Director Governance Risk and Compliance

Advance Stores Company Inc (500)

Raleigh (NC)

Hybrid

USD 180,000 - 260,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Advance Auto Parts seeks a Director of Governance and Risk to define and deploy governance and risk management frameworks across the company. The role reports to the CISO and will oversee policy, standards, and regulatory compliance while guiding risk discussions with the Board and ERM.

The incumbent will lead a cyber risk team, drive risk assessments including PCI-DSS/SOX, and oversee VRM and metrics programs.

Qualifications

  • Bachelor’s degree in information security, Computer Science, or a related field.
  • Minimum of 12 years of experience in cybersecurity, with a focus on risk management.
  • Expert in the implementation and operational management of OneTrust, working knowledge of Service Now, and Auditboard.
  • Process driven with knowledge of cyber risk management frameworks, tools, and methodologies
  • Ability to tell a story through PowerPoint leveraging metrics for the Enterprise level (Board, ERM)
  • Proven experience in senior leadership roles, managing teams, and influencing executives
  • Experience establishing and managing regulatory compliance in NIST, PCI-DSS, SOX, SOC 1/2, CCPA, HIPAA
  • Deep understanding in cybersecurity metrics programs that are meaningful and risk/risk posture reporting
  • Strategic thinker with strong understanding of cyber risks and mitigation options
  • Exceptional communication and executive level presentation skills

Responsibilities

  • Develop a short and long term Governance and Risk Management Strategy.
  • Create and implement enterprise security policy, standards, procedures, and guidelines.
  • Provide strategic guidance to the CISO for risk representation to Board and ERM.
  • Lead a cyber team and support their development.
  • Conduct risk assessments including PCI-DSS and SOX; develop risk management plans.
  • Support Internal Audit with technology-focused engagements.
  • Oversee Vendor Risk Management and third-party monitoring.
  • Identify, evaluate, and prioritize cyber risks across the organization.
  • Oversee cyber risk metrics, KPIs, KRIs, and reporting.
  • Drive automation, analytics, and continuous process improvements.
  • Engage senior stakeholders across Lines of Defense for oversight.
  • Collaborate with cross-functional teams on risk remediation.
  • Ensure regulatory compliance with NIST, PCI-DSS, SOX, SOC 1/2, CCPA, HIPAA
  • Maintain security policy compliance reporting platform.

Skills

Cybersecurity leadership
Risk management
Executive stakeholder mgmt
PowerPoint storytelling
Security metrics
Regulatory compliance
Team leadership
Communication skills

Education

Bachelor’s degree in information security/CS
Master’s degree preferred

Tools

OneTrust
ServiceNow
Auditboard

Job description

Job Description The Director of Governance and Risk will report to the CISO within Advance Auto Parts and will focus on the defining and deploying governance and risk management frameworks across Advance Auto Parts.

The Director of Governance and Risk will oversee cybersecurity policy, standards, procedures, compliance, ensuring the company adheres to relevant regulations, industry standards, and internal and 3rd party risk management.

The ideal candidate will combine expertise in both cybersecurity and risk management disciplines and have exceptional communication and stakeholder management skills.

This position is 4 days in office, 1 day remote per week, based at our corporate headquarters in Raleigh, North Carolina (North Hills)

