Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Sr. Director, Governance, Risk & Compliance
Cambridge, MA · On-site
$229K - $310K/yr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Sr. Director, Governance, Risk & Compliance
Cambridge, MA · On-site
$229K - $310K/yr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the ...
Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the ...
AI Risk & Compliance Analyst
Boston, MA · On-site
The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization. WHOOP is seeking a ...
AI Risk & Compliance Analyst
Boston, MA · On-site
The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization. WHOOP is seeking a ...
Compliance Risk Analyst
Marlborough, MA · On-site
$70K - $91K/yr
Manage the end-to-end governance lifecycle for emerging technology use cases-from intake and ... risk management, or technical compliance. • Technical Proficiency: 1-2 years of experience ...
Compliance Risk Analyst
Marlborough, MA · On-site
$70K - $91K/yr
Manage the end-to-end governance lifecycle for emerging technology use cases-from intake and ... risk management, or technical compliance. • Technical Proficiency: 1-2 years of experience ...
Director, AI Governance & Policy
Boston, MA · On-site
$184 - $276/hr
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
Director, AI Governance & Policy
Boston, MA · On-site
$184 - $276/hr
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
Director, AI Governance & Policy
Boston, MA · On-site
$184 - $276/hr
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
Director, AI Governance & Policy
Boston, MA · On-site
$184 - $276/hr
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
Head of GRC (Governance, Risk, & Compliance)
Kendall Square, MA · On-site
$220 - $260/hr
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
Head of GRC (Governance, Risk, & Compliance)
Kendall Square, MA · On-site
$220 - $260/hr
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
WHOOP is seeking a strategic and execution-oriented Manager and Senior Manager of Governance, Risk, and Compliance to lead the day-to-day execution and support the ongoing operation and enhancement ...
WHOOP is seeking a strategic and execution-oriented Manager and Senior Manager of Governance, Risk, and Compliance to lead the day-to-day execution and support the ongoing operation and enhancement ...
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
Head of GRC (Governance, Risk, & Compliance)
Cambridge, MA · On-site
$220 - $260/hr
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
Head of GRC (Governance, Risk, & Compliance)
Cambridge, MA · On-site
$220 - $260/hr
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
Sr. Director, Governance, Risk & Compliance United States + 1 more Information Technology Poste[...]
Cambridge, MA · On-site
$229.50 - $310.50/hr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Sr. Director, Governance, Risk & Compliance United States + 1 more Information Technology Poste[...]
Cambridge, MA · On-site
$229.50 - $310.50/hr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
IT Risk & Compliance Analyst
Andover, MA · On-site +1
$95K - $95K/yr
Three to five years of experience in IT compliance, IT audit, internal audit, risk management, controls, governance, risk and compliance (GRC), or information security compliance. * Working knowledge ...
IT Risk & Compliance Analyst
Andover, MA · On-site +1
$95K - $95K/yr
Three to five years of experience in IT compliance, IT audit, internal audit, risk management, controls, governance, risk and compliance (GRC), or information security compliance. * Working knowledge ...
IT Risk & Compliance Analyst
North Andover, MA · Remote
$100K - $101K/yr
Three to five years of experience in IT compliance, IT audit, internal audit, risk management, controls, governance, risk and compliance (GRC), or information security compliance. * Working knowledge ...
IT Risk & Compliance Analyst
North Andover, MA · Remote
$100K - $101K/yr
Three to five years of experience in IT compliance, IT audit, internal audit, risk management, controls, governance, risk and compliance (GRC), or information security compliance. * Working knowledge ...
Governance Risk Compliance information
See Boston, MA salary details
$34.2K - $42.2K
12% of jobs
$42.2K - $50.1K
7% of jobs
$52.9K is the 25th percentile. Wages below this are outliers.
$50.1K - $58.1K
17% of jobs
$58.1K - $66K
10% of jobs
The median wage is $68.1K / yr.
$66K - $74K
16% of jobs
$74K - $81.9K
9% of jobs
$87K is the 75th percentile. Wages above this are outliers.
$81.9K - $89.9K
7% of jobs
$89.9K - $97.8K
5% of jobs
$97.8K - $105.8K
7% of jobs
$105.8K - $113.7K
5% of jobs
$113.7K - $121.7K
4% of jobs
$34.2K
$74.7K
$121.7K
How much do governance risk compliance jobs pay per year?
What is governance risk compliance?
What are jobs in governance risk compliance?
Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.
What are the key skills and qualifications needed to thrive as a governance risk compliance professional?
How does a governance risk compliance professional typically collaborate with other departments within an organization?
What is the difference between Governance Risk Compliance vs Risk Analyst?
| Aspect | Governance Risk Compliance | Risk Analyst |
|---|---|---|
| Certifications | CRISC, CISA, CISSP | CFA, FRM, CRISC |
| Work Environment | Corporate, regulated industries | Financial, consulting firms |
| Employer & Industry Usage | Financial institutions, healthcare, government | Banking, investment firms, insurance |
Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.
What is the work of governance risk compliance?
What are the most commonly searched types of Governance Risk Compliance jobs in Boston, MA?
The most popular types of Governance Risk Compliance jobs in Boston, MA are:
What are popular job titles related to Governance Risk Compliance jobs in Boston, MA?
For Governance Risk Compliance jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Governance Risk Compliance jobs in Boston, MA look for?
The top searched job categories for Governance Risk Compliance jobs in Boston, MA are:
What cities near Boston, MA are hiring for Governance Risk Compliance jobs?
Cities near Boston, MA with the most Governance Risk Compliance job openings:

Principal Security Governance, Risk & Compliance Analyst
Boston, MA • On-site
Full-time
Posted 8 days ago
Job description
Role overview
The Principal Information Security GRC Analyst serves as a strategic leader responsible for designing, implementing, and continuously improving CarGurus' cybersecurity governance, risk, and compliance program. This role partners across Engineering, Product, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure security controls effectively manage cyber risk while enabling the business.
The Principal GRC professional leads key initiatives across cyber risk management, customer trust, security compliance, AI governance, third-party risk, and security policy, helping scale security programs to support CarGurus' continued growth.
What you'll do
- Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program.
- Build the cyber risk management program, including cybersecurity risk assessments, cyber risk register management, issue remediation tracking, risk reporting, and security metrics.
- Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring.
- Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and security-related SOX initiatives.
- Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices.
- Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements.
- Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors.
- Partner with Engineering and Product teams to integrate security and AI governance into the secure software development lifecycle.
- Lead third-party security risk management activities and vendor security assessments.
- Support customer trust by leading security questionnaires, customer security reviews, and Trust Center initiatives.
- Partner with Privacy and Legal on data classification, retention, privacy risk assessments, and regulatory compliance.
- Develop executive reporting on cyber risk, compliance posture, and key security metrics.
- Drive automation and continuous improvement across GRC processes and controls.
What you'll bring
- 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
- Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
- Extensive experience leading SOC 2 Type II compliance programs.
- Experience supporting SOX ITGCs in partnership with Internal Audit.
- Experience building AI governance frameworks and conducting AI security and risk assessments.
- Strong knowledge of SOC 2, NIST ISO 27001, GDPR, CCPA, and AWS security principles.
- Excellent executive communication skills with the ability to influence technical and business stakeholders.
About CarGurus
Sourced by ZipRecruiter
Industry
Internet and it
Company size
1,001 - 5,000 Employees
Headquarters location
Cambridge, MA, US
Year founded
2006