Sr. Manager, Information Security
Advance Auto Parts
Job Description Role Summary The Cybersecurity Compliance Manager is responsible for designing, operating, and continuously improving the company's cybersecurity compliance program within a large-scale retail environment. This role leads the day-to-day execution of compliance activities using the OneTrust GRC platform, with a strong focus on automation, controls monitoring, and audit-ready evidence generation. The role ensures enterprise alignment with NIST Cybersecurity Framework (CSF) and regulatory requirements including PCI DSS, HIPAA, and U.S. state privacy regulations (CCPA/CPRA). This role is hybrid and based in our corporate headquarters in Raleigh, NC. Key Responsibilities Cybersecurity Compliance Program Execution
- Operate and mature the enterprise cybersecurity compliance program aligned to NIST CSF and applicable regulatory frameworks (PCI DSS, HIPAA, CCPA/CPRA).
- Translate regulatory and framework requirements into clear, monitored internal controls mapped to business systems and processes.
- Serve as a subject matter expert for cybersecurity control compliance across IT, cloud, retail, e-commerce, and corporate environments.
- Lead day-to-day use of the OneTrust GRC compliance modules, including:
- Control libraries and framework mappings
- Automated evidence collection and surveys
- Workflow-driven control testing and remediation tracking
- Compliance reporting and dashboards
- Implement and enhance automation to reduce manual effort and eliminate point-in-time compliance gaps.
- Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories).
- Establish and operate a continuous controls monitoring (CCM) model in dynamic retail and cloud environments.
- Monitor control performance, SLA adherence, and exception trends across in-scope systems (e.g., PCI environments, customer data platforms).
- Track control effectiveness metrics and produce regular compliance reporting for leadership.
- Coordinate and support internal and external audits and assessments, including:
- PCI DSS attestations
- HIPAA risk and compliance reviews
- Privacy regulatory inquiries and assessments
- Maintain audit-ready evidence within OneTrust and drive timely remediation of findings.
- Partner with IT, Internal Audit, Legal, and Privacy to ensure consistent interpretation and execution of control requirements.
- Work closely with system owners, IT leaders, cybersecurity team, and business partners to ensure controls are properly implemented and operated.
- Assign control ownership, track accountability, and facilitate risk acceptance where appropriate.
- Provide guidance and training to control owners on compliance expectations, evidence requirements, and remediation processes.
- 6+ years of experience in cybersecurity compliance, GRC, or IT risk management, preferably in a retail or consumer-facing enterprise.
- Strong working knowledge of:
- NIST Cybersecurity Framework (CSF)
- PCI DSS
- HIPAA Security Rule
- CCPA/CPRA and U.S. privacy obligations
- Experience supporting audits and regulatory assessments in complex, distributed environments.
- Hands-on experience with OneTrust GRC (or comparable GRC platforms) including compliance automation and evidence workflows.
- Experience implementing continuous controls monitoring (CCM) or security metrics programs.
- Retail industry experience supporting point-of-sale (POS), e-commerce, or cardholder data environments (CDE).
- Familiarity with third-party risk and vendor compliance monitoring.
- Relevant certifications (preferred, not required):
- CISA, CISSP, CRISC, PCI ISA, or similar.
