1

Cyber Risk Analyst Jobs in Massachusetts (NOW HIRING)

Senior GRC Analyst

Boston, MA · On-site

$130K - $170K/yr

Lead cyber, AI, and technology risk assessments across systems, cloud environments, business ... analysis approaches such as FAIR to improve how risk is measured and communicated • Prepare ...

Lead cyber, AI, and technology risk assessments across systems, cloud environments, business ... cyber risk analysis approaches such as FAIR to improve how risk is measured and communicated ...

RESPONSIBILITIES: â—Ź Lead cyber, AI, and technology risk assessments across systems, cloud ... analysis approaches such as FAIR to improve how risk is measured and communicated â—Ź Prepare ...

Senior GRC Analyst

Boston, MA · On-site

$130K - $170K/yr

RESPONSIBILITIES: • Lead cyber, AI, and technology risk assessments across systems, cloud ... analysis approaches such as FAIR to improve how risk is measured and communicated • Prepare ...

next page

Showing results 1-20

Cyber Risk Analyst information

See Massachusetts salary details

$48.6K

$117.4K

$164.9K

How much do cyber risk analyst jobs pay per year?

As of Jul 24, 2026, the average yearly pay for cyber risk analyst in Massachusetts is $117,427.00, according to ZipRecruiter salary data. Most workers in this role earn between $99,900.00 and $138,200.00 per year, depending on experience, location, and employer.

What does a cyber risk analyst do?

A cyber risk analyst evaluates an organization's cybersecurity threats and vulnerabilities to identify potential risks. They analyze security data, develop risk mitigation strategies, and often use tools like risk assessment frameworks and security information and event management (SIEM) systems to protect digital assets.

What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?

AspectCyber Risk AnalystCyber Security Analyst
CertificationsCertified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC)CompTIA Security+, Certified Ethical Hacker (CEH)
Work EnvironmentRisk assessment, policy development, complianceNetwork monitoring, threat detection, incident response
Employer & IndustryFinancial, healthcare, government sectors focusing on risk managementIT departments, cybersecurity firms, tech companies

While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.

Can you make $500,000 a year in cyber security?

Cyber Risk Analysts typically earn between $70,000 and $150,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires senior roles such as Chief Information Security Officer or specialized consulting positions, often combined with extensive experience and advanced skills in areas like threat management and security architecture.

Is 30 too late for cyber security?

Cyber Risk Analysts and other cybersecurity professionals can enter the field at any age, including 30 or older. Success often depends on acquiring relevant skills, certifications, and experience, which can be achieved through training programs, self-study, or prior related work experience.

Can you make $200,000 in cyber security?

Cyber Risk Analysts and other cybersecurity professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP, and in senior or specialized roles. Salaries vary based on industry, location, and level of expertise, with high-demand areas offering higher compensation.

What are the key skills and qualifications needed to thrive as a Cyber Risk Analyst, and why are they important?

To thrive as a Cyber Risk Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and often a degree in cybersecurity, computer science, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and security information and event management (SIEM) systems is typically required, along with certifications like CISSP or CISM. Analytical thinking, attention to detail, and strong communication skills are essential soft skills for this role. These competencies ensure accurate identification, evaluation, and mitigation of cyber risks to protect organizational assets and maintain regulatory compliance.

How does a Cyber Risk Analyst typically collaborate with other departments to improve an organization's security posture?

Cyber Risk Analysts work closely with various departments, such as IT, compliance, and business units, to identify and assess potential security threats. They often facilitate risk assessments, conduct training sessions to raise awareness, and help develop incident response plans. Regular communication and collaboration are essential, as analysts must ensure that security recommendations align with business goals and regulatory requirements. This cross-functional teamwork creates a more resilient security environment and helps integrate cybersecurity best practices throughout the organization.
What are popular job titles related to Cyber Risk Analyst jobs in Massachusetts? For Cyber Risk Analyst jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching Cyber Risk Analyst jobs in Massachusetts look for? The top searched job categories for Cyber Risk Analyst jobs in Massachusetts are:
Infographic showing various Cyber Risk Analyst job openings in Massachusetts as of July 2026, with employment types broken down into 78% Full Time, and 22% Contract. Highlights an 74% In-person, 17% Hybrid, and 9% Remote job distribution, with an average salary of $117,427 per year, or $56.5 per hour.
Senior Analyst, Cyber Risk Quantification and GRC

Senior Analyst, Cyber Risk Quantification and GRC

Forrester

Cambridge, MA • On-site

Full-time

Posted 20 days ago


Job description

At Forrester, we're trusted to work on trailblazing, mission critical problems that business and technology leaders face today. That's why we're always looking to empower talented individuals to perform at their best every single day. We're proud of our community of smart people and vibrant voices who come together to do what's right by our clients and each other. Our success is driven by curiosity, courage and customer obsession. The confidence and drive to be bold at work. Join us and build an extraordinary future.

