1

Cyber Risk Analyst Jobs in Massachusetts (NOW HIRING)

Senior GRC Analyst

Boston, MA · On-site

$130K - $170K/yr

Lead cyber, AI, and technology risk assessments across systems, cloud environments, business ... Prepare materials and analysis to support the Cyber Risk Committee and executive risk reporting

next page

Showing results 1-20

Cyber Risk Analyst information

See Massachusetts salary details

$48.6K

$117.4K

$164.9K

How much do cyber risk analyst jobs pay per year?

As of Aug 27, 2026, the average yearly pay for cyber risk analyst in Massachusetts is $117,427.00, according to ZipRecruiter salary data. Most workers in this role earn between $99,900.00 and $138,200.00 per year, depending on experience, location, and employer.

How does a cyber risk analyst typically collaborate with other departments to improve an organization's security posture?

Cyber Risk Analysts work closely with various departments, such as IT, compliance, and business units, to identify and assess potential security threats. They often facilitate risk assessments, conduct training sessions to raise awareness, and help develop incident response plans. Regular communication and collaboration are essential, as analysts must ensure that security recommendations align with business goals and regulatory requirements. This cross-functional teamwork creates a more resilient security environment and helps integrate cybersecurity best practices throughout the organization.

What are the key skills and qualifications needed to thrive as a cyber risk analyst, and why are they important?

To thrive as a Cyber Risk Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and often a degree in cybersecurity, computer science, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and security information and event management (SIEM) systems is typically required, along with certifications like CISSP or CISM. Analytical thinking, attention to detail, and strong communication skills are essential soft skills for this role. These competencies ensure accurate identification, evaluation, and mitigation of cyber risks to protect organizational assets and maintain regulatory compliance.

What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?

AspectCyber Risk AnalystCyber Security Analyst
CertificationsCertified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC)CompTIA Security+, Certified Ethical Hacker (CEH)
Work EnvironmentRisk assessment, policy development, complianceNetwork monitoring, threat detection, incident response
Employer & IndustryFinancial, healthcare, government sectors focusing on risk managementIT departments, cybersecurity firms, tech companies

While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.

How much does a cyber risk analyst make?

The average salary for a cyber risk analyst typically ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in industries with high cybersecurity needs.

What does a cyber risk analyst do?

A cyber risk analyst evaluates an organization's cybersecurity threats and vulnerabilities to identify potential risks. They analyze security data, develop risk mitigation strategies, and often use tools like risk assessment frameworks and security information and event management (SIEM) systems to protect digital assets.

What are popular job titles related to Cyber Risk Analyst jobs in Massachusetts?

For Cyber Risk Analyst jobs in Massachusetts, the most frequently searched job titles are:

What job categories do people searching Cyber Risk Analyst jobs in Massachusetts look for?

The top searched job categories for Cyber Risk Analyst jobs in Massachusetts are:

Infographic showing various Cyber Risk Analyst job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 12% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $117,427 per year, or $56.5 per hour.

Senior Analyst, Cyber Risk Quantification and GRC

Cambridge, MA • On-site

Forrester Research, Inc. (US)
Scientific Research and Development Services • 1 - 5K employees

$119 - $193/hr

Other

Posted 9 days ago


Job description

About This Role

Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk management leaders and their teams.

Ideal Candidate Profile
  • A strong understanding of risk management roles, responsibilities, and the key security and risk trends and their business and technology implications.
  • Deep knowledge and experience with risk management practices, methods, and cyber risk quantification.
  • Experience in developing, maintaining, and communicating risk management artifacts such as risk standards, procedures, appetite, registry, and business strategy.
  • Strong expertise in compliance management, internal or external audit, and GRC platforms is highly desired.
Key Responsibilities
  • Develop a deep understanding of what Forrester clients require to be successful as risk management leaders and professionals, focusing on how they help organizations build resilient, opportunity‑seeking businesses.
  • Conduct primary research into risk management capabilities, practices, touchpoints, and artifacts to support C‑suite executives, business leaders, and relevant committees.
  • Help define the future of risk management, describing how risk leaders and professionals can collaborate with other key business functions to support organizational success.
  • Work with different focus areas across Forrester research teams to develop a comprehensive research portfolio on risk management, incorporating expertise from across Forrester for a “big‑picture” view.
  • Partner with other Forrester analysts on broader risk topics, including risk quantification, third‑party risk, systemic risk, compliance, and cyber risk.
  • Research, write, and create approximately six to eight research projects per year, including written reports, tools, webinars, videos, podcasts, infographics, and other intellectual property.
  • Build visibility for research and contribute to Forrester client communities.
  • Consult with clients to apply research in the context of their business environment and help solve their problems through inquiry, guidance, and advisory engagements.
  • Establish an industry presence as an influential speaker and thinker; build relationships with journalists who cover the sector; and participate in vendor briefings and field press inquiries as needed.
Qualifications
  • Five to seven years of experience as a research analyst, consultant, or practitioner focused on risk management, with a focus on cyber risk quantification, or an equal amount of time as product manager for vendors that serve the market.
  • Deep intellectual curiosity about the effect of technology on the business landscape, solid business instincts, and a practical understanding of what drives companies.
  • Creative view of markets, technologies, and attitudes combined with a fascination with the future.
  • Superior listening, critical thinking, and writing skills, as well as compelling presentation skills.
  • The ability to take complex, disparate ideas and distill them into simple, provocative concepts, and to take a stand on vendors and outcomes.
  • Ability to travel up to 20% of the time.
Compensation

Base salary range: $119,000 – $193,000 (U.S. exclusions: NewYork City – $136,000 – $222,000; Georgia – $106,000 – $174,000). Bonus target at Washington State: 10% of base salary (subject to performance and eligibility).

Application Deadline

July31,2026

Legal and Equal Opportunity Statements

FLSA Status: Exempt. Forrester Research, Inc. is an Equal Employment Opportunity Employer. As a federal contractor, Forrester encourages veterans and individuals with disabilities to apply for employment. If you would like to discuss a reasonable accommodation, please reach out to accommodationrequest@forrester.com.

#J-18808-Ljbffr