Head of Cybersecurity Operations

2 weeks ago


Cambridge, Massachusetts, United States CarGurus LLC Full time

About Us

At CarGurus (NASDAQ: CARG), we empower individuals to navigate their automotive journey with confidence. Originating from a dedicated group of developers, our goal has always been to instill trust and transparency in the car shopping experience. Over the years, our innovative spirit and rapid market entry have positioned us as the leading automotive marketplace, achieving profitability for over 15 years.

Our Mission

As the automotive landscape shifts, we are committed to transitioning the entire vehicle acquisition process online, assisting our customers from selling their old vehicles to financing, purchasing, and delivering new ones. With millions of consumers visiting our platform monthly and approximately 30,000 dealerships utilizing our services, we pride ourselves on a culture that prioritizes our people. We foster an environment of kindness, collaboration, and innovation, empowering our team members to advance their careers. Disrupting a multi-trillion-dollar industry requires diverse and fresh perspectives.

Position Overview

We are in search of a strategic and experienced cybersecurity executive with a background in publicly traded SaaS organizations to fill the role of Director of Information Security. This position entails overseeing and enhancing our information security framework, ensuring the application of best practices, policies, procedures, and technologies to safeguard against evolving cyber threats. The successful candidate will align our information security initiatives with the overarching strategic goals of the organization while keeping the team focused on shared objectives.

As a pivotal leader, collaboration with business stakeholders such as Legal, IT, Enterprise Applications, Product, and Engineering is essential to ensure compliance with relevant regulations and industry standards, while maintaining the confidentiality, integrity, and availability (CIA) of our systems and data. At CarGurus, we value teamwork and cooperative efforts.

A security-first mindset is crucial, as you will play a key role in fostering a culture of privacy and security across the organization by educating staff on standards and best practices in relatable terms. Comfort in being in the spotlight is necessary; this role is not for those who prefer to remain in the background.

Quickly assessing the dynamic security landscape and making informed decisions regarding potential risks and threats to the organization is vital. CarGurus operates at a rapid pace, requiring quick thinking, especially during security incidents, with appropriate escalation to senior management when necessary.

This role reports directly to the VP of Information Security, Technology, and Enterprise Applications, overseeing Security Operations, Application Security, and IT Risk and Compliance.

Key Responsibilities:

  • Lead, mentor, and develop a high-performing security team.
  • Conduct annual performance reviews and create personal development and onboarding plans.
  • Establish strong, collaborative relationships with peers and key partners across the organization.
  • Oversee technical regulatory and compliance requirements.
  • Embed security awareness within the organizational culture, engaging with the community and driving continuous education through training and discussions.
  • Manage vendor relationships effectively.
  • Oversee the security budget and collaborate with the VP on annual budget planning.
  • Develop long-term strategic plans for Information Security, aligning tactical tasks and goals with business objectives, risk tolerance, and regulatory requirements, and communicate these to key stakeholders.
  • Supervise security controls and enhance the organization’s information security maturity.
  • Ensure enforcement and regular review of information security policies, standards, and guidelines to mitigate risks and maintain compliance with industry regulations.
  • Collaborate with IT Risk and Compliance to identify, assess, and prioritize information security risks.
  • Report security metrics, risks, and mitigation strategies to leadership and relevant stakeholders.

Technical Qualifications:

  • Bachelor's Degree or equivalent experience in Information Security or Computer Science.
  • Previous experience at a Director level; this is not an entry-level position.
  • Industry certifications such as GIAC (GSLC, GSTRT, GLEG), CISM, CISA, or CRISC are advantageous but not mandatory.
  • In-depth knowledge of cybersecurity and privacy principles, standards, and risk frameworks (e.g., NIST Cybersecurity Framework, CIS Controls, PCI-DSS, GDPR, CPRA).
  • Experience with system audits and IT reporting for SOX and SOC compliance is essential.
  • Work closely with the Director of IT and Enterprise Applications on large-scale projects and cross-functional initiatives.
  • Familiarity with cloud and application security, particularly with GCP, AWS, or Azure.
  • Solid understanding of RBAC models, SSO solutions, identity stores, directory services (SAML 2.0, OAuth 2.0, OIDC), and identity governance.
  • Provide feedback to security leaders on technical solutions while allowing them the flexibility to make technical decisions.
  • Proven experience in authoring and maintaining security policies, standards, and procedures.

