Full-Time

Senior Manager of Cybersecurity

Third Party Risk

Updated on 8/24/2026

Advance Auto Parts

Advance Auto Parts

10,001+ employees

Automotive aftermarket parts retailer

No salary listed

Raleigh, NC, USA

Hybrid

Four days on-site and one day working from home per week.

Bachelor's

Category
IT & Security (1)
Required Skills
Incident Response
Cybersecurity
Vulnerability Analysis
SOC 2
Cryptography
Coupa
Penetration Testing

Get referred to Advance Auto Parts

See people who can refer or advise you

Requirements
  • A bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field, or equivalent experience.
  • At least 8 years of experience in cybersecurity, third-party risk management, vendor risk management, technology risk, IT audit, governance, risk and compliance, or related disciplines.
  • At least 3 years of leadership experience managing people, programs, or cross-functional risk initiatives.
  • Demonstrated experience operating cybersecurity risk management processes in a large enterprise, publicly traded, highly regulated, or Fortune 500 environment.
  • Strong understanding of cybersecurity control domains, including identity, cloud, network, endpoint, application security, data protection, vulnerability management, logging and monitoring, incident response, and resilience.
  • Experience reviewing vendor security evidence, including SOC 2, ISO 27001, SIG/CAIQ, penetration test summaries, vulnerability reports, audit reports, and remediation plans.
  • Experience partnering with Procurement and Legal on cybersecurity terms and vendor contract negotiations.
  • Ability to communicate cyber risk clearly to technical teams, business stakeholders, executives, legal partners, auditors, and risk committees.
  • Strong judgment, prioritization, program management, issue management, and stakeholder influence skills.
Responsibilities
  • Lead the enterprise Cybersecurity Third-Party Risk Management program, including strategy, operating model, governance, policies, standards, procedures, assessment methodology, and reporting.
  • Develop and maintain risk-based third-party cybersecurity requirements aligned to NIST CSF 2.0, NIST 800-161, SOC 2, PCI DSS, privacy obligations, and enterprise security standards.
  • Define and maintain the third-party cyber risk lifecycle, including intake, inherent risk scoring, due diligence, control assessment, remediation, risk acceptance, ongoing monitoring, renewal review, material change review, and offboarding.
  • Establish governance forums and escalation paths for high-risk vendors, overdue remediation, policy exceptions, and material cyber risk decisions.
  • Continuously improve program maturity, automation, workflow efficiency, stakeholder experience, and audit readiness.
  • Oversee cybersecurity risk assessments for new and existing vendors.
  • Evaluate vendor controls across identity and access management, network security, cloud security, application security, data protection, encryption, vulnerability management, endpoint protection, logging and monitoring, incident response, disaster recovery, secure software development lifecycle, privacy, and governance.
  • Review vendor evidence such as SOC 2 Type II reports, ISO 27001 certificates, bridge letters, penetration test summaries, vulnerability scan results, SIG/CAIQ questionnaires, security policies, architecture diagrams, audit reports, and remediation plans.
  • Determine residual risk and provide recommendations for approval, conditional approval, remediation, escalation, risk acceptance, or vendor rejection.
  • Partner with Legal, Procurement, Privacy, Compliance, and business teams to ensure cybersecurity requirements are embedded in vendor contracts and statements of work.
  • Review and advise on contractual clauses related to security controls, breach notification, incident cooperation, right to audit, data protection, encryption, access control, regulatory compliance, cyber insurance, subcontractors, business continuity, data retention, and secure data destruction.
  • Track deviations from standard cybersecurity terms, document risk implications, and route exceptions for appropriate approval.
  • Operate ongoing monitoring for high-risk and critical vendors, including security ratings, public breach intelligence, certification expiration, control failures, vulnerability exposure, service disruptions, and material business changes.
  • Maintain a centralized view of open vendor cyber findings, remediation commitments, accepted risks, compensating controls, and exceptions.
  • Drive remediation of vendor control gaps from identification through validation and closure.
  • Escalate overdue or unacceptable vendor risks through cybersecurity governance, procurement governance, enterprise risk forums, or executive leadership as appropriate.
  • Partner with business owners to ensure vendor risk decisions are understood, documented, and aligned to enterprise risk appetite.
  • Assess cybersecurity risks associated with subcontractors, subprocessors, hosting providers, offshore delivery models, managed service delivery chains, and other fourth-party dependencies.
  • Identify concentration risk related to common technology platforms, critical suppliers, geographic dependencies, cloud service providers, and systemic service providers.
  • Require transparency into material subcontractors and downstream access to company data or systems.
  • Partner with business continuity, resilience, procurement, and enterprise risk teams to evaluate critical supplier resilience and recovery capabilities.
  • Develop executive-level metrics, dashboards, and risk narratives showing third-party cyber risk posture, critical vendor coverage, assessment volume, remediation aging, risk acceptance trends, contractual coverage, and program maturity.
  • Report third-party cyber risk trends to cybersecurity leadership, enterprise risk committees, audit stakeholders, and executive leadership.
  • Translate technical findings into business risk language that enables informed decisions by senior leaders and business owners.
  • Prepare materials for audit, regulatory inquiries, board reporting, and internal governance reviews as needed.
Desired Qualifications
  • Experience with ServiceNow GRC/IRM, Archer, OneTrust, ProcessUnity, Coupa, Ariba, Prevalent, BitSight, SecurityScorecard, UpGuard, or similar third-party risk platforms.
  • Knowledge of NIST CSF 2.0, NIST SP 800-161, ISO 27001, SOC 2 Trust Services Criteria, PCI DSS, SOX, GDPR/CCPA, and SEC cybersecurity disclosure expectations.
  • Professional certification such as CISSP, CISM, CRISC, CISA, CCSP, CCSK, CDPSE, ISO 27001 Lead Auditor/Implementer, or a third-party risk management certification.
  • Experience with critical suppliers, cloud service providers, managed service providers, offshore support models, payment processors, data processors, and operationally critical vendors.
  • Experience supporting board, audit committee, enterprise risk committee, or executive-level cybersecurity reporting.
  • Experience transforming or scaling a third-party cyber risk program across a complex supplier ecosystem.

