TrueCar is a leading automotive digital marketplace and we are on a mission to make car buying and selling easy, transparent and efficient. We work to empower consumers with data, and foster connections with our network of Certified Dealers who share our belief that truth, transparency and fairness are the foundation to a great experience. We forge partnerships to power car buying programs for some of America’s most trusted brands. And we continually innovate to provide useful tools, research, market context and pricing transparency to help consumers feel empowered and confident all throughout their journey.
As consumers’ priorities and shopping habits shifted, so did we. We are building a modern day marketplace and invite you to come join the TrueCar Crew. You can have a real & direct impact on our journey as we continue to evolve and revolutionize the car buying and selling experience. We are seeking talented individuals who are excited by our mission to revolutionize & elevate the car buying & selling experience.
The Opportunity:
TrueCar, Inc. is hiring a Senior Governance, Risk, and Compliance Analyst to join our Security & Compliance team. The Senior Governance, Risk, and Compliance Analyst will report to the Director, Security & Compliance and will assist in improving the overall security and compliance posture of the organization. Senior Governance, Risk, and Compliance Analysts must continually adapt to stay up-to-date on the latest security, compliance, and regulatory frameworks; the individual in this role is expected to learn and grow consistently.
How you’ll contribute to TrueCar’s success:
- Collaborate with internal and external auditors and exam teams over internal controls, risks, documentation, and testing engagements while supporting stakeholders
- Evaluate, test, and document security solutions and controls, and work closely with other security team members to remediate risk while ensuring the business can innovate
- Work closely with business and technology stakeholders to identify, document, and implement processes to address areas of key risks
- Participate and assist with the implementation of new systems and processes to ensure continued business process improvement, operational efficiency, and industry compliance
- Support Sarbanes-Oxley (SOX) testing including coordinating with functional management personnel, internal stakeholders, and outside consultants
- Support Service Organization Control (SOC 2, Type 2) program through evidence gathering, testing, and coordination with auditors and stakeholders.
- Understand how privacy regulations and data governance models affect IT processes and compliance obligations
- Monitor evolving SOX, accounting guidance, and compliance requirements; identify relevant requirements, provide remediation plans, if necessary, and implement procedures to ensure the processes around the new requirements are in compliance
- Work with IT stakeholders on the implementation of new systems and software solutions
- Conduct Third Party Risk Assessments before onboarding and annual reviews for critical vendors to address risks and comply with Third Party Risk Management (TPRM) best practices
- Help to develop risk assessment framework to identify, analyze and track cybersecurity risk exposures and remediation plans
- Develop and maintain IT policies, standards, and procedures including IT standard operating procedures, disaster recovery plan, and business continuity plan
- Help support the Findings Program by clearly articulating audit finding remediation deadlines to control owners, document remediation plans and
Your Expertise:
- Proven experience in a related role
- Knowledge and experience with cybersecurity frameworks (NIST CSF/CIS), SOC 2, internal control frameworks (COSO/COBIT), Security System Development Life Cycle and risk methodologies
- Ability to effectively build strong productive cross-functional relationships with stakeholders regarding security practices and compliance obligations
- Operational SOX experience for ITGCs & ITACs
- Knowledge of US privacy requirements
- Excellent analytical and problem-solving skills
- Outstanding listening and communication skills to enhance security posture
- Strong documentation skills, attention to detail, and demonstrated integrity and professionalism
- Experience working in the technology industry preferred
- CISA certification preferred
Base salary range: $96,00 - $128,000
Your TrueCar Experience
As a crew member, you’ll be primarily based out of your home as a part of our Dynamic Workplace strategy. We provide additional benefits & perks to assist our crew members in having a sustainable home workstation including monthly internet/mobile phone service reimbursement and furniture & equipment for your space.
You will receive excellent benefits that include but aren’t limited to 100% employer-paid health/vision/dental premium, 401k with company contribution, equity, a wellness stipend program, and a learning & development reimbursement program. We recognize that everyone needs an occasional recharge, so we offer a flexible PTO policy for exempt TrueCar Crew along with a generous PTO accrual policy for non-exempt TrueCar Crew, in addition to 14 company-paid holidays and 2 floating holidays. In short, we care deeply about our crew members and build employee-centric programs that prove it.
At TrueCar, we believe in the power of diversity to build a deeper understanding of our consumers and partners and drive innovation in our products. We welcome a workforce that reflects all the diversity of car-buying consumers. We encourage everyone interested in our company mission to apply. We do not discriminate on the basis of race, gender, religion, sexual orientation, age, or any other trait that is protected by applicable law. We will consider qualified applicants with arrest and conviction records in accordance with applicable law. In addition, TrueCar will provide reasonable accommodations for qualified individuals with disabilities.
TrueCar does not accept unsolicited agency submissions.
If you are based in California, we encourage you to read this important information for California residents linked here.
#LI-Remote
Top Skills
What We Do