Full-Time

Director Information Security

Cybersecurity Compliance

Updated on 9/12/2026

Advance Auto Parts

Advance Auto Parts

10,001+ employees

Automotive aftermarket parts retailer

No salary listed

Hyderabad, Telangana, India

In Person

Bachelor's

Category
Cybersecurity (1)
Required Skills
Incident Response
Cybersecurity
Workiva
Vulnerability Analysis
SOC 2
Risk Management
HIPAA

Get referred to Advance Auto Parts

See people who can refer or advise you

Requirements
  • A bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, Business, Accounting, Compliance, or a related field, or equivalent professional experience.
  • At least 15 years of experience in cybersecurity, technology risk, IT compliance, IT audit, governance, risk and compliance, regulatory compliance, control assurance, or related disciplines.
  • At least 5 years of leadership experience managing teams, programs, or enterprise-wide risk and compliance initiatives.
  • Experience leading cybersecurity compliance activities in a large enterprise, publicly traded, highly regulated, or Fortune 500 environment.
  • Strong knowledge of cybersecurity control frameworks, regulatory expectations, audit practices, and risk management principles.
  • Experience with NIST Cybersecurity Framework, NIST 800-53, SOC 2, SOX IT general controls, PCI DSS, privacy and security regulations, and common cybersecurity control requirements.
  • Experience leading audit readiness, evidence collection, control testing, issue remediation, risk acceptance, and executive reporting.
  • Ability to interpret regulatory and control requirements and translate them into practical cybersecurity processes and measurable control expectations.
  • Strong understanding of enterprise cybersecurity domains, including identity and access management, vulnerability management, cloud security, data protection, incident response, application security, endpoint security, network security, logging and monitoring, third-party risk, and business continuity.
  • Ability to communicate complex cybersecurity compliance matters clearly to technical teams, business leaders, auditors, legal partners, regulators, and executives.
  • Strong executive presence, judgment, prioritization, stakeholder influence, program management, and decision-making skills.
Responsibilities
  • Lead the enterprise cybersecurity compliance program, including strategy, roadmap, governance, operating model, procedures, control oversight, compliance monitoring, and reporting.
  • Define and maintain cybersecurity compliance requirements aligned with applicable laws, regulations, industry standards, contractual obligations, and internal cybersecurity policies.
  • Establish a risk-based approach for evaluating cybersecurity compliance across enterprise systems, business processes, applications, infrastructure, cloud environments, third parties, and critical technology services.
  • Drive maturity of cybersecurity compliance processes, including control mapping, evidence management, issue tracking, audit support, reporting, and remediation governance.
  • Serve as a senior cybersecurity compliance advisor to executive leadership and cross-functional stakeholders.
  • Ensure cybersecurity compliance activities align with enterprise cyber strategy, risk appetite, regulatory expectations, and business priorities.
  • Oversee alignment of cybersecurity controls and compliance activities to NIST Cybersecurity Framework 2.0, NIST SP 800-53, NIST SP 800-171 where applicable, SOC 2 Trust Services Criteria, PCI DSS, SOX IT general controls, HIPAA/HITECH where applicable, GLBA where applicable, GDPR, CCPA/CPRA, SEC cybersecurity disclosure expectations where applicable, and customer or contractual cybersecurity requirements.
  • Maintain a common control framework that rationalizes cybersecurity requirements across multiple regulatory and audit obligations.
  • Partner with control owners to ensure cybersecurity controls are clearly defined, assigned, documented, tested, and evidenced.
  • Identify control gaps, maturity opportunities, and overlapping requirements to improve efficiency and reduce compliance burden.
  • Ensure compliance expectations are embedded into security architecture, identity and access management, vulnerability management, cloud security, incident response, data protection, application security, third-party risk, and business continuity processes.
  • Lead cybersecurity compliance support for internal audits, external audits, regulatory examinations, customer assessments, SOX testing, PCI assessments, SOC reporting, and other assurance activities.
  • Coordinate audit planning, evidence collection, walkthroughs, control owner engagement, management responses, remediation commitments, and closure validation.
  • Establish repeatable evidence management processes to ensure timely, accurate, and complete responses to audit and compliance requests.
  • Review audit findings and control deficiencies to assess root cause, risk impact, compensating controls, and remediation approach.
  • Drive reduction of repeat findings through stronger control ownership, accountability, monitoring, and remediation governance.
  • Partner with Internal Audit, Enterprise Risk, Legal, Privacy, and Compliance to coordinate cybersecurity audit activities with enterprise risk priorities.
  • Own or support the development, maintenance, and enforcement of cybersecurity policies, standards, procedures, and control requirements.
