2

Cyber Security Entry Level Risk Analyst Jobs in Boston, MA

Aqueduct Technologies is seeking a GRC Analyst to join our Governance, Risk, and Compliance (GRC ... Stay current on evolving cybersecurity risks, regulatory requirements, and industry standards

Aqueduct Technologies is seeking a GRC Analyst to join our Governance, Risk, and Compliance (GRC ... Stay current on evolving cybersecurity risks, regulatory requirements, and industry standards

Aqueduct Technologies is seeking a GRC Analyst to join our Governance, Risk, and Compliance (GRC ... Stay current on evolving cybersecurity risks, regulatory requirements, and industry standards

Deep understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls - ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS * Possess a strong risk mindset, exceptional attention to ...

Deep understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls - ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS * Possess a strong risk mindset, exceptional attention to ...

Deep understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls - ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS * Possess a strong risk mindset, exceptional attention to ...

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

Deep knowledge of network security, cryptography, threat analysis, vulnerability assessment ... Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk ...

next page

Showing results 1-20

Cyber Security Entry Level Risk Analyst information

See Boston, MA salary details

$46.7K

$108K

$163K

How much do cyber security entry level risk analyst jobs pay per year?

As of Jun 14, 2026, the average yearly pay for cyber security entry level risk analyst in Boston, MA is $107,988.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,400.00 and $125,500.00 per year, depending on experience, location, and employer.

What is the difference between Cyber Security Entry Level Risk Analyst vs Cyber Security Analyst?

AspectCyber Security Entry Level Risk AnalystCyber Security Analyst
CertificationsCompTIA Security+, CISSP (entry-level), CEH (entry-level)CompTIA Security+, CISSP, CEH, GIAC certifications
Work EnvironmentRisk assessment teams, security compliance departmentsSecurity operations centers, incident response teams
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk managementVarious industries including tech, finance, and government focusing on security monitoring

The main difference is that Cyber Security Entry Level Risk Analysts focus on identifying and assessing security risks and vulnerabilities, while Cyber Security Analysts are more involved in monitoring security systems, responding to incidents, and implementing security measures. Both roles require foundational certifications and are essential in maintaining organizational security, but they emphasize different aspects of cybersecurity operations.

What are some typical challenges faced by entry-level risk analysts in cyber security, and how can they overcome them?

Entry-level risk analysts in cyber security often face challenges such as quickly understanding complex IT environments, staying updated on evolving threats, and effectively communicating technical risks to non-technical stakeholders. To overcome these challenges, new analysts should focus on continuous learning, seek mentorship from experienced colleagues, and develop strong analytical and communication skills. Participating in regular team meetings and cross-functional projects can also help build a well-rounded understanding of the organization's risk landscape.

What does a Cyber Security Entry Level Risk Analyst do?

A Cyber Security Entry Level Risk Analyst is responsible for identifying, assessing, and helping to mitigate potential security risks within an organization’s digital systems. They assist in evaluating security measures, analyzing vulnerabilities, and supporting the implementation of risk management strategies. This role often involves working with security tools, compiling reports, and collaborating with other IT and security professionals to ensure that the organization’s data and assets are protected from cyber threats.

What are the key skills and qualifications needed to thrive as a Cyber Security Entry Level Risk Analyst, and why are they important?

To thrive as a Cyber Security Entry Level Risk Analyst, you need a foundational understanding of information security principles, risk assessment methodologies, and a relevant bachelor's degree such as in cybersecurity, information technology, or computer science. Familiarity with tools like vulnerability scanners, SIEM systems, and basic knowledge of frameworks such as NIST or ISO 27001 is often required, and certifications like CompTIA Security+ can be advantageous. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and explain findings to both technical and non-technical stakeholders. These skills are crucial for accurately assessing threats and helping organizations protect sensitive data in an evolving threat landscape.
What job categories do people searching Cyber Security Entry Level Risk Analyst jobs in Boston, MA look for? The top searched job categories for Cyber Security Entry Level Risk Analyst jobs in Boston, MA are:
Infographic showing various Cyber Security Entry Level Risk Analyst job openings in Boston, MA as of June 2026, with employment types broken down into 92% Full Time, and 8% Part Time. Highlights an 69% In-person, 23% Hybrid, and 8% Remote job distribution, with an average salary of $107,988 per year, or $51.9 per hour.
GRC Analyst

Full-time

Posted 28 days ago


Job description

Aqueduct Technologies is seeking a GRC Analyst to join our Governance, Risk, and Compliance (GRC) team. Reporting directly to the Director of GRC, this role plays a pivotal part in designing, executing, and maturing our clients' security and compliance programs.
 
