The VP, Cybersecurity is a senior security leader responsible for building and running Classic Collision's cybersecurity program — from security operations and threat detection through governance, risk, and compliance. This role is the CIO's key partner in establishing a security foundation for a company that is still early in its formal security maturity, and in making sure that foundation holds up as the company continues to scale through acquisition.
This is a working VP role: this person leads the security function and sets direction but is also expected to roll up their sleeves — tuning detections, working directly with vendors and auditors, writing or reviewing policy, and getting into incident response when it matters, not just directing from above. This is a hands-on leadership role suited to someone who can operate at both the strategic level (security architecture, vendor strategy, risk prioritization) and the operational level (incident response, detection engineering, closing real gaps) in a fast-paced, multi-unit, PE-backed environment.
Security Operations & Threat Detection
- Own day-to-day security operations across Classic Collision's stack (Microsoft Sentinel, Microsoft Defender, Microsoft 365 E5, SentinelOne, Check Point, Fortinet, and related tooling)
- Lead oversight of a Managed Detection & Response (MDR) partner, and manage that relationship going forward
- Personally close detection and monitoring gaps — including hands-on work building or refining detection logic and escalation paths — rather than only assigning it to the team
- Own identity management (e.g., Entra ID conditional access, MFA-fatigue detection and escalation) end to end
- Lead the Vulnerability Management program
- Own asset inventory and configuration management as the foundation for detection, incident response, and vulnerability management across a distributed, multi-site estate
- Own Data Loss Protection including endpoint, email, cloud and insider risk
- Own Cloud security Governance (Cloud posture management (CSPM), Cloud identity governance, Cloud Workload protection (CWPP), etc.)
- Develop a security testing program (penetration testing, red team, tabletop exercises)
Security Architecture & Engineering
- Define and maintain the security architecture strategy and standards across infrastructure, identity, endpoint, network, and cloud
- Partner with the VP, Enterprise Technology & Delivery and Director of IT Operations to ensure security is designed into new systems, integrations, and architecture decisions rather than bolted on afterward
- Establish application and product security practices for internally developed and customer-facing systems, including secure development standards, code and dependency scanning, and security review of new applications and integrations
- Lead technical responses to specific incidents and exposures (e.g., help-desk impersonation and social-engineering attempts, external collaboration hardening) with direct hands-on involvement
Governance, Risk & Compliance (GRC)
- Build Classic Collision's IT/security policy program (development and enforcement) essentially from the ground up, sequencing and prioritizing the policy set the business needs
- Oversee the cyber governance, regulatory compliance (e.g., PCI), audit relationships (both internal and external) and certification processes
- Establish a practical risk management framework appropriate to the company's size, pace, and PE-backed environment — enough rigor to be defensible, without slowing the business down
- Prepare the organization for future compliance, insurance, or diligence-driven requirements as the company scales
- Own the enterprise cyber risk register and risk acceptance processes
- Partner & design data governance and privacy — data classification, retention, and handling standards, and readiness for state privacy obligations — in coordination with Legal and IT
- Build and sustain a strong security culture through training, awareness, and partnership with business leaders
- Ensure contracts contain comprehensive and clearly defined cybersecurity provisions
- Build & run a third-party security risk program
Incident Response
- Own incident response process, playbooks, and readiness, and personally lead response for significant incidents
- Run or oversee root-cause analysis for security incidents and ensure identified gaps are closed, not just documented
- Serve as the executive point of contact for security incidents, including communication to the CIO and other executive stakeholders
- Partner with IT Operations on business continuity and disaster recovery — including backup and recovery integrity, ransomware recoverability, and regular exercise of continuity plans
Leadership
- Build, mentor, and scale a security team as the function matures beyond its current early stage
- Own the Cybersecurity budget ensuring effective multi-year security investment planning, cost optimization and effective forecasting for tool, MDR, staffing and compliance.
- Own Security metrics and reporting (define KPIs/ KRIs, regular reporting, etc.)
- Partner closely with the Director of IT Operations and the VP of Enterprise Technology & Delivery — fellow members of the IT leadership team — to ensure security is coordinated with infrastructure/operations and applications/architecture priorities
- Represent cybersecurity in executive, board, and M&A due-diligence discussions as needed
- Balance a working-manager style: lead and grow the team, while staying close enough to the work to contribute directly when the situation calls for it
- Deputize for the CIO on security matters as needed
- 10+ years of progressive cybersecurity experience, including leadership of security operations and/or GRC function
- Direct, hands-on experience with a Microsoft-centric security stack (Sentinel, Defender, Entra ID) and endpoint/network security tools (e.g., SentinelOne, Check Point, Fortinet, or equivalents)
- Experience selecting and managing an MDR or MSSP partner
- Experience building a security policy and governance program from limited or early-stage maturity
- Strong incident response experience, including leading response to real incidents (not just tabletop exercises)
- Comfortable operating as a "working VP" — willing and able to get into the details (detection tuning, policy drafting, vendor contracts, live incidents) rather than leading purely through delegation
- Experience operating in a private equity-backed, multi-unit, or high-growth environment a plus
- Relevant certifications (e.g., CISSP, CISM) preferred but not required
- Bachelor's degree in a related field required; advanced degree a plus
- A security operations function with reliable detection and response coverage, backed by a well-managed MDR partnership
- A functioning policy and governance program built from the ground up, with a clear, prioritized roadmap the business can act on
- Fast, well-led response to security incidents, with root causes actually closed rather than reopened
- A security posture that stands up to the scrutiny of future compliance, insurance, and M&A diligence requirements
Physical & Environmental
While performing the duties of this job, the employee is regularly required to use their hands and is required to talk and hear. The employee is frequently required to stand, sit, and walk occasionally for long periods at a time. The employee may occasionally be required to reach with hands, and arms and move objects up to 20 pounds. Specific vision abilities required by this job include close vision, peripheral vision, and the ability to adjust focus. In addition, abilities for assessing the accuracy, neatness, and thoroughness of the work assigned are required. The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodation may be provided to enable individuals with disabilities to perform essential functions.
Classic Collision is an Equal Opportunity Employer
As an equal opportunity employer, Classic Collision does not discriminate against any employee or candidate based on age, race, gender identity, gender expression, genetic information, national origin, physical or mental disability, protected veteran status, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by all applicable federal, state, and local laws.
Reasonable Accommodations:
Classic Collision is an equal opportunity employer that is committed to working with and providing reasonable accommodations to individuals with disabilities. If you have a disability and you believe you need reasonable accommodation to search for a job opening or submit an online application, please e-mail [email protected] or call (470)500-6808. This email is listed exclusively to assist disabled job seekers whose disability prevents them from being able to apply online.
This job description is not a complete statement of all duties and responsibilities comprising the position.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.