Principal GRC & Security Leader for AI & Cloud

CarGurus LLC

Boston (MA)

Hybrid

USD 135,000 - 168,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible hybrid model
RSUs
Discretionary bonuses

Job summary

CarGurus, a leading automotive marketplace, is seeking a Principal Information Security GRC Analyst to design and drive the company’s cyber risk governance, risk, and compliance program. You will partner across Engineering, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure controls effectively manage cyber risk while enabling the business.

You will lead strategic GRC initiatives, develop AI governance frameworks, oversee SOC 2 Type II compliance, and partner with finance for

Qualifications

  • 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
  • Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
  • Extensive experience leading SOC 2 Type II compliance programs.
  • Experience supporting SOX ITGCs in partnership with Internal Audit.
  • Experience building AI governance frameworks and conducting AI security and risk assessments.
  • Strong knowledge of SOC 2, ISO 27001, GDPR, CCPA, and AWS security principles.
  • Excellent executive communication skills with the ability to influence technical and business stakeholders.

Responsibilities

  • Lead the strategic direction and maturity of CarGurus’ Governance, Risk, and Compliance program.
  • Build the cyber risk management program, including risk assessments, risk register management, issue remediation tracking, risk reporting, and security metrics.
  • Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring.
  • Partner with Internal Audit to support SOX IT General Controls (ITGCs) and security-related SOX initiatives.
  • Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices.
  • Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and alignment with NIST AI RMF.
  • Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors.
  • Partner with Engineering and Product teams to integrate security and AI governance into the secure SDLC.
  • Lead third-party security risk management activities and vendor security assessments.
  • Support customer trust by leading security questionnaires, customer security reviews, and Trust Center initiatives.
  • Partner with Privacy and Legal on data classification, retention, privacy risk assessments, and regulatory compliance.
  • Develop executive reporting on cyber risk, compliance posture, and key security metrics.
  • Drive automation and continuous improvement across GRC processes and controls.

Skills

Information Security
GRC
SOC 2 Type II
AI governance
Executive communication

Job description

CarGurus, a leading automotive marketplace, is seeking a Principal Information Security GRC Analyst to design and drive the company’s cyber risk governance, risk, and compliance program. You will partner across Engineering, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure controls effectively manage cyber risk while enabling the business.

You will lead strategic GRC initiatives, develop AI governance frameworks, oversee SOC 2 Type II compliance, and partner with finance for

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security GRC Leader: SOC 2, AI Governance | Hybrid + Equity
Senior Security GRC Leader: SOC 2, AI Governance | Hybrid + Equity

CarGurus • Boston (MA)

Hybrid
USD 135,000 - 168,000
Daily free lunch
Car discount
Wellness programs
Principal Security Governance, Risk & Compliance Analyst
Principal Security Governance, Risk & Compliance Analyst

CarGurus LLC • Boston (MA)

Hybrid
USD 135,000 - 168,000
Flexible hybrid model
RSUs
Discretionary bonuses
Hybrid Information Security Risk & Compliance Analyst
Hybrid Information Security Risk & Compliance Analyst

CarGurus • Boston (MA)

On-site
USD 84,000 - 106,000
Equity for all employees
Hybrid work model
Generous time off
AI Governance & Security GRC Analyst
AI Governance & Security GRC Analyst

Metropolis Technologies • Los Angeles (CA)

On-site
USD 100,000 - 135,000
Healthcare benefits
401(k) plan
Disability coverage
+3
Principal Security Governance, Risk & Compliance Analyst
Principal Security Governance, Risk & Compliance Analyst

CarGurus • Boston (MA)

Hybrid
USD 135,000 - 168,000
Daily free lunch
Car discount
Wellness programs
GRC Analyst - AI Security & Policy Lead
GRC Analyst - AI Security & Policy Lead

Metropolis • Los Angeles (CA)

On-site
USD 100,000 - 135,000
Office on-site 4 days/week
Senior Cyber Risk Analyst: AI-Powered GRC Lead
Senior Cyber Risk Analyst: AI-Powered GRC Lead

Procore • Austin (TX)

On-site
USD 112,000 - 154,000
Equity compensation
Bonus incentive compensation
Senior Principal AI Architect — Consumer Platforms
Senior Principal AI Architect — Consumer Platforms

CarGurus LLC • Boston (MA)

Hybrid
USD 191,000 - 239,000
Equity for all employees
Hybrid work model
Daily free lunch
+4
Director, Product Cybersecurity & Compliance (GRC)
Director, Product Cybersecurity & Compliance (GRC)

General Motors • Warren (MI)

Hybrid
USD 180,000 - 240,000
Relocation benefits
GRC Analyst II — AI Governance & Security Policy
GRC Analyst II — AI Governance & Security Policy

Metropolis • Chicago (IL)

On-site
USD 100,000 - 135,000
Healthcare benefits
401(k) plan
Stock option plan
+3