Full-Time

Application Security Engineer II

Confirmed live in the last 24 hours

CarGurus

CarGurus

1,001-5,000 employees

Online marketplace for buying and selling cars

Data & Analytics
Automotive & Transportation

Mid, Senior

Boston, MA, USA

Hybrid model; specific in-office days not mentioned.

Category
Cybersecurity
IT & Security
Required Skills
Python
JavaScript

You match the following CarGurus's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • At least 3 years of experience in Information Security.
  • Experience with modern programming languages, particularly Python and JavaScript.
  • Proficiency with security testing tools such as Burp Suite, ZAP, or equivalent.
  • Hands-on experience with SAST, DAST, and SCA tools (e.g., Checkmarx, Veracode, GitHub Advanced Security).
  • Familiarity with vulnerability frameworks and scoring systems (e.g., CVSS, NIST 800-53).
  • Knowledge of secure design principles, authentication/authorization mechanisms, and encryption best practices.
  • Strong communication skills with the ability to convey complex security issues to non-technical stakeholders.
  • A pragmatic approach to balancing security risks with business needs.
  • A collaborative mindset with a 'can-do' attitude and adaptability to a fast-paced, dynamic environment.
  • Strong organizational and time management skills to handle multiple priorities effectively.
Responsibilities
  • Partner with product and engineering teams to identify potential threats, vulnerabilities, and attack vectors in the design phase with active threat modeling.
  • Perform in-depth analysis of applications, identifying security risks through penetration testing, dynamic/static analysis, and manual assessments.
  • Operationalize and enhance static (SAST), dynamic (DAST), and software composition analysis (SCA) tools in the CI/CD pipeline to streamline security processes.
  • Identify, validate, prioritize, and remediate vulnerabilities, aligning with risk-based methodologies and defined SLAs.
  • Respond to findings from external researchers and bug bounty programs, ensuring timely triage, validation, and remediation.
  • Contribute to the design and implementation of security controls and architecture for new and existing products.
  • Participate in assessing third-party applications and libraries for security risks.
  • Collaborate with engineering teams to embed security best practices throughout the SDLC, providing training and guidance as needed.

CarGurus operates an online marketplace that connects buyers and sellers of new and used cars, primarily in the United States, with additional presence in Canada, the United Kingdom, and Germany. Users can search for vehicles, compare prices, and read reviews on the platform. CarGurus employs advanced algorithms to rank car listings based on price, dealer reputation, and vehicle history, which helps users find the best deals. This focus on data transparency and user-friendly design distinguishes CarGurus from traditional car buying methods and competitors like AutoTrader and Cars.com. The company generates revenue mainly through subscription fees charged to dealerships for listing their inventory, along with advertising services and value-added offerings such as financing options and vehicle history reports. CarGurus aims to provide a reliable and efficient platform for car transactions, enhancing the buying and selling experience for both consumers and dealerships.

Company Size

1,001-5,000

Company Stage

IPO

Total Funding

$7.5M

Headquarters

Cambridge, Massachusetts

Founded

2006

Simplify Jobs

Simplify's Take

What believers are saying

  • Digital Deal tool adoption grew 150% in the U.S., indicating strong online transaction trends.
  • Expansion to Canada suggests potential for further international growth and market penetration.
  • Focus on affordability aligns with consumer demand, boosting sales in key price segments.

What critics are saying

  • Competition from platforms like AutoTrader and Cars.com could erode market share.
  • Economic uncertainties and high interest rates may impact consumer purchasing power.
  • Rapid shift towards EVs may require platform adaptation for new listings and partnerships.

What makes CarGurus unique

  • CarGurus uses proprietary algorithms for pricing analysis, enhancing transparency in car shopping.
  • The platform ranks listings based on price, dealer reputation, and vehicle history.
  • CarGurus offers a user-friendly interface with advanced search and comparison features.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company Equity

Hybrid Work Options

Flexible Work Hours

Paid Vacation

Meal Benefits

Commuter Benefits

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
The Manila Times
Jan 8th, 2025
CarGurus to Present at 27th Annual Needham Growth Conference

CarGurus to present at 27th Annual Needham Growth Conference.

CityBiz
Sep 3rd, 2024
CarGurus Appoints Mike O'Hanlon as Chief Revenue Officer

"Mike joins CarGurus during an exciting time where our marketplace business has accelerated, global dealer adoption has grown, and we are developing unique data-driven features that provide even more value to our dealer partners," said Sam Zales, CarGurus President and Chief Operating Officer.

Stock Titan
Jun 20th, 2024
Stabilizing Prices and Growing Inventory Create Bright Spots for Cost-Conscious Shoppers

CarGurus, a leading digital auto platform, released its 2024 Mid-Year Review highlighting affordability opportunities in the automotive market.

Stock Titan
Dec 12th, 2024
CarGurus Examines 2024 Auto Market Influences and Expectations for 2025 Following a Year Defined by Affordability

CarGurus (CARG) has released its 2024 Recap & 2025 Outlook, highlighting that affordability was the key market driver in 2024.

Intelligence360
May 21st, 2024
Cargurus To Spend $2,900,000.00 To Occupy 30,913 Square Feet Of Space In Addison Texas.

