Head of Cybersecurity, Risk & Compliance

CarParts.comLong Beach, CA

About The Position

CarParts.com is the go-to eCommerce platform for auto care and maintenance. We provide drivers with quality parts at competitive prices and enable them to schedule appointments with trusted mechanics directly through our website. Using world-class design principles and the latest technologies, we deliver a fast, intuitive digital experience backed by our company-owned national distribution network. With over 1,000 employees worldwide, we are scaling rapidly, fueled by our most recent strategic partnership and $35 million investment. This positions us for the next phase of growth as we continue to empower drivers along their journey. Our Culture At CarParts.com, our culture goes beyond our core values of Safety First, Customer Focused, and Commitment to Excellence. We are a performance-driven, data-focused, and fast-paced team where results matter and winning is expected. - Hungry & Hardworking: We set ambitious goals, measure progress with clear metrics, and hold ourselves accountable to deliver results. - Promote from Within: We reward top performers with opportunities for growth and advancement. - Collaborative & In-Person: We believe the best ideas and fastest execution happen face-to-face. - High Standards: We move quickly, pay attention to details, and dig deep - whether it’s analyzing contracts, aggregating complex scenarios, or building clear, data-driven presentations. - No Passengers: We value grit, ownership, and the relentless pursuit of results. Role Summary Head of Cybersecurity, Risk & Compliance separates technical security execution from risk governance, ensuring CarParts.com's security posture, regulatory compliance (PCI, SOX), and audit-readiness stay board-visible. This role reports directly to the CTO and closes the governance gap left by the departing AVP of Infrastructure and Security.

Requirements

  • 8+ years in cybersecurity/GRC
  • 3+ in a leadership role
  • Direct experience with PCI-DSS and SOX control environments
  • Experience presenting to audit committees or boards
  • Track record building or scaling a GRC function

Nice To Haves

  • CISSP, CISM, or equivalent certification
  • eCommerce/retail security experience
  • Familiarity with NIST frameworks and SIEM tooling (e.g. Splunk, Elastic)

Responsibilities

  • Own security engineering: controls, hardening, and security tooling
  • Lead threat detection & response — monitoring, triage, and incident response
  • Drive governance, risk & compliance: policies, evidence, and control mapping
  • Own PCI & SOX controls: control ownership, testing, and remediation
  • Manage vendor and third-party risk reviews, contracts, and remediation
  • Deliver board-ready audit committee reporting on posture, risks, and exceptions

Benefits

  • A reasonable salary estimate for the role based on experience, education, and geographical location is: $195,000-$250,000
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service