  • Establish governance processes for policy exceptions, control deviations, compensating controls, and risk acceptances.
  • Track policy adherence and report non-compliance trends to appropriate governance forums.
  • Support executive and board-level reporting related to cybersecurity governance, compliance posture, audit readiness, and control maturity.
  • Establish and oversee a cybersecurity control monitoring and testing program to evaluate the effectiveness of key security controls.
  • Define control testing schedules, procedures, evidence requirements, sampling methods, control ownership, and quality standards.
  • Monitor compliance with cybersecurity controls across cloud, infrastructure, applications, identity platforms, endpoints, networks, data repositories, and third-party services.
  • Track cybersecurity compliance issues, audit findings, control gaps, policy exceptions, and remediation plans through closure.
  • Ensure remediation plans include clear ownership, milestones, due dates, risk prioritization, and validation criteria.
  • Escalate overdue, high-risk, or under-resourced remediation activities through appropriate governance channels.
  • Validate closure of cybersecurity findings and ensure evidence supports sustainable remediation.
  • Develop executive-level reporting on cybersecurity compliance posture, control effectiveness, audit findings, remediation status, regulatory obligations, policy exceptions, and program maturity.
  • Establish compliance metrics and key risk indicators covering audit findings, control testing, remediation aging, policy exceptions, compliance coverage, evidence-request cycle time, repeat findings, control-owner accountability, and regulatory readiness.
  • Translate detailed control and compliance issues into clear business-risk narratives for executive leadership.
  • Prepare materials for cybersecurity governance forums, enterprise risk committees, audit committees, executive leadership meetings, and board reporting as needed.
  • Provide data-driven insight into areas requiring investment, prioritization, process improvement, or executive intervention.
  • Monitor changes in cybersecurity-related laws, regulations, standards, and industry expectations.
  • Partner with Legal, Privacy, Compliance, and Enterprise Risk Management to interpret new or changing cybersecurity compliance obligations.
  • Assess the impact of regulatory changes on cybersecurity policies, controls, processes, reporting, and technology capabilities.
  • Develop implementation plans to address new requirements and ensure accountability across relevant control owners.
  • Maintain visibility into customer, contractual, and industry-specific cybersecurity obligations that may affect enterprise compliance expectations.
  • Support management responses to regulatory inquiries, customer due diligence requests, cyber insurance requirements, and external compliance attestations.
  • Build working relationships with cybersecurity domain leaders, IT, infrastructure, application teams, cloud teams, identity teams, Legal, Privacy, Compliance, Enterprise Risk, Internal Audit, Finance, Procurement, and business leaders.
  • Influence control owners and business stakeholders to prioritize cybersecurity compliance obligations and remediation commitments.
  • Serve as a trusted advisor on cybersecurity compliance implications for enterprise initiatives, technology modernization, cloud adoption, mergers and acquisitions, outsourcing, digital transformation, and new business capabilities.
  • Represent the cybersecurity organization in cross-functional governance forums, audit discussions, risk reviews, and executive updates.
  • Lead, coach, and develop a team of cybersecurity compliance professionals, control analysts, governance, risk and compliance specialists, or assurance resources.
  • Set team objectives, priorities, performance expectations, service levels, and quality standards.
  • Build scalable processes, playbooks, templates, and workflows to support consistent execution across compliance activities.
  • Drive automation and tooling improvements for evidence management, control monitoring, issue tracking, reporting, and regulatory obligation management.
  • Manage workload across audits, assessments, control testing, regulatory requests, reporting cycles, and remediation activities.
Desired Qualifications
  • Experience building, transforming, or scaling a cybersecurity compliance or governance, risk and compliance program in a Fortune 500 or publicly traded company.
  • Experience supporting board, audit committee, enterprise risk committee, or executive-level cybersecurity reporting.
  • Experience with governance, risk and compliance platforms such as ServiceNow GRC/IRM, Archer, OneTrust, MetricStream, AuditBoard, Workiva, LogicGate, or similar tools.
  • Experience with SOX, PCI DSS, SOC 2, ISO 27001 certification, regulatory examinations, customer audits, or cyber insurance assessments.
  • Experience implementing or managing a common control framework across multiple compliance obligations.
  • Experience with automated control monitoring, continuous compliance, cloud compliance, or evidence automation.
  • Professional certification such as CISSP, CISM, CRISC, CISA, CGEIT, CDPSE, ISO 27001 Lead Auditor/Implementer, PCI ISA/QSA where applicable, CPA, or CIA.
  • Experience working in retail, financial services, healthcare, manufacturing, technology, logistics, or another large-scale regulated industry.
  • CRISC, CISSP, CISM, or relevant experience.

