Information Security Risk and Compliance Analyst
$84k - $106kCarGurus
Who we are
At CarGurus (NASDAQ: CARG), our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Since then, our history of innovation and go-to-market acceleration has driven industry-leading growth. In fact, we’re the largest and fastest-growing automotive marketplace, and we’ve been profitable for over 15 years.
What we do
The market is evolving, and we are too, moving the entire automotive journey online and guiding our customers through every step. That includes everything from the sale of an old car to the financing, purchase, and delivery of a new one. Today, tens of millions of consumers visit CarGurus.com each month, and ~30,000 dealerships use our products. But they're not the only ones who love CarGurus—our employees do, too. We have a people-first culture that fosters kindness, collaboration, and innovation, and empowers our Gurus with tools to fuel their career growth. Disrupting a trillion-dollar industry requires fresh and diverse perspectives. Come join us for the ride!
Role overview
The information security risk and compliance analyst supports the organization’s governance, risk, and compliance program by managing security risk, ensuring regulatory compliance and partnering across the business to strengthen the company’s security posture. This role is responsible for third party risk management, customer security assurance activities, cyber risk management, SOX IT General Controls and security governance initiatives. The analyst works closely with security, engineering, legal, internal audit, privacy, finance, procurement and business stakeholders to build scalable processes, improve operational maturity and reduce organizational risk.
What you'll do
- Third Party Risk Management
- Customer Security Assurance
- Cyber Risk Management
- SOX Compliance
- Governance and Compliance
What you'll bring
- Experience with GRC platforms such as Auditboard, SAFE, Loopio or similar tools.
- Professional certifications such as CISSP, CISA, CRISC, Security+ or CISM.
- Experience supporting cloud environments.
- Familiarity with AI governance, automation or security workflow optimization.
Successful candidates will
- Build trusted partnerships with technical and business teams.
- Drive scalable governance and risk management processes.
- Balance business enablement with effective risk management.
- Improve audit readiness and compliance maturity.
- Communicate complex security concepts clearly to both technical and non-technical stakeholders.
- Continuously identify opportunities to improve security governance through process optimization and automation.
The displayed range represents the expected annual base salary / On-Target Earnings (OTE) for this position. On-Target Earnings (OTE) is inclusive of base salary and on-target commission earnings, which applies exclusively to sales roles.
Individual pay within this range is determined by work location and other factors such as job-related skills, experience, and relevant education or training. This annual base salary forms part of a comprehensive Total Rewards Package. In addition to benefits, this role may qualify for discretionary bonuses/incentives and Restricted Stock Units (RSUs).Position Pay Range
$84,000—$106,000 USD
Working at CarGurus
We reward our Gurus’ curiosity and passion with best-in-class benefits and compensation, including equity for all employees, both when they start and as they continue to grow with us. Our career development and corporate giving programs, as well as our employee resource groups (ERGs) and communities, help people build connections while making an impact in personally meaningful ways. A flexible hybrid model and robust time off policies encourage work-life balance and individual well-being. Thoughtful perks like daily free lunch, a new car discount, meditation and fitness apps, commuting cost coverage, and more help our people create space for what matters most in their personal and professional lives.
