Director of Third-Party Cyber Risk & Governance

Advance Auto Business Support (300)

Raleigh (NC)

Hybrid

USD 180,000 - 230,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Advance Auto Parts, Inc. seeks a Sr. Manager of Cybersecurity Third-Party Risk Management to lead the enterprise program for identifying, assessing, monitoring, and reducing third-party cybersecurity risks across suppliers, vendors, and service providers.

The role emphasizes due diligence before onboarding, renewal, or material changes, with executive visibility into risk exposure and program maturity. The ideal candidate will bring 8+ years in cybersecurity and vendor risk management, strong

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field, or equivalent experience.
  • 8+ years of experience in cybersecurity, third-party risk management, vendor risk management, technology risk, IT audit, governance/risk/compliance, or related disciplines.
  • 3+ years of leadership experience managing people, programs, or cross-functional risk initiatives.
  • Demonstrated experience operating cybersecurity risk management processes in a large enterprise, publicly traded, highly regulated, or Fortune 500 environment.
  • Strong understanding of cybersecurity control domains, including identity, cloud, network, endpoint, application security, data protection, vulnerability management, logging/monitoring, incident response, and resilience.
  • Experience reviewing vendor security evidence, including SOC 2, ISO 27001, SIG/CAIQ, penetration test summaries, vulnerability reports, audit reports, and remediation plans.
  • Experience partnering with Procurement and Legal on cybersecurity terms and vendor contract negotiations.
  • Ability to communicate cyber risk clearly to technical teams, business stakeholders, executives, legal partners, auditors, and risk committees.
  • Strong judgment, prioritization, program management, issue management, and stakeholder influence skills.

Responsibilities

  • Lead the enterprise Cybersecurity Third-Party Risk Management program, including strategy, operating model, governance, policies, standards, procedures, assessment methodology, and reporting.
  • Oversee cybersecurity risk assessments for new and existing vendors.
  • Review and advise on contractual clauses related to security controls, breach notification, incident cooperation, right to audit, data protection, encryption, access control, regulatory compliance, cyber insurance, subcontractors, business continuity, data retention, and secure data destruction.
  • Operate ongoing monitoring for high-risk and critical vendors, including security ratings, public breach intelligence, certification expiration, control failures, vulnerability exposure, service disruptions, and material business changes.
  • Assess cybersecurity risks associated with subcontractors, subprocessors, hosting providers, offshore delivery models, managed service delivery chains, and other fourth-party dependencies.
  • Develop executive-level metrics, dashboards, and risk narratives showing third-party cyber risk posture, critical vendor coverage, assessment volume, remediation aging, risk acceptance trends, contractual coverage, and program maturity.
  • Translate technical findings into business risk language that enables informed decisions by senior leaders and business owners.
  • Prepare materials for audit, regulatory inquiries, board reporting, and internal governance reviews as needed.

Job description

Advance Auto Parts, Inc. seeks a Sr. Manager of Cybersecurity Third-Party Risk Management to lead the enterprise program for identifying, assessing, monitoring, and reducing third-party cybersecurity risks across suppliers, vendors, and service providers.

The role emphasizes due diligence before onboarding, renewal, or material changes, with executive visibility into risk exposure and program maturity. The ideal candidate will bring 8+ years in cybersecurity and vendor risk management, strong

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Hybrid Director of Cyber Risk & Governance
Hybrid Director of Cyber Risk & Governance

Advance Stores Company Inc (500) • Raleigh (NC)

Hybrid
USD 180,000 - 260,000
Sr. Manager of Cybersecurity, Third Party Risk
Sr. Manager of Cybersecurity, Third Party Risk

Advance Auto Business Support (300) • Raleigh (NC)

Hybrid
USD 180,000 - 230,000
Director Governance Risk and Compliance
Director Governance Risk and Compliance

Advance Stores Company Inc (500) • Raleigh (NC)

Hybrid
USD 180,000 - 260,000
Security Operations Director: Threat Response & IAM
Security Operations Director: Threat Response & IAM

Advance Auto Business Support (300) • Raleigh (NC)

Hybrid
USD 170,000 - 230,000
Third Party Cyber Risk Analyst
Third Party Cyber Risk Analyst

Selby Jennings • New York (NY)

On-site
USD 90,000 - 140,000
Security Risk Lead, Third-Party Automation
Security Risk Lead, Third-Party Automation

Affirm • San Diego (CA)

Hybrid
USD 165,000 - 225,000
Health care coverage
Flexible Spending Wallets
Time off
+1
VP, Third-Party Risk & Governance
VP, Third-Party Risk & Governance

GM Financial • Salt Lake City (UT)

Hybrid
USD 180,000 - 280,000
401K matching
Paid parental leave
Employee discount
+3
Security Risk Lead, Third-Party Automation
Security Risk Lead, Third-Party Automation

Affirm • Richmond (VA)

On-site
USD 146,000 - 206,000
Health care coverage
Flexible Spending Wallets
Time off
+1
Head of Security Operations & Incident Response
Head of Security Operations & Incident Response

Advance-Auto-Parts • Raleigh (NC)

Hybrid
USD 180,000 - 230,000
Director, Third-Party IT Risk & Automation
Director, Third-Party IT Risk & Automation

Wolters Kluwer • Riverwoods (IL)

On-site
USD 118,300 - 207,400
Medical, Dental, & Vision Plans
401(k)
FSA/HSA
+2