Principal Security Governance, Risk & Compliance Analyst

CarGurus - Boston, MA

Hiring: Principal Security Governance, Risk & Compliance Analyst Company: CarGurus Location: Boston, MA Job Posted Time: 2026-09-13 11:11:37 Employment Type: Hybrid Target Skills & Keywords : AWS, GDPR, Regulatory Compliance, Risk Management, SOC 2, SaaS About the job Experience: •8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit. Required Skills: •The Principal GRC professional leads key initiatives across cyber risk management, customer trust, security compliance, AI governance, third-party risk, and security policy, helping scale security programs to support CarGurus’ continued growth. •Lead the strategic direction and maturity of CarGurus’ Governance, Risk, and Compliance program. •Build the cyber risk management program, including cybersecurity risk assessments, cyber risk register management, issue remediation tracking, risk reporting, and security metrics. •Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring. •Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and security-related SOX initiatives. •Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices. •Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements. •Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors. Qualifications: •Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment. •Extensive experience leading SOC 2 Type II compliance programs. •Strong knowledge of SOC 2, NIST ISO 27001, GDPR, CCPA, and AWS security principles. •Excellent executive communication skills with the ability to influence technical and business stakeholders. •The displayed range represents the expected annual base salary / On-Target Earnings (OTE) for this position. On-Target Earnings (OTE) is inclusive of base salary and on-target commission earnings, which applies exclusively to sales roles. •Individual pay within this range is determined by work location and other factors such as job-related skills, experience, and relevant education or training. •This annual base salary forms part of a comprehensive Total Rewards Package. In addition to benefits, this role may qualify for discretionary bonuses/incentives and Restricted Stock Units (RSUs). Compensation: •$135,000 - $168,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!