Jobs › Massachusetts › Boston › Principal Security Governance, Risk & Compliance Analyst
Principal Security Governance, Risk & Compliance Analyst
CarGurus is hiring for the job of Principal Security Governance, Risk & Compliance Analyst, Boston, Massachusetts (On-site). This is a Compliance job in the governance, risk, and compliance field, with a posted range of $135,000. Review the full details below and apply directly with CarGurus.
Who we are
At CarGurus (NASDAQ CARG) our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Since then our history of innovation and go-to-market acceleration has driven industry-leading growth. In fact we’re the largest and fastest-growing automotive marketplace and we’ve been profitable for over 15 years.
What we do
The market is evolving and we are too moving the entire automotive journey online and guiding our customers through every step. That includes everything from the sale of an old car to the financing purchase and delivery of a new one. Today tens of millions of consumers visit CarGurus.com each month and ~30,000 dealerships use our products. But they re not the only ones who love CarGurus our employees do too. We have a people-first culture that fosters kindness collaboration and innovation and empowers our Gurus with tools to fuel their career growth. Disrupting a trillion-dollar industry requires fresh and diverse perspectives. Come join us for the ride!
12pt Role overview
The Principal Information Security GRC Analyst serves as a strategic leader responsible for designing implementing and continuously improving CarGurus’ cybersecurity governance risk and compliance program. This role partners across Engineering Product IT Legal Privacy Internal Audit and Security Operations to ensure security controls effectively manage cyber risk while enabling the business.
The Principal GRC professional leads key initiatives across cyber risk management customer trust security compliance AI governance third-party risk and security policy helping scale security programs to support CarGurus’ continued growth.
12pt What you ll do
Lead the strategic direction and maturity of CarGurus’ Governance Risk and Compliance program. Build the cyber risk management program including cybersecurity risk assessments cyber risk register management issue remediation tracking risk reporting and security metrics. Lead and mature the SOC 2 Type II compliance program including audit readiness evidence management control testing remediation tracking and continuous control monitoring. Partner with Internal Audit to support SOX IT General Controls (ITGCs) application controls and security-related SOX initiatives. Develop and maintain security policies standards and governance processes aligned with business objectives and industry best practices. Build and operationalize the AI Governance program including AI risk assessments acceptable use standards AI inventory third-party AI reviews and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements. Perform cybersecurity risk assessments for cloud services applications infrastructure AI solutions and third-party vendors. Partner with Engineering and Product teams to integrate security and AI governance into the secure software development lifecycle. Lead third-party security risk management activities and vendor security assessments. Support customer trust by leading security questionnaires customer security reviews and Trust Center initiatives. Partner with Privacy and Legal on data classification retention privacy risk assessments and regulatory compliance. Develop executive reporting on cyber risk compliance posture and key security metrics. Drive automation and continuous improvement across GRC processes and controls.
12pt What you ll bring
8+ years of experience in Information Security Cyber Risk GRC or IT Audit. Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment. Extensive experience leading SOC 2 Type II compliance programs. Experience supporting SOX ITGCs in partnership with Internal Audit. Experience building AI governance frameworks and conducting AI security and risk assessments. knowledge of SOC 2 NIST ISO 27001 GDPR CCPA and AWS security principles. Excellent executive communication skills with the ability to influence technical and business stakeholders.
The displayed range represents the expected annual base salary On-Target Earnings (OTE) for this position. On-Target Earnings (OTE) is inclusive of base salary and on-target commission earnings which applies exclusively to sales roles.
Individual pay within this range is determined by work location and other factors such as job-related skills experience and relevant education or training.
This annual base salary forms part of a comprehensive Total Rewards Package. In addition to benefits this role may qualify for discretionary bonuses/incentives and Restricted Stock Units (RSUs).
Position Pay Range $135,000 $168,000 USD
Working at CarGurus
We reward our Gurus’ curiosity and passion with best-in-class benefits and compensation including equity for all employees both when they start and as they continue to grow with us. Our career development and corporate giving programs as well as our employee resource groups (ERGs) and communities help people build connections while making an impact in personally meaningful ways. A flexible hybrid model and robust time off policies encourage work-life balance and individual well-being. Thoughtful perks like daily free lunch a new car discount meditation and fitness apps commuting cost coverage and more help our people create space for what matters most in their personal and professional lives.
