About the job
Who We Are
At CarGurus (NASDAQ: CARG), we empower people by simplifying their journey to car ownership. Our story began with a passionate team of developers dedicated to bringing trust and transparency to the automotive marketplace. Over the years, our innovative approach and rapid market growth have positioned us as the largest and fastest-growing automotive marketplace, maintaining profitability for over 15 years.
What We Do
As the automotive industry evolves, so do we. We are transforming the entire car buying experience online, assisting our customers from selling their old vehicles to financing, purchasing, and delivering new ones. Each month, millions of consumers visit CarGurus.com, and approximately 30,000 dealerships leverage our solutions. Our employees thrive in a people-first culture that promotes kindness, collaboration, and innovation, and provides the tools necessary for career advancement. Join us as we disrupt a trillion-dollar industry with fresh, diverse perspectives!
Role Overview:
As the Manager of Security Governance, Risk, and Compliance (GRC) within our Information Security team, you will play a pivotal role in the evolution of our established GRC function. You will not only maintain our program but also enhance our capabilities to ensure that security acts as a catalyst for our business success, converting complex regulatory demands into a competitive edge.
Your strategic leadership will focus on high-standard execution while emphasizing Revenue Enablement, ensuring our security posture alleviates friction in the enterprise sales cycle and strengthens our reputation as a trusted partner.
How You’ll Make a Difference:
- Lead an established team to elevate our GRC maturity, developing and refining our Integrated Management System (IMS) across standards such as ISO 27001, 27017, 27018, and SOC 2 Type II.
- Modernize our risk reporting through quantitative risk management, moving beyond traditional qualitative assessments to deliver real-time, data-driven insights and financial risk forecasts grounded in FAIR principles.
- Act as a key contributor on our AI Governance Committee, facilitating the secure implementation of AI/LLM features within our products and overseeing AI integration governance across our internal SaaS ecosystem in alignment with ISO 42001.
- Position GRC as a driver of revenue by enhancing our compliance and risk functions, ensuring our security trust posture promotes global growth and instills confidence in our stakeholders.