Non-Technical Qualifications:

  • Ability to prioritize projects and tasks pragmatically, understanding their critical impacts on the business.
  • Collaborate with leadership to create quarterly roadmaps, presenting them to key partners for alignment.
  • Strong organizational skills are essential.
  • Excellent communication and interpersonal skills, capable of conveying complex technical concepts to diverse audiences in an approachable manner.
  • Strong writing skills are necessary for drafting detailed reports for leadership and the Audit Committee.
  • Adaptability to the security needs of a fast-paced organization is crucial.
  • A passion for continuous learning and staying updated on emerging cybersecurity trends and threats is essential.
  • Must be comfortable operating in a dynamic environment with a focus on innovation.
  • Integrity, ownership, and accountability should be fundamental values.

Working at CarGurus

We recognize and reward our team members' curiosity and passion with competitive benefits and compensation, including equity for all employees. Our career development initiatives and corporate giving programs, along with employee resource groups (ERGs), foster connections while making a meaningful impact. A flexible hybrid work model and generous time-off policies promote work-life balance and individual well-being. Additional perks such as complimentary daily lunch, discounts on new vehicles, wellness apps, commuting cost coverage, and more support our employees in prioritizing what matters most in their personal and professional lives.

Our Commitment to Diversity

CarGurus is dedicated to creating an inclusive environment where individuals can express their true selves and reach their full potential. We do not discriminate based on race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. We encourage applicants to apply even if they do not meet every qualification listed in the job description. If you require accommodations during the hiring process due to a disability, please inform your recruiter so we can provide the necessary support. We are eager to learn what unique contributions you can bring to CarGurus.



  • Cambridge, Massachusetts, United States CarGurus LLC Full time

    About Us At CarGurus (NASDAQ: CARG), we are dedicated to empowering individuals to reach their goals. Our journey began with a small group of developers committed to bringing trust and transparency to the automotive marketplace. Over the years, our innovative approach and rapid market entry have resulted in remarkable growth, making us the largest and...


  • Cambridge, Massachusetts, United States CarGurus Full time

    Company Overview and Position SummaryCarGurus, a prominent player in the automotive marketplace sector (NASDAQ: CARG), is dedicated to enabling customers to navigate their car buying journey with clarity and confidence. Having transformed from a small development team into the largest and fastest-growing platform in the field, CarGurus has maintained...


  • Cambridge, Massachusetts, United States Philips Full time

    About the RoleWe are seeking a highly experienced and skilled professional to lead our cloud enablement and digital transformation efforts as the Head of Cloud Enablement and Innovation. This is a critical role that will play a key part in driving innovation and growth for our business units.Key ResponsibilitiesLead a global team responsible for building,...


  • Cambridge, Massachusetts, United States GlaxoSmithKline Full time

    About the RoleWe are seeking a highly experienced and strategic leader to join our team as the Global Head of Laboratory Systems and Automation. This is a critical role that will play a pivotal part in driving the success of our organization.Key ResponsibilitiesLeadershipDevelop and implement a comprehensive strategy for laboratory systems and automation,...


  • Cambridge, Massachusetts, United States Draper Labs Full time

    Overview:Draper Labs is a distinguished, nonprofit research and development organization dedicated to addressing significant national challenges. With a workforce exceeding 2,000 professionals, we are committed to delivering effective and practical solutions across various domains, including military defense, space exploration, and biomedical engineering....


  • Cambridge, Massachusetts, United States General Dynamics Information Technology Full time

    Type of Requisition: RegularClearance Level Must Currently Possess: Top Secret/SCIClearance Level Must Be Able to Obtain: Top Secret SCI + PolygraphSuitability:Public Trust/Other Required: NoneJob Family: Information SecurityJob Qualifications:Skills: Information Security, Information Security Management, Information System SecurityCertifications:Cisco...


  • Cambridge, Massachusetts, United States Moderna Therapeutics Full time

    Position Overview:This position presents a remarkable opportunity to play a pivotal role within the clinical development team of a rapidly advancing organization that is transforming the biotechnology landscape. The Head of Biostatistical Operations will engage in the planning, execution, analysis, and reporting of clinical trials across the organization's...


  • Cambridge, Massachusetts, United States Intellia Full time

    How you will Achieve More with Intellia:We are hiring a Head of Development for Ex Vivo Programs to oversee all functions for the ex vivo programs, including clinical, regulatory, and biometrics.You will act as a Program Team Lead for an innovative new Ex Vivo Cell Therapy Program.You will be responsible for the development and execution of short and...


  • Cambridge, Massachusetts, United States Takeda Full time

    About the RoleWe are seeking a highly experienced and skilled professional to lead our Analytical Development team as the Head of Analytical Development. This is a critical role that requires a strong background in pharmaceutical sciences, quality assurance, and regulatory compliance.Key ResponsibilitiesLead and develop a global team of managers and...


