Cybersecurity Risk Analysis (CRA) Additional Responsibilities * Software QMS management. Track and manage changes to software requirements and design documents. * Phase review coordination.
Cybersecurity Risk Analysis (CRA) Additional Responsibilities * Software QMS management. Track and manage changes to software requirements and design documents. * Phase review coordination.
Risk & Compliance Project Manager
Boston, MA · On-site
... cybersecurity, risk management, and project management processes while ensuring alignment with organizational policies, security requirements, and regulatory obligations. • Adhere to agreed project ...
Risk & Compliance Project Manager
Boston, MA · On-site
... cybersecurity, risk management, and project management processes while ensuring alignment with organizational policies, security requirements, and regulatory obligations. • Adhere to agreed project ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Our cybersecurity team plays an integral role in helping our clients proactively manage their ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Our cybersecurity team plays an integral role in helping our clients proactively manage their ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Our cybersecurity team plays an integral role in helping our clients proactively manage their ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Our cybersecurity team plays an integral role in helping our clients proactively manage their ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Our cybersecurity team plays an integral role in helping our clients proactively manage their ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Our cybersecurity team plays an integral role in helping our clients proactively manage their ...
Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business ...
Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business ...
Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business ...
Assess, manage and optimize information technology risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT regulatory and compliance requirements, and business ...
Work closely with client executives and management teams to understand their businesses and assist ... risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT ...
Work closely with client executives and management teams to understand their businesses and assist ... risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT ...
Work closely with client executives and management teams to understand their businesses and assist ... Cybersecurity* Third party risk* ITGC and application controls* SOC reporting* Regulatory and ...
Work closely with client executives and management teams to understand their businesses and assist ... Cybersecurity* Third party risk* ITGC and application controls* SOC reporting* Regulatory and ...
Sr. Director, Governance, Risk & Compliance United States + 1 more Information Technology Poste[...]
Cambridge, MA · On-site
$250/hr
Establish and maintain security governance frameworks, policies, standards, and exception management processes.* Provide cybersecurity governance and risk oversight for GxP-regulated systems ...
Sr. Director, Governance, Risk & Compliance United States + 1 more Information Technology Poste[...]
Cambridge, MA · On-site
$250/hr
Establish and maintain security governance frameworks, policies, standards, and exception management processes.* Provide cybersecurity governance and risk oversight for GxP-regulated systems ...
Risk & Compliance Project Manager
Boston, MA · On-site
$99K - $125K/yr
Identify opportunities to apply AI-enabled solutions to compliance, cybersecurity, risk management, and project management processes while ensuring alignment with organizational policies, security ...
Risk & Compliance Project Manager
Boston, MA · On-site
$99K - $125K/yr
Identify opportunities to apply AI-enabled solutions to compliance, cybersecurity, risk management, and project management processes while ensuring alignment with organizational policies, security ...
The ideal candidate brings deep expertise in cybersecurity strategy and risk management, a strong network within the private equity ecosystem, and a proven track record of leading high-performing ...
The ideal candidate brings deep expertise in cybersecurity strategy and risk management, a strong network within the private equity ecosystem, and a proven track record of leading high-performing ...
Work closely with client executives and management teams to understand their businesses and assist ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
Work closely with client executives and management teams to understand their businesses and assist ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
MD Senior BISO
Quincy, MA · On-site
Why this role is important to us The Managing Director is a trusted executive partner who translates cybersecurity risk into business terms, influences enterprise decision-making, and drives a ...
MD Senior BISO
Quincy, MA · On-site
Why this role is important to us The Managing Director is a trusted executive partner who translates cybersecurity risk into business terms, influences enterprise decision-making, and drives a ...
Why this role is important to us The Managing Director is a trusted executive partner who translates cybersecurity risk into business terms, influences enterprise decision-making, and drives a ...
Why this role is important to us The Managing Director is a trusted executive partner who translates cybersecurity risk into business terms, influences enterprise decision-making, and drives a ...
MD Senior BISO
Quincy, MA · On-site
Why this role is important to us The Managing Director is a trusted executive partner who translates cybersecurity risk into business terms, influences enterprise decision-making, and drives a ...
MD Senior BISO
Quincy, MA · On-site
Why this role is important to us The Managing Director is a trusted executive partner who translates cybersecurity risk into business terms, influences enterprise decision-making, and drives a ...
BCG delivers solutions through leading-edge management consulting along with technology and design ... cybersecurity, information security, GRC, audit, compliance, risk management, or technology ...
BCG delivers solutions through leading-edge management consulting along with technology and design ... cybersecurity, information security, GRC, audit, compliance, risk management, or technology ...
