Information Security Risk and Compliance Analyst
$84k - $106kCarGurus
Who We Are At CarGurus (NASDAQ: CARG), our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Since then, our history of innovation and go-to-market acceleration has driven industry-leading growth. In fact, we’re the largest and fastest-growing automotive marketplace, and we’ve been profitable for over 15 years. Who We Are At CarGurus (NASDAQ: CARG), our mission is to give people the power to reach their destination. We started as a small team of developers determined to bring trust and transparency to car shopping. Since then, our history of innovation and go-to-market acceleration has driven industry-leading growth. In fact, we’re the largest and fastest-growing automotive marketplace, and we’ve been profitable for over 15 years. What We Do The market is evolving, and we are too, moving the entire automotive journey online and guiding our customers through every step. That includes everything from the sale of an old car to the financing, purchase, and delivery of a new one. Today, tens of millions of consumers visit CarGurus.com each month, and ~30,000 dealerships use our products. But they're not the only ones who love CarGurus—our employees do, too. We have a people-first culture that fosters kindness, collaboration, and innovation, and empowers our Gurus with tools to fuel their career growth. Disrupting a trillion-dollar industry requires fresh and diverse perspectives. Come join us for the ride! Role Overview The information security risk and compliance analyst supports the organization’s governance, risk, and compliance program by managing security risk, ensuring regulatory compliance and partnering across the business to strengthen the company’s security posture. This role is responsible for third party risk management, customer security assurance activities, cyber risk management, SOX IT General Controls and security governance initiatives. The analyst works closely with security, engineering, legal, internal audit, privacy, finance, procurement and business stakeholders to build scalable processes, improve operational maturity and reduce organizational risk. What You’ll Do Third Party Risk Management Customer Security Assurance Cyber Risk Management SOX Compliance Governance and Compliance What You’ll Bring Experience with GRC platforms such as Auditboard, SAFE, Loopio or similar tools. Professional certifications such as CISSP, CISA, CRISC, Security+ or CISM. Experience supporting cloud environments. Familiarity with AI governance, automation or security workflow optimization. Successful candidates will Build trusted partnerships with technical and business teams. Drive scalable governance and risk management processes. Balance business enablement with effective risk management. Improve audit readiness and compliance maturity. Communicate complex security concepts clearly to both technical and non-technical stakeholders. Continuously identify opportunities to improve security governance through process optimization and automation. The displayed range represents the expected annual base salary / On-Target Earnings (OTE) for this position. On-Target Earnings (OTE) is inclusive of base salary and on-target commission earnings, which applies exclusively to sales roles. Individual pay within this range is determined by work location and other factors such as job-related skills, experience, and relevant education or training. This annual base salary forms part of a comprehensive Total Rewards Package. In addition to benefits, this role may qualify for discretionary bonuses/incentives and Restricted Stock Units (RSUs). Position Pay Range
$84,000—$106,000 USD
Working at CarGurus We reward our Gurus’ curiosity and passion with best-in-class benefits and compensation, including equity for all employees, both when they start and as they continue to grow with us. Our career development and corporate giving programs, as well as our employee resource groups (ERGs) and communities, help people build connections while making an impact in personally meaningful ways. A flexible hybrid model and robust time off policies encourage work-life balance and individual well-being. Thoughtful perks like daily free lunch, a new car discount, meditation and fitness apps, commuting cost coverage, and more help our people create space for what matters most in their personal and professional lives. CarGurus may require in-person interviews as part of our hiring process, particularly for positions based in our Boston and Dublin offices. Candidates selected for an in-person interview will be notified in advance. Please be aware that travel expenses are the responsibility of the candidate. We welcome all CarGurus strives to be a place to which people can bring the ultimate expression of themselves and their potential—starting with our hiring process. We do not discriminate based on race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. We foster an inclusive environment that values people for their skills, experiences, and unique perspectives. That’s why we hope you’ll apply even if you don’t check every box listed in the job description. We also encourage you to tell your recruiter if you require accommodations to participate in our hiring process due to a disability so we can provide the appropriate support. We want to know what only you can bring to CarGurus. #J-18808-Ljbffr CarGurus- The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory...SuggestedWork experience placementWork at officeLocal area
