Chief Information Security Officer

2 weeks ago


Cambridge, Massachusetts, United States CarGurus LLC Full time

About Us

At CarGurus (NASDAQ: CARG), we empower individuals to navigate their automotive journey with confidence. Our origins trace back to a dedicated group of developers who aimed to revolutionize car shopping through trust and transparency. Over the years, we have evolved into the largest and fastest-growing automotive marketplace, achieving profitability for over 15 years.

Our Mission

As the automotive landscape transforms, we are committed to moving the entire customer experience online, guiding users from selling their old vehicles to financing, purchasing, and delivering new ones. Each month, millions of consumers engage with our platform, supported by approximately 30,000 dealerships utilizing our innovative solutions. Our people-first culture fosters collaboration, kindness, and innovation, empowering our team members to thrive and grow in their careers. We believe that disrupting a trillion-dollar industry requires diverse and fresh perspectives.

Position Overview

We are in search of a seasoned and strategic leader in cybersecurity to fill the role of Director of Information Security. This pivotal position involves overseeing and enhancing our information security framework, ensuring the adoption of best practices, policies, and technologies to safeguard against emerging cyber threats. The individual will align security initiatives with the broader strategic goals of the organization while keeping the team focused on shared objectives.

In this leadership role, collaboration with key business stakeholders, including Legal, IT, Enterprise Applications, Product, and Engineering, is essential to ensure compliance with relevant regulations and industry standards, while maintaining the confidentiality, integrity, and availability of our systems and data. At CarGurus, we value teamwork and cooperative efforts.

A security-first mindset is crucial, as you will be responsible for cultivating a culture of privacy and security throughout the organization by educating employees on standards and best practices in relatable terms. Comfort in the spotlight is necessary, as this role demands visibility and engagement.

The ability to swiftly evaluate the dynamic security landscape and make informed decisions regarding potential risks and threats is essential. CarGurus operates at a rapid pace, requiring quick thinking, especially during security incidents, with appropriate escalation to senior management when necessary.

This role reports directly to the VP of Information Security, Technology, and Enterprise Applications, overseeing Security Operations, Application Security, and IT Risk and Compliance.

Key Responsibilities:

  • Lead, mentor, and develop a high-performing security team.
  • Conduct annual performance reviews and create personal development and onboarding plans.
  • Establish strong collaborative relationships with peers and key partners across the organization.
  • Oversee technical regulatory and compliance obligations.
  • Embed security awareness within the company culture, engaging with the community through training and presentations.
  • Manage vendor relationships effectively.
  • Oversee the security budget and collaborate with the VP on annual budget planning.
  • Develop long-term strategic plans for Information Security, aligning tactical goals with business objectives and regulatory requirements.
  • Supervise security controls and enhance the organization’s information security maturity.
  • Ensure enforcement and regular review of information security policies and standards to mitigate risks and maintain compliance.
  • Collaborate with IT Risk and Compliance to identify and prioritize information security risks.
  • Report security metrics, risks, and mitigation strategies to leadership and relevant stakeholders.

Technical Qualifications:

  • Bachelor's Degree or equivalent experience in Information Security or Computer Science.
  • Significant experience at a Director level; this is not an entry-level position.
  • Industry certifications such as GIAC (GSLC, GSTRT, GLEG), CISM, CISA, CRISC are advantageous but not mandatory.
  • Comprehensive understanding of cybersecurity and privacy principles, standards, and risk frameworks (e.g., NIST Cybersecurity Framework, CIS Controls, PCI-DSS, GDPR, CPRA).
  • Experience with system audits and IT reporting for SOX and SOC compliance is essential.
  • Collaborate closely with the Director of IT and Enterprise Applications on large-scale projects and initiatives.
  • Familiarity with cloud and application security principles, including GCP, AWS, or Azure.
  • Solid understanding of RBAC models, SSO solutions, and identity governance.
  • Proven experience in authoring and maintaining security policies and procedures.

Non-Technical Qualifications:

  • Ability to prioritize projects and tasks effectively, understanding their impact on the business.
  • Work with leadership to develop quarterly roadmaps and present them to key partners.
  • Strong organizational skills are essential.
  • Excellent communication and interpersonal skills, capable of conveying complex technical concepts to diverse audiences.
  • Strong writing skills are necessary for preparing detailed reports for leadership.
  • Adaptability to the evolving security needs of a dynamic organization.
  • A passion for continuous learning in the field of cybersecurity.
  • Willingness to operate in a fast-paced, innovative environment.
  • Integrity, accountability, and ownership are fundamental values.

