Vice President, Chief Information Security Officer (CISO)

Driven Brands Inc.United States of America - Remote NC, NC
$199,200 - $355,800Remote

About The Position

The Vice President, Chief Information Security Officer (CISO) is responsible for leading the company’s enterprise cybersecurity strategy, governance, risk management, and security operations program. The CISO serves as the senior cybersecurity advisor to executive leadership, the Board of Directors, and the Audit Committee. This role translates cybersecurity risks into clear business, financial, regulatory, and operational terms and recommends appropriate investments, remediation priorities, and risk-treatment decisions. The CISO partners with Information Technology, Internal Audit, Legal, Privacy, Finance, Human Resources, Enterprise Risk Management, and business leadership to protect the company’s information assets, customers, employees, franchisees, and brand.

Requirements

  • Bachelor’s degree in cybersecurity, information systems, computer science, engineering, business, risk management, or a related field; advanced degree preferred.
  • Fifteen or more years of progressive cybersecurity, technology-risk, or related experience.
  • Significant experience leading an enterprise cybersecurity program in a complex, distributed, regulated, or publicly traded organization.
  • Demonstrated experience advising executive leadership, Boards, and Audit Committees.
  • Strong knowledge of cybersecurity frameworks, security operations, incident response, identity and access management, vulnerability management, cloud security, data protection, third-party risk, AI security governance, and regulatory compliance.
  • Experience supporting SOX IT general controls, audits, remediation programs, and business transactions.
  • Experience managing cybersecurity teams, budgets, vendors, and managed security providers.
  • CISSP or CISM certification required or strongly preferred. CRISC, CISA, CCSP, GIAC, or equivalent credentials are beneficial.

Nice To Haves

  • Experience in retail, automotive services, franchise, hospitality, restaurant, or other multi-location consumer-facing industries preferred.
  • Experience supporting organizations with multiple brands, decentralized operations, and complex third-party partner ecosystems preferred.

Responsibilities

  • Develop and execute a multi-year enterprise cybersecurity strategy aligned with business objectives, regulatory requirements, and risk appetite.
  • Establish cybersecurity policies, standards, controls, and governance based on recognized frameworks such as NIST, CIS Controls, and ISO 27001.
  • Define accountability for cybersecurity across corporate functions, brands, technology teams, franchise environments, and third-party providers.
  • Evaluate emerging threats, technologies, regulations, and business risks.
  • Serve as the principal cybersecurity advisor to executive leadership, the Board, and the Audit Committee.
  • Establish and maintain a standardized cybersecurity scorecard that tracks progress against defined goals, key risk indicators, control maturity, strategic initiatives, and remediation commitments quarter over quarter.
  • Present scorecard results to executive leadership and the Board, highlighting progress, emerging risks, performance gaps, overdue actions, and matters requiring executive or Board attention.
  • Report on cybersecurity posture, material risks, incidents, control maturity, strategic initiatives, and remediation progress.
  • Advise leadership regarding cybersecurity investments, risk acceptance, and significant control exceptions.
  • Lead the identification, assessment, prioritization, treatment, and monitoring of enterprise cybersecurity risks.
  • Maintain the cybersecurity risk register and integrate material cyber risks into the enterprise risk management process.
  • Oversee security-related compliance obligations, including SOX, PCI DSS, privacy requirements, and contractual commitments.
  • Partner with Internal Audit, external auditors, Finance, and Legal to support audit readiness and timely remediation of findings.
  • Provide independent challenge regarding control deficiencies, exceptions, compensating controls, and accepted risks.
  • Provide executive oversight of security monitoring, detection, threat intelligence, investigation, containment, and response.
  • Oversee security technologies and services, including SIEM, SOAR, EDR/XDR, email security, cloud security, data protection, and managed security providers.
  • Lead the response to significant cybersecurity incidents and coordinate with Technology, Legal, Privacy, Communications, Finance, Human Resources, insurers, forensic firms, and law enforcement.
  • Maintain and test cybersecurity incident-response plans, escalation procedures, executive communications, and crisis-management processes.
  • Drive corrective actions through post-incident reviews and root-cause analysis.
  • Establish security governance for identity lifecycle management, multifactor authentication, privileged access, access reviews, segregation of duties, and non-human identities.
  • Oversee the enterprise vulnerability and exposure management program.
  • Define risk-based remediation, exception, escalation, and reporting requirements.
  • Establish security controls for confidential, personal, financial, employee, customer, and franchisee information.
  • Partner with Legal and Privacy leaders on data-protection and privacy obligations.
  • Establish enterprise security architecture principles and secure-design standards.
  • Provide cybersecurity oversight for cloud adoption, applications, digital products, major technology changes, artificial intelligence, and emerging technologies.
  • Partner with Technology, Legal, Privacy, Risk, and business leadership to establish governance for the secure and responsible use of artificial intelligence.
  • Define cybersecurity and data-protection requirements for the evaluation, acquisition, development, deployment, and use of artificial intelligence technologies.
  • Assess and monitor AI-related risks, including sensitive-data exposure, unauthorized use, third-party model risk, access control, regulatory compliance, and model manipulation.
  • Ensure AI initiatives are subject to appropriate security assessment, approval, monitoring, and periodic review.
  • Ensure security requirements are incorporated into architecture, procurement, development, implementation, and change processes.
  • Partner with infrastructure, application, cloud, data, and architecture teams without assuming responsibility for their day-to-day operations.
  • Lead the third-party cybersecurity risk management program, including due diligence, assessments, contracting requirements, monitoring, and reassessment.
  • Evaluate risks associated with critical vendors, cloud providers, payment environments, franchise platforms, and outsourced services.
  • Lead cybersecurity due diligence and risk planning for mergers, acquisitions, integrations, divestitures, and transition-service arrangements.
  • Ensure material third-party and transaction-related risks are communicated to executive leadership.
  • Establish cyber-resilience requirements and ensure cyberattack scenarios are included in business continuity and disaster-recovery planning.
  • Maintain oversight of ransomware readiness, backup protection, recovery access, and cyber-recovery testing without owning infrastructure recovery operations.
  • Lead enterprise cybersecurity awareness, phishing simulation, and role-based training programs.
  • Build and develop a high-performing cybersecurity organization.
  • Manage the cybersecurity budget, vendors, managed security providers, and strategic partners.

Benefits

  • paid time off
  • holiday pay
  • myFlexPay program (early access to earned wages)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service