Advance Auto Parts · 22 hours ago
Security Analyst
Advance Auto Parts is seeking a highly motivated Cyber Risk Analyst to join their Governance, Risk, and Compliance (GRC) team within Information Security. The role involves identifying, evaluating, and monitoring security risks across a complex retail ecosystem and collaborating with various stakeholders to ensure risks are understood and managed effectively.
AutomotiveRetail
Responsibilities
Conduct security risk assessments across applications, infrastructure, and operations
Analyze technical and business impacts, likelihood, and severity of identified risks
Document risks clearly in the InfoSec risk register, ensuring accuracy, completeness, and traceability
Evaluate proposed controls for adequacy and provide recommendations based inherent risk
Document risk treatment plans including mitigation strategies, compensating controls, ownership, and timelines
Collaborate with risk owners to ensure treatment plans are actionable and aligned with business priorities
Track and report on treatment progress, risk acknowledgements, and residual risk
Escalate critical risk items and overdue treatments to leadership as needed
Support ongoing risk monitoring and reporting activities, including dashboards and scorecards for senior leadership
Facilitate risk review meetings with technology and business owners
Maintain metrics to measure risk posture and treatment effectiveness
Collaborate with Security Operations, IT, and business teams to evaluate risks associated with security incidents, vulnerabilities, and audit findings
Provide recommendations to reduce residual risk or strengthen overall control posture
Assist with aligning internal processes to regulatory and industry standards relevant to retail (PCI DSS, SOX ITGC, etc.)
Contribute to updates of internal policy, standard, and procedure
Qualification
Required
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience
2–4 years of experience in cybersecurity, IT audit, risk management, or related discipline
Knowledge of common security frameworks (NIST CSF, NIST 800-53, ISO 27001, PCI DSS)
Experience conducting risk assessments and reviewing security controls
Strong analytical, communication, and documentation skills
Ability to translate technical details into clear business impacts
Preferred
Experience in a large enterprise or retail environment
Familiarity with GRC-related platforms (e.g., ServiceNow, OneTrust)
Understanding of cloud environments (AWS, Azure, GCP) and modern tech stacks
Knowledge of Cyber Third-Party Risk Management and Compliance
Company
Advance Auto Parts
Advance Auto Parts is the largest automotive aftermarket parts provider in North America, serves both the professional installer.
Funding
Current Stage
Public CompanyTotal Funding
$1.95B2025-07-28Post Ipo Debt· $1.95B
2001-11-29IPO
Leadership Team
Recent News
2025-12-30
Company data provided by crunchbase