Chief Information Security Officer

2 weeks ago


Cambridge, Massachusetts, United States CarGurus LLC Full time

About Us

At CarGurus (NASDAQ: CARG), we empower individuals to navigate their journeys with confidence. Our origins trace back to a dedicated group of developers committed to instilling trust and transparency in the automotive marketplace. Over the years, our innovative spirit and rapid market entry have propelled us to become the largest and most rapidly expanding automotive platform, maintaining profitability for over 15 years.

Our Mission

The automotive landscape is shifting, and so are we. We are transitioning the entire vehicle purchasing experience online, assisting our customers at every stage—from selling their old vehicles to financing, purchasing, and delivering new ones. Each month, millions of consumers engage with our platform, supported by approximately 30,000 dealerships utilizing our services. Our employees thrive in a culture that prioritizes people, fostering collaboration, kindness, and innovation while equipping our Gurus with the necessary tools for career advancement. Disrupting a multi-trillion-dollar industry requires diverse and fresh perspectives.

Position Overview

We are in search of a proficient and strategic leader in cybersecurity, with experience in publicly traded SaaS organizations, to take on the role of Director of Information Security. This position entails overseeing and enhancing our information security framework, ensuring the application of best practices, policies, procedures, and technologies to safeguard against emerging cyber threats. The successful candidate will align established information security initiatives with the overarching strategic goals of the organization while ensuring the team remains informed and focused on shared objectives.

As a pivotal leader, collaboration with business stakeholders such as Legal, IT, Enterprise Applications, Product, and Engineering is essential to ensure compliance with relevant regulations and industry standards, while upholding the confidentiality, integrity, and availability (CIA) of our systems and data. CarGurus values teamwork and collaborative efforts.

A security-first mindset is crucial, as you will be responsible for fostering a culture of privacy and security across the organization by educating staff on standards and best practices in accessible language. Comfort in being in the spotlight is necessary; this role is not suited for those who prefer to remain in the background.

Rapid assessment of the ever-evolving security landscape is required, enabling practical decision-making regarding potential risks and threats to the organization. CarGurus operates at a fast pace, necessitating quick thinking, especially during security incidents, with appropriate escalation to senior management.

This role reports directly to the VP of Information Security, Technology, and Enterprise Applications, overseeing Security Operations, Application Security, and IT Risk and Compliance.

Key Responsibilities:

  • Lead, mentor, and develop a high-performing security team.
  • Conduct annual performance reviews and create personal development and onboarding plans.
  • Establish strong, collaborative relationships with peers and key partners across the organization.
  • Maintain oversight of technical regulatory and compliance obligations.
  • Embed security awareness within the company culture, engaging with the community and driving continuous education through training and discussions.
  • Manage vendor relationships effectively.
  • Oversee the security budget in collaboration with the VP during annual budget planning.
  • Develop long-term strategic plans for Information Security, aligning tactical tasks and goals with business objectives, risk tolerance, and regulatory requirements.
  • Supervise security controls and the advancement of the organization's information security maturity.
  • Ensure enforcement and regular review of information security policies, standards, and guidelines to mitigate risks and maintain compliance with industry regulations.
  • Collaborate with IT Risk and Compliance to identify, assess, and prioritize information security risks across the organization.
  • Report security metrics, risks, and mitigation strategies to leadership and relevant stakeholders.

Technical Qualifications:

  • Bachelor's Degree or equivalent experience in Information Security or Computer Science.
  • Previous experience at a Director level; this is not an entry-level position.
  • Industry certifications such as GIAC (GSLC, GSTRT, GLEG), CISM, CISA, or CRISC are advantageous but not mandatory.
  • Comprehensive understanding of cybersecurity and privacy principles, standards, and risk frameworks (e.g., NIST Cybersecurity Framework, CIS Controls, PCI-DSS, GDPR, CPRA).
  • Experience with system audits and IT reporting for SOX and SOC compliance is essential.
  • Collaborate closely with the Director of IT and Enterprise Applications on large-scale projects and cross-functional initiatives.
  • Familiarity with cloud and application security fundamentals, including GCP, AWS, or Azure.
  • Solid understanding of RBAC models, SSO solutions, identity stores, and identity governance.
  • Provide constructive feedback to security leaders on technical solutions while allowing them the autonomy to make technical decisions.
  • Proven ability to author and maintain security policies, standards, and procedures.

