Sr. Manager of Security Operations, Incident Response

Reposted Yesterday
Be an Early Applicant
Raleigh, NC, USA
In-Office
Senior level
Automotive • eCommerce • Retail
The Role
Leads the enterprise Security Operations Center and incident response program, overseeing 24/7 monitoring, detection, threat hunting, cyber crisis management, and operational resilience. The role directs incident containment and recovery, improves detection engineering and automation, manages threat intelligence and preparedness exercises, reports security metrics to executives and the board, and develops cybersecurity operations personnel. Requires extensive cybersecurity leadership experience and knowledge of industry frameworks, security technologies, and process improvement methodologies.
Summary Generated by Built In
Job Description

The Sr. Manager, Security Operations is a senior cybersecurity leadership role responsible for leading Advance Auto Parts' enterprise security monitoring, detection, incident response, cyber crisis management, threat hunting, and operational resilience capabilities.

This leader is accountable for the strategic direction, operational effectiveness, and continuous improvement of the Security Operations Center (SOC) and Incident Response (IR) program. The role is responsible for ensuring threats are rapidly detected, investigated, contained, eradicated, and remediated while minimizing risk to business operations, customers, team members, and company reputation.

The Sr. Manager will partner across Cybersecurity, Technology, Legal, Privacy, Corporate Communications, Risk Management, Store Operations, Supply Chain Operations, and Business Leadership to advance the company's cyber defense capabilities and strengthen enterprise resilience against modern threats, including ransomware, identity-based attacks, cloud compromises, insider threats, and third-party breaches.

This role is based out of our corporate headquarters in Raleigh, NC. This is a hybrid work model (4 days in office, 1 day work from home)

Security Operations Leadership

  • Lead and mature Advance Auto Parts' Security Operations Center (SOC) capabilities.
  • Oversee 24x7 security monitoring, triage, escalation, analysis, and response activities.
  • Develop and execute the roadmap for security operations, detection engineering, threat hunting, and operational maturity.
  • Establish and track service-level objectives, KPIs, and operational metrics.
  • Drive continuous improvement of security operations processes, procedures, workflows, and automation.

Incident Response & Cyber Crisis Management

  • Own and manage the enterprise Cybersecurity Incident Response Program.
  • Serve as Incident Commander during high-severity cybersecurity events.
  • Lead response activities for ransomware, malware outbreaks, business email compromise, credential theft, cloud compromise, insider threats, and major security incidents.
  • Coordinate containment, eradication, recovery, and business restoration efforts.
  • Lead executive communications during significant cyber events.
  • Ensure alignment with legal, regulatory, compliance, privacy, and cyber insurance requirements.

Threat Intelligence

  • Drive improvements in enterprise detection capabilities across cloud, endpoint, network, identity, applications, and third-party environments.
  • Partner with Engineering and Architecture teams to improve detection coverage and response automation.
  • Lead use case development aligned to MITRE ATT&CK and emerging threat intelligence.
  • Establish detection effectiveness metrics and continuously improve signal-to-noise ratios.
  • Oversee tuning and optimization of monitoring technologies.
  • Lead proactive threat hunting operations to identify advanced attacker activity.
  • Leverage threat intelligence to improve security monitoring, investigations, and response readiness.
  • Maintain visibility into threat actor activity, TTPs, emerging campaigns, and vulnerabilities impacting the retail industry.
  • Collaborate with external intelligence providers, ISACs, law enforcement, and industry partners.

Cyber Preparedness & Resilience

  • Lead tabletop exercises and cyber crisis simulations.
  • Conduct ransomware preparedness exercises and executive-level response testing.
  • Ensure incident response playbooks remain current and actionable.
  • Perform post-incident reviews and drive corrective actions.
  • Maintain enterprise readiness for significant cyber events.

Metrics, Reporting & Governance

  • Develop operational dashboards and executive reporting.
  • Present security operations metrics, incident trends, threat intelligence insights, and program maturity updates to executive leadership.
  • Report on:
    • Mean Time to Detect (MTTD)
    • Mean Time to Respond (MTTR)
    • Incident Severity Trends
    • Detection Effectiveness
    • Threat Hunting Outcomes
    • SOC Performance Metrics
    • Automation Effectiveness
  • Support Board, Audit Committee, and executive cybersecurity reporting.

