About Rack Room Shoes:
Rack Room Shoes is recognized as a footwear industry innovator and has proudly served our communities, pairing people with their favorite shoes for over 100 years. We offer a great variety of on-trend styles for women, men and children in athletic, comfort and dress categories. We pride ourselves on a delightful and trusted shopping experience for our valued customers while offering an outstanding value on a wide selection of nationally recognized brands and exclusive private labels. We operate approximately 515 stores in 37 states.
Why Join Us?
At Rack Room Shoes, technology is a critical driver of our business success. As part of our IT team, you will play a key role in shaping the future of our enterprise data environment, supporting innovation, business intelligence, and data-driven decision-making across the organization. We value collaboration, continuous improvement, and forward-thinking solutions that enhance performance and scalability. If you are passionate about building reliable, high-performing data platforms and want to make a meaningful impact in a dynamic retail environment, we invite you to join our team and help drive our digital transformation journey.
Position Summary:
Responsible for defining, leading, and continuously improving the enterprise cybersecurity program for Rack Room Shoes. Owns cybersecurity strategy, governance, risk posture, security architecture, and cyber resilience, ensuring alignment with business priorities, regulatory requirements, and evolving threats.
Provides executive-level leadership across security operations, engineering, governance, compliance, risk management, and incident response while partnering with technology and business leaders to reduce risk and strengthen the organization’s security maturity.
Serves as the primary advisor to the CIO and executive leadership team on cybersecurity strategy, risk management, regulatory compliance, and cyber resilience. Establishes security frameworks, policies, and standards; oversees security operations and third-party partners; and guides investment decisions to protect company systems, networks, applications, customers, associates, and data assets.
Essential Functions:
- Serve as the accountable executive owner of enterprise cybersecurity risk, governance, and overall program effectiveness
- Define and execute the enterprise cybersecurity strategy, roadmap, and target maturity model
- Establish and maintain cybersecurity governance, policies, standards, and best practices
- Own the organization’s overall cyber risk posture, including identification, assessment, mitigation, and reporting of cybersecurity risks
- Provide executive-level reporting on cybersecurity posture, key risks, security metrics, and investment priorities
- Present cybersecurity strategy, risk posture, and investment recommendations to executive leadership and governance committees
- Own and lead the PCI DSS compliance program, including annual assessments, remediation efforts, audit coordination, and continuous compliance monitoring
- Ensure cybersecurity controls align with high-availability retail and eCommerce environments, balancing security with uptime and customer experience
- Oversee cybersecurity controls supporting retail store operations, point-of-sale systems, eCommerce platforms, cloud environments, corporate systems, and third-party services
- Direct security operations including monitoring, threat detection, incident response, recovery, and threat intelligence activities
- Lead crisis management efforts during significant cybersecurity incidents and coordinate cross-functional response activities
- Direct and guide security engineering, governance, and operations teams to ensure effective execution and continuous improvement
- Establish clear separation of responsibilities across security engineering, security operations, governance, risk, and compliance functions
- Oversee vulnerability management, threat detection, security monitoring, penetration testing, and enterprise remediation efforts
- Ensure continuous improvement of monitoring, detection capabilities, incident response readiness, and cyber resilience
- Define and maintain enterprise security architecture standards aligned with business and technology strategies
- Lead identity and access management (IAM) strategy, including MFA, identity governance, privileged access, and zero trust capability development
- Establish and manage third-party cybersecurity risk management processes for vendors, service providers, and technology partners
- Manage relationships with third-party security partners and ensure service effectiveness and contractual compliance
- Evaluate, approve, and oversee implementation of security technologies, platforms, and vendor engagements
- Lead enterprise security awareness and training initiatives
- Partner with Legal, HR, Finance, Internal Audit, and Technology teams to align cybersecurity initiatives with enterprise priorities
- Partner with Infrastructure and Business Continuity teams to ensure disaster recovery readiness, ransomware preparedness, and overall cyber resilience
- Recruit, develop, mentor, and retain cybersecurity talent while building a high-performing security organization
- Define and evolve the cybersecurity organizational structure to support program scale and maturity
- Develop and manage cybersecurity budgets, investments, resource planning, and strategic staffing plans
- Establish and report cybersecurity KPIs and KRIs aligned to business risk, regulatory expectations, and executive decision-making
- Drive continuous program improvement through benchmarking, maturity assessments, and industry best practices
- Own cybersecurity governance and technology-related data privacy controls, ensuring protection of customer, associate, and enterprise information assets.
Knowledge, Skills, and Abilities:
- Strong understanding of cybersecurity frameworks, governance, risk management, compliance, and security operations disciplines
- Deep knowledge of enterprise security architecture, network security, cloud security, identity management, and modern threat landscapes
- Proven ability to develop and execute cybersecurity strategy within a complex enterprise environment
- Strong leadership and organizational skills with the ability to influence across multiple business and technology functions
- Ability to translate technical risks into business impact and executive-level decision-making
- Experience managing incident response, crisis coordination, and post-incident improvement initiatives
- Strong knowledge of security monitoring, threat detection, vulnerability management, and remediation practices
- Ability to evaluate and implement cybersecurity technologies, platforms, and managed security services
- Excellent communication, presentation, and stakeholder engagement skills
- Strategic thinker with a strong focus on risk reduction and business alignment
- Strong decision-making ability under pressure, particularly during cybersecurity incidents
- High level of integrity, accountability, and professionalism
- Collaborative leader capable of building strong relationships across technical and business teams
- Analytical, proactive, and continuously focused on improving organizational security posture
- Ability to balance security requirements with business objectives and operational realities
Minimum Requirements:
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or related field required
- 12+ years of progressive experience in cybersecurity, information security, network security, or related disciplines
- 7+ years of leadership experience managing cybersecurity teams, programs, budgets, and strategic initiatives
- Experience leading enterprise cybersecurity programs across strategy, governance, architecture, engineering, operations, and compliance
- Experience operating within regulated environments including PCI DSS and related compliance frameworks
- Experience supporting multi-location retail, restaurant, hospitality, or other distributed enterprise environments preferred
- Experience managing third-party security providers and cybersecurity consulting engagements preferred
- Preferred Certifications: CISSP, CISM, CRISC, CCSP, or equivalent industry certifications
Work Environment:
- This position is located in Charlotte, NC and the candidate must be willing to relocate, if not already in the Charlotte Metro area.
Working primarily in an office environment.
We are an Equal Opportunity Employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic.
The above statements are intended to describe the general nature and level of work being performed by individuals assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties, and skills requires of the position. All employees may have other duties assigned at any time.
Rack Room Shoes provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex (including pregnancy, sexual orientation and gender identity), national origin, marital status, disability, genetic information, age, military service, or any other characteristic that is protected by applicable law. This policy of equal employment opportunity extends to all aspects of employment including, but not limited to, recruitment, hiring, training, promotion, transfer, reassignment, demotion, discipline, discharge, performance evaluation, compensation and benefits.