1

Cybersecurity Risk Management Jobs in Massachusetts

CYBERSECURITY MANAGER

Worcester, MA · On-site

$100K - $132K/yr

CYBERSECURITY MANAGER DEPARTMENT OF INNOVATION AND TECHNOLOGY CITY OF WORCESTER The City of ... Deep understanding of security principles, access control models, and risk management. * Strong ...

CYBERSECURITY MANAGER

Worcester, MA · On-site

$110K - $149K/yr

CYBERSECURITY MANAGERDEPARTMENT OF INNOVATION AND TECHNOLOGYCITY OF WORCESTER The City of Worcester ... Deep understanding of security principles, access control models, and risk management. * Strong ...

Cybersecurity Manager

Boston, MA · On-site

$120K - $163K/yr

Third-party and vendor risk management * Incident response, cyber resilience, and disaster recovery ... Cybersecurity operations and controls * Data protection principles * HIPAA Security and Privacy ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Massachusetts salary details

$62.3K

$145.2K

$203.1K

How much do cybersecurity risk management jobs pay per year?

As of Sep 10, 2026, the average yearly pay for cybersecurity risk management in Massachusetts is $145,211.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,200.00 and $163,800.00 per year, depending on experience, location, and employer.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are popular job titles related to Cybersecurity Risk Management jobs in Massachusetts?

For Cybersecurity Risk Management jobs in Massachusetts, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management jobs in Massachusetts look for?

The top searched job categories for Cybersecurity Risk Management jobs in Massachusetts are:

What cities in Massachusetts are hiring for Cybersecurity Risk Management jobs?

Cities in Massachusetts with the most Cybersecurity Risk Management job openings:

Infographic showing various Cybersecurity Risk Management job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 78% Full Time, 16% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 82% Physical, 3% Hybrid, and 15% Remote job distribution, with an average salary of $145,211 per year, or $69.8 per hour.

Product Cybersecurity Engineer (Medical Devices)

Wilmington, MA • On-site

Analog Devices, Inc.
Electrical Equipment, Appliance, and Component Manufacturing • 5 - 10K employees

