BostonFull TimeEngineering
Remotely
awsgrcai governanceiso 27001gdprccpanistsoc 2 type ii
Job Description
📋 Description
- Lead the strategic direction and maturity of CarGurus’ Governance, Risk, and Compliance program.
- Build the cyber risk management program, including cybersecurity risk assessments, risk register
- Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence
- Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and
- Develop and maintain security policies, standards, and governance processes aligned with business
- Build and operationalize the AI Governance program, including AI risk assessments, acceptable use
🎯 Requirements
- 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
- Proven experience building and maturing cyber risk management programs in a cloud-native SaaS
- Extensive experience leading SOC 2 Type II compliance programs.
- Experience supporting SOX ITGCs in partnership with Internal Audit.
- Experience building AI governance frameworks and conducting AI security and risk assessments.
- Strong knowledge of SOC 2, NIST ISO 27001, GDPR, CCPA, and AWS security principles.
🎁 Benefits
- The role offers a competitive base salary with a total rewards package including equity
- Hybrid work model with flexible benefits and comprehensive time-off policies.
- Perks such as daily free lunch, a new car discount, wellness apps, commuting cost coverage, and