×
Register Here to Apply for Jobs or Post Jobs. X

Principal Security Governance, Risk & Compliance Analyst

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: CarGurus LLC
Full Time position
Listed on 2026-09-11
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 135000 - 168000 USD Yearly USD 135000.00 168000.00 YEAR
Job Description & How to Apply Below

Who we are

At Car Gurus (NASDAQ: CARG), our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Since then, our history of innovation and go-to-market acceleration has driven industry-leading growth. In fact, we’re the largest and fastest-growing automotive marketplace, and we’ve been profitable for over 15 years.

What

we do

The market is evolving, and we are too, moving the entire automotive journey online and guiding our customers through every step. That includes everything from the sale of an old car to the financing, purchase, and delivery of a new one. Today, tens of millions of consumers visit  each month, and 30,000 dealerships use our products. But they’re not the only ones who love Car Gurus - our employees do, too.

We have a people-first culture that fosters kindness, collaboration, and innovation, and empowers our Gurus with tools to fuel their career growth. Disrupting a trillion-dollar industry requires fresh and diverse perspectives. Come join us for the ride!

Role overview

The Principal Information Security GRC Analyst serves as a strategic leader responsible for designing, implementing, and continuously improving Car Gurus’ cybersecurity governance, risk, and compliance program. This role partners across Engineering, Product, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure security controls effectively manage cyber risk while enabling the business.

The Principal GRC professional leads key initiatives across cyber risk management, customer trust, security compliance, AI governance, third-party risk, and security policy, helping scale security programs to support Car Gurus’ continued growth.

What you'll do
  • Lead the strategic direction and maturity of Car Gurus’ Governance, Risk, and Compliance program.
  • Build the cyber risk management program, including cybersecurity risk assessments, cyber risk register management, issue remediation tracking, risk reporting, and security metrics.
  • Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring.
  • Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and security-related SOX initiatives.
  • Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices.
  • Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements.
  • Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors.
  • Partner with Engineering and Product teams to integrate security and AI governance into the secure software development lifecycle.
  • Lead third-party security risk management activities and vendor security assessments.
  • Support customer trust by leading security questionnaires, customer security reviews, and Trust Center initiatives.
  • Partner with Privacy and Legal on data classification, retention, privacy risk assessments, and regulatory compliance.
  • Develop executive reporting on cyber risk, compliance posture, and key security metrics.
  • Drive automation and continuous improvement across GRC processes and controls.
What you'll bring
  • 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
  • Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
  • Extensive experience leading SOC 2 Type II compliance…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary