Full-Time

Information Security Risk and Compliance Analyst II

Confirmed live in the last 24 hours

CarGurus

CarGurus

1,001-5,000 employees

Online marketplace for buying and selling cars

No salary listed

Mid

Boston, MA, USA

Hybrid model with flexible in-office days.

Category
Cybersecurity
IT & Security
Required Skills
Risk Management
Requirements
  • Bachelor’s Degree or equivalent combination of education and experience in Information Security, Computer Science, Management Information Systems, or related curriculum.
  • 3 years of experience in risk management, information security, audit, regulatory compliance, and data privacy functions.
  • Knowledge of frameworks/compliance regimes (e.g., CIS Controls, NIST, PCI, SOX compliance).
  • Proven experience working with control owners, auditors, and supporting the implementation of risk-based controls in cloud-native environments.
  • Understanding of risk assessment methodologies, frameworks, procedures, and the ability to work flexibly with them to meet organizational size, maturity, and culture considerations.
  • Ability to gauge risks posed to the company based on contextual factors and the organization’s risk tolerance.
  • Knowledge of risk assessment tools, technologies, and methods.
  • Ability to think strategically about security risks and tie those to tactical organizational activities and goals.
  • Open to learning and working on new domains and technology.
  • Ability to clearly articulate issues and communicate in an effective and personable manner.
  • Ability to adjust quickly to the security needs of a highly agile organization.
  • Experience building relationships cross-functionally and facilitating good partnerships is critical in the role.
Responsibilities
  • Maintain the framework controls in the GRC platform and ensure that appropriate documentation and evidence is uploaded.
  • Assist in conducting proof of concept(s) on new risk technology and assisting with implementation and onboarding of it.
  • Perform risk assessments and audits across all areas of the business including third party risk complying with regulatory controls, such as SOX, GDPR, CPRA, SOC 2 Type 1 and 2. etc.
  • Document and develop risk mitigation plans and strategies for identified risks.
  • Develop and deliver security awareness training to the organization and assume responsibility that we are meeting compliance requirements.
  • Conduct third-party vendor, partner, and contractor security risk assessments.
  • Perform audits to test the design and operational effectiveness of IT General Controls.
  • Work closely with financial application owners to design, document, and implement controls.
  • Measure the efficacy and efficiency of controls and design improvements as necessary.
  • Right size the design of controls to fit our organizational environments.
  • Stay current with industry trends relating to cybersecurity, privacy, and risk.
Desired Qualifications
  • Ability to work flexibly with risk assessment methodologies, frameworks, procedures, and the ability to work flexibly with them to meet organizational size, maturity, and culture considerations.
  • Open to learning and working on new domains and technology.

CarGurus is an online marketplace that connects buyers and sellers of new and used cars, primarily in the United States, with additional operations in Canada, the United Kingdom, and Germany. The platform allows users to search for vehicles, compare prices, and read reviews, utilizing advanced algorithms to rank listings based on price, dealer reputation, and vehicle history. This data-driven approach provides transparency, helping users find the best deals and setting CarGurus apart from traditional car buying methods. The company generates revenue mainly through subscription fees charged to dealerships for listing their inventory, along with advertising services and value-added offerings like financing options and vehicle history reports. In a competitive market with players like AutoTrader and Cars.com, CarGurus distinguishes itself through its focus on data transparency and a user-friendly interface, aiming to be a leading platform for car transactions.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Cambridge, Massachusetts

Founded

2006

Simplify Jobs

Simplify's Take

What believers are saying

  • Digital Deal tool adoption increased 150% among U.S. dealers in 2024.
  • Expansion of Digital Deal to Canada offers significant international growth opportunities.
  • Recent website redesign and app updates enhance user experience and lead generation.

What critics are saying

  • CFO Elisa Palazzo's departure in March 2025 may cause financial management instability.
  • Carvana's strong market presence poses a competitive threat to CarGurus.
  • Economic uncertainty may shift consumer focus to more affordable vehicle segments.

What makes CarGurus unique

  • CarGurus uses proprietary algorithms to rank car listings by price and reputation.
  • The platform offers a unique Digital Deal tool for online car buying processes.
  • CarGurus emphasizes data transparency and user-friendly interfaces in its marketplace.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company Equity

Hybrid Work Options

Flexible Work Hours

Paid Vacation

Meal Benefits

Commuter Benefits

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Yahoo Finance
Mar 10th, 2025
Tesla Stock Is Still A Sell After Its 40% Plunge, Ubs Warns

Leaning into the bear narrative on Tesla (TSLA). UBS analyst Joseph Spak reiterated his 12-month Sell rating on Tesla shares on Monday, voicing considerable concern on the near-term demand outlook for the Model 3 and Model Y. He slashed his price target on Tesla to $225 from $259. The consensus price target on the Street is $239, according to Yahoo Finance data. The stock tanked 8% to $242 in early trading alongside a broader hit to markets due to tariff concerns. NasdaqGS - Delayed Quote • USD As of 12:28:59 PM EDT

TipRanks
Feb 24th, 2025
CarGurus Announces CFO Departure and Leadership Shift

Elisa Palazzo will step down as CFO of CarGurus on March 7, 2025.

PYMNTS
Feb 21st, 2025
Carvana And Cargurus Leverage Ai To Drive Digital Transformation In Car Sales

Consumer preferences are moving toward digital experiences in the online car marketplace, and Carvana and CarGurus are leveraging technology and artificial intelligence (AI) to improve the buying process. Both companies reported strong performances in 2024, using digital tools to optimize customer engagement and refine their business models, though each has faced distinct challenges along the way. Carvana’s Strategic Growth Drivers and AI Investment. Carvana recorded a 33% year-over-year increase in retail units sold (416,348) and saw its revenue rise 27%, to $13.67 billion. According to the company’s Q4 shareholder letter, Carvana has three main growth drivers: continuously improving its customer offering; increasing awareness, understanding and trust of the brand; and increasing inventory selection and other benefits of scale

The Manila Times
Jan 8th, 2025
CarGurus to Present at 27th Annual Needham Growth Conference

CarGurus to present at 27th Annual Needham Growth Conference.

Stock Titan
Dec 12th, 2024
CarGurus Examines 2024 Auto Market Influences and Expectations for 2025 Following a Year Defined by Affordability

CarGurus (CARG) has released its 2024 Recap & 2025 Outlook, highlighting that affordability was the key market driver in 2024.