Sonny's Enterprises Inc. - Conveyorized Car Wash Equipment Leader · 3 days ago
VP - Cyber Security
Sonny's Enterprises Inc. is the world's largest manufacturer of conveyorized car wash equipment, recognized for innovation in the industry. The Vice President of Cybersecurity will lead the company's cybersecurity program, focusing on protecting internal operations and customer-facing technologies while collaborating with various teams to enhance security measures.
Automotive
Responsibilities
Design and execute a comprehensive cybersecurity strategy and roadmap that addresses both internal IT security and external product/application security
Conduct enterprise-wide maturity assessments using frameworks such as NIST CSF or ISO 27001; maintain a risk register and corrective action plans to close identified gaps
Lead risk management, vulnerability management, incident response, threat intelligence, and security awareness initiatives
Ensure security tools and processes (e.g., vulnerability management, MDR, cloud security, endpoint security) are effectively integrated into IT, engineering, and product workflows
Establish and oversee application security and secure SDLC practices; conduct assessments, baseline maturity, and drive remediation plans for external-facing technologies and software development processes
Manage and hold accountable external cybersecurity partners (MDR, CNAPP, MSSP) and ensure findings are prioritized and remediated on time
Build and manage a third-party risk management program, including vendor security assessments and ongoing monitoring
Ensure data classification, retention, and privacy controls meet regulatory and customer requirements
Oversee security audits and ensure compliance with industry frameworks and regulatory requirements (e.g., NIST, ISO 27001, SOC2, data privacy laws)
Represent the company’s cybersecurity posture during customer security reviews, RFPs, and contractual assessments, building confidence and trust in company practices
Define and track cybersecurity KPIs and KRIs to measure posture and drive continuous improvement; provide periodic updates to senior leadership on posture and risks
Foster a security-minded culture and develop internal capability (directly and through external partners) to meet evolving threats
Perform other duties as required to support the cybersecurity mission and enterprise objectives
Qualification
Required
Bachelor's Degree in Information Security, Computer Science, or a related field
10+ years of progressive cybersecurity experience with a strong record of building or significantly maturing security programs
Broad expertise in internal IT security, cloud security (Azure, AWS), vulnerability management, and data protection
Proven track record of leading operations within multi-cloud environments and using security tools for threat detection, monitoring, and response
Track record of conducting enterprise-wide assessments and building corrective action plans using frameworks such as NIST CSF, ISO 27001, or SOC2
Hands-on experience with SIEM, endpoint security, DLP, vulnerability management, and M365 security tools
Experience leading application security and secure SDLC initiatives, including assessing and governing security in software development environments
Ability to engage with engineers and developers on application and product security while also managing operational IT security
Demonstrated strength in representing cybersecurity posture to executives, customers, and auditors
Experience managing outsourced security partners (MDR, CNAPP, MSSP) and coordinating with IT, engineering, product, and business leaders
Administration and Management - Knowledge of business and management principles involved in strategic planning, resource allocation, human resources modeling, leadership technique, production methods, and coordination of people and resources
Leadership – Exhibits confidence in self and others; inspires and motivates other to perform well; effectively influences actions and opinions of others; accepts feedback from others; gives appropriate recognition to others
Computer Proficiency – Ability to manipulate datasets using SQL, Excel and other data wrangling tools. Experience in BI/Visualization tools is a plus. Strong understanding of ERP data structure and data model creation. Experience with the Azure data platform a plus
Quality Control Analysis - Conducts tests and inspections of data to evaluate the quality of data submissions. Attention to detail is critical to detect defects that could be easily missed
Communication Skills - Work requires professional written and verbal communication, the ability to write clearly, succinctly, and understandably. Ability to participate in and facilitate group meetings
Active Listening - Giving full attention to what other people are saying, taking time to understand the points being made, asking questions as appropriate, and not interrupting at inappropriate times
Interpersonal Relationships – Ability to build rapport and relate well to all kinds of people, treats all people with respect, courtesy and consideration, respects differences in attitudes and perspectives of others. Listens, observes, and strives to gain understanding of others
Personal Accountability - Accepts personal responsibility for the consequences of personal actions; avoids placing unnecessary blame on others
Detail Oriented – Possesses a high attention to detail and can process multiple data requirements accurately and in a timely manner
Time Management - Managing one's own time and the time of others. Ability to motivate teams to produce quality materials within tight timeframes and simultaneously manage several projects
Judgment and Decision Making - Considers the relative costs, benefits, impact or consequences of potential actions to choose the most appropriate one. Ability to make decisions in a timely manner
Critical Thinking - Using logic and reasoning to identify the strengths and weaknesses of alternative solutions, conclusions or approaches to problems
Preferred
Master's degree preferred
CISSP, CISM, or similar certifications strongly preferred
Relevant security certifications (e.g. CISSP, CISM) are strongly preferred
Benefits
100% employer paid medical plan
401(k) match
Additional medical plans
Dental
Vision
Flex spending account
Short-term and long-term disability & life insurance coverage
Company
Sonny's Enterprises Inc. - Conveyorized Car Wash Equipment Leader
With complete tunnel systems in each of the 50 United States and equipment in countries worldwide, Sonny's equipment delivers millions of clean, dry, shiny cars each year, around the globe.
Funding
Current Stage
Late StageTotal Funding
unknownKey Investors
Genstar Capital
2020-08-06Private Equity
Recent News
2025-08-24
2025-08-23
Company data provided by crunchbase