HHiring Reality
← CarGurus

Principal Security Governance, Risk & Compliance Analyst

CarGurus
Location
Boston, Massachusetts, United States
Posted
1 month ago
Department
Engineering & Technology
What they actually want (must-haves)
  • 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit
  • Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment
  • Extensive experience leading SOC 2 Type II compliance programs
  • Experience supporting SOX ITGCs in partnership with Internal Audit
  • Experience building AI governance frameworks and conducting AI security and risk assessments
  • Strong knowledge of SOC 2, NIST ISO 27001, GDPR, CCPA, and AWS security principles
What the job really is

The Principal Security Governance, Risk & Compliance Analyst at CarGurus is responsible for leading the cybersecurity governance, risk, and compliance program. This role involves building and maturing cyber risk management initiatives, managing SOC 2 Type II compliance, and integrating security into the software development lifecycle, while collaborating with various teams across the organization.

Benefits
  • Equity for all employees
  • Career development programs
  • Corporate giving programs
  • Employee resource groups (ERGs)
  • Flexible hybrid model
  • Robust time off policies
Things to weigh
  • No specific mention of team size or structure
  • In-person interviews may be required for candidates in Boston
  • Travel expenses for in-person interviews are the candidate's responsibility
Job score3.8/5
Benefits5/5
Freshness4/5
Career value5/5
Role clarity5/5
Pay transparency0/5

Applying to CarGurus?

See how your résumé matches this role — and tailor it from what actually gets interviews.