About This Role:

Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk management leaders and their teams. The ideal candidate has a strong understanding of risk management roles, responsibilities, and the most important security and risk trends and their business and technology implications; deep knowledge and experience with risk management practices and methods; deep knowledge and expertise in cyber risk quantification; and deep experience in developing, maintaining, and communicating risk management artifacts including risk standards, procedures, appetite, registry, and business strategy. Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired.

The successful candidate researches and uncovers the strategies, technologies, and best practices of risk management that create a resilient and opportunity-seeking business. The Senior Analyst delivers these insights and recommendations in written reports, presentations, inquiries, guidance sessions, and custom advisory for risk leaders across industries and geographies. Our research is aimed at helping enterprise clients solve business problems and improve business results by applying principles and best practices. We also advise vendors on their strategies, roadmaps, and messaging in line with our market insights and our recommendations for enterprise clients.

Job Description:

The Senior Analyst works as part of a high-performing team with a strong emphasis on collaborating with others in all aspects of the job. The Senior Analyst is expected to:

  • Develop a deep understanding of what Forrester clients require to be successful as risk management leaders and professionals with a focus on how they help their organizations develop risk management capabilities that enable a resilient and opportunity-seeking business.
  • Conduct primary research into risk management capabilities, practices, touchpoints, and artifacts in the context of supporting C-suite executives, business leaders, and appropriate committees.
  • Help define the future of risk management, including how risk leaders and professionals can work with other key business functions and support organizational success.
  • Work with different focus areas across Forrester research teams to develop a complete research portfolio on risk management, providing both input to others' research and writing reports incorporating expertise from across Forrester to provide a "big picture" view.
  • Partner as appropriate with other Forrester analysts on broader risk topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk.
  • Research/write/create approximately six to eight research projects per year - a mix of written reports, tools, webinars, videos, podcasts, infographics, and other intellectual property. Build visibility for their research and contribute to Forrester client communities.
  • Consult with clients to apply Forrester's research in the context of their specific business environment and help solve their problems through inquiry, guidance, and advisory engagements.
  • Establish an industry presence as an influential speaker and thinker; build relationships with journalists who cover the sector; and participate in vendor briefings and field press inquiries as necessary.

Job Requirements:

  • Five to seven years as a research analyst, consultant, or practitioner where you have led or been involved in risk management, with a focus on cyber risk quantification, or an equal amount of time as product manager for vendors that serve the market.
  • A deep intellectual curiosity about the effect of technology on the business landscape; solid business instincts and a practical understanding of what makes companies tick; and a creative view of markets, technologies, and attitudes combined with a fascination with the future.
  • Superior listening, critical thinking, and writing skills as well as compelling presentation skills.
  • The ability to take complex, disparate ideas and distill them into simple, provocative concepts - and be willing to take a stand on vendors and outcomes.
  • The ability to travel up to 20% of the time.

Please note that the base salary range indicated here is inclusive of all applicable US geographies listed in this requisition, with the exception of New York City and Georgia. This salary range is based upon the position as described in the job listing. The offered compensation may vary within this range and is dependent upon the successful candidate's primary work location, experience, training, education, and credentials.

Base salary range: $119,000 - $193,000

Base salary range for Georgia: $106,000 - $174,000

Base salary range for New York City, NY: $136,000 - $222,000

For employees based in Washington State, the percentage listed here is an estimated bonus target as a percentage of base salary,in accordance with the Forrester Employee Bonus plan. Individual and company performance, as well as other eligibility criteria, will determine the actual incentive amount.

Bonus target: 10%

For information on benefits, please visit: https://forresterbenefits.com/

The application deadline is July 31, 2026. Please refer to the job posting on Forrester.com careers page if the deadline has been extended.

#LI-JM1

#LI-DNP#LI-DNI

We're a network of knowledge and experience leading to richer, fuller careers. Here, we're always learning. Whether you want to hone your strengths or discover new ones, Forrester is the place to go for it. It's a place where everyone is given the tools, support, and runway they need to go far. We'll be right there beside you, every step of the way.

Let's be bold, together.

Explore #ForresterLife on:

Instagram

LinkedIn

Glassdoor

FLSA Status:

Exempt

Here at Forrester, we welcome people from all backgrounds and perspectives. Our aim is for all candidates to be able to fully participate in Forrester's recruitment process. If you would like to discuss a reasonable accommodation, please reach out to accommodationrequest@forrester.com.

Forrester Research, Inc. is an Equal Employment Opportunity Employer. As a federal contractor, Forrester encourages veterans and individuals with disabilities to apply for employment.


Benefits at a Glance

Benefits at a Glance - Cambridge