Role SummaryHead of Cybersecurity, Risk & Compliance separates technical security execution from risk governance, ensuring CarParts.com's security posture, regulatory compliance (PCI, SOX), and audit-readiness stay board-visible. This role reports directly to the CTO and closes the governance gap left by the departing AVP of Infrastructure and Security.
Key Responsibilities- Own security engineering: controls, hardening, and security tooling
- Lead threat detection & response - monitoring, triage, and incident response
- Drive governance, risk & compliance: policies, evidence, and control mapping
- Own PCI & SOX controls: control ownership, testing, and remediation
- Manage vendor and third-party risk reviews, contracts, and remediation
- Deliver board-ready audit committee reporting on posture, risks, and exceptions
Required Qualifications- 8+ years in cybersecurity/GRC, 3+ in a leadership role
- Direct experience with PCI-DSS and SOX control environments
- Experience presenting to audit committees or boards
- Track record building or scaling a GRC function
Preferred Qualifications- CISSP, CISM, or equivalent certification
- eCommerce/retail security experience
- Familiarity with NIST frameworks and SIEM tooling (e.g. Splunk, Elastic)
What Success Looks Like- Clean PCI/SOX audit cycles with no material findings
- Documented, tested incident response process
- Established board/audit committee reporting cadence
A reasonable salary estimate for the role based on experience, education, and geographical location is: $195,000-$250,000
The above-noted job description is not intended to describe, in detail, the multitude of tasks that may be assigned but rather to give the incumbent a general sense of the responsibilities and expectations of his/her position. As the nature of business demands change so, too, may the essential functions of this position.