CISO will be responsible for developing and executing an enterprise-wide information security strategy that aligns with the business objectives of Advance Auto Parts. This includes providing strategic direction to the information security program and leading a high-performing information security team. Risk management is another critical area of focus, where the CISO will identify, assess, and prioritize security risks while developing appropriate mitigation plans. Establishing and enforcing security policies, standards, and guidelines, as well as conducting regular security risk assessments and audits, will also fall under this role's purview. Compliance and governance are essential components of the CISO's responsibilities, ensuring adherence to relevant laws, regulations, and industry standards such as PCI-DSS and GDPR. The CISO will oversee the development and implementation of security policies and procedures and collaborate with internal and external auditors to address compliance issues. In the event of security incidents, the CISO will lead the response efforts, including forensic analysis and root cause determination, while also overseeing disaster recovery and business continuity planning. Cybersecurity operations will involve the implementation and management of security technologies, monitoring and analyzing security threats and vulnerabilities, and managing security operations center (SOC) activities. Collaboration and communication are key aspects of this role, as the CISO will work with IT, legal, and other departments to ensure a cohesive approach to information security. Additionally, the CISO will communicate security-related topics to executive leadership and the board of directors, fostering a culture of security awareness across the organization.

Responsibilities

  • Develop and execute an enterprise-wide information security strategy.
  • Provide strategic direction to the information security program to ensure alignment with business objectives.
  • Lead and mentor a high-performing information security team.
  • Identify, assess, and prioritize security risks and develop mitigation plans.
  • Establish and enforce security policies, standards, and guidelines.
  • Conduct regular security risk assessments and audits.
  • Ensure compliance with relevant laws, regulations, and industry standards (e.g., PCI-DSS, GDPR).
  • Oversee the development and implementation of security policies and procedures.
  • Collaborate with internal and external auditors to address compliance issues.
  • Develop and maintain an incident response plan.
  • Lead the response to security incidents, including forensic analysis and root cause determination.
  • Oversee disaster recovery and business continuity planning.
  • Oversee the implementation and management of security technologies (e.g., firewalls, intrusion detection systems).
  • Monitor and analyze security threats and vulnerabilities.
  • Manage security operations center (SOC) activities.
  • Collaborate with IT, legal, and other departments to ensure a cohesive approach to information security.
  • Communicate security-related topics to executive leadership and the board of directors.
  • Foster a culture of security awareness across the organization.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Master's degree preferred.
  • Minimum of 10 years of experience in information security, with at least 5 years in a senior leadership role.
  • Proven experience in developing and implementing information security strategies.
  • Strong understanding of current and emerging cybersecurity threats and technologies.
  • Excellent leadership, communication, and interpersonal skills.
  • Relevant certifications.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service