Advance Auto Parts supplies automotive aftermarket parts and accessories to both professional installers and DIY customers through thousands of stores in North America. Its product lineup includes replacement parts, maintenance items, and car accessories for cars, vans, and light trucks, sold in-store and online with staff guidance to help customers select the right parts. The company differs from many competitors through its extensive store network, broad product assortment, and ability to serve both professional businesses and individual customers with knowledgeable service and a nationwide distribution and retail model. Its goal is to be the preferred source for auto parts by offering a wide selection, convenient locations, and expert customer assistance.

Company Size

10,001+

Company Stage

IPO

Headquarters

Raleigh, North Carolina

Founded

1932

Get referred to Advance Auto Parts

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 free cash flow reached $120 million year-to-date, reversing prior outflows.
  • Q2 2026 gross margin hit 46.2%, driven by merchandising gains.
  • Management reaffirmed August 20, 2026 guidance, including $2.60-$3.30 adjusted EPS.

What critics are saying

  • DIY sales fell sharply in Q2 2026, especially during the final four weeks.
  • The $26 million Q2 2026 tariff refund disappears in second-half results.
  • If holiday 2026 DIY demand weakens, positive free cash flow disappears again.

What makes Advance Auto Parts unique

  • Advance Auto Parts runs 38 market hubs, targeting 60 by mid-2027.
  • Its June 17, 2026 OneRail expansion strengthens same-day fulfillment across 4,000 locations.
  • The Pro channel outgrew DIY in Q2 2026, favoring installer demand.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Performance Bonus

Growth & Insights and Company News

Headcount

6 month growth

14%

1 year growth

14%

2 year growth

14%
Yahoo Finance
Aug 20th, 2026
Dow drops 703 points as Treasury yields surge past 4.7%, Walmart tumbles 9% on sales miss

Stocks fell Thursday as Treasury yields rebounded and retail earnings disappointed. The Dow Jones Industrial Average dropped 703 points, or 1.3%, to 52,759. The S&P 500 declined 0.9% to 7,641, whilst the Nasdaq Composite fell 1.0% to 26,067. Rising yields on the 10-year and 30-year Treasuries pressured equities after US debt crossed $40 trillion. Walmart led decliners, tumbling 9.2% despite beating earnings expectations. The retailer's same-store sales growth of 2.6% fell short of forecasts, and it issued soft third-quarter guidance. Advance Auto Parts plunged 24.6% after reporting revenue below analyst expectations, despite stronger-than-expected earnings per share.