- Strong analytical and risk-based thinking
- Ability to translate regulatory language into practical, business-aligned controls
- Excellent stakeholder communication and influence skills
- Detail-oriented with a strong audit and evidence mindset
- Comfortable operating in fast-moving, matrixed retail organizations
Vacancy posted 10 hours ago
Similar jobs that could be interesting for youBased on the Sr. Manager, Information Security in Raleigh, NC vacancy
- ...Our Team This position is for a Cloud Product SOC Manager in the Security Center of Excellence for PC and Smart Devices business (... ...analysis and reporting Perform event correlation using information gathered from a variety of sources within the enterprise...SeniorLocal areaImmediate startHome office
- ...Columbus, United States | Posted on 05/19/2026 Atlas Advisors is seeking a Senior Security Manager to provide personnel security, information security, SCIF management, access control, badging, classified document control, and security management assistance in support...SeniorTemporary workWork at officeLocal areaOverseasRelocation package
- ...computing power for the connections that are changing business and society. About Our Team This position is for a Senior Manager Software Security in the Security Center of Excellence for PC and Smart Devices business (PCSD). This is an exciting role where you will be...SeniorLocal areaHome office
- ...As a Senior Account Manager here at Honeywell, you will be responsible for managing and... ...including but not limited to; BMS, Fire, Security, and SaaS knowledge. WE VALUE Bachelor... ...leave), and 12 Paid Holidays. For more information visit: click here ( _ ) The...SeniorPermanent employmentTemporary workRemote workFlexible hours
$170.6k - $390k
...practice – the best place in the world to grow your career in information security! The opportunity The Senior Network Security... ...security operations teams. Join our dynamic team as a Senior Manager in Cybersecurity Engineering, where you will play a pivotal...SeniorSummer holidayRemote workFlexible hours- ...Controls Officer - Lending, the Senior Manager, 1LoD Business Controls Manager plays a... ...the control identification for RBC Bank's Securities Based Lending (SBL) products and broader... ...partnership with control owners Provide informed and valuable risk and control...SeniorFull timeFlexible hours
$184k - $233k
...Senior Product Manager We are seeking an experienced Senior Product Manager to lead the strategy, roadmap, and execution of Lenovo... ...Cloud and agentic platform solutions. This role will own our AI Security offering, aimed to address emerging risks across agentic...SeniorWork at officeLocal areaRemote workWork from home3 days per week$90k - $105k
Technology-Partner is seeking a Low Voltage Project Manager in Raleigh-Durham, NC, offering an annual salary of $90K - $105K along with... ...over 5 years of experience managing large scale enterprise security projects and possess strong project management skills. This role...Senior- 慨正橡扯 seeks an experienced Product Manager to join our Trust and Security team. This role involves leading strategy, discovery, and delivery for innovative products that ensure customer protection and enhance their experience. The ideal candidate will have a minimum of...Senior
- Instrata is seeking an experienced Project Manager in Raleigh, NC, to drive multiple low-voltage projects. The role involves ensuring project execution, managing client relationships, and mentoring junior professionals. With 7-10 years of experience and strong skills in...SeniorWork at office
- Durham, United States | Posted on 08/08/2023 Sr. Technical Project Manager position, based in Durham, North Carolina - We... ...professional to lead complex projects within the Information Technology - Computer & Network Security industry, specifically those with previous...SeniorFull timeWork experience placement
$55.3k - $126k
Booz Allen Hamilton is looking for a Senior SCIF Entry Control Point Manager in North Carolina. This role requires overseeing physical security and ensuring compliance with access control procedures in a SCIF environment. The successful candidate will have over 3 years...SeniorFlexible hours- Labcorp is seeking a Senior Manager, HR Technology (Workday Security) for a team in Durham, NC. The Senior Manager, HR Technology (Workday Security)... ...foregoing benefits except PTO or FTO. For more detailed information, please click here. Equal Opportunity Employer Labcorp...SeniorFull timeTemporary workCasual workInternshipWork at officeLocal areaMonday to FridayFlexible hoursDay shift3 days per week
- ...a full range of multi-disciplined engineering, architecture, information technology, and related services to public agencies and private... ...requirements and prepares invoices. Develop Project Management plans for assigned projects Establish project pricing and...SeniorContract workWork at officeLocal area
- Atlas Advisors is looking for a Senior Security Manager based in Wiesbaden, Germany, to oversee personnel security and SCIF management. The role includes developing security objectives, conducting security briefings, and managing classified programs. Ideal candidates have...SeniorOverseas
$172k - $250k