Working at CarGurus

We recognize and reward our team members' curiosity and passion with competitive benefits and compensation, including equity for all employees. Our career development programs and employee resource groups foster connections and community engagement. We promote a flexible hybrid work model and offer generous time-off policies to support work-life balance. Additional perks such as daily complimentary lunch, discounts on new vehicles, wellness apps, and commuting cost coverage enhance our employees' personal and professional lives.

Our Commitment to Diversity

CarGurus is dedicated to creating an inclusive environment where individuals can express their authentic selves. We do not discriminate based on race, color, religion, national origin, age, sex, marital status, ancestry, disability, veteran status, gender identity, or sexual orientation. We encourage applicants from diverse backgrounds to apply, even if they do not meet every qualification listed. We are committed to providing accommodations during the hiring process to ensure accessibility for all candidates.


#J-18808-Ljbffr

  • Cambridge, Massachusetts, United States CarGurus LLC Full time

    About Us At CarGurus (NASDAQ: CARG), we empower individuals to navigate their journeys with confidence. Our origins trace back to a dedicated group of developers committed to instilling trust and transparency in the automotive marketplace. Over the years, our innovative spirit and rapid market entry have propelled us to become the largest and most rapidly...


  • Cambridge, Massachusetts, United States General Dynamics Information Technology Full time

    Type of Requisition: RegularClearance Level Must Currently Possess: Top Secret/SCIClearance Level Must Be Able to Obtain: Top Secret SCI + PolygraphSuitability:Public Trust/Other Required: NoneJob Family: Information SecurityJob Qualifications:Skills: Information Security, Information Security Management, Information System SecurityCertifications:Cisco...


  • Cambridge, Massachusetts, United States Proprietors of the Cemetery of Mount Auburn Full time

    Position OverviewThe Proprietors of the Cemetery of Mount Auburn are seeking a seasoned and innovative Director of Information Technology to spearhead our IT division. This pivotal role will be essential in establishing a robust framework for our forthcoming digital transformation efforts. As a prominent entity in our sector, we are increasingly leveraging...


  • Cambridge, Massachusetts, United States Proprietors of the Cemetery of Mount Auburn Full time

    Position OverviewThe Proprietors of the Cemetery of Mount Auburn, a distinguished nonprofit organization, is seeking a seasoned and innovative Director of Information Technology to spearhead our IT division. This pivotal role will be instrumental in laying the groundwork for our forthcoming digital transformation journey. As a leader in our sector, we are...


  • Cambridge, Massachusetts, United States Proprietors of the Cemetery of Mount Auburn Full time

    Position OverviewThe Proprietors of the Cemetery of Mount Auburn, a distinguished nonprofit organization with a dedicated workforce, is seeking a seasoned and innovative Director of Information Technology. This pivotal role will guide our IT department as we embark on a significant digital transformation journey, enhancing our operational capabilities...


  • Cambridge, Massachusetts, United States Massachusetts Institute of Technology Full time

    Massachusetts Institute of Technology (MIT)Position: Chief Financial Officer for Research OperationsThe Office of the Vice President for Research (OVPR) at MIT is in search of a Chief Financial Officer to lead its financial strategies and operations. This role is pivotal in providing strategic guidance to the Vice President for Research (VPR) and enhancing...


  • Cambridge, Massachusetts, United States National Opera Center Full time

    Position OverviewThe National Opera Center is in search of a Chief Executive Officer who will champion our creative and visionary mission.As a non-profit organization, we are committed to fostering emerging talent, producing performances in unique and intimate settings, commissioning original works, and reimagining classic operatic masterpieces.The ideal...


  • Cambridge, Massachusetts, United States Draper Labs Full time

    Overview:Draper is a distinguished, nonprofit research and development organization based in Cambridge, MA. With over 2,000 dedicated employees, Draper addresses significant national challenges, ensuring the delivery of effective and practical solutions. Our work spans military defense, space exploration, and biomedical engineering, where the solutions we...


  • Cambridge, Massachusetts, United States General Dynamics Information Technology Full time

    Type of Requisition: RegularClearance Level Must Currently Possess: Top Secret/SCIClearance Level Must Be Able to Obtain: Top Secret SCI + PolygraphSuitability:Public Trust/Other Required: NoneJob Family: Information SecurityJob Qualifications:Skills: Information Security, Information Security Management, Information System SecurityCertifications:Cisco...


