Назад
Company hidden
5 дней назад

Principal Security Governance, Risk & Compliance Analyst (AI Governance)

135 000 - 168 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Ireland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security Governance, Risk & Compliance Analyst (AI Governance): Designing and maturing CarGurus’ cybersecurity governance, risk, and compliance program with an accent on cyber risk management, SOC 2 Type II, SOX ITGCs, third-party risk, and AI governance. Focus on building risk assessment frameworks, operationalizing NIST-aligned AI controls, automating GRC processes, and reporting security posture to executives.

Location: Flexible hybrid model; in-person interviews may be required for positions based in Boston or Dublin.

Annual base salary: $135,000–$168,000 USD, plus potential discretionary bonuses or incentives and RSUs.

Company

hirify.global is a profitable automotive marketplace helping consumers and dealerships manage the online car-shopping, financing, purchasing, and delivery journey.

What you will do

  • Lead the strategic direction and maturity of the cybersecurity governance, risk, and compliance program.
  • Build cyber risk management capabilities, including assessments, risk registers, remediation tracking, reporting, and security metrics.
  • Lead the SOC 2 Type II program and support SOX IT General Controls, application controls, audit readiness, evidence management, and control testing.
  • Develop security policies, standards, governance processes, and customer trust initiatives such as security questionnaires and Trust Center activities.
  • Build and operationalize AI governance, including AI risk assessments, acceptable-use standards, AI inventory, third-party AI reviews, and NIST AI Risk Management Framework alignment.
  • Drive cloud, application, infrastructure, AI solution, and vendor risk assessments, secure development lifecycle integration, automation, and continuous control improvement.

Requirements

  • 8+ years of experience in information security, cyber risk, GRC, or IT audit.
  • Experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
  • Extensive experience leading SOC 2 Type II compliance programs and supporting SOX ITGCs with Internal Audit.
  • Experience building AI governance frameworks and conducting AI security and risk assessments.
  • Strong knowledge of SOC 2, NIST, ISO 27001, GDPR, CCPA, and AWS security principles.
  • Excellent executive communication skills and the ability to influence technical and business stakeholders.

Culture & Benefits

  • People-first culture focused on kindness, collaboration, innovation, and inclusion.
  • Flexible hybrid work model and robust time-off policies supporting work-life balance.
  • Comprehensive benefits and compensation, including equity for all employees and potential bonuses or RSUs.
  • Career development programs, employee resource groups, communities, and corporate giving opportunities.
  • Daily free lunch, new-car discounts, meditation and fitness apps, and commuting cost coverage.

Hiring process

  • In-person interviews may be required for positions based in Boston and Dublin, with advance notification.
  • Travel expenses for required in-person interviews are the candidate’s responsibility.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →