Director, Technology Compliance

3 days ago


Richmond, United States CarMax Full time

Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 100 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row. Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical cybersecurity compliance capabilities?

Do you want to work with a team of talented professionals that have highly advanced technical knowledge and be the subject matter expert in technology compliance governance and audit compliance?

Then your job search begins and ends here….


Who we are looking for:

We are seeking a strategic and experienced Director of Technology Compliance with proven leadership skills, advanced subject matter expertise in IT compliance management, information security controls and IT auditing to lead our organization's compliance program across all Technology and Cybersecurity operations. This critical leadership role will be responsible for overseeing the development, implementation, and maintenance of compliance strategy, mission, frameworks, and roadmap that align with industry standards and regulatory requirements, ensuring the integrity, security, and reliability of our IT systems and data. This is a unique opportunity to join a Fortune 100 company and national brand to expand your skills and influence in the Cybersecurity Program.

The ideal candidate will possess deep knowledge of technology-related regulations, standards, and best practices, and be versed in negotiations with external assessors and influencing broadly. Perform highly advanced work, providing direction and guidance to leadership across different business areas throughout CarMax and its strategic partners. This position is responsible for ensuring that all technology initiatives and operations are compliant with applicable laws, regulations, and standards which govern publicly traded companies, retailers and financial institutes.

The IT Compliance Director’s primary responsibility is to provide compliance direction and assurance across the technology controls landscape to peers and senior leadership. This includes removing roadblocks to team success, strong collaboration with peers and business partners at all levels of the organization, strategic planning, and development of team members. Oversee and ensure the delivery of high-quality compliance and audit results, leading best-in-class SOX/ITGC, and IT compliance strategies to accomplish goals. You will be responsible for setting the direction, the design, and administration of the CarMax Compliance Mission, framework, strategic roadmap and processes, with a high concentration on Sarbanes-Oxley (SOX) and other regulatory compliance requirements including a continuous monitoring program to demonstrate program effectiveness. You will be overseeing an ever-evolving landscape, collaborating, and aligning regularly with internal and external stakeholders in a fast-paced environment that builds strong partnerships to ensure that technology delivers business value and enables the achievement of compliance objectives and key results.


The Day to Day:

Lead the creation, implementation, and oversight of a strategic compliance program to ensure organizational adherence to legal, regulatory, and internal standards.

Develop and execute a multi-year risk-based IT compliance plan endorsed by the CISO.

Develop and maintain the framework for technology compliance management including validation and classification methods, comprehensive IT compliance policies and procedures for technology to ensure and enforce compliance with all company policies, state and national regulations.

Evaluate the adequacy and effectiveness of the companies' internal financial, administrative, and operational information systems policies and controls. Ascertain the extent to which company assets are accounted for and safeguarded from inappropriate modifications or losses across lines of business.

Align recruiting, mentoring, and developing of the compliance analyst team with business goals, managing support and implementing strategic goals within IT. Foster strong team collaboration and conflict resolution, aligning efforts with CarMax’s technical and business standards.

Serve as trusted advisor and technology key controls subject matter expert.

Oversee the IT compliance team in the execution of testing, controls assessment and documentation across all domains for IT General Controls, SOX, PCI DSS, Data Privacy, HIPAA among others, to evaluate the effectiveness of existing controls, pinpointing control weaknesses and steering leaders on remediation.

Oversee and coordinate internal and external audits across the technology teams and lead external business partner compliance assessments.

Prepare and present clear and concise compliance reports to steering committee and senior management.

As an integral member of the team, exhibiting ownership, follow through, initiative, awareness and effective communication with peers and management and ability to speak to details of compliance.

Exemplify leadership in team development and support professional growth. Foster organizational maturity.

Champions technical compliance with cybersecurity related regulatory requirements (GLBA, CFPB, SOX, PCI, PII, NYDFS, HIPAA, etc) across the company by demonstrating ownership of the design aspects of the compliance lifecycle.

Collaborate broadly with Technology, Audit, Finance and third parties for assessment improvements.

Spearhead IT compliance training and awareness programs on technology compliance across the organization to foster a culture of compliance and ethical technology use with proven results.

