Simplify Logo

Full-Time

Director of Information Security

Confirmed live in the last 24 hours

CarGurus

CarGurus

1,001-5,000 employees

Online marketplace for buying and selling cars

Data & Analytics
Automotive & Transportation
Consumer Software
Consumer Goods

Senior, Expert

Boston, MA, USA

Category
Cybersecurity
IT & Security
Requirements
  • Bachelor’s Degree or equivalent combination of education and experience in Information Security or Computer Science.
  • Prior experience at a Director level; this is not a step-up role.
  • Industry certifications such as GIAC certifications (GSLC, GSTRT, GLEG) and others; CISM, CISA, CRISC, are nice to have but if certifications aren’t your thing that is OK too.
  • Deep understanding of cybersecurity and privacy principles, standards, and risk frameworks (e.g., NIST Cybersecurity Framework, CIS Controls, PCI-DSS, GDPR, CPRA).
  • Prior experience with system audits and IT reporting for SOX (Sarbanes Oxley) and SOC compliance is a must.
  • Solid understanding of RBAC models, SSO solutions, identity stores, directory services (SAML 2.0, OAuth 2.0, OIDC) and identity governance.
Responsibilities
  • Manage, lead, mentor, and develop a high-performing security team.
  • Conduct annual performance evaluations, build personal development and onboarding plans.
  • Form solid, collaborative relationships with peers and key partners across the business.
  • Maintain oversight of technical regulatory and compliance requirements.
  • Ensure security is embedded in the minds and culture of all employees. This includes being involved with our community and continuously driving awareness through training, conversations, presentations, etc.
  • Help manage vendor relationships.
  • Own the security budget inclusive of working with the VP on annual budget planning.
  • Set forth long-term Information Security strategic plans while including tactical tasks and goals aligning them with business objectives, risk tolerance, and regulatory requirements. Deliver and communicate them to key partners.
  • Supervise security controls and the evolution of the company’s information security maturity.
  • Ensure that information security policies, standards, and guidelines to mitigate risks, maintain compliance with industry regulations (e.g., GDPR, CPRA) and contractual obligations are enforced and reviewed on an appropriate cadence.
  • Work with IT Risk and Compliance to identify, assess, and prioritize information security risks across the organization.
  • Report on security metrics, risks, and mitigation strategies to leadership, relevant stakeholders, and the Audit Committee.

CarGurus is an online marketplace that connects buyers and sellers of new and used cars, primarily in the United States, with additional operations in Canada, the United Kingdom, and Germany. The platform allows users to search for vehicles, compare prices, and read reviews, utilizing advanced algorithms to rank listings based on price, dealer reputation, and vehicle history. This data-driven approach provides transparency, helping users find the best deals and setting CarGurus apart from traditional car buying methods. The company generates revenue mainly through subscription fees charged to dealerships for listing their inventory, along with advertising services and value-added offerings like financing options and vehicle history reports. In a competitive market with players like AutoTrader and Cars.com, CarGurus distinguishes itself through its focus on data transparency and a user-friendly interface, aiming to be a leading platform for car transactions.

Company Stage

Series A

Total Funding

$1.8M

Headquarters

Cambridge, Massachusetts

Founded

2006

Growth & Insights
Headcount

6 month growth

2%

1 year growth

5%

2 year growth

12%
Simplify Jobs

Simplify's Take

What believers are saying

  • CarGurus' expansion into new office space in Addison, Texas, indicates growth and potential for increased market presence.
  • The company's continuous innovation, such as the rollout of AI features, demonstrates a commitment to enhancing user experience and operational efficiency.
  • Investment from entities like Daiwa Securities Group Inc. reflects confidence in CarGurus' business model and growth prospects.

What critics are saying

  • The highly competitive automotive marketplace requires CarGurus to continuously innovate to maintain its market position.
  • Economic fluctuations and high interest rates can impact consumer affordability and inventory turnover, posing challenges for sustained growth.

What makes CarGurus unique

  • CarGurus leverages advanced algorithms to rank listings based on price, dealer reputation, and vehicle history, providing a data-driven approach that sets it apart from traditional car buying methods.
  • The platform's focus on transparency and user-friendly interface distinguishes it from competitors like AutoTrader and Cars.com.
  • CarGurus' integration of AI-powered insights to help dealers adjust prices and boost sales further enhances its competitive edge.