Non-technical Qualifications:

  • Ability to prioritize projects and tasks pragmatically, understanding their critical impacts on the business.
  • Collaborate with leadership to develop quarterly roadmaps, presenting them to key partners for alignment.
  • Strong organizational skills are essential.
  • Excellent communication and interpersonal skills, capable of conveying complex technical concepts to diverse audiences.
  • Strong writing skills are necessary for preparing detailed reports for leadership and the Audit Committee.
  • Adaptability to the security needs of a dynamic organization is crucial.
  • A passion for continuous learning and staying updated on emerging cybersecurity trends and threats.
  • Comfort with calculated risk-taking and innovation in a fast-paced environment.
  • Integrity, accountability, and ownership must be fundamental values.

Working at CarGurus

We recognize and reward our Gurus' curiosity and passion with competitive benefits and compensation, including equity for all employees. Our career development initiatives and corporate giving programs, along with employee resource groups (ERGs), foster connections while making a meaningful impact. A flexible hybrid work model and generous time-off policies promote work-life balance and personal well-being. Additional perks, such as daily complimentary lunch, discounts on new vehicles, and wellness resources, help our team focus on what matters most in their professional and personal lives.

Our Commitment to Inclusion

CarGurus is dedicated to creating an environment where individuals can express their true selves and realize their potential. We do not discriminate based on race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. We value diverse skills, experiences, and perspectives, and encourage applications from all qualified candidates.



  • Cambridge, Massachusetts, United States CarGurus LLC Full time

    About Us At CarGurus (NASDAQ: CARG), we empower individuals to navigate their automotive journey with confidence. Our origins trace back to a dedicated group of developers who aimed to revolutionize car shopping through trust and transparency. Over the years, we have evolved into the largest and fastest-growing automotive marketplace, achieving profitability...


  • Cambridge, Massachusetts, United States General Dynamics Information Technology Full time

    Type of Requisition: RegularClearance Level Must Currently Possess: Top Secret/SCIClearance Level Must Be Able to Obtain: Top Secret SCI + PolygraphSuitability:Public Trust/Other Required: NoneJob Family: Information SecurityJob Qualifications:Skills: Information Security, Information Security Management, Information System SecurityCertifications:Cisco...


  • Cambridge, Massachusetts, United States Proprietors of the Cemetery of Mount Auburn Full time

    Position OverviewThe Proprietors of the Cemetery of Mount Auburn are seeking a seasoned and innovative Director of Information Technology to spearhead our IT division. This pivotal role will be essential in establishing a robust framework for our forthcoming digital transformation efforts. As a prominent entity in our sector, we are increasingly leveraging...


  • Cambridge, Massachusetts, United States Proprietors of the Cemetery of Mount Auburn Full time

    Position OverviewThe Proprietors of the Cemetery of Mount Auburn, a distinguished nonprofit organization, is seeking a seasoned and innovative Director of Information Technology to spearhead our IT division. This pivotal role will be instrumental in laying the groundwork for our forthcoming digital transformation journey. As a leader in our sector, we are...


  • Cambridge, Massachusetts, United States Proprietors of the Cemetery of Mount Auburn Full time

    Position OverviewThe Proprietors of the Cemetery of Mount Auburn, a distinguished nonprofit organization with a dedicated workforce, is seeking a seasoned and innovative Director of Information Technology. This pivotal role will guide our IT department as we embark on a significant digital transformation journey, enhancing our operational capabilities...


  • Cambridge, Massachusetts, United States Massachusetts Institute of Technology Full time

    Massachusetts Institute of Technology (MIT)Position: Chief Financial Officer for Research OperationsThe Office of the Vice President for Research (OVPR) at MIT is in search of a Chief Financial Officer to lead its financial strategies and operations. This role is pivotal in providing strategic guidance to the Vice President for Research (VPR) and enhancing...


  • Cambridge, Massachusetts, United States National Opera Center Full time

    Position OverviewThe National Opera Center is in search of a Chief Executive Officer who will champion our creative and visionary mission.As a non-profit organization, we are committed to fostering emerging talent, producing performances in unique and intimate settings, commissioning original works, and reimagining classic operatic masterpieces.The ideal...


  • Cambridge, Massachusetts, United States Draper Labs Full time

    Overview:Draper is a distinguished, nonprofit research and development organization based in Cambridge, MA. With over 2,000 dedicated employees, Draper addresses significant national challenges, ensuring the delivery of effective and practical solutions. Our work spans military defense, space exploration, and biomedical engineering, where the solutions we...


