Job Description
Company: Driven Brands
Location: Durham, US
Driven Brands is North America’s largest automotive services company, with a portfolio of iconic brands including Take 5 Oil Change, Meineke, Maaco, 1-800-Radiator & A/C, Auto Glass Now, and CARSTAR. Headquartered in Charlotte, NC, we’re more than just a workplace — we’re a launchpad for careers, dreams, and people driven to do great things. Every day, we fuel the pursuit for our customers chasing life’s moments, our franchisees building lasting legacies, and each other as we grow, lead, and succeed together.
## About the Role
The Vice President, Chief Information Security Officer (CISO) leads our enterprise cybersecurity strategy, governance, risk management, and security operations. As the senior cybersecurity advisor to executive leadership, the Board of Directors, and the Audit Committee, you’ll translate cybersecurity risks into clear business, financial, regulatory, and operational terms, recommending appropriate investments, remediation priorities, and risk-treatment decisions. You’ll partner with Information Technology, Internal Audit, Legal, Privacy, Finance, Human Resources, Enterprise Risk Management, and business leadership to protect our information assets, customers, employees, franchisees, and brand.
### Cybersecurity Strategy and Governance
You’ll develop and execute a multi-year enterprise cybersecurity strategy aligned with business objectives and risk appetite. This involves establishing policies, standards, and controls based on recognized frameworks like NIST, CIS Controls, and ISO 27001. You’ll define accountability across corporate functions, brands, technology teams, franchise environments, and third-party providers, while evaluating emerging threats, technologies, and regulations.
### Executive and Board Reporting
Serving as the principal cybersecurity advisor, you’ll establish a standardized cybersecurity scorecard tracking progress against goals, key risk indicators, control maturity, strategic initiatives, and remediation commitments. You’ll present these results quarterly to executive leadership and the Board, highlighting progress, emerging risks, performance gaps, and matters requiring attention. You’ll advise on investments, risk acceptance, and significant control exceptions.
### Cyber Risk and Compliance
You’ll lead identification, assessment, prioritization, treatment, and monitoring of enterprise cybersecurity risks, maintaining the risk register and integrating material risks into the enterprise risk management process. Oversee compliance obligations including SOX, PCI DSS, privacy requirements, and contractual commitments. You’ll partner with Internal Audit and external auditors to support audit readiness and timely remediation, providing independent challenge on control deficiencies and accepted risks.
### Security Operations and Incident Response
Provide executive oversight of security monitoring, detection, threat intelligence, investigation, containment, and response. Oversee technologies like SIEM, SOAR, EDR/XDR, email security, cloud security, and managed security providers. Lead response to significant incidents, coordinating with Technology, Legal, Privacy, Communications, Finance, HR, insurers, forensic firms, and law enforcement. Maintain and test incident-response plans, escalation procedures, and crisis-management processes, driving corrective actions through post-incident reviews.
### Identity, Vulnerability and Data Protection
Establish security governance for identity lifecycle management, multifactor authentication, privileged access, access reviews, and non-human identities. Oversee the enterprise vulnerability and exposure management program with risk-based remediation, exception, and escalation requirements. Establish controls for confidential, personal, financial, employee, customer, and franchisee information, partnering with Legal and Privacy leaders on data-protection obligations.
### Security Architecture, AI Governance and Business Enablement
Define enterprise security architecture principles and secure-design standards. Provide cybersecurity oversight for cloud adoption, applications, digital products, major technology changes, artificial intelligence, and emerging technologies. Partner with Technology, Legal, Privacy, Risk, and business leadership to establish governance for secure and responsible AI use. Define requirements for evaluation, acquisition, development, deployment, and use of AI technologies, assessing risks like sensitive-data exposure, unauthorized use, third-party model risk, and regulatory compliance. Ensure security requirements are incorporated into all architecture, procurement, and change processes.
### Third
– Party Risk and Transactions
Lead the third-party cybersecurity risk management program including due diligence, assessments, contracting requirements, and monitoring. Evaluate risks from critical vendors, cloud providers, payment environments, franchise platforms, and outsourced services. Lead cybersecurity due diligence and risk planning for mergers, acquisitions, integrations, divestitures, and transition-service arrangements, ensuring material risks are communicated to executive leadership.
### Resilience, Awareness and Leadership
Establish cyber-resilience requirements and ensure cyberattack scenarios are included in business continuity and disaster-recovery planning. Maintain oversight of ransomware readiness, backup protection, and cyber-recovery testing. Lead enterprise cybersecurity awareness, phishing simulation, and role-based training programs. Build and develop a high-performing cybersecurity organization, managing the budget, vendors, managed security providers, and strategic partners.
## What You’ll Bring
You should have a Bachelor’s degree in cybersecurity, information systems, computer science, engineering, business, risk management, or a related field (advanced degree preferred). You’ll bring fifteen or more years of progressive cybersecurity or technology-risk experience, with significant experience leading an enterprise cybersecurity program in a complex, distributed, regulated, or publicly traded organization. Demonstrated experience advising executive leadership, Boards, and Audit Committees is essential. Strong knowledge of cybersecurity frameworks, security operations, incident response, identity and access management, vulnerability management, cloud security, data protection, third-party risk, AI security governance, and regulatory compliance is required. Experience supporting SOX IT general controls, audits, remediation programs, and business transactions is expected. You should have experience managing cybersecurity teams, budgets, vendors, and managed security providers. Experience in retail, automotive services, franchise, hospitality, restaurant, or other multi-location consumer-facing industries is preferred, as is experience supporting organizations with multiple brands and decentralized operations. CISSP or CISM certification is required or strongly preferred; CRISC, CISA, CCSP, GIAC, or equivalent credentials are beneficial.
## Measures of Success
Success in this role is defined by measurable reduction in material cybersecurity risk, consistent quarter-over-quarter reporting demonstrating progress against goals, improved cybersecurity-program maturity, timely remediation of vulnerabilities and audit findings, effective detection and recovery during incidents, clear reporting to leadership, effective governance for AI adoption, and cybersecurity investments aligned with business priorities.
## Compensation and Benefits
This position offers a compensation range of $199,200.00 to $355,800.00 annually. Base pay offered may vary depending on location, knowledge, skills, and experience. Supplemental pay types may include commissions or bonus incentives. Driven Brands provides a variety of health and wellness benefits including paid time off and holiday pay. Additionally, you’ll get early access to 50% of your earned wages at any time through our my. Flex. Pay program. The position is remote, based in North Carolina. Applicants are considered without regard to race, ethnicity, national origin, sex, sexual orientation, gender identity, age, disability, religion, military or veteran status, or any other protected characteristic.
Source: Bandana.com