Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Principal Security Governance, Risk & Compliance Analyst
Boston, MA · On-site
$135K - $168K/yr
Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program. * Build the cyber risk management program, including cybersecurity risk assessments, cyber risk ...
Sr. Director, Governance, Risk & Compliance
Cambridge, MA · Hybrid
$229K - $310K/yr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Sr. Director, Governance, Risk & Compliance
Cambridge, MA · Hybrid
$229K - $310K/yr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Sr. Director, Governance, Risk & Compliance
Cambridge, MA · On-site
$229K - $310K/yr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Sr. Director, Governance, Risk & Compliance
Cambridge, MA · On-site
$229K - $310K/yr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the ...
Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the ...
Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the ...
Role Summary The Associate Director, Information Security Governance Risk and Compliance serves as the functional leader for Governance, Risk and Compliance across the US affiliate, reporting to the ...
AI Risk & Compliance Analyst
Boston, MA · On-site
The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization. WHOOP is seeking a ...
AI Risk & Compliance Analyst
Boston, MA · On-site
The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization. WHOOP is seeking a ...
Director, AI Governance & Policy
Boston, MA · On-site
$184 - $276/hr
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
Director, AI Governance & Policy
Boston, MA · On-site
$184 - $276/hr
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
Director, AI Governance & Policy
Boston, MA · On-site
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
Director, AI Governance & Policy
Boston, MA · On-site
The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...
Head of GRC (Governance, Risk, & Compliance)
Kendall Square, MA · On-site
$220 - $260/hr
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
Head of GRC (Governance, Risk, & Compliance)
Kendall Square, MA · On-site
$220 - $260/hr
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
WHOOP is seeking a strategic and execution-oriented Manager and Senior Manager of Governance, Risk, and Compliance to lead the day-to-day execution and support the ongoing operation and enhancement ...
WHOOP is seeking a strategic and execution-oriented Manager and Senior Manager of Governance, Risk, and Compliance to lead the day-to-day execution and support the ongoing operation and enhancement ...
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
Head of GRC (Governance, Risk, & Compliance)
Cambridge, MA · On-site
$220 - $260/hr
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
Head of GRC (Governance, Risk, & Compliance)
Cambridge, MA · On-site
$220 - $260/hr
As Head of GRC, you'll own a compliance program that's audit-ready by design, not by scramble. To be clear about scope, this role is not: * A paperwork-only compliance role with no rigor. * A job ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
The Director, Federal Security Governance, Risk & Compliance (SGRC) serves as the senior accountable lead for the SGRC pillar. This role drives the strategy, risk governance, regulatory compliance ...
Sr. Director, Governance, Risk & Compliance United States + 1 more Information Technology Poste[...]
Cambridge, MA · On-site
$229.50 - $310.50/hr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
Sr. Director, Governance, Risk & Compliance United States + 1 more Information Technology Poste[...]
Cambridge, MA · On-site
$229.50 - $310.50/hr
Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk ...
The Manager, Security Governance & Risk leads Emburse's security governance, risk, and compliance function, with primary focus on enterprise security risk management, security metrics and reporting ...
The Manager, Security Governance & Risk leads Emburse's security governance, risk, and compliance function, with primary focus on enterprise security risk management, security metrics and reporting ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager
Boston, MA · On-site
$124K - $280K/yr
... governance objectives - Promoting a culture of compliance and ethical behavior through training and development initiatives What You Must Have - At least a Bachelor's degree - At least 7 years of ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager
Boston, MA · On-site
$124K - $280K/yr
... governance objectives - Promoting a culture of compliance and ethical behavior through training and development initiatives What You Must Have - At least a Bachelor's degree - At least 7 years of ...
Governance Risk Compliance information
See Canton, MA salary details
$33.3K - $41K
12% of jobs
$41K - $48.8K
7% of jobs
$51.4K is the 25th percentile. Wages below this are outliers.
$48.8K - $56.5K
17% of jobs
$56.5K - $64.3K
10% of jobs
The median wage is $66.3K / yr.
$64.3K - $72K
16% of jobs
$72K - $79.7K
9% of jobs
$84.7K is the 75th percentile. Wages above this are outliers.
$79.7K - $87.5K
7% of jobs
$87.5K - $95.2K
5% of jobs
$95.2K - $103K
7% of jobs
$103K - $110.7K
5% of jobs
$110.7K - $118.4K
4% of jobs
$33.3K
$72.7K
$118.4K
How much do governance risk compliance jobs pay per year?
What is governance risk compliance?
What are jobs in governance risk compliance?
Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.
What are the key skills and qualifications needed to thrive as a governance risk compliance professional?
How does a governance risk compliance professional typically collaborate with other departments within an organization?
What is the difference between Governance Risk Compliance vs Risk Analyst?
| Aspect | Governance Risk Compliance | Risk Analyst |
|---|---|---|
| Certifications | CRISC, CISA, CISSP | CFA, FRM, CRISC |
| Work Environment | Corporate, regulated industries | Financial, consulting firms |
| Employer & Industry Usage | Financial institutions, healthcare, government | Banking, investment firms, insurance |
Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.
What is the work of governance risk compliance?
What cities near Canton, MA are hiring for Governance Risk Compliance jobs?
Cities near Canton, MA with the most Governance Risk Compliance job openings:

Principal Security Governance, Risk & Compliance Analyst
Boston, MA
Full-time
Posted 9 days ago
Job description
Role overview
The Principal Information Security GRC Analyst serves as a strategic leader responsible for designing, implementing, and continuously improving CarGurus' cybersecurity governance, risk, and compliance program. This role partners across Engineering, Product, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure security controls effectively manage cyber risk while enabling the business.
The Principal GRC professional leads key initiatives across cyber risk management, customer trust, security compliance, AI governance, third-party risk, and security policy, helping scale security programs to support CarGurus' continued growth.
What you'll do
- Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program.
- Build the cyber risk management program, including cybersecurity risk assessments, cyber risk register management, issue remediation tracking, risk reporting, and security metrics.
- Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring.
- Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and security-related SOX initiatives.
- Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices.
- Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements.
- Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors.
- Partner with Engineering and Product teams to integrate security and AI governance into the secure software development lifecycle.
- Lead third-party security risk management activities and vendor security assessments.
- Support customer trust by leading security questionnaires, customer security reviews, and Trust Center initiatives.
- Partner with Privacy and Legal on data classification, retention, privacy risk assessments, and regulatory compliance.
- Develop executive reporting on cyber risk, compliance posture, and key security metrics.
- Drive automation and continuous improvement across GRC processes and controls.
What you'll bring
- 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
- Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
- Extensive experience leading SOC 2 Type II compliance programs.
- Experience supporting SOX ITGCs in partnership with Internal Audit.
- Experience building AI governance frameworks and conducting AI security and risk assessments.
- Strong knowledge of SOC 2, NIST ISO 27001, GDPR, CCPA, and AWS security principles.
- Excellent executive communication skills with the ability to influence technical and business stakeholders.
About CarGurus
Sourced by ZipRecruiter
Industry
Internet and it
Company size
1,001 - 5,000 Employees
Headquarters location
Cambridge, MA, US
Year founded
2006