- Salary
- $199k – $356k
- Location
- United States of America - Remote NC
- Workplace
- Remote
- Type
- Full-time
- Department
- Administration
- Seniority
- VP
- Source
- Workday
Description
Driven Brands is North America's largest automotive services company with a portfolio of iconic brands including Take 5 Oil Change®, Meineke Car Care Centers®, Maaco®, 1-800-Radiator & A/C®, Auto Glass Now®, and CARSTAR®. Our vision is to fuel the pursuit with the simplest, most convenient, and most reliable car care experience.
Headquartered in Charlotte, NC, Driven Brands is more than a workplace. We're a launchpad — for careers, for dreams, and for people driven to do great things.
Every day, we fuel the pursuit — for our customers chasing life's moments, for our franchisees building lasting legacies, and for each other as we grow, lead, and succeed together.
Performance matters. We take pride in it. We own it. We show up for one another and for our communities.
Because at Driven Brands, we're not just fixing cars. We're building futures, unlocking potential, and fueling what's possible — together.
JOB DESCRIPTION:
The Vice President, Chief Information Security Officer is responsible for leading the company’s enterprise cybersecurity strategy, governance, risk management, and security operations program.
The CISO serves as the senior cybersecurity advisor to executive leadership, the Board of Directors, and the Audit Committee. This role translates cybersecurity risks into clear business, financial, regulatory, and operational terms and recommends appropriate investments, remediation priorities, and risk-treatment decisions.
The CISO partners with Information Technology, Internal Audit, Legal, Privacy, Finance, Human Resources, Enterprise Risk Management, and business leadership to protect the company’s information assets, customers, employees, franchisees, and brand.
How you will Own It:
Cybersecurity Strategy and Governance
- Develop and execute a multi-year enterprise cybersecurity strategy aligned with business objectives, regulatory requirements, and risk appetite.
- Establish cybersecurity policies, standards, controls, and governance based on recognized frameworks such as NIST, CIS Controls, and ISO 27001.
- Define accountability for cybersecurity across corporate functions, brands, technology teams, franchise environments, and third-party providers.
- Evaluate emerging threats, technologies, regulations, and business risks.
Executive and Board Reporting
- Serve as the principal cybersecurity advisor to executive leadership, the Board, and the Audit Committee.
- Establish and maintain a standardized cybersecurity scorecard that tracks progress against defined goals, key risk indicators, control maturity, strategic initiatives, and remediation commitments quarter over quarter.
- Present scorecard results to executive leadership and the Board, highlighting progress, emerging risks, performance gaps, overdue actions, and matters requiring executive or Board attention.
- Report on cybersecurity posture, material risks, incidents, control maturity, strategic initiatives, and remediation progress.
- Advise leadership regarding cybersecurity investments, risk acceptance, and significant control exceptions.
Cyber Risk and Compliance
- Lead the identification, assessment, prioritization, treatment, and monitoring of enterprise cybersecurity risks.
- Maintain the cybersecurity risk register and integrate material cyber risks into the enterprise risk management process.
- Oversee security-related compliance obligations, including SOX, PCI DSS, privacy requirements, and contractual commitments.
- Partner with Internal Audit, external auditors, Finance, and Legal to support audit readiness and timely remediation of findings.
- Provide independent challenge regarding control deficiencies, exceptions, compensating controls, and accepted risks.
Security Operations and Incident Response
- Provide executive oversight of security monitoring, detection, threat intelligence, investigation, containment, and response.
- Oversee security technologies and services, including SIEM, SOAR, EDR/XDR, email security, cloud security, data protection, and managed security providers.
- Lead the response to significant cybersecurity incidents and coordinate with Technology, Legal, Privacy, Communications, Finance, Human Resources, insurers, forensic firms, and law enforcement.
- Maintain and test cybersecurity incident-response plans, escalation procedures, executive communications, and crisis-management processes.
- Drive corrective actions through post-incident reviews and root-cause analysis.
Identity, Vulnerability and Data Protection
- Establish security governance for identity lifecycle management, multifactor authentication, privileged access, access reviews, segregation of duties, and non-human identities.
- Oversee the enterprise vulnerability and exposure management program.
- Define risk-based remediation, exception, escalation, and reporting requirements.
- Establish security controls for confidential, personal, financial, employee, customer, and franchisee information.
- Partner with Legal and Privacy leaders on data-protection and privacy obligations.