Leadership & Talent Development

  • Lead, mentor, and develop security analysts, incident responders, threat hunters, and detection engineers.
  • Build a high-performing cybersecurity operations culture focused on accountability, resilience, and continuous improvement.
  • Establish workforce development plans and professional growth opportunities.
  • Support recruiting and retention of cybersecurity talent.

Qualifications:

  • 10+ years of experience in cybersecurity, incident response and threat intelligence with a strong focus on operational excellence.
  • Proven leadership experience in security architectures, security tools and controls, cloud, operations, governance, or risk management.
  • Strong background in process improvement methodologies (Lean, Six Sigma, ITIL, Agile).
  • Experience with cybersecurity frameworks (NIST, ISO 27001, MITRE ATT&CK).
  • Familiarity with security technologies (SIEM, SOAR, EDR, cloud security tools, vulnerability management).
  • Excellent communication and leadership skills to drive alignment across security, IT, and business teams.

Preferred Qualifications:

  • Certifications: CISSP, CISM, CISA, ITIL,
  • Experience in large-scale, complex organizations or highly regulated industries.
  • Expertise in cybersecurity automation and analytics.
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age national origin, religion, sexual orientation, gender identity, status as a veteran and basis of disability or any other federal, state or local protected class. We comply with all applicable federal, state, and local laws.

California Residents click below for Privacy Notice:

https://jobs.advanceautoparts.com/us/en/disclosures

Skills Required

  • 10+ years of experience in cybersecurity, incident response, and threat intelligence, with a strong focus on operational excellence
  • Proven leadership experience in security architectures, security tools and controls, cloud, operations, governance, or risk management
  • Strong background in Lean, Six Sigma, ITIL, or Agile process improvement methodologies
  • Experience with NIST, ISO 27001, and MITRE ATT&CK cybersecurity frameworks
  • Familiarity with SIEM, SOAR, EDR, cloud security tools, and vulnerability management
  • Excellent communication and leadership skills to align security, IT, and business teams
  • CISSP, CISM, CISA, or ITIL certification
  • Experience in large-scale, complex organizations or highly regulated industries
  • Expertise in cybersecurity automation and analytics

Advance Auto Parts Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Advance Auto Parts and has not been reviewed or approved by Advance Auto Parts.

  • Retirement Support Benefits are described as including a 401(k) plan with company matching, which is repeatedly positioned as a notable strength. Retirement tools like HSAs/FSAs and related financial protections (life and disability coverage) further reinforce the sense of baseline financial support.
  • Healthcare Strength Health coverage is presented as broad, including medical, prescription, dental, and vision options, with additional supplemental medical plans. Eligibility beginning shortly after hire for full-time roles is framed as a practical advantage for accessing coverage earlier in tenure.
  • Leave & Time Off Breadth Paid time off is described as accruing and increasing with tenure, and parental leave is included among the offerings. Flexible PTO for longer-tenured employees is positioned as an added offset for a subset of roles.

Advance Auto Parts Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Raleigh, North Carolina
24,252 Employees

What We Do

Advance Auto Parts, Inc. is a leading automotive aftermarket parts provider that serves both professional installer and do-it-yourself customers. As of January 3, 2026, Advance operated 4,305 stores primarily within the United States, with additional locations in Canada, Puerto Rico and the U.S. Virgin Islands. The Company also served 809 independently owned Carquest branded stores across these locations in addition to Mexico and various Caribbean islands. Additional information about Advance, including employment opportunities, customer services, and online shopping for parts, accessories and other offerings can be found at www.AdvanceAutoParts.com.

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

Business Systems Analyst

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Charlotte, NC, USA
40000 Employees
88K-150K Annually

Collectors Logo Collectors

Staff Engineer

Consumer Web • eCommerce • Machine Learning • Software • Sports • Analytics
In-Office or Remote
2 Locations
2246 Employees
166K-269K Annually

CrowdStrike Logo CrowdStrike

Security Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
120K-180K Annually

CrowdStrike Logo CrowdStrike

Senior Consultant

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
115K-160K Annually

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account