Maintain a strong knowledge base and awareness of industry trends and emerging threats while also keeping a keen eye to changing external regulations to adapt core compliance processes accordingly.


Education and/or Experience:

Bachelor’s degree in Technology, Computer Science, Business, or a related field.

Master’s degree or relevant professional certification (e.g., CIA, CIPP, CRISC, CISM, GIAC, CISSP) is preferred. CISA required.

A minimum of 10 years of leadership experience in technology audit, compliance, in a publicly traded company with a concentration on SOX ITGC’s and PCI.

Extensive knowledge of auditing standards, relevant regulations and standards (e.g., GLBA, SOX, CFPB, NIST, COBIT, CIS, ISO 27001/2, HIPAA, CCPA, PCI-DSS) governing technology and data security in retail and financial context.

Excellent analytical, problem-solving, and decision-making skills; high level of accuracy and attention to detail.

Strong leadership and organizational skills; ability to manage multiple projects and teams in a fast-paced environment.

Exceptional interpersonal and communication skills, both written and verbal, with the ability to explain complex compliance issues to stakeholders at all levels.

Demonstrated leadership - ability to gain consensus across teams without direct reporting responsibility.

Strong leadership skills, with the ability to manage and mentor a team of compliance professionals.

Dedication and commitment to top-quality service and to exceeding customer expectations.

Proven ability to influence without authority the compliance direction of others.

Proven ability to effectively communicate prevention and remediation approaches via leading practices.

Ability to build relationships that help overcome obstacles and time constraints to successfully deliver remediation to completion.

Demonstrated ability to assess alternative technology compliance approaches and methodologies while assessing Compliance both quantitatively and qualitatively to meet the business needs.



Work Location and Arrangement: This role will be based out of the Richmond, VA Technology Innovation Center and have a Hybrid work arrangement.

Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis.



  • Richmond, United States CarMax Full time

    Do you want to play a key role in enhancing the Cybersecurity program for a Fortune 100 company and national brand that has also been listed on the Fortune 100 Best Places to Work for the past 20 years in a row. Do you enjoy working in a collaborative environment where your experience and ideas can shape the direction and development of critical...


  • Richmond, United States CarMax Full time

    Are you eager to enhance a robust Cybersecurity program for a top Fortune 100 company renowned for its exceptional workplace culture? If you thrive in collaborative environments where your insights can significantly impact critical cybersecurity compliance capabilities, then this opportunity is for you! We are seeking a strategic and experienced Director of...


  • Richmond, California, United States Jumpstart Consultants, Inc. Full time

    Key ResponsibilitiesThe Compliance and Process Excellence Director will be responsible for leading all Engineering and Compliance functions with vision and accountability, designing and implementing innovative processes across manufacturing, IT, AI, and automation.You will ensure compliance with Health & Safety regulations while fostering a culture of...


  • Richmond, California, United States CarMax Full time

    Job OverviewThis is a unique opportunity to join CarMax as a key member of our technology team and expand your skills and influence in the Cybersecurity Program. As an IT Compliance Director, you will be responsible for providing compliance direction and assurance across the technology controls landscape to peers and senior leadership, ensuring that all...


  • Richmond, California, United States Restaurant Technologies Full time

    OverviewAt Restaurant Technologies, we're revolutionizing the food service industry with our innovative bulk cooking oil management services. As an Operations Director, you'll be at the forefront of our growth strategy, driving double-digit expansion in the coming year.


  • Richmond, United States AMC Technology Full time

    Here at AMC Technology, we build robust software products that lead the industry in contact center and business application integration. DaVinci™ is the only orchestration platform specifically designed for enterprise customer engagement by improving the customer and agent experience.We're looking for a Director of Sales who will shape the future of AMC...


  • Richmond, United States AMC Technology Full time

    Here at AMC Technology, we build robust software products that lead the industry in contact center and business application integration. DaVinci™ is the only orchestration platform specifically designed for enterprise customer engagement by improving the customer and agent experience.We're looking for a Director of Sales who will shape the future of AMC...


  • Richmond, California, United States Genworth Full time

    At Genworth, we empower families to navigate the aging journey with confidence. We are compassionate, experienced allies for those navigating care with guidance, products, and services that meet families where they are. Further, we are the spouses, children, siblings, friends, and neighbors of those that need care—and we bring those experiences with us to...