The key responsibilities of the role include:
  • Develop a short term and long-term comprehensive Governance and Risk Management Strategy
  • Develop, communicate, and implement enterprise-wide security policy, standards, procedures, and guidelines.
  • Provide strategic guidance to the CISO for the representation of risks to the Board, Audit committee, and ERM
  • Lead a team of cyber specialists, providing direction and supporting their development
  • Conduct regular risk assessments, including PCI-DSS and SOX, and develop comprehensive risk management plans for various business units and projects
  • Support Internal Audit with engagements requiring technology support.
  • Vendor Risk Management (VRM): Oversee the VRM integration, including risk reviews, contract management, and ongoing monitoring to manage risks associated with third-party vendors and suppliers
  • Support the identification, evaluation, and prioritization of cyber risks across the organization
  • Oversee production, reporting and evolution of cyber risk metrics, including Key Performance Indicators (KPIs), scorecards, and Key Risk Indicators (KRIs)
  • Conduct risk analysis, providing insights on issues and direction on risk mitigation strategies
  • Drive automation, analytics, and continuous improvement of processes
  • Engage with a range of senior stakeholders across Lines of Defense to ensure appropriate oversight and reporting of cybersecurity risks and vulnerabilities
  • Collaborate with cross-functional teams on cyber risk remediation activities
  • Ensure regulatory compliance with frameworks in NIST, SOC 1/2, PCI, SOX, CCPA
  • Maintain the database and reporting platform to ensure compliance to our security policies and standards.
Skills/ Qualifications:
  • Bachelor’s degree in information security, Computer Science, or a related field; Master’s degree preferred
  • Minimum of 12 years of experience in cybersecurity, with a focus on risk management
  • Expert in the implementation and operational management of OneTrust, working knowledge of Service Now, and Auditboard.
  • Process driven with an extensive knowledge of cyber risk management frameworks, tools, and methodologies
  • Master in the ability to “tell a story” through PowerPoint leveraging metrics and creativity for various levels of the enterprise (Board, ERM, Steerco, Business and/or tech leaders)
  • Proven experience in senior leadership roles, managing teams, and influencing executive stakeholders, driving outcomes
  • Experience in establishing and managing regulatory compliance in NIST, PCI-DSS, SOX, SOC 1/2, CCPA, HIPAA
  • Deep understanding in cybersecurity metrics programs that are meaningful and risk/risk posture reporting
  • Strategic thinker with a strong understanding of cyber risks, vulnerabilities, and risk mitigation options
  • Innovative thinker, adaptable to change, self-driven, aggressive, and detail oriented with the ability to establish true partnerships that drives business enablement while managing risk
  • Exceptional communication and executive level presentation skills, capable of translating technical risk into business terms
  • Must have the ability to drive enterprise aligned roadmaps focusing on top cyber risks, cyber priorities, industry threats that align to the business
  • Excellent analytical, problem-solving, and decision-making skills

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age national origin, religion, sexual orientation, gender identity, status as a veteran and basis of disability or any other federal, state or local protected class. We comply with all applicable federal, state, and local laws.

Advance Auto Parts, Inc. is a leading automotive aftermarket parts provider that serves both professional installers and do-it-yourself customers. As of October 5, 2024, Advance operated 4,781 stores primarily within the United States, with additional locations in Canada, Puerto Rico and the U.S. Virgin Islands. The company also served 1,125 independently owned Carquest branded stores across these locations in addition to Mexico and various Caribbean islands. Additional information about Advance, including employment opportunities, customer services and online shopping for parts, accessories and other offerings can be found at www.AdvanceAutoParts.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Manager of Cybersecurity, Third Party Risk
Sr. Manager of Cybersecurity, Third Party Risk

Advance Auto Business Support (300) • Raleigh (NC)

Hybrid
USD 180,000 - 230,000
Director of Security Operations
Director of Security Operations

Advance Auto Business Support (300) • Raleigh (NC)

Hybrid
USD 170,000 - 230,000
Sr. Manager of Security Operations, Incident Response
Sr. Manager of Security Operations, Incident Response

Advance Auto Business Support (300) • Raleigh (NC)

Hybrid
USD 170,000 - 250,000
Hybrid work model
Principal Security Architect
Principal Security Architect

Advance Auto Business Support (300) • Raleigh (NC)

Hybrid
USD 150,000 - 190,000
Director of Security Operations
Director of Security Operations

Advance-Auto-Parts • Raleigh (NC)

On-site
USD 170,000 - 210,000
Hybrid Director of Cyber Risk & Governance
Hybrid Director of Cyber Risk & Governance

Advance Stores Company Inc (500) • Raleigh (NC)

Hybrid
USD 180,000 - 260,000
Sr. Manager of Security Operations, Incident Response
Sr. Manager of Security Operations, Incident Response

Advance-Auto-Parts • Raleigh (NC)

On-site
USD 180,000 - 230,000
Director, Employee Relations
Director, Employee Relations

Advance Auto Parts • Raleigh (NC)

Hybrid
USD 140,000 - 200,000
Facilities Director
Facilities Director

Advance Stores Company Inc (500) • Raleigh (NC)

Hybrid
USD 180,000 - 240,000
Health & wellness benefits
Senior Corporate Strategy Manager
Senior Corporate Strategy Manager

Advance Stores Company Inc (500) • Raleigh (NC)

Hybrid
USD 140,000 - 190,000
Health benefits
Hybrid work
Executive exposure