Head of Cybersecurity, Risk & Compliance
Manager
Cybersecurity Tools
Data Security
Facilities Management
Financial Compliance
Incident Response
Information Security
InfoSec
Pci Compliance
Project Management
Risk Governance
Risk Management
Security
Security Compliance
Security Engineering
Security Operations
Security Standards
Security Testing
Job Description
The Head of Cybersecurity, Risk & Compliance at CarParts.com focuses on aligning hands-on security execution with risk governance, ensuring the organization maintains a board-visible security posture, PCI and SOX compliance, and audit readiness. This position reports directly to the CTO and is based onsite in Long Beach, CA.
Key Responsibilities
- Own security engineering activities, including security controls, system hardening, and security tooling.
- Lead threat detection and response efforts, covering monitoring, triage, and incident response processes.
- Drive governance, risk, and compliance through the development and maintenance of policies, evidence collection, and control mapping.
- Own PCI and SOX control responsibilities, including control ownership, testing, and remediation activities.
- Manage vendor and third-party risk reviews, including contract-related risk considerations and remediation follow-through.
- Provide board-ready audit committee reporting on security posture, risks, and documented exceptions.
Required Qualifications
- 8+ years of cybersecurity and/or GRC experience, including 3+ years in a leadership role.
- Direct experience working within PCI-DSS and SOX control environments.
- Experience presenting findings and updates to audit committees or boards.
- Demonstrated track record building or scaling a GRC function.
Preferred Qualifications
- CISSP, CISM, or an equivalent certification.
- Experience in eCommerce or retail security.
- Familiarity with NIST frameworks and SIEM tooling (for example, Splunk or Elastic).
Technologies and Frameworks
- NIST frameworks
- SIEM tooling, including examples such as Splunk and Elastic
What Success Looks Like
- Maintain clean PCI and SOX audit cycles with no material findings.
- Have a documented and tested incident response process in place.
- Establish a consistent reporting cadence to the board and audit committee.
Role Details
- Location: Long Beach, CA (onsite)
- Compensation: USD 195,000 - 250,000 per year
- Minimum Experience: 8 years