1

Cyber Risk Assessment Jobs in Massachusetts (NOW HIRING)

Lead comprehensive enterprise-wide cyber risk assessments across all business operations, systems, and infrastructure * Identify, analyze, and evaluate cybersecurity risks including threats ...

Senior GRC Analyst

Boston, MA ยท On-site

$130K - $170K/yr

Lead cyber, AI, and technology risk assessments across systems, cloud environments, business processes, and major initiatives, evaluating threats, vulnerabilities, control effectiveness, and residual ...

next page

Showing results 1-20

Cyber Risk Assessment information

What is a cyber risk assessment?

A cyber risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities in an organization's information systems. It helps organizations understand the potential impact of cyber threats and determine the likelihood of such events occurring. By conducting a cyber risk assessment, businesses can implement appropriate security controls and strategies to mitigate risks, comply with regulatory requirements, and protect sensitive data from cyberattacks. Regular assessments are essential to adapt to evolving threats and maintain a strong cybersecurity posture.

What are the key skills and qualifications needed to thrive as a cyber risk assessor?

To thrive as a Cyber Risk Assessor, you need a strong understanding of cybersecurity principles, risk management frameworks, and relevant regulations, often backed by a degree in information security or related certifications like CISSP or CISA. Familiarity with security assessment tools, vulnerability scanners, and risk analysis platforms is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills for accurately identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets and ensuring compliance in an evolving threat landscape.

What are some common challenges faced by professionals in cyber risk assessment, and how can they be addressed?

Professionals in Cyber Risk Assessment often encounter challenges such as rapidly evolving threat landscapes, keeping up with regulatory changes, and ensuring clear communication of technical risks to non-technical stakeholders. To address these, staying current with industry trends through continuous learning, leveraging robust risk assessment frameworks, and developing strong communication skills are essential. Additionally, collaborating closely with IT, compliance, and business units helps ensure comprehensive and effective risk management.

What is the difference between Cyber Risk Assessment vs Cyber Security Analyst?

AspectCyber Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating cybersecurity risks and vulnerabilitiesMonitoring, detecting, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams
ResponsibilitiesRisk analysis, vulnerability assessments, complianceThreat detection, incident response, security monitoring

While both roles involve cybersecurity, Cyber Risk Assessments focus on evaluating potential risks and vulnerabilities to inform security strategies, whereas Cyber Security Analysts actively monitor and respond to ongoing security threats. Understanding these differences helps organizations assign the right roles for comprehensive cybersecurity management.

What are popular job titles related to Cyber Risk Assessment jobs in Massachusetts?

For Cyber Risk Assessment jobs in Massachusetts, the most frequently searched job titles are:

What job categories do people searching Cyber Risk Assessment jobs in Massachusetts look for?

The top searched job categories for Cyber Risk Assessment jobs in Massachusetts are:

What cities in Massachusetts are hiring for Cyber Risk Assessment jobs?

Cities in Massachusetts with the most Cyber Risk Assessment job openings:

Sr Risk Analyst

Informa

Newton, MA โ€ข Hybrid

Full-time

Medical, Dental, Vision, Retirement

Posted 4 days ago


Job description

Company Description

Do you want to develop your career and make an impact in the fast-growth, fast-moving B2B technology space?

At Informa TechTarget, you'll collaborate and grow alongside some of the industry's most respected experts. You'll work with leading brands and be exposed to world-shaping innovations. You'll apply your energy and intellect to helping clients be faster to market and faster to revenue.

We're a vibrant community of world-class practitioners - over 2000 colleagues strong - with offices in 19 locations around the world. We're traded on Nasdaq and also part of Informa PLC, a global leader in business-to-business events, digital services, and academic research in the FTSE 100.

About Informa TechTarget

Informa TechTarget (Nasdaq: TTGT) informs, influences and connects the world's technology buyers and sellers, to accelerate growth from R&D to ROI.

With an unparalleled reach of over 220 highly targeted technology-specific websites and more than 50 million permissioned first-party audience members, Informa TechTarget has a unique understanding of and insight into technology markets.

Underpinned by those audiences and their data, we offer expert-led, data-driven, and digitally enabled services that deliver significant impact and measurable outcomes to our clients. We provide our customers with:

  • Trusted information that shapes the industry and informs investment
  • Intelligence and advice that guides and influences strategy
  • Advertising that grows reputation and establishes thought leadership
  • Custom content that engages and prompts action
  • Intent and demand generation that more precisely targets and converts

Our organization is committed to sustainability, diversity, wellbeing, and ethical working practices. Visit informatechtarget.com and follow us on LinkedIn.

For more information, visit informatechtarget.com and follow us on LinkedIn

Job Description

This role is based in our Newton, MA office.

We are seeking an experienced and strategic Senior Cyber Risk Analyst to join our team. This role requires deep expertise in enterprise cybersecurity risk management, with responsibility for identifying, assessing, and mitigating cyber risks across the organization. You will lead enterprise risk assessments, partner with engineering and security teams on strategic initiatives, and provide executive-level reporting on the organization's cyber risk posture. This position also includes emerging responsibilities in AI governance and technology risk as part of a comprehensive enterprise risk management approach.

Key Responsibilities

Enterprise Risk Assessment & Management

  • Lead comprehensive enterprise-wide cyber risk assessments across all business operations, systems, and infrastructure
  • Identify, analyze, and evaluate cybersecurity risks including threats, vulnerabilities, and potential business impacts
  • Develop and maintain enterprise risk registers, ensuring all cyber risks are properly documented, prioritized, and monitored
  • Create and implement risk treatment plans and mitigation strategies to reduce organizational exposure
  • Conduct risk assessments for new technologies, systems, and business initiatives in partnership with engineering and product teams
  • Utilize risk management frameworks (NIST CSF, ISO 27005, FAIR) to quantify and communicate risk

Cloud Security & Infrastructure Risk

  • Assess security risks associated with cloud environments (AWS, Azure, GCP) and hybrid infrastructure
  • Evaluate cloud architecture designs and configurations for security and compliance risks
  • Partner with cloud engineering teams to implement security controls and risk mitigation measures
  • Review and assess risks related to cloud migration projects and infrastructure changes

Vulnerability & Threat Management

  • Oversee vulnerability management program effectiveness and risk prioritization
  • Analyze vulnerability scan results and penetration test findings to assess enterprise risk exposure
  • Work with IT and security teams to ensure timely remediation of critical vulnerabilities
  • Monitor threat intelligence and assess potential impact to the organization
  • Evaluate the effectiveness of security controls in mitigating identified vulnerabilities

Third-Party & Vendor Risk Management

  • Conduct cybersecurity risk assessments of third-party vendors, suppliers, and business partners
  • Review vendor security questionnaires, certifications, and audit reports
  • Assess risks associated with vendor access to systems and data
  • Monitor ongoing third-party risk and ensure compliance with security requirements
  • Support vendor risk remediation efforts and contract security requirements

Governance, Compliance & Policy

  • Ensure compliance with relevant cybersecurity regulations, standards, and frameworks (SOC 2, ISO 27001, NIST, Sox, etc.)
  • Support the development and maintenance of cybersecurity policies, standards, and procedures
  • Participate in internal and external audits related to cybersecurity and risk management
  • Monitor regulatory changes and assess impact on organizational risk posture
  • Contribute to the organization's cybersecurity governance structure and risk committee activities

Executive Reporting & Metrics

  • Prepare comprehensive cyber risk reports and presentations for executive leadership, board of directors, and key stakeholders
  • Develop and maintain cyber risk dashboards with Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)
  • Communicate complex cybersecurity risks in business terms to non-technical executive audiences
  • Provide regular updates on risk trends, threat landscape, and mitigation progress
  • Present risk-based recommendations to support strategic business decisions

Strategic Partnership & Advisory

  • Partner with engineering, IT, security, and product teams on new initiatives and technology implementations
  • Provide expert cybersecurity risk guidance during project planning and system design phases
  • Advise business units on cyber risk implications of strategic decisions and initiatives
  • Collaborate with cross-functional teams including legal, compliance, privacy, and internal audit

Emerging Technology & AI Governance

  • Assess cybersecurity and privacy risks associated with AI/ML systems and emerging technologies
  • Support the development of AI governance frameworks and responsible AI practices
  • Evaluate risks related to AI implementation including data privacy, model security, and ethical considerations
  • Stay current with emerging technology risks and evolving regulatory requirements

Required Qualifications

Education & Experience

  • Bachelor's degree in Cybersecurity, Information Security, Risk Management, Computer Science, Information Technology, or related field
  • 5-8 years of progressive experience in cybersecurity risk management, information security, or IT risk
  • Proven track record of conducting enterprise-level cyber risk assessments in complex technology environments
  • Experience with cloud security risk assessment and cloud platforms (AWS, Azure, GCP)
  • Demonstrated experience in third-party risk management and vendor security assessments

