1

Cyber Risk Manager Jobs in Massachusetts (NOW HIRING)

Develop and document Cyber Risk Management Program and related procedures: Develop Risk Management Program. Revise and update existing Risk Inventory. Define Risk Management Escalation. Define Risk ...

Contribute to the continued development of cyber risk management processes, methodologies, and governance practices across the GRC program. QUALIFICATIONS: * 6+ years of experience in cybersecurity ...

Contribute to the continued development of cyber risk management processes, methodologies, and governance practices across the GRC program. QUALIFICATIONS: * 6+ years of experience in cybersecurity ...

Contribute to the continued development of cyber risk management processes, methodologies, and governance practices across the GRC program. QUALIFICATIONS: * 6+ years of experience in cybersecurity ...

Apply Early

Contribute to the continued development of cyber risk management processes, methodologies, and governance practices across the GRC program. QUALIFICATIONS: * 6+ years of experience in cybersecurity ...

next page

Showing results 1-20

Cyber Risk Manager information

See Massachusetts salary details

$56.2K

$121.8K

$185.7K

How much do cyber risk manager jobs pay per year?

As of Jul 5, 2026, the average yearly pay for cyber risk manager in Massachusetts is $121,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,300.00 and $140,900.00 per year, depending on experience, location, and employer.

How does a Cyber Risk Manager typically collaborate with other departments to strengthen an organization's cybersecurity posture?

A Cyber Risk Manager frequently works with IT, legal, compliance, and business units to identify, assess, and mitigate cyber risks across the organization. This collaboration involves leading risk assessments, facilitating security awareness training, and ensuring that cybersecurity policies align with business objectives. Regular cross-department meetings and incident response simulations are common, fostering a shared responsibility for cyber resilience. Effective communication and relationship-building skills are essential in this role to bridge technical and non-technical teams.

What is the difference between Cyber Risk Manager vs Cybersecurity Analyst?

AspectCyber Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, security firms, corporate environments

The Cyber Risk Manager focuses on identifying, assessing, and mitigating organizational cyber risks through strategic planning and policy development. In contrast, the Cybersecurity Analyst primarily monitors security systems, responds to incidents, and tests vulnerabilities. Both roles require certifications like CISSP, but their daily tasks and focus areas differ significantly, with the manager taking a broader, strategic approach and the analyst handling operational security tasks.

What are the key skills and qualifications needed to thrive as a Cyber Risk Manager, and why are they important?

To thrive as a Cyber Risk Manager, you need a solid background in information security, risk assessment, and compliance, often supported by a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC tools, and relevant certifications like CISSP or CISM is typically required. Excellent analytical thinking, communication, and leadership skills set top performers apart in this role. These skills are crucial for identifying risks, implementing effective controls, and ensuring the organization’s digital assets remain secure and compliant.

Can you make $200,000 in cyber security?

Cyber Risk Managers and senior cybersecurity professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and in high-demand industries or locations. Salary levels depend on factors such as expertise, certifications, industry, and geographic region, with leadership roles and specialized skills commanding higher compensation.

Can you make $500,000 a year in cyber security?

Cyber Risk Managers and senior cybersecurity professionals can potentially earn $500,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and leadership roles such as Chief Information Security Officer. High salaries are often associated with large organizations, specialized skills, and strategic responsibilities in cybersecurity management.

What does a cyber risk manager do?

A cyber risk manager assesses and mitigates cybersecurity threats to an organization’s information systems. They develop risk management strategies, implement security policies, and often use tools like risk assessment frameworks and security audits to protect digital assets. Certification such as CISSP or CISM can enhance their effectiveness in this role.

Is a CISO a stressful job?