  • Cambridge, Massachusetts, United States City of Cambridge Full time

    ABOUT THE DEPARTMENT:The Cambridge License Commission operates as a three-member Board tasked with the issuance of licenses and permits, as well as the enforcement of regulations, local ordinances, and state laws governing the sale and service of alcoholic beverages, restaurant operations, lodging establishments, entertainment venues, and various other...


  • Cambridge, Massachusetts, United States Harvard University Full time

    Job SummaryWe are seeking a highly skilled and experienced Chief Communications Marketing Officer to join our team at Harvard University. The successful candidate will be responsible for leading our communications and marketing efforts, developing and implementing strategic plans to promote the university's programs and priorities.Key ResponsibilitiesDevelop...

  • Security Officer

    2 weeks ago


    Cambridge, Massachusetts, United States Draper Full time

    Overview: Draper is a nonprofit research and development organization based in Cambridge, MA, dedicated to addressing significant national challenges through innovative solutions. With a workforce of over 2,000 professionals, Draper focuses on critical areas such as military defense, space exploration, and biomedical engineering, where the outcomes of our...


  • Cambridge, Massachusetts, United States CarGurus Full time

    About the RoleWe are seeking a seasoned cybersecurity professional to join our team as Director of Information Security. As a key member of our leadership team, you will be responsible for developing and implementing our information security strategy, ensuring the confidentiality, integrity, and availability of our systems and data.Key...


  • Cambridge, Massachusetts, United States Intellia Therapeutics Full time

    Why Join Intellia?Our mission is to develop curative genome editing treatments that can positively transform the lives of people living with severe and life-threatening diseases.Beyond our science, we live our four core values: One, Explore, Disrupt, Deliver and feel strongly that you can achieve more at Intellia. We have a single-minded determination to...


  • Cambridge, Massachusetts, United States National Opera Center Full time

    Network(s): General, Executive, & Artistic DirectorsPOSITION SUMMARYThe National Opera Center is on the lookout for a Chief Executive Officer who will champion our innovative and visionary approach to opera. As a dedicated non-profit organization, we focus on fostering emerging talent, producing performances in unique and intimate settings, commissioning...

  • Security Officer

    3 days ago


    Cambridge, Massachusetts, United States Draper Labs Full time

    Job Summary: Draper Labs is seeking a highly skilled and detail-oriented Security Officer to join our team. As a Security Officer, you will be responsible for safeguarding company property, facilities, and personnel against various threats. Key Responsibilities: Patrol company premises to ensure security and detect potential threats.Monitor CCTV and access...

  • Security Officer

    1 week ago


    Cambridge, Massachusetts, United States Draper Full time

    Position OverviewThe role of a Security Officer involves maintaining a secure environment within the premises. Responsibilities include:Fixed Post Monitoring: Remaining at a designated location during standard operational hours.Patrol Duties: Conducting regular patrols throughout the facility to ensure safety.Access Control: Verifying identification badges...


  • Cambridge, Massachusetts, United States General Dynamics Information Technology Full time

    Type of Requisition: RegularClearance Level Must Currently Possess: Top Secret/SCIClearance Level Must Be Able to Obtain: Top Secret SCI + PolygraphSuitability:Public Trust/Other Required:Job Family: TelecommunicationsJob Qualifications:Skills: Communications Security (COMSEC), Electronic Security Systems, Information Systems, Team Leadership, Program...

  • Chief Legal Officer

    2 weeks ago


    Cambridge, Massachusetts, United States The Ladders Full time

    Position Overview: The Chief Legal Officer serves as the principal legal advisor and compliance leader for the organization, offering strategic guidance to the executive team and Board of Directors regarding the legal ramifications, risks, and strategies associated with the company's policies, initiatives, and operations. This role encompasses a wide range...

  • Security Officer

    5 days ago


    Cambridge, Massachusetts, United States Hyatt Regency BostonCambridge Full time

    Job Summary:We are seeking a skilled and experienced Security Officer to join our team at Hyatt Regency Boston/Cambridge. As a Security Officer, you will be responsible for ensuring the safety and security of our guests and staff.Key Responsibilities:Monitor and maintain the security of the hotel premises, including the lobby, corridors, and guest...