Professional Certifications

Required (at least one):

  • CRISC (Certified in Risk and Information Systems Control)
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)

Preferred:

  • CISA (Certified Information Systems Auditor)
  • CGRC (Certified in Governance, Risk and Compliance)
  • CCSP (Certified Cloud Security Professional)
  • Additional relevant cybersecurity or risk management certifications

Cybersecurity & Technical Skills

  • Deep understanding of cybersecurity principles, threats, vulnerabilities, and attack vectors
  • Strong knowledge of risk management frameworks (NIST, ISO 27001, Soc2, Sox)
  • Experience with vulnerability management tools and processes
  • Understanding of cloud security architecture and controls (AWS, Azure, GCP)
  • Knowledge of security controls, defense-in-depth strategies, and compensating controls
  • Familiarity with compliance frameworks (SOC 2, ISO 27001, NIST 800-53)
  • Experience with GRC (Governance, Risk, and Compliance) platforms
  • Understanding of network security, application security, and infrastructure security
Qualifications

Professional Skills

  • Exceptional analytical and critical thinking skills with strong attention to detail
  • Excellent written and verbal communication skills, particularly for executive audiences
  • Ability to translate technical cybersecurity concepts into business risk language
  • Strong stakeholder management and influence skills across all organizational levels
  • Proficiency in data analysis and visualization tools
  • Project management capabilities and ability to manage multiple priorities

Preferred Qualifications

  • Master's degree in Cybersecurity, Information Security, Risk Management, or related field
  • Background in information security operations or security engineering
  • Knowledge of security architecture and secure design principles
  • Experience with security incident response and business continuity planning
  • Familiarity with AI/ML security risks and emerging technology governance
  • Understanding of privacy regulations (GDPR, CCPA, PIPEDA)

Key Competencies

  • Strategic risk thinking and business acumen
  • Proactive risk identification and problem-solving
  • Executive presence and communication
  • Stakeholder influence and relationship building
  • Adaptability to evolving threat landscape
  • Ethical judgment and integrity
  • Continuous learning and professional development
  • Collaboration and cross-functional partnership
Additional Information

TechTarget, Inc., doing business as Informa TechTarget, including its subsidiaries is an equal opportunity employer andย complies withย all applicable federal, state, and local fair employment practices laws. We strictly prohibit and do not tolerate discrimination against employees, applicants, or any other covered persons because of race,ย color, sex (including pregnancy), age, national origin or ancestry, ethnicity, religion, creed, sexual orientation, gender identity or expression, status as a veteran, and basis of disability or any other federal, state or local protected class. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, training, promotion, discipline, compensation, benefits, and termination of employment. If you would like to request reasonable adjustments or accommodations toย assistย your participation in the hiring process and, or in the advertised position, please inform theย appropriate Talentย Acquisition Partner for the role once they have been in touch. Your request will be reviewed and considered in confidence.ย 

Informa TechTargetย complies withย the Americans with Disabilities Act (ADA), as amended by the ADA Amendments Act, and all applicable federal,ย stateย or local law.ย 

We believe thatย great thingsย happen when people connect face-to-face.ย That'sย why we work in-person with each other, or with customers and partners, three days a week or more. Whenย you'reย not spending time together in one of our offices or other workplaces - like at an Informa event - you get the flexibility and support to work from home or remotely.

Our benefits include:ย 

  • Great community: a welcoming culture with in-person and online social events, our fantastic Walk the World charity day and active colleague groups and networks promoting a positive, supportive, and collaborative work environment
  • Broader impact: take up to four days per year to volunteer with a philanthropic organization
  • Career opportunity: the opportunity to develop your career with bespoke training and learning, mentoring platforms and on-demand access to thousands of courses on LinkedIn Learning. Whenย it'sย time for the next step, we encourage and support internal job movesย 
  • Time out:ย Open Vacation, plus 10 national holidays,ย and theย chanceย to work fromย (almost!) anywhere for up to four weeks a yearย 
  • Competitive benefits, including a 401k match, health, vision and dental insurance, parental leave and an ESPP offering company shares at a minimum 15% discountย 
  • Strong wellbeing support through EAPย assistance, mental health first aiders, free access to a wellness app and moreย 
  • Recognition forย great work, with global awards and kudos programsย 
  • As an international company, the chance to collaborate with teams around the worldย 

The salary range for this role is $150K-$170K/YR, based on experience.

This posting will automatically expire on September 4, 2026.