- CarGurus in Boston is seeking an Information Security Risk and Compliance Analyst to manage security risk, ensure regulatory compliance, and partner with security, engineering, legal, finance, and procurement to strengthen the company’s security posture. The role covers...Suggested
$100k - $140k
...healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure... ...Governance, Risk, and Compliance Analyst II, to lead the day-to-day... ...,SDLC reviews and security compliance process ownership... ...remediationBachelor’s degree in Information Security, Computer Science,...SuggestedFull timeWork at officeRelocation$80k - $125k
...identity intelligence and risk operations. We deliver... ...and the U.K. For more information, visit Position... ...Governance, Risk & Compliance (GRC) Analystis responsible... ...across Information Security, Engineering, Product,... .... The GRC Analyst will assist in maintaining...SuggestedFlexible hours- ...Healthcare industry is seeking an AI Risk & Compliance Analyst to join their team. You will be responsible... ...risks related to bias, privacy, security, and regulatory noncompliance. The... ...with AI development teams to gather information for assessments and prepare clear findings...Suggested
$130k - $170k
...and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and... ...Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support... ...management, SDLC reviews and security compliance process ownership. The role...Full timeWork at officeRelocation- ...Office of Research and Academic Compliance (ORAC) within the Office of... ..., including proactive risk assessment, consultation, and... ...mitigation, compliance, research security, operations, and education/training... ..., and working groups to inform decision-making by leadership...Work at office
- Randstad USA is seeking a Compliance Operations Analyst to support the healthcare compliance program through data analysis, monitoring, and auditing. The role focuses on ensuring adherence to regulatory requirements while maintaining thorough documentation and dashboards...Contract work
$70k - $90k
...Compliance Specialist CopperPoint has an exciting opportunity for a Compliance Specialist... ...with internal teams to identify risks, implement solutions, and promote regulatory... ...related legal and regulatory changes and information arising from bulletins and other information...Hourly payTemporary workFlexible hours$60k - $70k
...exceptional breadth and depth of expertise. The Compliance Analyst works closely with the Compliance Team... ...on responding to client requests for information about the firm's capabilities,... ..., policies and practices, and IT/data security infrastructure. Essential Job...Work experience placementWork at officeLocal areaWorldwideFlexible hoursShift work- ...an active acquiror of other asset management platforms. Role: Compliance Officer Callodine is seeking a Compliance Officer to report to... ...Evaluate, identify, escalation and solve for potential areas of risk in compliance Assist with maintenance of Restricted List Assist...Permanent employment
$174.5k - $274.23k
...Ethics & Compliance Business Partner, U.S. Oncology Business Unit Join to apply for the Ethics... ...with Takeda will commence and that the information I provide in my application will be... ...ethical behavior plays a fundamental role in risk mitigation, being a forward-thinking...Minimum wageFull timeTemporary workWork at officeLocal areaRemote workWork from homeHome office$60.5k - $104.5k
...Description What is the opportunity? As a Senior Marketing Compliance Analyst, you will play a critical role in supporting the firm’s... ...Associate Director’s oversight. Identify and escalate high-risk or ambiguous compliance matters to the Associate Director for...Full timeFlexible hours$90k - $200k
...American Investigations, Diligence and Compliance practice is seeking a Senior Manager based... ...(client) investigations, insider risk compliance assessments, consulting projects... ...research where necessary. Ability to lead information gathering and investigative interviews...Temporary workFlexible hours- ...accurately and efficiently. You will also help identify regulatory risks, resolve complex issues, and improve processes across the... ...documentation and submissions for completeness, accuracy, consistency, and compliance, identifying gaps and driving resolution.Manage complex...Temporary workWork at office2 days per week