A Chief Information Security Officer (CISO) role is often considered high-stress due to the responsibility for an organization's cybersecurity strategy, risk management, and incident response. The job requires managing complex threats, compliance requirements, and often involves long hours, especially during security breaches or audits.
What are popular job titles related to Cyber Risk Manager jobs in Massachusetts? For Cyber Risk Manager jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching Cyber Risk Manager jobs in Massachusetts look for? The top searched job categories for Cyber Risk Manager jobs in Massachusetts are:
MD GRC Risk Management and Governance

MD GRC Risk Management and Governance

State Street Global Advisors

Quincy, MA • Hybrid

$170K - $282K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


Job description

The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ensures cyber risk is consistently identified, assessed, governed, and reported in alignment with the Enterprise Risk Framework, regulatory expectations, and the firm's risk appetite. The role serves as a central coordination point, with a strong focus on framework governance, risk management, findings oversight and management, and executivelevel reporting.

Key Responsibilities

  • Own and evolve the Cyber Risk Management Framework, ensuring alignment with the Enterprise Risk Framework and regulatory expectations.
  • Govern cyber risk taxonomies, risk appetite statements, risk metrics, and assessment methodologies.
  • Support embedding cyber risk practices across the L3 Cyber risk methodology and support functional and business risk owners in their efforts to improve and sustain cyber risk posture.
  • Provide oversight of control assurance and remediation execution and quality, including challenge, escalation, and consistency.
  • Ensure consistent linkage between assessment outcomes, risk appetite, and remediation priorities.
  • Enable and guide Enterprise Process Owner (EPO) / Metric Owners with challenges related to processes area / Key Risk Indicator improvement, ensuring clear accountability and effective operation.
  • Support the second line of defense in defining, maintaining, and overseeing Cyber Key Risk Indicators (KRIs) and thresholds, ensuring they provide meaningful insight into risk posture and trends.
  • Coordinate cyber risk matters for managementlevel and executive Risk Committees, including agenda development, materials, and escalation.
  • Produce and oversee executivelevel cyber risk reporting, including risk posture, trends, material issues, and emerging risks.
  • Ensure reporting is concise, decisionoriented, and aligned with enterprise and Board risk governance expectations.
  • Serve as the primary cyber risk interface with Technology Risk Advisors (TRAs), coordinating inputs, challenge, outcomes, and followthrough.
  • Oversee LOD and legal entity cyber risk reporting, ensuring a consistent Global Cybersecurity view.
  • Coordinate with Cyber Compliance teams to provide accurate data sharing for regulatory engagement and legal entities.
  • Provide governance oversight for issues that impact cyber risk, including intake, severity assessment, challenge, escalation, and closure monitoring.
  • Oversee cyber risk acceptance governance, ensuring decisions are riskinformed, appropriately documented, timebound, and approved at the correct level.
  • Ensure alignment between issues, risk acceptances, and risk appetite.
  • Lead the intake and governance of cyber findings from audits, regulatory reviews, assessments, and testing activities.
  • Ensure findings are consistently riskrated, challenged where appropriate, and tracked through remediation to closure.
  • Monitor remediation progress, aging, and systemic themes, escalating concerns as needed to governance/management committees.

Required Qualifications

  • 10+ years of experience in cybersecurity risk management, technology risk, or enterprise risk governance, with significant experience at a senior leadership level.
  • Bachelor's degree in information systems, computer science, data analytics, cybersecurity or related field (or equivalent experience).
  • Deep understanding of cyber risk frameworks, enterprise risk management, and regulatory expectations within a large, complex financial services or regulated environment.
  • Proven experience with risk governance, control assurance and assessments, KRIs, issue management, and executive reporting.
  • Strong ability to build relationships across the three lines of defense and influence at executive and Board levels.
  • Exceptional communication skills, with the ability to translate technical and risk concepts into executivelevel insights.
  • Experience leading highly successful teams in achieving objectives and key results.

Preferred Skills

  • Cybersecurity Certifications such as: CISSP, CISM or equivalent.
  • Experience implementing automated and/or continuous controls monitoring in cloud and hybrid environments.
  • Strong analytical mindset with the ability to translate ambiguous risk or control questions into measurable metrics and repeatable tests.
  • Clear written and verbal communication skills, including the ability to explain complex technical findings and trends to leadership.

Salary Range:

$170,000 - $282,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.