Jobs · Massachusetts

Principal Security Governance, Risk & Compliance Analyst

CarGurus · Boston, MA · 1 wk ago
Hybrid$135k–$168k/yrFull-time

About Us

At CarGurus (NASDAQ: CARG), our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Today, we’re the largest and fastest-growing automotive marketplace, profitable for over 15 years. We’re evolving the entire automotive journey online—from selling an old car to financing, purchasing, and delivering a new one. Tens of millions of consumers visit CarGurus.com each month, and ~30,000 dealerships use our products. Our people-first culture fosters kindness, collaboration, and innovation, empowering employees with tools to fuel their career growth.

About the Role

The Principal Information Security GRC Analyst serves as a strategic leader responsible for designing, implementing, and continuously improving CarGurus’ cybersecurity governance, risk, and compliance program. This role partners across Engineering, Product, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure security controls effectively manage cyber risk while enabling the business. The Principal GRC professional leads key initiatives across cyber risk management, customer trust, security compliance, AI governance, third-party risk, and security policy, helping scale security programs to support CarGurus’ continued growth.

Responsibilities

  • Lead the strategic direction and maturity of CarGurus’ Governance, Risk, and Compliance program.
  • Build the cyber risk management program, including cybersecurity risk assessments, cyber risk register management, issue remediation tracking, risk reporting, and security metrics.
  • Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring.
  • Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and security-related SOX initiatives.
  • Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices.
  • Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements.
  • Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors.
  • Partner with Engineering and Product teams to integrate security and AI governance into the secure software development lifecycle.
  • Lead third-party security risk management activities and vendor security assessments.
  • Support customer trust by leading security questionnaires, customer security reviews, and Trust Center initiatives.
  • Partner with Privacy and Legal on data classification, retention, privacy risk assessments, and regulatory compliance.
  • Develop executive reporting on cyber risk, compliance posture, and key security metrics.
  • Drive automation and continuous improvement across GRC processes and controls.

Requirements

  • 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
  • Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
  • Extensive experience leading SOC 2 Type II compliance programs.
  • Experience supporting SOX ITGCs in partnership with Internal Audit.
  • Experience building AI governance frameworks and conducting AI security and risk assessments.
  • Strong knowledge of SOC 2, NIST, ISO 27001, GDPR, CCPA, and AWS security principles.
  • Excellent executive communication skills with the ability to influence technical and business stakeholders.

Pay

The expected annual base salary range for this position is $135,000—$168,000 USD. Individual pay is determined by work location and other factors such as job-related skills, experience, and relevant education or training. This role may also qualify for discretionary bonuses/incentives and Restricted Stock Units (RSUs).

Benefits

  • Best-in-class benefits and compensation, including equity for all employees.
  • Career development and corporate giving programs.
  • Employee resource groups (ERGs) and communities for connection and impact.
  • Flexible hybrid model and robust time off policies for work-life balance.
  • Daily free lunch, new car discount, meditation and fitness apps, and commuting cost coverage.

Similar jobs