  • Cambridge, Massachusetts, United States General Dynamics Information Technology Full time

    Type of Requisition: RegularClearance Level Must Currently Possess: Top Secret/SCIClearance Level Must Be Able to Obtain: Top Secret SCI + PolygraphSuitability:Public Trust/Other Required: NoneJob Family: Information SecurityJob Qualifications:Skills: Information Security, Information Security Management, Information System SecurityCertifications:Cisco...


  • Cambridge, Massachusetts, United States City of Cambridge Full time

    ABOUT THE DEPARTMENT:The Cambridge License Commission operates as a three-member Board tasked with the issuance of licenses and permits, as well as the enforcement of regulations, local ordinances, and state laws governing the sale and service of alcoholic beverages, restaurant operations, lodging establishments, entertainment venues, and various other...


  • Cambridge, Massachusetts, United States Harvard University Full time

    Job SummaryWe are seeking a highly skilled and experienced Chief Communications Marketing Officer to join our team at Harvard University. The successful candidate will be responsible for leading our communications and marketing efforts, developing and implementing strategic plans to promote the university's programs and priorities.Key ResponsibilitiesDevelop...

  • Security Officer

    2 weeks ago


    Cambridge, Massachusetts, United States Draper Full time

    Overview: Draper is a nonprofit research and development organization based in Cambridge, MA, dedicated to addressing significant national challenges through innovative solutions. With a workforce of over 2,000 professionals, Draper focuses on critical areas such as military defense, space exploration, and biomedical engineering, where the outcomes of our...


  • Cambridge, Massachusetts, United States CarGurus Full time

    About the RoleWe are seeking a seasoned cybersecurity professional to join our team as Director of Information Security. As a key member of our leadership team, you will be responsible for developing and implementing our information security strategy, ensuring the confidentiality, integrity, and availability of our systems and data.Key...


  • Cambridge, Massachusetts, United States Intellia Therapeutics Full time

    Why Join Intellia?Our mission is to develop curative genome editing treatments that can positively transform the lives of people living with severe and life-threatening diseases.Beyond our science, we live our four core values: One, Explore, Disrupt, Deliver and feel strongly that you can achieve more at Intellia. We have a single-minded determination to...


  • Cambridge, Massachusetts, United States National Opera Center Full time

    Network(s): General, Executive, & Artistic DirectorsPOSITION SUMMARYThe National Opera Center is on the lookout for a Chief Executive Officer who will champion our innovative and visionary approach to opera. As a dedicated non-profit organization, we focus on fostering emerging talent, producing performances in unique and intimate settings, commissioning...

  • Security Officer

    3 days ago


    Cambridge, Massachusetts, United States Draper Labs Full time

    Job Summary: Draper Labs is seeking a highly skilled and detail-oriented Security Officer to join our team. As a Security Officer, you will be responsible for safeguarding company property, facilities, and personnel against various threats. Key Responsibilities: Patrol company premises to ensure security and detect potential threats.Monitor CCTV and access...


  • Cambridge, Massachusetts, United States General Dynamics Information Technology Full time

    Type of Requisition: RegularClearance Level Must Currently Possess: Top Secret/SCIClearance Level Must Be Able to Obtain: Top Secret SCI + PolygraphSuitability:Public Trust/Other Required:Job Family: TelecommunicationsJob Qualifications:Skills: Communications Security (COMSEC), Electronic Security Systems, Information Systems, Team Leadership, Program...

  • Security Officer

    1 week ago


    Cambridge, Massachusetts, United States Draper Full time

    Position OverviewThe role of a Security Officer involves maintaining a secure environment within the premises. Responsibilities include:Fixed Post Monitoring: Remaining at a designated location during standard operational hours.Patrol Duties: Conducting regular patrols throughout the facility to ensure safety.Access Control: Verifying identification badges...

  • Chief Legal Officer

    2 weeks ago


    Cambridge, Massachusetts, United States The Ladders Full time

    Position Overview: The Chief Legal Officer serves as the principal legal advisor and compliance leader for the organization, offering strategic guidance to the executive team and Board of Directors regarding the legal ramifications, risks, and strategies associated with the company's policies, initiatives, and operations. This role encompasses a wide range...

  • Security Officer

    5 days ago


    Cambridge, Massachusetts, United States Hyatt Regency BostonCambridge Full time

    Job Summary:We are seeking a skilled and experienced Security Officer to join our team at Hyatt Regency Boston/Cambridge. As a Security Officer, you will be responsible for ensuring the safety and security of our guests and staff.Key Responsibilities:Monitor and maintain the security of the hotel premises, including the lobby, corridors, and guest...