Yahoo Finance
Aug 20th, 2026
Advance Auto Parts returns to positive free cash flow of $120M amid DIY spending slowdown

Advance Auto Parts reported positive free cash flow of $120 million year-to-date in Q2 2026, marking a significant turnaround supported by improved working capital management and tariff refunds. However, the company experienced a slight decline in comparable sales due to weaker-than-expected DIY spending during the quarter's final four weeks. The Pro channel met expectations, with Main Street business growth outpacing the segment by 200 basis points. Operational improvements included Net Promoter Scores rising to nearly 80 points and in-store attachment rates reaching 30%. The company completed its distribution centre consolidation, reducing from nearly 40 facilities to 15 locations. Management maintained full-year comparable sales guidance of 1% to 2% and reaffirmed a medium-term adjusted operating margin target of 7%. Advance Auto Parts plans to open 15 to 20 Market Hubs this year, reaching 60 locations by mid-2027.

Yahoo Finance
Aug 20th, 2026
Advance Auto Parts raises EPS guidance to $2.60–$3.30 despite DIY sales drop

Advance Auto Parts reported second-quarter sales of $2 billion, with comparable sales declining slightly. Low-single-digit growth in the professional channel was offset by a larger-than-expected low-double-digit drop in DIY sales as tighter household budgets weighed on consumer spending. Adjusted operating margin expanded to 5.6% and adjusted EPS rose to $1.03. The company benefited from product-margin gains and $26 million in tariff refunds. Free cash flow improved to $120 million year to date, whilst net-debt leverage fell to 2.1 times. The company reaffirmed its 2026 sales, margin and free-cash-flow outlook but raised adjusted EPS guidance to $2.60–$3.30, largely due to higher expected interest income.

Yahoo Finance
Aug 20th, 2026
Advance Auto Parts plunges 21% on $2B revenue miss despite $26M tariff refund boosting earnings

Advance Auto Parts shares plunged 21% to $44.33 after reporting second-quarter results that missed revenue expectations despite an earnings beat. The company posted adjusted earnings per share of $1.03, beating estimates of $0.81, but revenue of $2 billion fell short of the $2.04 billion forecast. Comparable sales declined 0.5%. The earnings beat included a one-time $26 million tariff refund worth $0.31 per share. Management noted the DIY channel weakened sharply in the quarter's final four weeks, whilst the Pro channel delivered low single-digit growth. The sell-off rippled through the auto parts sector. AutoZone fell 4% to $2,961, O'Reilly Automotive dropped 2% to $89.57, and Genuine Parts slipped 3% to $131.05, reflecting concerns about softening do-it-yourself demand across the industry.

Yahoo Finance
Aug 4th, 2026
Advance Auto Parts vs. Caterpillar: Which stock offers better value in 2026?

Advance Auto Parts and Caterpillar present contrasting investment profiles for 2026, balancing retail recovery against industrial stability. Advance Auto Parts operates in the automotive aftermarket, serving mechanics and DIY enthusiasts. The company recently expanded its AI-powered same-day delivery partnership with OneRail. FY 2025 revenue fell 5.4% year-over-year to $8.6 billion, with net income of $44 million and a 0.5% margin. The firm faces a 2.4x debt-to-equity ratio and negative $298 million free cash flow whilst implementing multi-year restructuring. Caterpillar serves construction, mining, and energy sectors through a global dealer network across nearly 190 countries. FY 2025 revenue grew 4.3% to $67.6 billion. Net income declined to $8.9 billion from $10.8 billion previously, yielding a 13.1% margin. The company is acquiring mining software providers to enhance digital services. Both face distinct macroeconomic pressures, making valuation critical for investment decisions.