Head of Cybersecurity, Risk & Compliance
CarParts.com Long Beach, California, United States · $195K–$250K/yr
Technology, Information and Internet · 1,001-5,000 employees
About the role
The Head of Cybersecurity, Risk & Compliance will own security engineering, threat detection, and incident response while managing regulatory compliance for PCI and SOX. This role is responsible for delivering board-ready audit committee reporting and overseeing third-party risk management.
What they look for
Requirements
Candidates must have at least 8 years of experience in cybersecurity or GRC, including 3 years in a leadership role. Direct experience with PCI-DSS and SOX control environments is required, along with a proven track record of presenting to audit committees or boards.
Full description
What We Do
CarParts.com is the go-to eCommerce platform for auto care and maintenance. We provide drivers with quality parts at competitive prices and enable them to schedule appointments with trusted mechanics directly through our website. Using world-class design principles and the latest technologies, we deliver a fast, intuitive digital experience backed by our company-owned national distribution network. With over 1,000 employees worldwide, we are scaling rapidly, fueled by our most recent strategic partnership and $35 million investment. This positions us for the next phase of growth as we continue to empower drivers along their journey.
Our Culture
At CarParts.com, our culture goes beyond our core values of Safety First, Customer Focused, and Commitment to Excellence. We are a performance-driven, data-focused, and fast-paced team where results matter and winning is expected. - Hungry & Hardworking: We set ambitious goals, measure progress with clear metrics, and hold ourselves accountable to deliver results. - Promote from Within: We reward top performers with opportunities for growth and advancement. - Collaborative & In-Person: We believe the best ideas and fastest execution happen face-to-face. - High Standards: We move quickly, pay attention to details, and dig deep - whether it’s analyzing contracts, aggregating complex scenarios, or building clear, data-driven presentations. - No Passengers: We value grit, ownership, and the relentless pursuit of results
Role Summary
Head of Cybersecurity, Risk & Compliance separates technical security execution from risk governance, ensuring CarParts.com's security posture, regulatory compliance (PCI, SOX), and audit-readiness stay board-visible. This role reports directly to the CTO and closes the governance gap left by the departing AVP of Infrastructure and Security.
Key Responsibilities
- Own security engineering: controls, hardening, and security tooling
- Lead threat detection & response — monitoring, triage, and incident response
- Drive governance, risk & compliance: policies, evidence, and control mapping
- Own PCI & SOX controls: control ownership, testing, and remediation
- Manage vendor and third-party risk reviews, contracts, and remediation
- Deliver board-ready audit committee reporting on posture, risks, and exceptions
Required Qualifications
- 8+ years in cybersecurity/GRC, 3+ in a leadership role
- Direct experience with PCI-DSS and SOX control environments
- Experience presenting to audit committees or boards
- Track record building or scaling a GRC function
Preferred Qualifications
- CISSP, CISM, or equivalent certification
- eCommerce/retail security experience
- Familiarity with NIST frameworks and SIEM tooling (e.g. Splunk, Elastic)
What Success Looks Like
- Clean PCI/SOX audit cycles with no material findings
- Documented, tested incident response process
- Established board/audit committee reporting cadence
A reasonable salary estimate for the role based on experience, education, and geographical location is: $195,000-$250,000
Equal Opportunity Employer
CarParts.com is an equal-opportunity employer. We enthusiastically accept our responsibility to make employment decisions without regard to race, religious creed, color, age, sex, sexual orientation, national origin, religion, marital status, medical condition, physical or mental disability, military service, pregnancy, childbirth and related medical conditions, or any other classification protected by federal, state, and local laws and ordinances. Our management is dedicated to ensuring that we fulfill this policy with respect to hiring, placement, promotion, transfer, demotion, layoff, termination, recruitment advertising, pay, and other forms of compensation, training, and general treatment during employment.
The above-noted job description is not intended to describe, in detail, the multitude of tasks that may be assigned but rather to give the incumbent a general sense of the responsibilities and expectations of his/her position. As the nature of business demands change so, too, may the essential functions of this position.
Similar roles
-
Embedded Systems Security Engineer
ALTEN Technology USA Foster City, California, United States · $120K–$150K/yr
-
Cybersecurity Specialist
LANDI Global Singapore
-
Security Engineer
Golden Analytics Bellevue, Washington, United States
-
Customer Support Engineer - Endpoint/MTD (Device) & Cybersecurity
Jobgether India
-
Security Engineer, AWS Security
Amazon Melbourne, Victoria, Australia
-
Network Security Engineer
Accenture City of Brisbane, Queensland, Australia