JOBSEARCHER

Sr. Manager, Information Security

Job DescriptionRole SummaryThe Cybersecurity Compliance Manager is responsible for designing, operating, and continuously improving the company’s cybersecurity compliance program within a large‑scale retail environment. This role leads the day‑to‑day execution of compliance activities using the OneTrust GRC platform, with a strong focus on automation, controls monitoring, and audit‑ready evidence generation.The role ensures enterprise alignment with NIST Cybersecurity Framework (CSF) and regulatory requirements including PCI DSS, HIPAA, and U.S. state privacy regulations (CCPA/CPRA).This role is hybrid and based in our corporate headquarters in Raleigh, NC. Key ResponsibilitiesCybersecurity Compliance Program ExecutionOperate and mature the enterprise cybersecurity compliance program aligned to NIST CSF and applicable regulatory frameworks (PCI DSS, HIPAA, CCPA/CPRA).Translate regulatory and framework requirements into clear, monitored internal controls mapped to business systems and processes.Serve as a subject matter expert for cybersecurity control compliance across IT, cloud, retail, e‑commerce, and corporate environments.Lead day‑to‑day use of the OneTrust GRC compliance modules, including:Control libraries and framework mappingsAutomated evidence collection and surveysWorkflow‑driven control testing and remediation trackingCompliance reporting and dashboardsImplement and enhance automation to reduce manual effort and eliminate point‑in‑time compliance gaps.Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories).Controls Monitoring & AssuranceEstablish and operate a continuous controls monitoring (CCM) model in dynamic retail and cloud environments.Monitor control performance, SLA adherence, and exception trends across in‑scope systems (e.g., PCI environments, customer data platforms).Track control effectiveness metrics and produce regular compliance reporting for leadership.Coordinate and support internal and external audits and assessments, including:PCI DSS attestationsHIPAA risk and compliance reviewsPrivacy regulatory inquiries and assessmentsMaintain audit‑ready evidence within OneTrust and drive timely remediation of findings.Partner with IT, Internal Audit, Legal, and Privacy to ensure consistent interpretation and execution of control requirements.Work closely with system owners, IT leaders, cybersecurity team, and business partners to ensure controls are properly implemented and operated.Assign control ownership, track accountability, and facilitate risk acceptance where appropriate.Provide guidance and training to control owners on compliance expectations, evidence requirements, and remediation processes.Required Qualifications6+ years of experience in cybersecurity compliance, GRC, or IT risk management, preferably in a retail or consumer‑facing enterprise.Strong working knowledge of:NIST Cybersecurity Framework (CSF)PCI DSSHIPAA Security RuleCCPA/CPRA and U.S. privacy obligationsExperience supporting audits and regulatory assessments in complex, distributed environments.Preferred QualificationsHands‑on experience with OneTrust GRC (or comparable GRC platforms) including compliance automation and evidence workflows.Experience implementing continuous controls monitoring (CCM) or security metrics programs.Retail industry experience supporting point‑of‑sale (POS), e‑commerce, or cardholder data environments (CDE).Familiarity with third‑party risk and vendor compliance monitoring.Relevant certifications (preferred, not required):CISA, CISSP, CRISC, PCI ISA, or similar.Key CompetenciesStrong analytical and risk‑based thinkingAbility to translate regulatory language into practical, business‑aligned controlsExcellent stakeholder communication and influence skillsDetail‑oriented with a strong audit and evidence mindsetComfortable operating in fast‑moving, matrixed retail organizationsCalifornia Residents Click Below For Privacy Noticehttps://jobs.advanceautoparts.com/us/en/disclosuresWe are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age national origin, religion, sexual orientation, gender identity, status as a veteran and basis of disability or any other federal, state or local protected class.