Other

Medical, Dental, Vision, Retirement, PTO

Re-posted 20 days ago


Analog Devices rating

8.7

Company rating: 8.7 out of 10

Based on 19 frontline employees who took The Breakroom Quiz


Job description

## Product Cybersecurity Engineer (Medical Devices)Applylocations: US, MA, Wilmingtontime type: Full timeposted on: Posted Todayjob requisition id: R263547**About Analog Devices**Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI, and software technologies into solutions that combat climate change, reliably connect humans and the world, and help drive advancements in automation and robotics, mobility, healthcare, energy and data centers. With revenue of more than $11 billion in FY25, ADI ensures today's innovators stay Ahead of What's Possible. Learn more at www.analog.com and on LinkedIn and X.**Product Cybersecurity Engineer – Medical Devices**The Health Solutions Business Unit at Analog Devices is seeking a Product Cybersecurity Engineer to lead cybersecurity activities across the medical device product lifecycle. This role focuses on ensuring the security, privacy, and regulatory compliance of connected medical devices and Software as a Medical Device (SaMD) solutions. The candidate will collaborate with internal and external teams to drive cybersecurity risk management activities, secure product design, threat modeling, vulnerability management, and cybersecurity compliance throughout the product lifecycle, from concept and development through post-market support.A significant portion of this role involves performing threat modeling and supporting cybersecurity risk management activities aligned with FDA cybersecurity guidance. The successful candidate will also contribute to cybersecurity documentation supporting FDA regulatory submissions, including 510(k) activities, while helping to establish and maintain post-market cybersecurity processes and secure development lifecycle (SDL) practices for regulated medical devices.**Key Responsibilities*** Perform product security risk assessments and threat modeling for medical devices and SaMD platforms.* Lead cybersecurity risk management activities throughout the product lifecycle in alignment with FDA guidance and industry best practices.* Support cybersecurity documentation for FDA regulatory submissions, including cybersecurity risk management files, SBOM requirements, and other regulatory deliverables.* Conduct security architecture reviews and evaluate system designs against secure architecture principles, cybersecurity frameworks, and regulatory expectations.* Develop and maintain cybersecurity risk management documentation, vulnerability management processes, and incident response procedures.* Partner with internal and external teams to integrate secure-by-design principles into product development and lifecycle management activities.* Participate in secure development lifecycle (SDL/SSDLC) activities, including security requirements definition, design reviews, and cybersecurity verification activities.* Analyze results from vulnerability assessments, static analysis, dynamic analysis, penetration testing, and security scanning activities.* Support SBOM generation, third-party software assessments, and supply chain cybersecurity risk evaluations.* Investigate and support remediation of cybersecurity vulnerabilities affecting medical devices, software platforms, and connected product ecosystems.* Participate in vulnerability management, coordinated vulnerability disclosure, product security incident response, and post-market cybersecurity monitoring activities.* Support internal audits, external assessments, FDA inspections, and cybersecurity reviews related to medical device security and regulatory compliance.* Serve as a cybersecurity subject matter expert (SME) for cross-functional teams and product cybersecurity initiatives.**Requirements*** Master’s or Ph.D. degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, or a related technical discipline. Ph.D. preferred.* 7+ years of experience in cybersecurity, product security, software security, or related engineering roles.* Experience supporting cybersecurity activities for medical devices, connected healthcare products, or Software as a Medical Device (SaMD).* Demonstrated experience supporting FDA-regulated medical devices, including 510(k) submissions.* Demonstrated experience performing threat modeling for complex systems using methodologies such as STRIDE, attack trees, misuse cases, or equivalent frameworks.* Experience defining security controls, cybersecurity requirements, and mitigation strategies based on identified threats and risks.* Familiarity with cybersecurity standards and frameworks such as NIST Cybersecurity Framework, ISO 14971, IEC 62304, AAMI TIR57, and OWASP guidance.* Experience with vulnerability management, security testing, penetration testing, and remediation processes.* Familiarity with Software Bill of Materials (SBOM), third-party software risk management, and supply chain cybersecurity concepts.* Experience integrating cybersecurity requirements into Secure Development Lifecycle (SDL/SSDLC) processes.* Strong analytical, technical writing, communication, and cross-functional collaboration skills.**Additional Desired Skills and Qualifications*** Experience with connected medical devices, SaMD, cloud-connected platforms, or AI/ML-enabled medical products.* Experience with post-market cybersecurity monitoring, vulnerability disclosure, and incident response processes.* Experience with connected medical devices, cloud-connected platforms, IoMT, or digital health solutions.* Professional certifications such as CISSP, CSSLP, HCISPP, GICSP, Security+, or equivalent.*For positions requiring access to technical data, Analog Devices, Inc. may have to obtain export licensing approval from the U.S. Department of Commerce - Bureau of Industry and Security and/or the U.S. Department of State - Directorate of Defense Trade Controls. As such, applicants for this position – except US Citizens, US Permanent Residents, and protected individuals as defined by 8 U.S.C. 1324b(a)(3) – may have to go through an export licensing review process.**Analog Devices is an equal opportunity employer. We foster a culture where everyone has an opportunity to succeed regardless of their race, color, religion, age, ancestry, national origin, social or ethnic origin, sex, sexual orientation, gender, gender identity, gender expression, marital status, pregnancy, parental status, disability, medical condition, genetic information, military or veteran status, union membership, and political affiliation, or any other legally protected group.**EEO is the Law: Notice of Applicant Rights Under the Law.*Job Req Type: ExperiencedRequired Travel: Yes, 10% of the timeShift Type: 1st Shift/DaysThe expected wage range for a new hire into this position is $134,644 to $201,966.* Actual wage offered may vary depending on work location, experience, education, training, external market data, internal pay equity, or other bona fide factors.* This position qualifies for a discretionary performance-based bonus which is based on personal and company factors.* This position includes medical, vision and dental coverage, 401k, paid vacation, **holidays, and sick time**, and other benefits. #J-18808-Ljbffr

What Analog Devices employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Analog Devices logo

About Analog Devices

Sourced by ZipRecruiter

Analog Devices (NASDAQ: ADI) designs and manufactures semiconductor products and solutions. We enable our customers to interpret the world around us by intelligently bridging the physical and digital worlds with unmatched technologies that sense, measure and connect.

Industry

Electrical equipment, appliance, and component manufacturing

Company size

5,001 - 10,000 Employees

Headquarters location

Norwood, MA, US