This is an analyst to mid level position designed for a GRC professional who is ready to take ownership of key workstreams while continuing to develop under senior leadership guidance. You will work directly with clients in a consulting environment, contributing to meaningful security improvements across diverse industries.
 
As part of our growing GRC practice, you will:
- Support and progressively lead client compliance engagements
- Contribute to the development of Aqueduct's GRC service offerings
- Assist with internal compliance initiatives and audit readiness activities
Core Responsibilities:
  • Compliance Readiness and Assessments:
  • Support and conduct readiness assessments aligned to frameworks such as NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, and CMMC
  • Identify control gaps and provide practical, risk based remediation recommendations
  • Assist clients in preparing for external audits and certification efforts
 
Risk Assessments:
  • Perform organizational risk assessments and document risk findings
  • Evaluate control effectiveness and recommend mitigation strategies aligned with business objectives
  • Maintain risk registers and support risk reporting processes
 
Third Party Risk Management:
  • Conduct vendor risk assessments and due diligence reviews
  • Support the development and maintenance of third party risk programs
  • Assist with ongoing monitoring activities and documentation
 
Client Reporting and Communication:
  • Prepare clear, structured reports summarizing findings, risks, and recommended actions
  • Present results to client stakeholders with guidance from senior team members
  • Translate technical findings into business relevant insights
 
Collaboration and Internal Support:
  • Work closely with security operations, engineering, and account teams to align GRC initiatives
  • Support internal compliance initiatives including SOC 2 readiness and audit activities
  • Contribute to documentation development, templates, and process improvement efforts
 
Professional Development:
  • Stay current on evolving cybersecurity risks, regulatory requirements, and industry standards
  • Expand expertise across multiple frameworks and advisory domains
Required Skills & Qualifications:
  • Core Competencies:
  • Strong written and verbal communication skills
  • Analytical thinking and attention to detail
  • Ability to manage multiple client workstreams in a consulting environment
  • Professional presence in client facing situations
 
Technical and Compliance Experience:
  • Experience supporting or conducting assessments across one or more major frameworks such as NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, or CMMC
  • Working knowledge of risk assessment methodologies
  • Familiarity with third party risk management concepts and processes
  • Foundational understanding of Zero Trust principles and modern security architecture concepts
 
Professional Background:
  • 3 or more years of experience in information security with exposure to GRC functions
  • Experience in consulting, advisory, or managed services environments preferred
  • Experience with GRC platforms such as ServiceNow GRC, Archer, Drata, Vanta, or similar tools is a plus
 
Certifications:
  • One or more of the following certifications is preferred but not required:
  • CISA
  • CISM
  • CRISC
  • CISSP
  • CCSP
 
Work Model:
  • Ability to work in a hybrid model in the Canton, MA area
  • Willingness to travel locally for client engagements as needed
Growth Opportunity
  • This role offers a clear path toward Senior GRC Consultant responsibilities. Analysts who demonstrate strong client delivery, technical depth, and engagement ownership will have opportunities to lead larger assessments, mentor junior team members, and expand into broader advisory engagements.
Aqueduct Technologies is committed to developing a diverse and talented team. We celebrate and support diversity and are committed to making an inclusive environment for all employees and applicants including women, minorities, individuals with disabilities, members of the LGBTQIA community, veterans, and any other legally protected group. We are an Equal Opportunity Employer and do not discriminate against any employee or applicant on the basis of any status protected by federal, state, or local laws.
 
Aqueduct Technologies is one of the largest IT solutions providers in the US, recognized for our relentless pursuit of customer satisfaction, our corporate culture, technology leadership, and our commitment to the local community. We pride ourselves on our world-class engineering, the investments we make in our employees and our systems, and on our loyal base of customers and manufacturers. Recognized as one of the fastest-growing, private companies in Massachusetts-and awarded the Best Place to Work in Boston for six, consecutive years-there is no better time to join Aqueduct than now!
 
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job