...Grant Thornton is seeking a Director of Information Security Audit & Compliance to join the team. Approved office locations can be found below... ...be responsible for establishing global delivery centers, managing internal and external audits, and ensuring the information security...InternshipSeasonal workWork at officeLocal areaFlexible hours3 days per week$130k - $140k
...Job Description Role: Manager, Security Operations Location: United States (Hybrid - Durham, NC) Department: Cybersecurity - Security... ...eligible to participate in an annual incentive program, and information on benefits offered is here. #LI-EB1 Who we are: At...Full time- ...Description: The Network Engineer III manages the purchase, installation, and support... ...zones. ~ Knowledge of DNSSEC and secure zone transfers. ~ Knowledge of... ...with Product Managers, Platform Leads, and Information Security teams, to design and implement...SeniorH1bWork at officeLocal areaImmediate startRemote workVisa sponsorshipWork visa1 day per week
- Regional Sales Manager (RSM), Cloud Security, Remote Introduction We are a specialized security services provider within a global cybersecurity leader... ...activity, and customer needs; share insights to inform strategic decisions. This list of duties is not exhaustive...Remote jobTemporary workWork at officeLocal areaWorldwideFlexible hours
- ...in NC, AZ, TX, and VA. This position leads daily engineering, operations, analysis, management, and administration of tools, systems, or processes that secure the Bank's information assets and technology infrastructure. Assesses organizational networks, applications,...Remote work
- 慨正橡扯 is seeking a Senior Business Engagement Specialist to join our Information Security organization in Raleigh, North Carolina. This role focuses on embedding security principles into the business lifecycle and requires expertise in building relationships across teams...SeniorFlexible hours
- Ensono is looking for a Security Senior Solution Architect to lead security architecture... ...This role requires strong expertise in information security and active participation in project... ...with cross-functional teams, manage client security infrastructures, and suggest...SeniorRemote job
- First Citizens Bank is looking for a Security Engineering Lead to oversee daily security operations and enhance the Bank's information security. This remote position requires 8 years of experience in relevant fields and involves mentoring team members while leading security...SeniorRemote job
- JOB DESCRIPTION Global Security | Technical Security Product Delivery Manager, Vice President As a Product Delivery Manager in Global Security, you will work... ...skills and capabilities Relevant experience in information security or technology controls. Experience managing...Work at officeMonday to FridayWeekend workAfternoon shift
- ...Please review the following job description: Truist Senior Audit Manager is responsible for providing a leadership role in the... ...Development Life Cycle (SDLC). Significant knowledge of IT, information security and Cloud management and control frameworks (COSO, COBIT, NIST...SeniorFull timePart timeWork at officeRelocationShift workDay shift
- General Information Req # WD00099070 Career area: Product Management Country/Region: United States of America State: North Carolina City: Morrisville Date: Thursday... .... Description and Requirements We are seeking a Security Product Manager to lead security strategy and...SeniorFull timeLocal area
- ...reporting directly to the Digital Audit Manager. Senior IT Auditor Job Responsibilities:... ...function looking at the activities in ITGC, Security and Application Controls space You will... ...will need to be an expert in general information security concepts and technology infrastructure...Senior
- ...Identity And Access Management Lead We are seeking an experienced Identity and Access... ...organization while partnering closely with Security, Infrastructure, Application Owners, HR... ...working within an enterprise Information/Cyber Security setting, or equivalent experience...SeniorWork experience placement
$150k - $180k
...150,000.00 - $180,000.00 per year Job Category: Marketing Title: Sr. Director of Franchise Operations - Cluck Face Restaurants LM Restaurants... ...looking for someone who thrives in fast‑paced environments, can manage multiple moving pieces at once, and knows how to take projects...SeniorHourly payFull timeFor contractorsHome office$104.9k - $174.7k
...technical authority for high-severity security events, providing executive-ready decision... ...technology. The position supports the Information Security department's goals and... ...incident response leadership, providing management with insight and input into overall security...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Manager, Information Security. Be the first to apply!
Related searches
- security systems manager Raleigh, NC
- senior security manager Raleigh, NC
- security manager Raleigh, NC
- director information security Raleigh, NC
- corporate security manager Raleigh, NC
- security operations manager Raleigh, NC
- director global security Raleigh, NC
- senior director information security Raleigh, NC
- surveillance manager Raleigh, NC
- physical security manager Raleigh, NC