Advance Auto Parts supplies automotive aftermarket parts and accessories to both professional installers and DIY customers through thousands of stores in North America. Its product lineup includes replacement parts, maintenance items, and car accessories for cars, vans, and light trucks, sold in-store and online with staff guidance to help customers select the right parts. The company differs from many competitors through its extensive store network, broad product assortment, and ability to serve both professional businesses and individual customers with knowledgeable service and a nationwide distribution and retail model. Its goal is to be the preferred source for auto parts by offering a wide selection, convenient locations, and expert customer assistance.

Company Size

10,001+

Company Stage

IPO

Headquarters

Raleigh, North Carolina

Founded

1932

Get referred to Advance Auto Parts

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 free cash flow reached $120 million year-to-date, reversing prior outflows.
  • Q2 2026 gross margin hit 46.2%, driven by merchandising gains.
  • Management reaffirmed August 20, 2026 guidance, including $2.60-$3.30 adjusted EPS.

What critics are saying

  • DIY sales fell sharply in Q2 2026, especially during the final four weeks.
  • The $26 million Q2 2026 tariff refund disappears in second-half results.
  • If holiday 2026 DIY demand weakens, positive free cash flow disappears again.

What makes Advance Auto Parts unique

  • Advance Auto Parts runs 38 market hubs, targeting 60 by mid-2027.
  • Its June 17, 2026 OneRail expansion strengthens same-day fulfillment across 4,000 locations.
  • The Pro channel outgrew DIY in Q2 2026, favoring installer demand.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Performance Bonus

Growth & Insights and Company News

Headcount

6 month growth

13%

1 year growth

13%

2 year growth

13%
Yahoo Finance
Aug 20th, 2026
Dow drops 703 points as Treasury yields surge past 4.7%, Walmart tumbles 9% on sales miss

Stocks fell Thursday as Treasury yields rebounded and retail earnings disappointed. The Dow Jones Industrial Average dropped 703 points, or 1.3%, to 52,759. The S&P 500 declined 0.9% to 7,641, whilst the Nasdaq Composite fell 1.0% to 26,067. Rising yields on the 10-year and 30-year Treasuries pressured equities after US debt crossed $40 trillion. Walmart led decliners, tumbling 9.2% despite beating earnings expectations. The retailer's same-store sales growth of 2.6% fell short of forecasts, and it issued soft third-quarter guidance. Advance Auto Parts plunged 24.6% after reporting revenue below analyst expectations, despite stronger-than-expected earnings per share.

Yahoo Finance
Aug 20th, 2026
Advance Auto Parts returns to positive free cash flow of $120M amid DIY spending slowdown

Advance Auto Parts reported positive free cash flow of $120 million year-to-date in Q2 2026, marking a significant turnaround supported by improved working capital management and tariff refunds. However, the company experienced a slight decline in comparable sales due to weaker-than-expected DIY spending during the quarter's final four weeks. The Pro channel met expectations, with Main Street business growth outpacing the segment by 200 basis points. Operational improvements included Net Promoter Scores rising to nearly 80 points and in-store attachment rates reaching 30%. The company completed its distribution centre consolidation, reducing from nearly 40 facilities to 15 locations. Management maintained full-year comparable sales guidance of 1% to 2% and reaffirmed a medium-term adjusted operating margin target of 7%. Advance Auto Parts plans to open 15 to 20 Market Hubs this year, reaching 60 locations by mid-2027.

Yahoo Finance
Aug 20th, 2026
Advance Auto Parts raises EPS guidance to $2.60–$3.30 despite DIY sales drop

Advance Auto Parts reported second-quarter sales of $2 billion, with comparable sales declining slightly. Low-single-digit growth in the professional channel was offset by a larger-than-expected low-double-digit drop in DIY sales as tighter household budgets weighed on consumer spending. Adjusted operating margin expanded to 5.6% and adjusted EPS rose to $1.03. The company benefited from product-margin gains and $26 million in tariff refunds. Free cash flow improved to $120 million year to date, whilst net-debt leverage fell to 2.1 times. The company reaffirmed its 2026 sales, margin and free-cash-flow outlook but raised adjusted EPS guidance to $2.60–$3.30, largely due to higher expected interest income.

Yahoo Finance
Aug 20th, 2026
Advance Auto Parts plunges 21% on $2B revenue miss despite $26M tariff refund boosting earnings

Advance Auto Parts shares plunged 21% to $44.33 after reporting second-quarter results that missed revenue expectations despite an earnings beat. The company posted adjusted earnings per share of $1.03, beating estimates of $0.81, but revenue of $2 billion fell short of the $2.04 billion forecast. Comparable sales declined 0.5%. The earnings beat included a one-time $26 million tariff refund worth $0.31 per share. Management noted the DIY channel weakened sharply in the quarter's final four weeks, whilst the Pro channel delivered low single-digit growth. The sell-off rippled through the auto parts sector. AutoZone fell 4% to $2,961, O'Reilly Automotive dropped 2% to $89.57, and Genuine Parts slipped 3% to $131.05, reflecting concerns about softening do-it-yourself demand across the industry.

Yahoo Finance
Aug 4th, 2026
Advance Auto Parts vs. Caterpillar: Which stock offers better value in 2026?

Advance Auto Parts and Caterpillar present contrasting investment profiles for 2026, balancing retail recovery against industrial stability. Advance Auto Parts operates in the automotive aftermarket, serving mechanics and DIY enthusiasts. The company recently expanded its AI-powered same-day delivery partnership with OneRail. FY 2025 revenue fell 5.4% year-over-year to $8.6 billion, with net income of $44 million and a 0.5% margin. The firm faces a 2.4x debt-to-equity ratio and negative $298 million free cash flow whilst implementing multi-year restructuring. Caterpillar serves construction, mining, and energy sectors through a global dealer network across nearly 190 countries. FY 2025 revenue grew 4.3% to $67.6 billion. Net income declined to $8.9 billion from $10.8 billion previously, yielding a 13.1% margin. The company is acquiring mining software providers to enhance digital services. Both face distinct macroeconomic pressures, making valuation critical for investment decisions.