CarGurus may require in-person interviews as part of our hiring process particularly for positions based in our Boston and Dublin offices. Candidates selected for an in-person interview will be notified in advance. Please be aware that travel expenses are the responsibility of the candidate.
We welcome all
CarGurus strives to be a place to which people can bring the ultimate expression of themselves and their potential starting with our hiring process. We do not discriminate based on race color religion national origin age sex marital status ancestry physical or mental disability veteran status gender identity or sexual orientation. We foster an inclusive environment that values people for their skills experiences and unique perspectives. That’s why we hope you’ll apply even if you don’t check every box listed in the job description. We also encourage you to tell your recruiter if you require accommodations to participate in our hiring process due to a disability so we can provide the appropriate support. We want to know what only you can bring to CarGurus. rgb(236 240 241);t;Working at CarGurus \nWe reward our Gurus’ curiosity and passion with best-in-class benefits and compensation including equity for all employees both when they start and as they continue to grow with us. Our career development and corporate giving programs as well as our employee resource groups (ERGs) and communities help people build connections while making an impact in personally meaningful ways. A flexible hybrid model and robust time off policies encourage work-life balance and individual well-being. Thoughtful perks like daily free lunch a new car discount meditation and fitness apps commuting cost coverage and more help our people create space for what matters most in their personal and professional lives.;m;s:0;n;a;v;left;s:0;n;p;v:1.;s:0;n;b;v:true;e;s:0;n;c;v;#000000ff;e;s:0;n;s;v:19.;e;s:19;n;p;v:1.;s:21;n;a;v;left;s:21;n;p;v:1.;s:21;n;c;v;#1d1c1dff;e;s:21;n;s;v:20;e # -Hybrid
Location and market context
This job is based in Boston on-site. Local candidates benefit from being close to CarGurus's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About compliance jobs
Compliance programs turn law, regulation, and policy into controls the business can actually run. Demand is strongest where regulatory change, enforcement risk, and new technology intersect. Jobs like this one are typically evaluated against frameworks such as relevant regulatory frameworks, control libraries, and audit and monitoring practices.
How to position yourself for this compliance job
Strong candidates emphasize building and monitoring controls, regulatory mapping, policy and training, and partnering with the business to make compliance practical. In your resume and outreach, tie your experience to how CarGurus would apply relevant regulatory frameworks, control libraries, and audit and monitoring practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Director Global Trade Compliance · Vertex Pharmaceuticals · Boston, MA
- Senior Director - Quality Data, Digital Systems & Compliance · Vertex Pharmaceuticals · Boston, MA
- Director, Compliance Business Partner · Vertex Pharmaceuticals · Boston, MA
- Director CMC Quality Compliance (Hybrid) · Vertex Pharmaceuticals · Boston, MA
- Associate Director, CMC Quality Compliance and Inspection Readiness (Hybrid) · Vertex Pharmaceuticals · Boston, MA
- Senior Compliance Specialist · Singlestore · India
- Senior IT Governance & Compliance Manager · Logicgate · Chicago, Illinois
- Governance, Risk, and Compliance Expert, GTM, Pre-Sales · Vanta · . · Remote
More GRC jobs in Boston
- Director, Enterprise Third-Party Risk Management Operations & Governance · Vertex Pharmaceuticals · Boston, MA
- Auditor · Executive Office for U.S. Attorneys and the Office of the U.S. Attorneys · Boston, Massachusetts
- Global Head of Data & AI Governance & Oversight, SVP · State Street · Boston, MA
- Director, Regulatory Affairs CMC · Vertex Pharmaceuticals · Boston, MA
- DTE Audit & Compliance Manager (Sr. Principal Analyst) · Vertex Pharmaceuticals · Boston, MA
- Director, Regulatory Data Management (Boston, MA) · Vertex Pharmaceuticals · Boston, MA
Hiring for Compliance?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Principal Security Governance, Risk & Compliance Analyst in Boston, Massachusetts open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.