CarGurus to spend $2,900,000.00 to occupy 30,913 square feet of space in Addison Texas. CarGurus to spend $2,900,000.00 to occupy 30,913 square feet of space in Addison Texas.Addison, Texas — According to state and local development sources, CarGurus plans to invest $2,900,000.00 to build out 30,913 square feet of new space in Addison. The company plans to occupy the new space at 15601 Dallas Parkway in Addison, on or about January 1, 2025. According to the company website CarGurus was founded in 2006 in Cambridge, Massachusetts by Langley Steinert, co-founder of TripAdvisor, who saw an opportunity to create a better car-shopping experience using technology and data analytics. In just over a decade, CarGurus has become the most visited automotive shopping site in the US, with more car listings than any other major online automotive marketplace. CarGurus also operates sites in Canada and the UK

Stock Titan
Oct 15th, 2024
CarGurus Teams With NFL Legend Drew Brees for "Keys to Success" Campaign

CarGurus (Nasdaq: CARG), the leading digital auto platform, has launched the 'Keys to Success' campaign featuring NFL legend Drew Brees.

Maple Leaf Times
Sep 16th, 2024
CarGurus Appoints Jennifer Hanson as Chief People Officer

CarGurus appoints Jennifer Hanson as Chief People Officer.

Stock Titan
Oct 8th, 2024
Need for Vehicle Affordability Becoming More Pronounced, According to New CarGurus Report

CarGurus has released its Quarterly Review for Q3 2024, highlighting key trends in the automotive market.

PR Newswire
Dec 11th, 2024
Cncf Ecosystem Continues To Drive Innovation With New Silver Members

Organizations join the ever-growing cloud native ecosystem to drive innovation across industries and geographiesNEW DELHI, Dec. 10, 2024 /PRNewswire/ -- KubeCon + CloudNativeCon India – December 11, 2024 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, has announced that more than 26 new Silver CNCF members have joined this quarter, highlighting the sustained investments organizations are making as cloud native innovation accelerates."As cloud native technologies drive unprecedented global transformation, CNCF is expanding its reach with new KubeCon + CloudNativeCon events in India and Japan, and a partnership with Andela to cultivate engineering talent across Africa," said Priyanka Sharma, executive director of CNCF. "These efforts reflect our commitment to fostering an inclusive global community, empowering organizations to innovate at scale, and advancing the cloud native ecosystem across the world. We are appreciative of the support these new members will bring to our expansive community and look forward to collaborating as we move into 2025."New and existing CNCF members are gathering this week in Delhi at the first-ever KubeCon + CloudNativeCon India. Joining the community at upcoming 2025 CNCF-hosted events, including KubeCon + CloudNativeCon Europe , April 1-4 in London, KubeCon + CloudNativeCon China , June 10-11 in Hong Kong, the inaugural KubeCon + CloudNativeCon Japan , June 16-17 in Tokyo, and more .About the newest Silver Members:Altinity helps enterprises run open source ClickHouse® better.helps enterprises run open source ClickHouse® better. Armored Gate is a multi-national cybersecurity company dedicated to advancing responsible technology, like Armored Containers: The long-awaited production solution for single-layer, single-purpose, on-demand microservice containers that meet requirements of Zero Trust, NIST, ISO and other regulations.is a multi-national cybersecurity company dedicated to advancing responsible technology, like Armored Containers: The long-awaited production solution for single-layer, single-purpose, on-demand microservice containers that meet requirements of Zero Trust, NIST, ISO and other regulations

PYMNTS
Nov 8th, 2024
Cargurus: Shifting Car-Buying Process Online Boosts Customer Satisfaction

Offering car dealers and shoppers value beyond the leads it has traditionally delivered is paying off for digital auto platform CarGurus.The company’s fastest-growing product is its Digital Deal tool, which enables consumers to start their financial application, book an appointment and start a trade-in online before completing the process at the dealership, CarGurus CEO Jason Trevisan said Thursday (Nov. 7) during the company’s third-quarter earnings call.“The transaction elements of car buying and selling continue to shift online, and we are enhancing and expanding our digital capabilities to empower our dealer partners to compete on a broader scale beyond their local presence while sourcing and selling inventory more efficiently online,” Trevisan said. “Digital Deal is our fastest growing product in the U.S., and we are very pleased with its continued strong adoption and elevated customer satisfaction.”The adoption of Digital Deal in the U.S. leaped 150% year over year to reach 8,474 dealers, CarGurus said in an earnings presentation released Thursday.The company expanded this offering to Canada Monday (Nov. 4), saying in a press release that Digital Deal gives dealers access to shoppers who are ready to buy, gives consumers greater confidence by helping them understand their financing eligibility up front, and saves both parties time in completing the transaction.“With increasing demand for more digitally enabled solutions from both consumers and dealers, we see significant opportunities to replicate the success of our transaction enablement playbook as our international business continues to mature and gain share,” Trevisan said during the Thursday earnings call.During the third quarter, CarGurus also launched a website redesign, added swipeable photos and updated browsing to its app, and updated its lead submission experience, according to the presentation.Trevisan said during the call that the updated website offers a more personalized experience that is resonating with consumers, that the mobile app now drives 30% of the company’s leads, and that the lead submission experience is now faster and more intuitive.CarGurus is making these updates to its marketplace at a time when car shoppers are focused on affordability, the company said in an Oct. 8 press release.The firm reported that it is seeing the greatest sales growth in price segments that are affordable: $20,000 to $30,000 for new vehicles and $15,000 to $20,000 for used ones.It attributed this trend to consumers facing economic uncertainty and interest rates and vehicle prices that remain high.“We continue to build a transaction-enabled platform that leverages our unique and extensive consumer data to deliver actionable insights, tools and functionalities for our dealer partners, supporting them in their daily decision-making processes,” Trevisan said during the Thursday earnings call