1

Cybersecurity Risk Analyst Jobs in Massachusetts

Bachelor's degree in Cybersecurity, Information Technology, Risk Management, Business Continuity ... analyzing resumes, or assessing responses. These tools assist our recruitment team but do not ...

Sr. Cyber Security Analyst

Waltham, MA · Hybrid

$107K - $139K/yr

... Sr. Cyber Security Analyst Locations: Waltham, MA / Boston, MA - Hybrid / New York / Florida ... Collaborating with cross-functional teams, you will drive risk-informed decision-making, support ...

Sr. Cyber Security Analyst

Waltham, MA · On-site

$107K - $139K/yr

... Sr. Cyber Security Analyst Locations: Waltham, MA / Boston, MA - Hybrid / New York / Florida ... Collaborating with cross-functional teams, you will drive risk-informed decision-making, support ...

Bachelor's degree in Cybersecurity, Information Technology, Risk Management, Business Continuity ... analyzing resumes, or assessing responses. These tools assist our recruitment team but do not ...

Bachelor's degree in Cybersecurity, Information Technology, Risk Management, Business Continuity ... analyzing resumes, or assessing responses. These tools assist our recruitment team but do not ...

Risk Operations Analyst Position: Wednesday - Saturday 11:00am -9:00pm Pay Rate: $28.00p/h Role ... CyberSecurity, and Remote Services (iSOC) divisions to create meaningful 'Hybrid Security ...

Deep understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls - ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS * Possess a strong risk mindset, exceptional attention to ...

Deep understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls - ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS * Possess a strong risk mindset, exceptional attention to ...

The cybersecurity analyst will provide day-to-day cybersecurity operations support ... Understanding of security frameworks (e.g., NIST, ISO 27001) and risk management methodologies

They are hiring a Cybersecurity Analyst to aid the Enterprise Cybersecurity Team by providing day ... ISO 27001) and risk management methodologies • Hands-on experience with security tools ...

The Information Security Analyst III is a key member of the Security Operation Center (SOC) team ... Generate reports to monitor cybersecurity risk. * Share in the representation of IT Security in non ...

Cybersecurity Analyst

Woburn, MA · On-site

$104K - $120K/yr

The cybersecurity analyst will provide day-to-day cybersecurity operations support ... Understanding of security frameworks (e.g., NIST, ISO 27001) and risk management methodologies

The cybersecurity analyst will provide day-to-day cybersecurity operations support ... Understanding of security frameworks (e.g., NIST, ISO 27001) and risk management methodologies

next page

Showing results 1-20

Cybersecurity Risk Analyst information

See Massachusetts salary details

$16

$44

$71

How much do cybersecurity risk analyst jobs pay per hour?

As of Jun 11, 2026, the average hourly pay for cybersecurity risk analyst in Massachusetts is $44.21, according to ZipRecruiter salary data. Most workers in this role earn between $32.55 and $53.80 per hour, depending on experience, location, and employer.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

What are the key skills and qualifications needed to thrive as a Cybersecurity Risk Analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

Can I make $200,000 a year in cyber security?

Cybersecurity Risk Analysts can potentially earn $200,000 or more annually, especially with advanced certifications like CISSP, extensive experience, and specialized skills in areas such as threat management or security architecture. High salaries are often found in senior roles, management positions, or in organizations with complex security needs. Factors like location, industry, and company size also influence earning potential.

What does a cyber risk analyst do?

A cybersecurity risk analyst evaluates an organization’s information systems to identify vulnerabilities and assess potential threats. They analyze security data, develop risk mitigation strategies, and recommend security improvements, often using tools like risk assessment frameworks and security software. The role requires strong analytical skills and knowledge of cybersecurity principles and standards.

What are some common challenges faced by Cybersecurity Risk Analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

Is SOC 1 entry level?

SOC 1 (Service Organization Control 1) reports are audit reports used by organizations to demonstrate controls over financial reporting. The term SOC 1 itself does not specify an entry-level position; however, roles involved in preparing or auditing SOC 1 reports, such as cybersecurity risk analysts or auditors, typically require some experience in controls, compliance, or auditing, but entry-level positions may assist with documentation and testing under supervision.

What does a Cybersecurity Risk Analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

Can you make $500,000 a year in cyber security?

Cybersecurity Risk Analysts typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires advanced roles such as cybersecurity executives, consultants, or specialists with extensive expertise and leadership responsibilities.
Infographic showing various Cybersecurity Risk Analyst job openings in Massachusetts as of June 2026, with employment types broken down into 70% Full Time, 5% Temporary, and 25% Contract. Highlights an 80% In-person, 5% Hybrid, and 15% Remote job distribution, with an average salary of $91,967 per year, or $44.2 per hour.
Technology Risk & Continuity Analyst

Technology Risk & Continuity Analyst

GMO

Boston, MA

$80/hr

Full-time

Posted 9 days ago


Job description

Company Profile
 
Founded in 1977, GMO is a global investment manager committed to delivering superior long-term investment performance and advice to our clients. We offer investment strategies and solutions where we believe we are positioned to add the greatest value for our investors. These include multi-asset class, equity, fixed income and alternative offerings.
 
We manage approximately $80bn for a client base that includes many of the world’s most sophisticated institutions, financial intermediaries, and private clients. Industry-wide, we are well known for our focus on valuation-based investing, willingness to take bold positions when conditions warrant, and candid and academically rigorous thought leadership. Jeremy Grantham, GMO’s Co-Founder and Long-Term Investment Strategist, is renowned as an expert in identifying speculative investment bubbles and also as a leading climate investor and advocate.
 
