1

Cybersecurity Risk Analyst Jobs in Massachusetts

Risk Analyst

Lowell, MA · On-site

$25/hr

... CyberSecurity, and Remote Services (iSOC) divisions to create meaningful 'Hybrid Security ... The main responsibility of the Risk Analyst is threat intelligence risk escalation, travel ...

The IT Risk Analyst's primary responsibility will be to conduct various risk assessments, including ... Bachelor's degree, preferably in Accounting, Cybersecurity (Information Assurance), Computer ...

New

The IT Risk Analyst's primary responsibility will be to conduct various risk assessments, including ... Bachelor's degree, preferably in Accounting, Cybersecurity (Information Assurance), Computer ...

New

The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are ... As a Senior Risk & Compliance Analyst, you will play a key role in supporting the design, execution ...

The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are ... As a Senior Risk & Compliance Analyst, you will play a key role in supporting the design, execution ...

The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are ... As a Senior Risk & Compliance Analyst, you will play a key role in supporting the design, execution ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst ... Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Finance ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst ... Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Finance ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst ... Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Finance ...

Risk Intelligence Analyst Prosegur is searching for hard-working, motivated, and dedicated ... CyberSecurity, and Remote Services (iSOC) divisions to create meaningful 'Hybrid Security ...

... CyberSecurity, and Remote Services (iSOC) divisions to create meaningful 'Hybrid Security ... The Risk Operations Analyst will use internal and external intelligence sources to support active ...

Sr. Cyber Security Analyst

Boston, MA · Hybrid

$108K - $140K/yr

... Sr. Cyber Security Analyst Locations: Waltham, MA / Boston, MA - Hybrid / New York / Florida ... Collaborating with cross-functional teams, you will drive risk-informed decision-making, support ...

next page

Showing results 1-20

Cybersecurity Risk Analyst information

See Massachusetts salary details

$16

$44

$71

How much do cybersecurity risk analyst jobs pay per hour?

As of Jun 11, 2026, the average hourly pay for cybersecurity risk analyst in Massachusetts is $44.21, according to ZipRecruiter salary data. Most workers in this role earn between $32.55 and $53.80 per hour, depending on experience, location, and employer.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

What are the key skills and qualifications needed to thrive as a Cybersecurity Risk Analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

Can I make $200,000 a year in cyber security?

Cybersecurity Risk Analysts can potentially earn $200,000 or more annually, especially with advanced certifications like CISSP, extensive experience, and specialized skills in areas such as threat management or security architecture. High salaries are often found in senior roles, management positions, or in organizations with complex security needs. Factors like location, industry, and company size also influence earning potential.

What does a cyber risk analyst do?

A cybersecurity risk analyst evaluates an organization’s information systems to identify vulnerabilities and assess potential threats. They analyze security data, develop risk mitigation strategies, and recommend security improvements, often using tools like risk assessment frameworks and security software. The role requires strong analytical skills and knowledge of cybersecurity principles and standards.

What are some common challenges faced by Cybersecurity Risk Analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

Is SOC 1 entry level?

SOC 1 (Service Organization Control 1) reports are audit reports used by organizations to demonstrate controls over financial reporting. The term SOC 1 itself does not specify an entry-level position; however, roles involved in preparing or auditing SOC 1 reports, such as cybersecurity risk analysts or auditors, typically require some experience in controls, compliance, or auditing, but entry-level positions may assist with documentation and testing under supervision.

What does a Cybersecurity Risk Analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

Can you make $500,000 a year in cyber security?

Cybersecurity Risk Analysts typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires advanced roles such as cybersecurity executives, consultants, or specialists with extensive expertise and leadership responsibilities.
Infographic showing various Cybersecurity Risk Analyst job openings in Massachusetts as of June 2026, with employment types broken down into 70% Full Time, 5% Temporary, and 25% Contract. Highlights an 80% In-person, 5% Hybrid, and 15% Remote job distribution, with an average salary of $91,967 per year, or $44.2 per hour.
Technology Risk Director- CyberSecurity

Technology Risk Director- CyberSecurity

Citizens

Westwood, MA • On-site

Other

Medical, Dental, Vision, Retirement, PTO

Posted 15 days ago


Job description

Description

As a First Line of Defense Cybersecurity Risk Director within the Enterprise Technology Security (ETS) Risk organization, you will provide strategic leadership in protecting the organization against evolving cyber threats while enabling business innovation. This role is accountable for the design, execution, and continuous maturity of the cybersecurity risk management framework, ensuring cyber risks are proactively identified, assessed, mitigated, monitored, and transparently reported.  You will serve as a trusted advisor to senior leadership, translating complex cybersecurity and technology risks into clear business impacts and risk-based decisions aligned to enterprise risk appetite. The role partners closely with Technology, Corporate Security, Legal, Compliance, Risk, Audit, and business leaders to ensure cybersecurity risk strategies are fully integrated with business objectives, regulatory expectations, and enterprise resilience goals.  You will also lead and develop a high performing team of cybersecurity risk professionals, fostering a culture of strong risk discipline, constructive challenge, and continuous improvement across the organization.

