Full-Time

Principal Security Engineer

Operations

Posted on 6/25/2025

CarGurus

CarGurus

1,001-5,000 employees

Online automotive marketplace with price comparisons

Compensation Overview

$152k - $190k/yr

+ RSUs + Discretionary bonuses/incentives

Boston, MA, USA

Hybrid

Hybrid model; exact on-site days not specified.

Category
IT & Security (1)
Requirements
  • 7+ years in detection engineering, security operations, or a similar role, with a strong track record building detection logic in large-scale or cloud-native environments.
  • Experience architecting and deploying detection pipelines across platforms like AWS, GCP, or Azure using tools such as Chronicle, Splunk, Panther, or open-source equivalents.
  • Strong red + blue team mindset: you think like an attacker and build defenses that go beyond surface-level detection.
  • Expertise in cloud control plane monitoring, identity threat detection, and infrastructure log analysis.
  • Deep familiarity with adversary TTPs (MITRE ATT&CK), anomaly-based detection techniques, and event correlation strategies.
  • Experience operationalizing detection-as-code pipelines (e.g., CI/CD for detection logic).
  • Ability to communicate detection priorities and incident insights to technical and non-technical stakeholders.
  • Authored and maintained infrastructure security policies, standards, and procedures
  • History of working on a Security Incident Response Team (SIRT) investigating events, triaging potential incidents, containing environments, conducting forensics analysis
  • Experience evaluating, running PoCs, and deploying new security tooling solutions.
Responsibilities
  • Evaluate, advise, and deploy new security technologies alongside other technologies Information Security and peer partners (e.g. Platform Engineering, IT).
  • Design, architect, and implement scalable detection pipelines across cloud (e.g. AWS, Azure, GCP) endpoints, identity, DLP, and SaaS platforms that support proactive threat identification and response.
  • Mature our Security Information and Event Management (SIEM) and centralized logging capabilities, focusing on enrichment, correlation, and high-signal detections.
  • Develop detection-as-code practices and CI/CD pipelines for deployment and tuning of detection logic.
  • Make thoughtful long-term architectural design and strategy decisions for our Cloud Native Application Protection Platform (CNAPP) to ensure coverage, efficiencies and reduce false positives while maintaining continuity across multiple infrastructure environments.
  • Work with infrastructure-as-code (IAC) technologies to establish automated security configurations for platform hardening and cloud-native control enforcement.
  • Collaborate closely with AppSec offensive security, and Cloud Engineering teams to identify detection opportunities and test control efficacy.
  • Partner with our Technical Leadership Team (TLT) to provide feedback and guidance related to security operational decisions to support the product development of our platform.
  • Implement necessary security changes to support our Identity Governance Access (IAG) program and Role-Based Access Control (RBAC) models.
  • Contribute to third-party vulnerability and penetration testing engagements and feed learnings into the broader detection engineering strategy.
  • Continuously improve our vulnerability management program by triaging issues and identifying gaps in pre-production versus post-production detection.
  • Ensure alignment to industry frameworks such as CIS Controls, ISO 27XXX, and NIST, embedding defensible security practices across the stack.
  • Act as the Incident Commander of the Security Incident Response Team (SIRT), overseeing triage, containment, and forensics during investigations.

CarGurus runs an online marketplace that connects buyers and sellers of new and used cars, mainly in the United States with presence in Canada, the United Kingdom, and Germany. It helps buyers, private sellers, and dealerships search listings, compare prices, and read dealer reviews, with a data-driven ranking that weighs price, dealer reputation, and vehicle history. Revenue comes from dealership subscriptions, advertising, and value-added services like financing options and vehicle history reports. The platform aims to make car buying and selling easier and more transparent by providing clear data and a simple, accessible interface.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Cambridge, Massachusetts

Founded

2006

Simplify Jobs

Simplify's Take

What believers are saying

  • Q1 2026 revenue grows 15% to $244M with 39% international surge.
  • PriceVantage users see 117% turn time improvement, 47% more page views.
  • ChatGPT-integrated Discover search increases leads 52% quarter-over-quarter.

What critics are saying

  • February 2026 ShinyHunters breach exposes 12.5M accounts, triggers lawsuits.
  • Cars.com surpasses CarGurus in US traffic per Similarweb Q2 2025 data.
  • Autotrader's Deal Builder captures UK dealers via complete online transactions.