GMO is privately owned and employs over 430 people worldwide. We are headquartered in Boston, with additional offices in Europe, Asia and Australia. Our company-wide culture emphasizes commitment to clients, intellectual curiosity, and open debate. We celebrate and respect our differences, while embracing and valuing what each of us brings to work, as we know that diverse teams in an inclusive, caring environment achieve higher engagement and better client results.
 
Please follow the prompts included in this job posting to apply. The application window for this role is anticipated to remain open until the job is filled, or as otherwise determined by GMO.
 

Overview:

As a key member of the Security Risk & Audit team, the Technology Risk & Continuity Analyst supports the firm’s security risk, business continuity, and incident management programs, contributing across prevention, preparedness, and response activities.

This role performs core security risk functions such as risk and control support, audit readiness, access review coordination, and security awareness enablement. It also supports the development, maintenance, and testing of business continuity and incident response plans, including coordinating exercises and tracking remediation activities.

The analyst monitors threats and incidents, supports resilience and training platforms, and contributes to audit and due diligence efforts. Working closely with technology, risk, and business stakeholders, this role provides broad organizational exposure while helping ensure the firm is prepared for operational disruptions and cyber events, and continually improving its security posture.

We value individuals who are reliable, curious, collaborative, proactive, and strong communicators—professionals who enjoy problem-solving and are eager to build hands-on experience across security risk management, continuity planning, and incident management.

Primary Responsibilities:

Business Continuity

  • Work with all areas of the firm to map critical service dependencies and document recovery strategies through the BIA process, gathering recovery requirements, and identifying single points of failure
  • Support maintenance of Business Continuity and Incident Response Plans through regular reviews and exercises, with a focus on continuous improvement
  • Maintain program documentation including incident and exercise reporting, program metrics and reports for a variety of stakeholders
  • Develop and maintain BCP standards and templates.
  • Participate in Business Continuity and risk forums
  • Identify emerging risks (e.g., regulatory changes, natural and man-made risk) and perform risk assessments.
  • Administer and maintain the Riskonnect Resilience platform including monitoring platform updates, attending vendor training, and managing the vendor relationship

Security & Risk Management

  • Monitor IT incidents and document significant events
  • Prepare incident summaries for internal tracking and reporting
  • Coordinate security awareness programs via Learning Pool, including onboarding, annual training, and phishing simulations
  • Support internal and external audits by collecting evidence, documenting control activities, and maintaining audit artifacts
  • Assist with annual program reviews and audit readiness activities
  • Respond to client due diligence requests and RFPs, leveraging knowledge bases and SMEs as needed
  • Participate in vendor risk assessments, onboarding reviews, and ongoing monitoring of critical vendors
Job Requirements:
  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, Business Continuity, or a related field (or equivalent experience)
  • 2–5 years of experience in cybersecurity, business continuity, disaster recovery, operational risk, or IT risk management
Core Skills & Knowledge:
  • Interest in business continuity and operational resilience practices (BIAs, recovery strategies, dependency mapping, exercises, and issue remediation)
  • Familiarity with resilience or GRC platforms (e.g., Riskonnect or similar tools)
  • Ability to master learning management systems and security awareness training programs (e.g., Learning Pool)
  • Understanding of incident management frameworks and IT service management tools (e.g., ServiceNow)
  • Knowledge of client and third-party due diligence processes
  • Familiarity with threat intelligence sources and relevant frameworks/standards (e.g., NIST, ISO 22301, ITIL) is a plus
Professional Skills:
  • Strong written and verbal communication skills, with the ability to clearly document plans, exercises, and incidents
  • Excellent organizational skills and attention to detail, with the ability to manage multiple concurrent workstreams
  • Ability to collaborate across technology, risk, compliance, and business teams
  • Comfort facilitating discussions (e.g., tabletop exercises, walkthroughs), capturing outcomes, and driving follow-through
  • Continuous improvement mindset with the ability to learn, document, measure, and iterate
Certifications (Preferred):
  • ABCP, CBCP, Security+, or similar certifications are a plus

This is a reasonable, good faith estimate of the current salary range for this role. GMO’s salary range accounts for a wide array of factors that are considered in making compensation decisions including but not limited to skill sets and market demand for skills; level of experience and training; specific qualifications, performance, time in role/company, geographic location, and other business and organizational needs.

In addition, this position is eligible for a discretionary annual bonus award, which award may be determined by individual, team, department and firm performance, and is subject to the terms of GMO’s compensation plan. This position is also benefits eligible. GMO’s comprehensive benefits program includes medical insurance, dental insurance, life insurance, long-term disability coverage, a 401(k)/profit-sharing retirement plan, open paid time off, leaves of absences, dependent care resources, tuition reimbursement, charitable gifts matching, flexible spending accounts, and commuter benefits.

GMO is committed to the recruitment, employment, and promotion of all candidates equally, regardless of an individual's gender, race, color, national origin, ancestry, age, religion, pregnancy, marital status, sexual orientation, gender identity or expression, military or veteran status, genetic information, physical or mental disability (except where such disability is a bona fide occupational disqualification) or any other classification protected under federal, state or local law.

GMO will not offer visa sponsorship for this opportunity.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.


GMO logo

About GMO

Sourced by ZipRecruiter

Industry

Finance and insurance

Company size

501 - 1,000 Employees

Headquarters location

Boston, MA, US

Year founded

1977

Social media