Principal Information Security Risk and Compliance Analyst
Boston, Massachusetts, United States
$135k-$168k/yrHybridFull Time
CarGurusNasdaq Global Select Market: CARG: Public online automotive marketplace helping consumers and dealers buy and sell new and used vehicles.
8+ YOERequires 8+ years in information security, cyber risk, GRC, or IT audit; experience with cloud-native SaaS, SOC 2 Type II, SOX ITGCs, AI governance, risk assessments, and executive communication.
Citizens Financial GroupNYSE: CFG: US regional bank holding providing diverse financial services.
Experience performing third-party vendor assessments and understanding of cyber security controls and regulatory frameworks (ISO 27001, GLBA, SOX, PCI, HIPAA, FFIEC). Able to evaluate controls, perform QA, and support remediation and regulatory exam activities.
WHOOP: Wearable technology developing health and fitness tracking devices.
6+ YOE6+ years in cybersecurity or enterprise risk; experience conducting structured cyber/IT risk assessments, maintaining risk registers, familiarity with security frameworks and AI risk; strong communication and analysis skills.
NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, NIST AI RMF, ISO/IEC 42001, FAIR