CarGurus

Information Security Risk and Compliance Analyst

CarGurus$84K — $106K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Experience with GRC platforms like Auditboard, SAFE, Loopio, or similar tools.
  • Professional certifications such as CISSP, CISA, CRISC, Security+, or CISM.
  • Experience supporting cloud environments.
  • Familiarity with AI governance and security workflow optimization.

Responsibilities

  • Manage third-party risk effectively.
  • Conduct customer security assurance activities.
  • Oversee cyber risk management initiatives.
  • Ensure SOX compliance and reporting.
  • Drive governance and compliance efforts across the organization.

Benefits

  • Comprehensive Total Rewards Package.
  • Eligibility for discretionary bonuses/incentives.
  • Potential for Restricted Stock Units (RSUs).
Full Job Description
Role overview

The information security risk and compliance analyst supports the organization's governance, risk, and compliance program by managing security risk, ensuring regulatory compliance and partnering across the business to strengthen the company's security posture. This role is responsible for third party risk management, customer security assurance activities, cyber risk management, SOX IT General Controls and security governance initiatives. The analyst works closely with security, engineering, legal, internal audit, privacy, finance, procurement and business stakeholders to build scalable processes, improve operational maturity and reduce organizational risk.

What you'll do
  • Third Party Risk Management
  • Customer Security Assurance
  • Cyber Risk Management
  • SOX Compliance
  • Governance and Compliance

What you'll bring
  • Experience with GRC platforms such as Auditboard, SAFE, Loopio or similar tools.
  • Professional certifications such as CISSP, CISA, CRISC, Security+ or CISM.
  • Experience supporting cloud environments.
  • Familiarity with AI governance, automation or security workflow optimization.

Successful candidates will
  • Build trusted partnerships with technical and business teams.
  • Drive scalable governance and risk management processes.
  • Balance business enablement with effective risk management.
  • Improve audit readiness and compliance maturity.
  • Communicate complex security concepts clearly to both technical and non-technical stakeholders.
  • Continuously identify opportunities to improve security governance through process optimization and automation.


The displayed range represents the expected annual base salary / On-Target Earnings (OTE) for this position. On-Target Earnings (OTE) is inclusive of base salary and on-target commission earnings, which applies exclusively to sales roles.

Individual pay within this range is determined by work location and other factors such as job-related skills, experience, and relevant education or training.

This annual base salary forms part of a comprehensive Total Rewards Package. In addition to benefits, this role may qualify for discretionary bonuses/incentives and Restricted Stock Units (RSUs).

Position Pay Range

$84,000-$106,000 USD

About CarGurus

CarGurus is an online automotive marketplace that allows users to search for and compare new and used cars. The company was founded in 2006 and is headquartered in Cambridge, Massachusetts. CarGurus has a strong focus on transparency and provides users with information on pricing, dealer reputation, and vehicle history. The company has been recognized for its innovative approach to car shopping and has won several awards for its platform.
Learn more about CarGurus
Size
1,203 employees
Market Cap
$1.5 billion
Industry
Net Income
$77.5 million
Founded
2006
5 Year Trend
+36.9%
Revenue
$551.4 million
NASDAQ

Similar Jobs

More Jobs at CarGurus

More Information Technology Jobs

Find similar Information Security Risk and Compliance Analyst jobs: