Demo

Sr. Manager, Information Security

Advance Auto Parts
Raleigh, NC Full Time
POSTED ON 5/6/2026
AVAILABLE BEFORE 7/6/2026

Job Description

Role Summary

The Cybersecurity Compliance Manager is responsible for designing, operating, and continuously improving the company’s cybersecurity compliance program within a large‑scale retail environment. This role leads the day‑to‑day execution of compliance activities using the OneTrust GRC platform, with a strong focus on automation, controls monitoring, and audit‑ready evidence generation.

The role ensures enterprise alignment with NIST Cybersecurity Framework (CSF) and regulatory requirements including PCI DSS, HIPAA, and U.S. state privacy regulations (CCPA/CPRA).

This role is hybrid and based in our corporate headquarters in Raleigh, NC.

Key Responsibilities

Cybersecurity Compliance Program Execution

  • Operate and mature the enterprise cybersecurity compliance program aligned to NIST CSF and applicable regulatory frameworks (PCI DSS, HIPAA, CCPA/CPRA).
  • Translate regulatory and framework requirements into clear, monitored internal controls mapped to business systems and processes.
  • Serve as a subject matter expert for cybersecurity control compliance across IT, cloud, retail, e‑commerce, and corporate environments.
  • Lead day‑to‑day use of the OneTrust GRC compliance modules, including:
    • Control libraries and framework mappings
    • Automated evidence collection and surveys
    • Workflow‑driven control testing and remediation tracking
    • Compliance reporting and dashboards
  • Implement and enhance automation to reduce manual effort and eliminate point‑in‑time compliance gaps.
  • Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories).

Controls Monitoring & Assurance

  • Establish and operate a continuous controls monitoring (CCM) model in dynamic retail and cloud environments.
  • Monitor control performance, SLA adherence, and exception trends across in‑scope systems (e.g., PCI environments, customer data platforms).
  • Track control effectiveness metrics and produce regular compliance reporting for leadership.
  • Coordinate and support internal and external audits and assessments, including:
    • PCI DSS attestations
    • HIPAA risk and compliance reviews
    • Privacy regulatory inquiries and assessments
  • Maintain audit‑ready evidence within OneTrust and drive timely remediation of findings.
  • Partner with IT, Internal Audit, Legal, and Privacy to ensure consistent interpretation and execution of control requirements.
  • Work closely with system owners, IT leaders, cybersecurity team, and business partners to ensure controls are properly implemented and operated.
  • Assign control ownership, track accountability, and facilitate risk acceptance where appropriate.
  • Provide guidance and training to control owners on compliance expectations, evidence requirements, and remediation processes.

Required Qualifications

  • 6 years of experience in cybersecurity compliance, GRC, or IT risk management, preferably in a retail or consumer‑facing enterprise.
  • Strong working knowledge of:
    • NIST Cybersecurity Framework (CSF)
    • PCI DSS
    • HIPAA Security Rule
    • CCPA/CPRA and U.S. privacy obligations
  • Experience supporting audits and regulatory assessments in complex, distributed environments.

Preferred Qualifications

  • Hands‑on experience with OneTrust GRC (or comparable GRC platforms) including compliance automation and evidence workflows.
  • Experience implementing continuous controls monitoring (CCM) or security metrics programs.
  • Retail industry experience supporting point‑of‑sale (POS), e‑commerce, or cardholder data environments (CDE).
  • Familiarity with third‑party risk and vendor compliance monitoring.
  • Relevant certifications (preferred, not required):
    • CISA, CISSP, CRISC, PCI ISA, or similar.

Key Competencies

  • Strong analytical and risk‑based thinking
  • Ability to translate regulatory language into practical, business‑aligned controls
  • Excellent stakeholder communication and influence skills
  • Detail‑oriented with a strong audit and evidence mindset
  • Comfortable operating in fast‑moving, matrixed retail organizations

California Residents click below for Privacy Notice:

https://jobs.advanceautoparts.com/us/en/disclosures

Salary.com Estimation for Sr. Manager, Information Security in Raleigh, NC
$187,786 to $223,085
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Sr. Manager, Information Security?

Sign up to receive alerts about other jobs on the Sr. Manager, Information Security career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$220,784 - $286,649
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Advance Auto Parts

  • Advance Auto Parts Laramie, WY
  • Job Description What is a Retail Parts Pro? Professional level sales position capable of supporting advanced functions of the DIY business. The role has ex... more
  • 5 Days Ago

  • Advance Auto Parts Casper, WY
  • Job Description Professional level sales position capable of supporting advanced functions on the commercial side of the business. Position is responsible ... more
  • 5 Days Ago

  • Advance Auto Parts Lovell, WY
  • Job Description Professional level sales position capable of supporting advanced functions on the commercial side of the business. Position is responsible ... more
  • 5 Days Ago

  • Advance Auto Parts Sioux, SD
  • Job Description What is a Retail Parts Pro? Professional level sales position capable of supporting advanced functions of the DIY business. The role has ex... more
  • 5 Days Ago


Not the job you're looking for? Here are some other Sr. Manager, Information Security jobs in the Raleigh, NC area that may be a better fit.

  • Piper Companies Raleigh, NC
  • Piper Companies is seeking an Information Security Manager who will be responsible for developing, implementing, and maintaining the organization’s informa... more
  • 13 Days Ago

  • Hellios Information Raleigh, NC
  • Job Title Customer Success Manager Location: Raleigh, North Carolina, The United States Reporting To Country Manager Job Summary To manage Relationship wit... more
  • 9 Days Ago

AI Assistant is available now!

Feel free to start your new journey!