Vice President, Chief Information Security Officer (CISO
Listed on 2026-08-17
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Company:
Driven Brands
Driven Brands is North America's largest automotive services company with a portfolio of iconic brands including Take 5 Oil Change®, Meineke Car Care Centers®, Maaco®, 1-800-Radiator & A/C®, Auto Glass Now®, and CARSTAR®. Our vision is to fuel the pursuit with the simplest, most convenient, and most reliable car care experience.
Headquartered in Charlotte, NC, Driven Brands is more than a workplace. We're a launchpad — for careers, for dreams, and for people driven to do great things.
Every day, we fuel the pursuit — for our customers chasing life's moments, for our franchisees building lasting legacies, and for each other as we grow, lead, and succeed together.
Performance matters. We take pride in it. We own it. We show up for one another and for our communities.
Because at Driven Brands, we're not just fixing cars. We're building futures, unlocking potential, and fueling what's possible — together.
JOB DESCRIPTION:
The Vice President, Chief Information Security Officer is responsible for leading the company’s enterprise cybersecurity strategy, governance, risk management, and security operations program.
The CISO serves as the senior cybersecurity advisor to executive leadership, the Board of Directors, and the Audit Committee. This role translates cybersecurity risks into clear business, financial, regulatory, and operational terms and recommends appropriate investments, remediation priorities, and risk-treatment decisions.
The CISO partners with Information Technology, Internal Audit, Legal, Privacy, Finance, Human Resources, Enterprise Risk Management, and business leadership to protect the company’s information assets, customers, employees, franchisees, and brand.
How you will Own It:
Cybersecurity Strategy and Governance- Develop and execute a multi-year enterprise cybersecurity strategy aligned with business objectives, regulatory requirements, and risk appetite.
- Establish cybersecurity policies, standards, controls, and governance based on recognized frameworks such as NIST, CIS Controls, and ISO 27001.
- Define accountability for cybersecurity across corporate functions, brands, technology teams, franchise environments, and third-party providers.
- Evaluate emerging threats, technologies, regulations, and business risks.
- Serve as the principal cybersecurity advisor to executive leadership, the Board, and the Audit Committee.
- Establish and maintain a standardized cybersecurity scorecard that tracks progress against defined goals, key risk indicators, control maturity, strategic initiatives, and remediation commitments quarter over quarter.
- Present scorecard results to executive leadership and the Board, highlighting progress, emerging risks, performance gaps, overdue actions, and matters requiring executive or Board attention.
- Report on cybersecurity posture, material risks, incidents, control maturity, strategic initiatives, and remediation progress.
- Advise leadership regarding cybersecurity investments, risk acceptance, and significant control exceptions.
- Lead the identification, assessment, prioritization, treatment, and monitoring of enterprise cybersecurity risks.
- Maintain the cybersecurity risk register and integrate material cyber risks into the enterprise risk management process.
- Oversee security-related compliance obligations, including SOX, PCI DSS, privacy requirements, and contractual commitments.
- Partner with Internal Audit, external auditors, Finance, and Legal to support audit readiness and timely remediation of findings.
- Provide independent challenge regarding control deficiencies, exceptions, compensating controls, and accepted risks.
- Provide executive oversight of security monitoring, detection, threat intelligence, investigation, containment, and response.
- Oversee security technologies and services, including SIEM, SOAR, EDR/XDR, email security, cloud security, data protection, and managed security providers.
- Lead the response to significant cybersecurity incidents and coordinate with Technology, Legal, Privacy, Communications, Finance, Human Resources, insurers, forensic…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).