Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program ... Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program ... Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program ... Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program ... Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI ...
Sr. Director, Governance, Risk & Compliance
Cambridge, MA · On-site
$229K - $310K/yr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Sr. Director, Governance, Risk & Compliance
Cambridge, MA · On-site
$229K - $310K/yr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program ... Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI ...
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program ... Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI ...
Cyber Policy Enforcement Lead, VP
$116K - $157K/yr
... governance mechanisms. * Partner with SMEs from Global Cybersecurity, Technology, Risk, Compliance, and Business stakeholders to establish enforcement priorities, remediation expectations, and ...
Cyber Policy Enforcement Lead, VP
$116K - $157K/yr
... governance mechanisms. * Partner with SMEs from Global Cybersecurity, Technology, Risk, Compliance, and Business stakeholders to establish enforcement priorities, remediation expectations, and ...
Cyber Policy Enforcement Lead, VP
Quincy, MA · On-site
$116K - $157K/yr
... governance mechanisms. * Partner with SMEs from Global Cybersecurity, Technology, Risk, Compliance, and Business stakeholders to establish enforcement priorities, remediation expectations, and ...
Cyber Policy Enforcement Lead, VP
Quincy, MA · On-site
$116K - $157K/yr
... governance mechanisms. * Partner with SMEs from Global Cybersecurity, Technology, Risk, Compliance, and Business stakeholders to establish enforcement priorities, remediation expectations, and ...
Cybersecurity Compliance Coordinator SY26-27
Needham, MA · On-site
$100.28 - $114.66/hr
Rather than focusing on hands‑on technical engineering, this position focuses on the governance, risk, compliance and project management side of cybersecurity. This position is responsible for ...
Cybersecurity Compliance Coordinator SY26-27
Needham, MA · On-site
$100.28 - $114.66/hr
Rather than focusing on hands‑on technical engineering, this position focuses on the governance, risk, compliance and project management side of cybersecurity. This position is responsible for ...
Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as ... Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk ...
Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as ... Cybersecurity. This role establishes and leads the GRC operating model, governance framework, risk ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior ... YOU'RE GOOD AT You excel at leading complex federal cybersecurity and compliance programs by ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior ... YOU'RE GOOD AT You excel at leading complex federal cybersecurity and compliance programs by ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior ... YOU'RE GOOD AT You excel at leading complex federal cybersecurity and compliance programs by ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior ... YOU'RE GOOD AT You excel at leading complex federal cybersecurity and compliance programs by ...
Sr. Director, Governance, Risk & Compliance United States + 1 more Information Technology Poste[...]
Cambridge, MA · On-site
$229.50 - $310.50/hr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Sr. Director, Governance, Risk & Compliance United States + 1 more Information Technology Poste[...]
Cambridge, MA · On-site
$229.50 - $310.50/hr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
AI Risk & Compliance Analyst
Boston, MA · On-site
The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization. WHOOP is seeking a ...
AI Risk & Compliance Analyst
Boston, MA · On-site
The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization. WHOOP is seeking a ...
Cybersecurity Governance, Risk & Compliance (GRC) * Enterprise Architecture * Cloud Engineering & DevOps Teams * Application Owners and Technology Leaders * Data & Analytics Teams * ServiceNow IRM ...
Cybersecurity Governance, Risk & Compliance (GRC) * Enterprise Architecture * Cloud Engineering & DevOps Teams * Application Owners and Technology Leaders * Data & Analytics Teams * ServiceNow IRM ...
Cybersecurity Governance, Risk & Compliance (GRC) * Enterprise Architecture * Cloud Engineering & DevOps Teams * Application Owners and Technology Leaders * Data & Analytics Teams * ServiceNow IRM ...
Cybersecurity Governance, Risk & Compliance (GRC) * Enterprise Architecture * Cloud Engineering & DevOps Teams * Application Owners and Technology Leaders * Data & Analytics Teams * ServiceNow IRM ...
Cybersecurity Governance, Risk & Compliance (GRC) * Enterprise Architecture * Cloud Engineering & DevOps Teams * Application Owners and Technology Leaders * Data & Analytics Teams * ServiceNow IRM ...
Cybersecurity Governance, Risk & Compliance (GRC) * Enterprise Architecture * Cloud Engineering & DevOps Teams * Application Owners and Technology Leaders * Data & Analytics Teams * ServiceNow IRM ...
Cybersecurity Solutions Architect
Canton, MA · On-site
$120 - $170/hr
... help identify governance, risk, compliance, third‑party risk, and broader security program ... Conduct cybersecurity-focused discovery sessions with prospective and existing clients.