$119k - $218.3k
Position Summary Senior Consultant - Risk, Regulatory, & Licensing - Digital... ...clients with up-to-date perspectives on compliance obligations and industry best practices.... ...accelerate their path to value creation. Information for applicants with a need for accommodation...Work at office- ...essential regulatory documents to support study activation and ongoing compliance.Prepare and coordinate initial IRB submissions, amendments,... ...to drive timely resolution.Identify and escalate regulatory risks, delays, or compliance concerns and support resolution and...Temporary workWork at office2 days per week
- ...economics consulting firm is seeking a Compliance & Client Response Analyst to join its Boston-based team.... ...responding to client requests for information about the firm’s capabilities, projects... ...and practices, and IT/data security infrastructure. Key Responsibilities...Work at officeFlexible hoursShift work
$70k - $110k
As a GRC Analyst, you will support the the company Governance, Risk, and Compliance program. You will help manage third-party vendor... ...requests, in cross-functional security compliance workflows. Success... ...and expedient escalations with informed recommendations to management...Full timeWork at officeRelocation$100k - $140k
Overview Compliance Associate - Global Regulatory Oversight. This range is provided by Origin... ...relationships, expert networks, and information barriers Contribute to compliance policy... ...$100,000.00-$140,000.00 Compliance and Risk Management Associate — Boston, MA $83,00...Full time- ...program and project administration at our Greater Boston-area offices. The role covers COI and bond administration, subcontractor compliance, claims coordination, audit support, and document control across multiple projects with cross‑functional teams. You will prepare...For subcontractor
$60k - $90k
As a GRC Analyst, Operations & Risk, you will support the WHOOP Governance, Risk, and Compliance program by helping manage GRC intake, coordinate... ..., process documentation, security awareness coordination,... ...Bachelor’s degree in Information Security, Computer Science...Full timeWork at officeRelocation- Babel Street is seeking a GRC Analyst to support cybersecurity governance, risk management, and compliance across multiple stakeholders. You will help maintain compliance with NIST CSF, CMMC, ISO/IEC 27001, SOC 2, and related controls, and support audits and policy management...
- KAYAK, part of Booking Holdings, is seeking an Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team. This early‑career role develops skills in risk assessments, policy management, and control monitoring while modernizing GRC practices. The position...Work at office3 days per week
$119k - $193k
Forrester Research, Inc. is seeking a Senior Analyst based in Cambridge, Massachusetts. This role involves delivering strategic advice for risk management leaders and conducting impactful research. The ideal candidate will have 5-7 years of experience in risk management...- United States Digital Space LLC is seeking a Senior Governance, Risk, and Compliance Analyst to lead day-to-day GRC operations in a fast-growing environment. The role partners with Legal, Security, Product, and other teams to advance compliance objectives and reduce enterprise...Relocation
$60k - $90k
Whoop is searching for a GRC Analyst in Boston, MA, to enhance the Governance, Risk, and Compliance program. This role involves managing GRC intake processes, coordinating third-party risk reviews, and ensuring effective compliance operations. The ideal candidate will...- KAYAK is seeking an Associate GRC Analyst to join the Cyber Governance, Risk, and Compliance team in Cambridge/Concord, MA. Early‑career professional with a solid foundation in GRC and interest in automation will thrive here. The role focuses on risk assessments, policy...Work at office3 days per week
- ...respected team handling environmental transactions, regulatory compliance, permitting, remediation, and enforcement matters. The role offers... ...development, business transactions, financings, and corporate risk management.This role is ideal for an attorney with strong...Local areaRemote work2 days per week
- Ropes & Gray LLP in Boston seeks a Conflicts Analyst to support the Office of General Counsel by conducting corporate research, building... .... The role requires a bachelor’s degree and experience in a compliance or legal environment, with proficiency in research databases...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Risk and Compliance Analyst. Be the first to apply!
- senior information security analyst Boston, MA
- cloud security analyst Boston, MA
- entry level security analyst Boston, MA
- security analyst remote Boston, MA
- security analyst intern Boston, MA
- IT security analyst Boston, MA
- security analyst Boston, MA
- security operations analyst Boston, MA
- bond analyst Boston, MA
- junior security analyst Boston, MA