CarGurus may require in-person interviews as part of our hiring process, particularly for positions based in our Boston and Dublin offices. Candidates selected for an in-person interview will be notified in advance. Please be aware that travel expenses are the responsibility of the candidate.We welcome all
CarGurus strives to be a place to which people can bring the ultimate expression of themselves and their potential—starting with our hiring process. We do not discriminate based on race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. We foster an inclusive environment that values people for their skills, experiences, and unique perspectives. That’s why we hope you’ll apply even if you don’t check every box listed in the job description. We also encourage you to tell your recruiter if you require accommodations to participate in our hiring process due to a disability so we can provide the appropriate support. We want to know what only you can bring to CarGurus. #LI-Hybrid
$111.2k - $139k
...Yours As a Senior Technical Compliance Analyst, you’ll strengthen our... ...Working across Engineering, Security, Legal, Compliance, Internal... ...validate controls, address risks, and provide clear guidance... ...Standard (PCI DSS), Sarbanes-Oxley Information Technology General Controls...SuggestedFull timeImmediate start- ...opportunity for an IT Third Party and Compliance Analyst in the Technology Department of... ...benefits package. Position Summary The IT Risk and Compliance Analyst will take a lead... ..., and management of the firms’ Information Security Program. This position will consist of...SuggestedFull timeWork experience placementWork at office
- The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory...SuggestedWork experience placementWork at officeLocal area
$100k - $140k
...healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure... ...Governance, Risk, and Compliance Analyst II, to lead the day-to-day... ...,SDLC reviews and security compliance process ownership... ...remediationBachelor’s degree in Information Security, Computer Science,...SuggestedFull timeWork at officeRelocation$80k - $125k
...identity intelligence and risk operations. We deliver... ...and the U.K. For more information, visit Position... ...Governance, Risk & Compliance (GRC) Analystis responsible... ...across Information Security, Engineering, Product,... .... The GRC Analyst will assist in maintaining...SuggestedFlexible hours$110.7k - $218.3k
...Senior Consultant - Regulatory & Compliance - Enterprise Operations & Risk Our Deloitte Regulatory, Risk & Forensic... ...Required: Bachelor’s degree in Information Systems, Law, Business Management,... ..., or Chartered Financial Analyst designation The wage range for this...Local areaVisa sponsorship- ...Office of Research and Academic Compliance (ORAC) within the Office of... ..., including proactive risk assessment, consultation, and... ...mitigation, compliance, research security, operations, and education/training... ..., and working groups to inform decision-making by leadership...Work at office
$130k - $170k
...and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and... ...Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support... ...management, SDLC reviews and security compliance process ownership. The role...Full timeWork at officeRelocation- Randstad USA is seeking a Compliance Operations Analyst to support the healthcare compliance program through data analysis, monitoring, and auditing. The role focuses on ensuring adherence to regulatory requirements while maintaining thorough documentation and dashboards...Contract work
$90k - $200k
...American Investigations, Diligence and Compliance practice is seeking a Senior Manager based... ...(client) investigations, insider risk compliance assessments, consulting projects... ...research where necessary.Ability to lead information gathering and investigative interviews with...Temporary work$60.5k - $104.5k
...Description What is the opportunity? As a Senior Marketing Compliance Analyst, you will play a critical role in supporting the firm’s... ...Associate Director’s oversight. Identify and escalate high-risk or ambiguous compliance matters to the Associate Director for...Full timeFlexible hours- ...accurately and efficiently. You will also help identify regulatory risks, resolve complex issues, and improve processes across the... ...documentation and submissions for completeness, accuracy, consistency, and compliance, identifying gaps and driving resolution.Manage complex...Temporary workWork at office2 days per week
$119k - $218.3k
Position Summary Senior Consultant - Risk, Regulatory, & Licensing - Digital... ...clients with up-to-date perspectives on compliance obligations and industry best practices.... ...accelerate their path to value creation. Information for applicants with a need for accommodation...Work at office- ...essential regulatory documents to support study activation and ongoing compliance.Prepare and coordinate initial IRB submissions, amendments,... ...to drive timely resolution.Identify and escalate regulatory risks, delays, or compliance concerns and support resolution and...Temporary workWork at office2 days per week
- ...economics consulting firm is seeking a Compliance & Client Response Analyst to join its Boston-based team.... ...responding to client requests for information about the firm’s capabilities, projects... ...and practices, and IT/data security infrastructure. Key Responsibilities...Work at officeFlexible hoursShift work
- Babel Street is seeking a GRC Analyst to support cybersecurity governance, risk management, and compliance across multiple stakeholders. You will help maintain compliance with NIST CSF, CMMC, ISO/IEC 27001, SOC 2, and related controls, and support audits and policy management...