  • Richmond, United States Capital One Full time

    West Creek 1 (12071), United States of America, Richmond, VirginiaDirector, Software Engineering - Card TechnologyCapital One's Card Tech Engineering Organization is seeking a Director of Software Engineering to lead, manage, mentor, and build exceptional software engineering teams to deliver game changing technologies. The Director must have the ability to...


  • Richmond, California, United States Crescens Full time

    We are seeking an Enterprise Web Technology Administrator to join our team at Crescens. The successful candidate will be responsible for coordinating the delivery of enterprise web technology tools for the Commonwealth of Virginia web ecosystem.This role is within the Enterprise Solutions Directorate and requires a web technologist background with experience...


  • richmond, United States Software Technology Inc. Full time

    Job Title: .NET Application ArchitectLocation: Richmond, VA Seven years of progressive responsibility in an IT environment with demonstrated technical knowledge which provides the necessary skills, knowledge and abilities. Three years relevant Experience with enterprise-wide integration architecture in .net environment required.Experience designing and...


  • Richmond, California, United States Capital One Full time

    Capital One is seeking a Senior Director, Technical Program Management to work on a large integration project within our Card Technology organization.This role will drive execution of a cohesive roadmap across multiple workstreams in collaboration with our enterprise partners.The ideal candidate will have at least 9 years of experience in technical program...


  • Richmond, United States Apex Systems Full time

    IT COMPLIANCE ANALYSTWHO WE ARE Apex Systems is a leading global technology services firm that incorporates industry insights and experience to deliver solutions that fulfill our clients’ digital visions. We provide a continuum of services, including strategy and enablement, innovation and productivity, and technology foundations to drive better results...


  • Richmond, United States Apex Systems Full time

    IT COMPLIANCE ANALYSTWHO WE ARE Apex Systems is a leading global technology services firm that incorporates industry insights and experience to deliver solutions that fulfill our clients’ digital visions. We provide a continuum of services, including strategy and enablement, innovation and productivity, and technology foundations to drive better results...


  • Richmond, United States Capital One Full time

    Locations: NY - New York, United States of America, New York, New YorkDirector, Resiliency Advisory & Oversight, Technology Risk ManagementTechnology Risk Management (TRM) is a growing organization focused on providing expert advice, credible challenge, and effective oversight of information security and technology activities to identify, assess, control,...


  • Richmond, California, United States InsideHigherEd Full time

    Responsibilities and RequirementsWe are seeking a highly qualified candidate to fill the position of Director of Human Subjects Protection. The successful applicant will have significant experience in managing human research protections programs at an academic medical center and a proven track record of success in ensuring compliance with federal regulations...


  • Richmond, Virginia, United States Timmons Group Full time

    Job OverviewTimmons Group, a leading engineering and technology firm, is seeking a highly motivated Environmental Compliance Specialist to join our team in Richmond, VA.About the RoleWe are looking for an individual with strong environmental compliance skills and experience working on various projects, including construction of data centers, residential...

  • Utilities Director

    1 week ago


    Richmond, United States Sugarbush Resort Full time

    Utilities Director at Sugarbush Resort summary: The Utilities Director at Sugarbush Resort is responsible for overseeing all aspects of the resort's utilities operations, including compliance, financial planning, maintenance, and customer relations. The role involves ensuring safe, reliable, and environmentally compliant functioning of water and...

  • Utilities Director

    2 weeks ago


    Richmond, United States Sugarbush Resort Full time

    Utilities Director at Sugarbush Resort summary: The Utilities Director at Sugarbush Resort is responsible for overseeing all aspects of the resort's utilities operations, including compliance, financial planning, maintenance, and customer relations. The role involves ensuring safe, reliable, and environmentally compliant functioning of water and...

  • Utilities Director

    1 week ago


    Richmond, United States Sugarbush Resort Full time

    Utilities Director at Sugarbush Resort summary: The Utilities Director at Sugarbush Resort is responsible for managing the operations, maintenance, and regulatory compliance of water and wastewater systems. This role includes financial oversight, permit management, and developing budgets to ensure safe and efficient utility services. The position...