GP
VP & Chief Information Security Officer - Global Industrial
Genuine Parts Company
Birmingham, Alabama, US
Birmingham, Alabama, US (On-site)2 open jobs
Genuine Parts Company is a global distributor of automotive and industrial replacement parts operating nearly 6,000 NAPA stores and serving 190,000+ customers across North America, Europe, and Australasia.
Genuine Parts Company operates at a scale that makes its attack surface genuinely interesting. The 1928-founded distributor runs logistics, point-of-sale, and supply chain infrastructure across nearly 6,000 NAPA Auto Parts stores in the U.S., plus operations in Canada, Mexico, Europe, and Australasia. Its Industrial Parts Group connects over 190,000 MRO and OEM customers to more than 18 million replacement parts. That's a sprawling, decades-old estate of interconnected systems - legacy and modern - handling transactions, inventory, and partner integrations at a combined turnover exceeding $15 billion.
The threat model here is operational and distributed. A global parts distribution network spanning multiple continents means defending against supply chain compromise, credential abuse across partner portals, and securing a massive SKU catalog (800,000+ automotive parts alone) tied to logistics and fulfillment systems. The company's longevity - 70 consecutive years of dividend increases - implies institutional stability, but also likely means patchwork IT layers accumulated over decades. Cybersecurity roles here involve securing environments where uptime directly impacts physical-world operations: warehouses, shipping, and retail endpoints.
Domains likely in play include endpoint security across thousands of retail locations, cloud and on-prem infrastructure hardening, identity and access management for a workforce spread across North America, Europe, and Australasia, and third-party risk given the volume of industrial and automotive suppliers in the ecosystem. Tooling specifics aren't public, but the operational profile suggests a focus on SIEM, vulnerability management, and network segmentation across a hybrid environment. The team operates in an industry where margins are thin and disruption is physical - ransomware hitting a distribution center isn't a hypothetical here.