Security Architecture, AI Governance and Business Enablement
- Establish enterprise security architecture principles and secure-design standards.
- Provide cybersecurity oversight for cloud adoption, applications, digital products, major technology changes, artificial intelligence, and emerging technologies.
- Partner with Technology, Legal, Privacy, Risk, and business leadership to establish governance for the secure and responsible use of artificial intelligence.
- Define cybersecurity and data-protection requirements for the evaluation, acquisition, development, deployment, and use of artificial intelligence technologies.
- Assess and monitor AI-related risks, including sensitive-data exposure, unauthorized use, third-party model risk, access control, regulatory compliance, and model manipulation.
- Ensure AI initiatives are subject to appropriate security assessment, approval, monitoring, and periodic review.
- Ensure security requirements are incorporated into architecture, procurement, development, implementation, and change processes.
- Partner with infrastructure, application, cloud, data, and architecture teams without assuming responsibility for their day-to-day operations.
Third-Party Risk and Transactions
- Lead the third-party cybersecurity risk management program, including due diligence, assessments, contracting requirements, monitoring, and reassessment.
- Evaluate risks associated with critical vendors, cloud providers, payment environments, franchise platforms, and outsourced services.
- Lead cybersecurity due diligence and risk planning for mergers, acquisitions, integrations, divestitures, and transition-service arrangements.
- Ensure material third-party and transaction-related risks are communicated to executive leadership.
Resilience, Awareness and Leadership
- Establish cyber-resilience requirements and ensure cyberattack scenarios are included in business continuity and disaster-recovery planning.
- Maintain oversight of ransomware readiness, backup protection, recovery access, and cyber-recovery testing without owning infrastructure recovery operations.
- Lead enterprise cybersecurity awareness, phishing simulation, and role-based training programs.
- Build and develop a high-performing cybersecurity organization.
- Manage the cybersecurity budget, vendors, managed security providers, and strategic partners.
What you’ll Bring:
- Bachelor’s degree in cybersecurity, information systems, computer science, engineering, business, risk management, or a related field; advanced degree preferred.
- Fifteen or more years of progressive cybersecurity, technology-risk, or related experience.
- Significant experience leading an enterprise cybersecurity program in a complex, distributed, regulated, or publicly traded organization.
- Demonstrated experience advising executive leadership, Boards, and Audit Committees.
- Strong knowledge of cybersecurity frameworks, security operations, incident response, identity and access management, vulnerability management, cloud security, data protection, third-party risk, AI security governance, and regulatory compliance.
- Experience supporting SOX IT general controls, audits, remediation programs, and business transactions.
- Experience managing cybersecurity teams, budgets, vendors, and managed security providers.
- Experience in retail, automotive services, franchise, hospitality, restaurant, or other multi-location consumer-facing industries preferred.
- Experience supporting organizations with multiple brands, decentralized operations, and complex third-party partner ecosystems preferred.
- CISSP or CISM certification required or strongly preferred. CRISC, CISA, CCSP, GIAC, or equivalent credentials are beneficial.
Measures of Success
- Measurable reduction in material cybersecurity risk.
- Consistent quarter-over-quarter reporting demonstrating progress against defined cybersecurity goals, risk-reduction priorities, control improvements, and remediation commitments.
- Improved cybersecurity-program maturity and control effectiveness.
- Timely remediation of vulnerabilities, audit findings, and security deficiencies.
- Effective detection, containment, communication, and recovery during cybersecurity incidents.
- Clear and actionable cybersecurity reporting to executive leadership and the Board.
- Effective governance and security controls for enterprise artificial intelligence adoption.
- Effective oversight of identity, third-party, data-protection, and regulatory risks.
- Cybersecurity investments aligned with business priorities and risk reduction.
Applicants for our positions are considered without regard to race, ethnicity, national origin, sex, sexual orientation, gender identity or expression, age, disability, religion, military or veteran status, or any other characteristics protected by law.
#LI-DM1
#LI-Remote
#DBCORP
Position Location:
North CarolinaCompensation Range:
$199,200.00 - $355,800.00Compensation Frequency:
AnnualBase pay offered may vary depending on actual location, job-related knowledge, skills, and experience. Supplemental pay types may include commissions or bonus incentives, depending on the role. Driven Brands offers a variety of health and wellness benefits including paid time off and holiday pay. Details regarding our benefits can be found here: https://www.drivenbrandsbenefits.com
Get early access to 50% of your earned wages at any time through our myFlexPay program.