Key Responsibilities

Leadership & Strategy

  • Lead, coach, and develop a team of cybersecurity risk analysts, principals, and managers, establishing a consistent, scalable, and value driven risk support model across the enterprise.
  • Define and evolve the cybersecurity risk management strategy and operating model, ensuring alignment with enterprise risk appetite, regulatory requirements, and business priorities.
  • Translate cyber and technology risks into business relevant impacts, enabling senior management to make informed, risk-based decisions.

Cybersecurity Risk Management & Oversight

  • Establish and oversee an end-to-end cybersecurity risk management process that enables continuous identification, analysis, assessment, treatment, and monitoring of cyber and technology risks.
  • Define and maintain key risk indicators (KRIs), controls, and control testing strategies to measure cybersecurity risk exposure and control effectiveness.
  • Provide oversight of Risk and Control Self Assessments (RCSAs), Targeted Risk Reviews, business initiative risk assessments, and issue management, ensuring timely remediation and sustainable risk reduction.
  • Maintain visibility into detailed cyber risk assessments, advising business and technology leaders on prioritized mitigation strategies and risk tradeoffs.

Business Partnership & Advisory

  • Act as a strategic risk advisor to business lines and technology leaders, providing day to day guidance on regulatory compliance, risk mitigation, and industry best practices.
  • Advise on new products, processes, technologies, and strategic initiatives, ensuring appropriate risk identification, control design, and governance approvals are in place.
  • Guide business partners through enterprise governance forums and approval processes, ensuring cyber risks are understood, documented, and appropriately managed.

Regulatory, Audit & External Engagement

  • Serve as the primary risk lead for regulatory exams and audits related to cybersecurity and technology risk for assigned products or functions.
  • Partner with Internal Audit, and second line stakeholders, leading exam preparation, responses, and ongoing issue remediation.
  • Ensure compliance with applicable laws, regulations, and supervisory guidance, including FFIEC, GLBA, SOX, and other relevant standards.

Collaboration & Stakeholder Management

  • Build and maintain strong, trusted relationships with business partners, technology leaders, security teams, project stakeholders, and subject matter experts.
  • Collaborate across lines of defense to provide effective challenge while enabling responsible innovation and delivery.
  • Promote a culture of cybersecurity awareness and operational resilience across the organization.

Qualifications - Experience & Skills

  • 10+ years of experience in Cybersecurity and/or Information Technology, with deep exposure to enterprise environments.
  • 10+ years of risk management experience within financial services, preferably in cybersecurity, technology risk, or operational risk.
  • Strong experience with cloud technologies (IaaS, PaaS, SaaS), DevSecOps, web applications, operating systems, databases, and networking.
  • Broad knowledge of cybersecurity domains including:
    • Network and infrastructure security
    • Vulnerability and configuration management
    • Identity and Access Management including Customer Identity
    • API and application security
    • Data protection and cryptography
    • Operational resilience
    • Incident, problem, and change management
  • Experience operating in a highly regulated environment under significant supervisory scrutiny.
  • Solid understanding of internal controls, risk assessments, and governance processes.
  • Working knowledge of FFIEC guidance, GLBA, SOX, and related regulatory frameworks.
  • Familiarity with leading industry frameworks, including Cybersecurity Risk Institute, NIST Cybersecurity Framework, Cloud Security Alliance, NIST 800 53, and ISO 27001.
  • Demonstrated ability to synthesize complex risk data, prioritize mitigation actions, and influence outcomes.
  • Exceptional communication and executive presence skills, with the ability to engage all levels of the organization.
  • Proven leadership, coaching, and talent development experience.
  • Strong project and program management capabilities across multiple stakeholders.

Education & Certifications (Preferred)

  • Bachelor's Degree required; Master's Degree preferred.
  • Professional certifications strongly preferred, including:
    • Certified Information Systems Security Professional (CISSP)
    • Certified Cloud Security Professional (CCSP)
    • Cloud security specialty certification in AWS and Azure
    • Certified Information Security Manager (CISM)
    • Certified Information Systems Auditor (CISA)
    • Certified in Risk and Information Systems Control (CRISC)

Hours & Work Schedule

  • Hours per Week: 40
  • Work Schedule: Monday-Friday
  • Hybrid: 4 days onsite, 1 day remote

Pay Transparency

The salary range for this position is $190,000 - $240,000 per year, plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to the work location, and relevant skills and experience.

We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens' paid time off policy exceeds the mandatory, paid sick or paid time-away policy of every local and state jurisdiction in the United States. For an overview of our benefits, visit https://jobs.citizensbank.com/benefits .

#LI-Citizens1

Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague's or a dependent's reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Education:Why Work for UsEmployment Type: 1ST