Jobs and Careers
CA

VP, Information Security

Cars.com
United States, Remote, United StatesRemotefull_timeVerifiedPosted 10 Oct 2023

About the role

Discover Your Possibilities at CARS

Here at CARS, we are constantly developing technology that innovates how customers and dealers buy and sell their vehicles. In 1998, we invented the car search with Cars.com and revolutionized the way the industry does business. Now, we bring that same boldness, energy, and drive to optimizing solutions across our brands every single day. We are constantly creating new possibilities, traversing uncharted routes and welcoming challenges along the way.

No one ever travels alone here: at its core, CARS is collaboration. Whether it is within individual teams, across departments, or the company at large, our employees support one another across every dimension of life at CARS. We operate as a collective, utilizing all of our diverse strengths to approach problems from every single angle, united by our award-winning company culture and our mission to make car shopping the best experience possible.

As a U.S. News & World Report Best Company to Work For in 2024, we're obsessive about the employee experience. We are among the top 20% being declared “Best” of our industry based on six critical factors that are important to employee wellbeing, like quality of pay, benefits, work life balance and more.

CARS includes the following brands: Cars.com, Dealer Inspire, DealerRater, FUEL, CreditIQ & Accu-Trade. Learn more here!

About the Role

Job Duties:

  • Develops, leads and implements Information Security policies, practices, and programs for the Company, with responsibility for overseeing the overall strategy, design, implementation, and compliance of information security initiatives across the Company.
  • Responsible for company-wide compliance with Information Security Standards and Policies, including relevant certifications such as ISO 27001, PCI, and SOC 2.
  • Directly connected to Executive engagement through a reporting line to the Chief Technology Officer with matrix reporting to the Chief Legal Officer and Chief Financial Officer.  Additionally, supporting a cadence of reporting to the Audit Committee of the Board of Directors on strategy, issues and remediation.
  • Directs the planning, implementation, monitoring, and investigation of all applications, systems, and business operation defenses against security breaches, cybersecurity crimes and vulnerability issues.
  • Defines and ensures the implementation of critical information security strategies, threat and vulnerability management plans, oversees the ongoing risk assessments, security architecture and engineering. 
  • Develops and communicates guidelines and controls to mitigate risks and to ensure compliance with legal and contractual requirements and corporate security to safeguard a secure business environment. 
  • Responsible for the development, direction, coordination and execution of business continuity and disaster recovery plans with businesses and the Technology organization.
  • Promote a culture of strong information security, and to facilitate broad security cultural change across their organization, this role should act as a thought leader, continually communicating their strategy and vision. Effectively tailoring communications to different parts of the organization and being topical for the intended audience.
  • Cybersecurity awareness and training by keeping the Company well informed about the latest cybersecurity threats, development and improvement of the Company's cybersecurity awareness and training program, and overseeing its implementation.
  • Oversees information security personnel and develops the team structure, roles, and operating model for those personnel to support each of these areas of responsibility.

Experience & Qualifications:

  • Bachelor’s Degree with a Major in Computer Science, Technology, Information Security; or equivalent, relevant work experience.
  • At minimum one relevant Industry Certification preferred: C|CISO, CISSP, CISM, CISA, or CRISC.
  • Demonstrated experience in a variety of Cybersecurity Frameworks such as NIST, MITRE, ISO 27001, SOX, HITRUST, CCPA, GDPR.
  • Regulated or Large/Global Industries – Prior experience working in a highly regulated or large/global enterprise.
  • Transformation & Cloud – Prior experience conducting security transformations driving technology change to cloud and cloud-enabled solutions.
  • Executive Presence – Effective communicator that can distill technical issues into business terms and language by successfully working with senior leaders, board and audit/risk commit

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Cars.com

View company profile →