Vice President, Chief Information Security Officer, CISO

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Driven Brands Inc.

Driven Brands Inc.

5001 - 10000 employees

Founded 1972

🚘 Automotive

💰 Post-IPO Debt on 2022-10

Automotive

Driven Brands Inc. is a leading provider of consumer and commercial automotive services, delivering a comprehensive range of car care solutions across over 5,000 brand locations. They service more than 70 million vehicles annually and offer a broad suite of services including paint, collision repair, glass replacement, oil changes, general vehicle maintenance, and car washes. The company's well-known brands include Take 5 Oil Change, Maaco, Meineke, CARSTAR, and 1-800-Radiator & A/C, among others. Driven Brands emphasizes convenience and customer satisfaction, positioning themselves as a one-stop shop for all automotive aftermarket needs. Founded with a strong heritage and a portfolio of trusted brands, Driven Brands also engages in franchise opportunities and charitable initiatives.

📋 Description

• Lead the company’s enterprise cybersecurity strategy, governance, risk management, and security operations program • Serve as senior cybersecurity advisor to executive leadership, the Board of Directors, and the Audit Committee • Develop and execute a multi-year enterprise cybersecurity strategy aligned with business objectives, regulations, and risk appetite • Establish cybersecurity policies, standards, controls, and governance using frameworks such as NIST, CIS Controls, and ISO 27001 • Define cybersecurity accountability across corporate functions, brands, technology teams, franchise environments, and third-party providers • Present standardized cybersecurity scorecard results and report posture, risks, incidents, control maturity, initiatives, and remediation progress • Lead identification, assessment, prioritization, treatment, and monitoring of enterprise cybersecurity risks • Oversee SOX, PCI DSS, privacy, and contractual compliance obligations and support audit remediation • Provide executive oversight of security monitoring, detection, threat intelligence, investigation, containment, and incident response • Oversee SIEM, SOAR, EDR/XDR, email security, cloud security, data protection, and managed security providers • Lead significant cybersecurity incident response, crisis processes, post-incident reviews, and root-cause analysis • Establish governance for identity lifecycle management, multifactor authentication, privileged access, access reviews, and segregation of duties • Oversee enterprise vulnerability and exposure management and risk-based remediation • Establish controls for confidential, personal, financial, employee, customer, and franchisee information • Provide cybersecurity oversight for cloud adoption, applications, digital products, technology changes, artificial intelligence, and emerging technologies • Establish governance for secure and responsible artificial intelligence use and monitor AI-related risks • Lead third-party cybersecurity risk management, including due diligence, assessments, contracting, monitoring, and reassessment • Lead cybersecurity due diligence and risk planning for mergers, acquisitions, integrations, divestitures, and transition-service arrangements • Establish cyber-resilience requirements and oversee ransomware readiness, backup protection, recovery access, and cyber-recovery testing • Lead cybersecurity awareness, phishing simulation, and role-based training programs • Build and develop the cybersecurity organization • Manage the cybersecurity budget, vendors, managed security providers, and strategic partners

🎯 Requirements

• Bachelor’s degree in cybersecurity, information systems, computer science, engineering, business, risk management, or a related field; advanced degree preferred • Fifteen or more years of progressive cybersecurity, technology-risk, or related experience • Significant experience leading an enterprise cybersecurity program in a complex, distributed, regulated, or publicly traded organization • Demonstrated experience advising executive leadership, Boards, and Audit Committees • Strong knowledge of cybersecurity frameworks, security operations, incident response, identity and access management, vulnerability management, cloud security, data protection, third-party risk, AI security governance, and regulatory compliance • Experience supporting SOX IT general controls, audits, remediation programs, and business transactions • Experience managing cybersecurity teams, budgets, vendors, and managed security providers • CISSP or CISM certification required or strongly preferred • CRISC, CISA, CCSP, GIAC, or equivalent credentials beneficial • Experience in retail, automotive services, franchise, hospitality, restaurant, or other multi-location consumer-facing industries preferred • Experience supporting organizations with multiple brands, decentralized operations, and complex third-party partner ecosystems preferred

🏖️ Benefits

• Health and wellness benefits • Paid time off • Holiday pay • Early access to 50% of earned wages at any time through the myFlexPay program • Supplemental pay types may include commissions or bonus incentives, depending on the role

Apply Now

Similar Jobs

🔥 13 hours ago

Bixal

51 - 200

📣 Marketing

📦 Logistics

🏥 Healthcare

Staff Security Engineer embedding secure-by-design controls into Bixal’s federal agency platforms. Automating FedRAMP compliance, identity security, threat modeling, and audit evidence.

🔥 22 hours ago

General Dynamics Information Technology

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Cybersecurity Architect securing GDIT’s global government and defense IT services. Designing SIEM, Zero Trust, compliance, and infrastructure security architectures.

🕒 Yesterday

Addepar

501 - 1000

💸 Finance

💳 Fintech

☁️ SaaS

Staff AI Security Engineer securing Addepar’s global investment data and AI platform. Leading AI security architecture, guardrails, governance, automation, and organization-wide security initiatives.

🕒 Yesterday

CVS Health

10,000+ employees

🏥 Healthcare

⚕️ Healthcare Insurance

🛒 Retail

Chief of Staff advancing CVS Health’s enterprise cybersecurity strategy and Deputy CISO operations. Coordinating governance, budgets, executive communications, and strategic programs across security teams.

🕒 Yesterday

Affirm

1001 - 5000

💳 Fintech

👥 B2C

🛍️ eCommerce

Staff Product Security Engineer building CIAM backend services for Affirm’s buy-now-pay-later platform. Securing authentication, authorization, and account lifecycle flows at scale.