- KAYAK, part of Booking Holdings, is seeking an Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team. This early‑career role develops skills in risk assessments, policy management, and control monitoring while modernizing GRC practices. The position...Work at office3 days per week
- ...an active acquiror of other asset management platforms. Role: Compliance Officer Callodine is seeking a Compliance Officer to report to... ...Evaluate, identify, escalation and solve for potential areas of risk in compliance Assist with maintenance of Restricted List Assist...Permanent employment
$119k - $193k
Forrester Research, Inc. is seeking a Senior Analyst based in Cambridge, Massachusetts. This role involves delivering strategic advice for risk management leaders and conducting impactful research. The ideal candidate will have 5-7 years of experience in risk management...$85k - $95k
...for a motivated Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team! This is an exciting opportunity... ..., and procedures aligned with security and compliance frameworks such... ...field (such as cybersecurity, information systems, computer science, risk...InternshipWork at officeFlexible hours2 days per week3 days per week- ...respected team handling environmental transactions, regulatory compliance, permitting, remediation, and enforcement matters. The role offers... ...development, business transactions, financings, and corporate risk management.This role is ideal for an attorney with strong...Local areaRemote work2 days per week
$310k - $420k
...Area: ~ Global Data Governance, Incident Response & Information Security Regulatory Compliance Location: ~ Washington, D.C., New York, NY or Boston... ...and The Legal 500, serving as the vanguard for digital risk management. The group is comprised of an unparalleled...Full timeFixed term contractFlexible hours$160k - $190k
...Security, Risk and Compliance ConsultantBoston, Massachusetts, United StatesAn SEI-er is a master communicator and active listener who understands... ...following:Management or participation in Cybersecurity, Information Security, Risk, Compliance and/or Data Privacy Programs...Permanent employment$77k - $202k
...AssociateJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus on maintaining... ...analytical thinking to interpret data and inform insights and recommendations- Implementing compliance...Full timeH1b$80k - $150k
...solutions, tailored to the unique return and risk objectives of institutional clients in... ....About the RolePosition OverviewThe Compliance Analyst will support Wellington Management’s... ...training of client-facing personnel•Staying informed of regulatory changes and industry...Full timeRemote workFlexible hours1 day per week$70k - $150k
...American Investigations, Diligence and Compliance - Specialist practice is seeking an Associate... ...identification of evidence, performing information gathering and investigative interviews,... ...internal controls, performing insider risk compliance assessments, managing projects...Temporary workInterim roleFlexible hours$147.4k
Posting Description SENIOR LICENSING AND BUSINESS DEVELOPMENT OFFICER, Technology Licensing Office, is responsible for the commercialization of MIT’s IP portfolio arising from research and activities on MIT’s campus; managing a large portfolio of cases, including, technology...Full timeWork at officeVisa sponsorship$120.44k
...closely and coordinates with other TLO staff throughout the lifecycle of the technology including Transactions, IP Portfolio Managers, Compliance, Operations and Finance teams. Job Requirements REQUIRED: Minimum of Bachelor’s degree in scientific, technical or business field...Permanent employmentFull timeWork at officeVisa sponsorship- ...and development organization, seeks a Government Accounting & Compliance Analyst 2 in Cambridge, MA. You will ensure compliance with federal... ...development, monitoring, and submission support, with potential security clearance requirements. #J-18808-Ljbffr Inuplands
- ...purpose of the role is to ensure PMA’s compliance with regulatory requirements regarding PMA... ...insurance producer personnel to collect information and documents supporting onboarding and... ...critical thinking and problem solving skills. #J-18808-Ljbffr Old Republic Commercial Risk
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Risk and Compliance Analyst. Be the first to apply!
- IT security analyst Boston, MA
- senior security analyst Boston, MA
- application security analyst Boston, MA
- entry level security analyst Boston, MA
- work from home security analyst Boston, MA
- rate analyst Boston, MA
- information security compliance analyst Boston, MA
- security analyst Boston, MA
- network security analyst Boston, MA
- senior information security analyst Boston, MA