What makes CarGurus unique

  • Proprietary algorithms deliver Instant Market Value deal ratings from millions of listings.
  • Dealer rankings emphasize reputation and price transparency over advertising spend.
  • AI PriceVantage tool launched October 2025 optimizes inventory for faster turns.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company Equity

Hybrid Work Options

Flexible Work Hours

Paid Vacation

Meal Benefits

Commuter Benefits

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Yahoo Finance
Apr 14th, 2026
CarGurus shares jump 19% after Q4 revenue beats expectations at $241M

CarGurus reported Q4 revenues of $241.1 million, up 14.7% year-on-year, exceeding analyst expectations by 0.8%. The automotive marketplace delivered mixed results, with next quarter's revenue guidance topping expectations but EBITDA guidance falling short. CEO Jason Trevisan called 2025 "a pivotal year" as the company expanded products across dealer workflows and consumer journeys whilst delivering strong financial performance. The stock has risen 19.3% since reporting and currently trades at $34.85. Amongst 12 tracked online marketplace stocks, Q4 results were mixed overall. Revenues beat consensus estimates by 1.5%, whilst next quarter's guidance was in line. Share prices have increased 3.1% on average since earnings. eBay posted the strongest quarter with revenues of $2.97 billion, up 15% year-on-year.

Yahoo Finance
Mar 11th, 2026
CarGurus sheds loss-making CarOffer as AI dealer tools drive 47% cash flow surge to $266M

CarGurus has raised its profile amongst auto marketplace competitors by divesting unprofitable operations whilst monetising AI-powered dealer tools that demonstrably improve customer results. The stock is up 12.4% since its fourth-quarter earnings report, outperforming the SPY index which dropped 2.11% over the same period. The company completed the wind-down of CarOffer, its struggling wholesale vehicle transactions business, on 31 December 2025. Full-year 2025 gross profit reached $841.5 million, up nearly 14% year-over-year, whilst free cash flow hit $265.96 million, up 47.49%. CarGurus' AI-powered inventory pricing tool, PriceVantage, showed early adopters achieving five times faster vehicle turn times and a 71% increase in daily shopper connections. Total paying dealers reached 34,409 in fourth quarter, up 7% year-over-year.

IT Security News
Feb 24th, 2026
CarGurus data breach affects 12.5 million accounts

CarGurus data breach affects 12.5 million accounts. 2026-02-24 23:02 Discover more Incident response planning Malware removal service Password managers IT security articles Malware analysis tools Automotive marketplace CarGurus was the target of a data breach in which the names, email addresses, phone numbers, and physical addresses of millions of customers were stolen. Read the original article: Malware analysis software Discover more Information security training Security awareness training Data privacy solutions Cybersecurity news subscription Information security consulting Cybersecurity training courses Cloud security solutions In February 2026, the automotive marketplace CarGurus was the target of a data breach attributed to the threat actor ShinyHunters. Following an attempted extortion, the data was published publicly and contained more than 12M email addresses across multiple files including user account ID mappings, finance pre-qualification application data and dealer... February 22, 2026 Discover more Digital forensics tools Security policy templates Data breach monitoring Digital information management Identity security software Endpoint security software Secure email gateways Latest in a rash of grab-and-leak data incidents CarGurus allegedly suffered a data breach with 1.7 million corporate records stolen, according to a notorious cybercrime crew that posted the online vehicle marketplace on its leak site on Wednesday... This article has been indexed from The Register - SecurityRead the original article:... February 18, 2026 Discover more Antivirus software Network security appliances IT Security Computer security Penetration testing services Data leak detection HealthEquity said the March data breach included personal information and protected health data on millions of people. (C) 2024 TechCrunch. All rights reserved. For personal use only. This article has been indexed from Security News | TechCrunch Read the original article: HealthEquity data breach affects 4.3 million people July 30, 2024

Yahoo Finance
Feb 24th, 2026
CarGurus reports 14% revenue growth to $907M, adds 1,357 US dealers in record expansion

CarGurus reported 14% annual revenue growth to $907 million for 2025, driven by record dealer network expansion. The company added 1,357 paying US dealers and achieved a 14% increase in international accounts. Fourth-quarter revenue reached $241.09 million, up 5.49% year-over-year. International revenue surged 32% in the quarter, whilst the company launched new products to enhance dealer workflows and consumer digital capabilities. CarGurus wound down its car offer business in Q4, incurring $13.3 million in related costs. For first-quarter 2026, the company projects revenue growth between 13% and 16%. However, it anticipates margin compression of 1.5 to 2.5 percentage points as it prioritises investments in international expansion, account management and technology over short-term profitability.

VivaLanka.com
Feb 24th, 2026
CarGurus data breach affects 12.5 million accounts

CarGurus data breach affects 12.5 million accounts. Tuesday, February 24, 2026 - https://techcrunch.com/ Automotive marketplace CarGurus was the target of a data breach in which the names, email addresses, phone numbers, and physical addresses of millions of customers were stolen.

INACTIVE