  • Cambridge, Massachusetts, United States BioTalent Full time

    Join a Leading Cell Therapy CompanyWe are collaborating with a dynamic cell therapy organization to identify a Head of Technology Transfer who will spearhead initiatives aimed at enhancing the efficiency of Technology Transfer processes and elevating overall operational performance.This position presents a unique opportunity to become part of a rapidly...

  • Head of Science

    1 day ago


    Cambridge, Massachusetts, United States Kytopen Full time

    About the RoleKytopen is a pioneering biotechnology company that is revolutionizing the field of cell engineering. We are seeking a highly experienced and skilled individual to join our leadership team as the Head of Science.Key ResponsibilitiesOversee the scientific programs and operations at Kytopen, ensuring alignment with the company's commercial and...


  • Cambridge, Massachusetts, United States Takeda Pharmaceutical Full time

    Job SummaryWe are seeking a highly experienced and skilled professional to lead our Analytical Controls team as a Head, Analytical Controls Specialist. This is a critical role that requires a strong background in pharmaceutical sciences, analytical development, and quality assurance.Key ResponsibilitiesLead and develop a global team of managers and...


  • Cambridge, Massachusetts, United States City of Cambridge Full time

    About the Department of Human Service ProgramsThe Department of Human Service Programs (DHSP) is a leading provider of human services in Cambridge, Massachusetts. Our mission is to enhance the quality of life for Cambridge residents by creating and coordinating services that address the complex needs of our community.About the RoleThe Division Head will...


  • Cambridge, Massachusetts, United States MEDIPOST America, Inc. Full time

    MEDIPOST America, Inc. is a prominent umbilical cord blood banking and cellular therapy organization dedicated to pioneering advanced stem cell treatments for degenerative conditions such as Alzheimer's disease, Diabetic Neuropathy, and Osteoarthritis.Our flagship product, CARTISTEM, represents the first stem cell therapy specifically designed for knee...


  • Cambridge, Massachusetts, United States MEDIPOST America, Inc. Full time

    MEDIPOST America, Inc. is a prominent umbilical cord blood banking and cellular therapy organization, dedicated to pioneering advanced stem cell treatments for degenerative conditions such as Alzheimer's disease, Diabetic Neuropathy, and Osteoarthritis.Our flagship product, CARTISTEM, represents the first-ever stem cell therapy for knee Osteoarthritis...


  • Cambridge, Massachusetts, United States MEDIPOST America, Inc. Full time

    MEDIPOST America, Inc. is a prominent player in the field of umbilical cord blood banking and cellular therapies. Our mission is to pioneer advanced stem cell treatments aimed at combating degenerative conditions such as Alzheimer's disease, Diabetic Neuropathy, and Osteoarthritis.Our flagship product, CARTISTEM, stands as the first-ever stem cell therapy...


  • Cambridge, Massachusetts, United States MonteVerdi Full time

    At MonteVerdi, we take pride in delivering exceptional, contemporary Italian dishes infused with creativity. Our culinary offerings highlight premium ingredients, expert techniques, and a commitment to innovative cuisine that delights our guests. We are a lively, fast-paced establishment dedicated to creating unforgettable dining experiences. Position...


  • Cambridge, Massachusetts, United States Intellia Therapeutics Full time

    Why Join Intellia?Our mission is to develop curative genome editing treatments that can positively transform the lives of people living with severe and life-threatening diseases.Beyond our science, we live our four core values: One, Explore, Disrupt, Deliver and feel strongly that you can achieve more at Intellia. We have a single-minded determination to...


  • Cambridge, Massachusetts, United States MEDIPOST America, Inc. Full time

    MEDIPOST America, Inc. is a prominent entity in the field of umbilical cord blood banking and cellular therapy, dedicated to pioneering advanced stem cell treatments for degenerative conditions such as Alzheimer's disease, Diabetic Neuropathy, and Osteoarthritis.Our flagship product, CARTISTEM, represents a groundbreaking stem cell therapy specifically...

  • US Paralegal Site Head

    2 months ago


    Cambridge, Massachusetts, United States U175 (FCRS = US175) Novartis Institutes for BioMedical Research, Inc. Full time

    What you will be doing:Talent Management:• Ensuring patent paralegal team is up-to-date on relevant worldwide practice and procedures, particularly EP and/or US law changes, including leading workshops for a global audience.Processes and Data Quality:• Manage deadlines in docketing database, including data relating to global patent portfolio.• Prepare...