Cybersecurity Solutions Architect
Canton, MA · On-site
$120 - $170/hr
... help identify governance, risk, compliance, third‑party risk, and broader security program ... Conduct cybersecurity-focused discovery sessions with prospective and existing clients.
Lead the enterprise cybersecurity governance, risk, and compliance program * Establish and maintain cybersecurity risk management processes, risk assessments, remediation plans, and risk reporting
Lead the enterprise cybersecurity governance, risk, and compliance program * Establish and maintain cybersecurity risk management processes, risk assessments, remediation plans, and risk reporting
Senior Director, Chief Information Security Officer
Cambridge, MA · On-site
$230 - $360/hr
Lead the enterprise cybersecurity governance, risk, and compliance program * Establish and maintain cybersecurity risk management processes, risk assessments, remediation plans, and risk reporting
Senior Director, Chief Information Security Officer
Cambridge, MA · On-site
$230 - $360/hr
Lead the enterprise cybersecurity governance, risk, and compliance program * Establish and maintain cybersecurity risk management processes, risk assessments, remediation plans, and risk reporting
Lead the enterprise cybersecurity governance, risk, and compliance program * Establish and maintain cybersecurity risk management processes, risk assessments, remediation plans, and risk reporting
Lead the enterprise cybersecurity governance, risk, and compliance program * Establish and maintain cybersecurity risk management processes, risk assessments, remediation plans, and risk reporting
Lead the enterprise cybersecurity governance, risk, and compliance program * Establish and maintain cybersecurity risk management processes, risk assessments, remediation plans, and risk reporting
Lead the enterprise cybersecurity governance, risk, and compliance program * Establish and maintain cybersecurity risk management processes, risk assessments, remediation plans, and risk reporting
Cybersecurity Governance Risk Compliance information
What is cybersecurity governance, risk, and compliance (GRC)?
What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?
What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?
What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?
| Aspect | Cybersecurity Governance Risk Compliance | Cybersecurity Analyst |
|---|---|---|
| Certifications | CISA, CISSP, CISM | CompTIA Security+, CISSP, CEH |
| Work Environment | Policy development, audits, compliance frameworks | Monitoring security systems, incident response |
| Employer & Industry Usage | Organizations with compliance needs, regulatory bodies | IT security teams, cybersecurity firms |
While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Massachusetts?
For Cybersecurity Governance Risk Compliance jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Massachusetts look for?
The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Massachusetts are:
What cities in Massachusetts are hiring for Cybersecurity Governance Risk Compliance jobs?
Cities in Massachusetts with the most Cybersecurity Governance Risk Compliance job openings:

Principal Security Governance, Risk & Compliance Analyst
Boston, MA
Full-time
Posted 7 days ago
Job description
Role overview
The Principal Information Security GRC Analyst serves as a strategic leader responsible for designing, implementing, and continuously improving CarGurus' cybersecurity governance, risk, and compliance program. This role partners across Engineering, Product, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure security controls effectively manage cyber risk while enabling the business.
The Principal GRC professional leads key initiatives across cyber risk management, customer trust, security compliance, AI governance, third-party risk, and security policy, helping scale security programs to support CarGurus' continued growth.
What you'll do
- Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program.
- Build the cyber risk management program, including cybersecurity risk assessments, cyber risk register management, issue remediation tracking, risk reporting, and security metrics.
- Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring.
- Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and security-related SOX initiatives.
- Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices.
- Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements.
- Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors.
- Partner with Engineering and Product teams to integrate security and AI governance into the secure software development lifecycle.
- Lead third-party security risk management activities and vendor security assessments.
- Support customer trust by leading security questionnaires, customer security reviews, and Trust Center initiatives.
- Partner with Privacy and Legal on data classification, retention, privacy risk assessments, and regulatory compliance.
- Develop executive reporting on cyber risk, compliance posture, and key security metrics.
- Drive automation and continuous improvement across GRC processes and controls.
What you'll bring
- 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
- Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
- Extensive experience leading SOC 2 Type II compliance programs.
- Experience supporting SOX ITGCs in partnership with Internal Audit.
- Experience building AI governance frameworks and conducting AI security and risk assessments.
- Strong knowledge of SOC 2, NIST ISO 27001, GDPR, CCPA, and AWS security principles.
- Excellent executive communication skills with the ability to influence technical and business stakeholders.
About CarGurus
Sourced by ZipRecruiter
Industry
Internet and it
Company size
1,001 - 5,000 Employees
Headquarters location
Cambridge, MA, US
Year founded
2006