BCG delivers solutions through leading-edge management consulting along with technology and design ... cybersecurity, information security, GRC, audit, compliance, risk management, or technology ...
BCG delivers solutions through leading-edge management consulting along with technology and design ... cybersecurity, information security, GRC, audit, compliance, risk management, or technology ...
Work closely with client executives and management teams to understand their businesses and assist ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
Work closely with client executives and management teams to understand their businesses and assist ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
Cybersecurity Manager
Westborough, MA · On-site
$114K - $154K/yr
Oversee risk assessments and vulnerability management programs. * Monitor and report on cybersecurity performance metrics and compliance status. * Maintain relationships with relevant product and ...
Cybersecurity Manager
Westborough, MA · On-site
$114K - $154K/yr
Oversee risk assessments and vulnerability management programs. * Monitor and report on cybersecurity performance metrics and compliance status. * Maintain relationships with relevant product and ...
Cybersecurity Risk Management information
See Boston, MA salary details
$61.9K - $74.7K
1% of jobs
$74.7K - $87.4K
4% of jobs
$87.4K - $100.1K
5% of jobs
$100.1K - $112.9K
9% of jobs
$119.9K is the 25th percentile. Wages below this are outliers.
$112.9K - $125.6K
11% of jobs
$125.6K - $138.4K
10% of jobs
The median wage is $143.3K / yr.
$138.4K - $151.1K
28% of jobs
$158.4K is the 75th percentile. Wages above this are outliers.
$151.1K - $163.8K
14% of jobs
$163.8K - $176.6K
11% of jobs
$176.6K - $189.3K
4% of jobs
$189.3K - $202K
4% of jobs
$61.9K
$144.4K
$202K
How much do cybersecurity risk management jobs pay per year?
What is cybersecurity risk management?
What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?
What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?
What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?
| Aspect | Cybersecurity Risk Management | Cybersecurity Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment, policy development, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Financial, healthcare, government, large enterprises | IT departments, cybersecurity firms, corporate security teams |
Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.
What are popular job titles related to Cybersecurity Risk Management jobs in Boston, MA?
For Cybersecurity Risk Management jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Boston, MA look for?
The top searched job categories for Cybersecurity Risk Management jobs in Boston, MA are:
What cities near Boston, MA are hiring for Cybersecurity Risk Management jobs?
Cities near Boston, MA with the most Cybersecurity Risk Management job openings:

Design, Process, and Software Quality Risk Specialist
Cambridge, MA • On-site
Other
Posted 9 days ago
Key responsibilities
Own and conduct design risk assessments (dFMEA).
Manage process risk assessments (pFMEA) and software risk assessments (SRA).
Track and manage changes to software requirements and design documents, and support regulatory inspections and internal audits.
Job description
Axoft is building a new class of implantable neural interface-ultra-flexible, minimally reactive, and designed to remain functional for decades inside the human brain. Our software connects that hardware to the world: acquisition firmware, embedded configuration tools, clinical monitoring applications, and the cloud infrastructure that ties them together. Every release we ship ultimately affects a patient.
We are a small, technical team building compliant medical device systems the right way: risk-driven, Agile, and grounded in the international standards that govern product development, quality systems, and medical device software globally. We are looking for someone to help own the organizational risk management infrastructure that makes that possible, with software risk as the immediate priority.
The RoleWe are hiring a Design, Process, and Software Quality Risk Specialist to help own Axoft’s organizational risk management system across product design, development processes, and software. The immediate priority will be software risk, but the role is intended to support risk management more broadly across the organization as our device and quality system mature.
The ideal candidate has hands-on experience with FMEA or structured risk assessment from any regulated industry, some grounding in quality systems, and enough software literacy to engage credibly with engineers. If you have a cybersecurity engineering background and are looking to apply it to medical device safety, this role is a natural transition—we will teach you the medical device regulatory framework, and your security expertise will be immediately valuable as we establish our secure product development framework.
What You Will Own-
Design risk assessments (dFMEA)
-
Process risk assessments (pFMEA)
-
Software Risk Assessment (SRA)
-
Cybersecurity Risk Analysis (CRA)
-
Software QMS management. Track and manage changes to software requirements and design documents.
-
Phase review coordination.
-
Cybersecurity threat modeling.
-
Software complaint management.
-
Triage anomalies for safety and cybersecurity impact, drive disposition decisions, and manage quality remediation of serious issues.
-
Maintain audit-ready quality records and support regulatory inspections and internal audits of the product development process.
-
Software Complaint management: Triage anomalies for safety and cybersecurity impact, drive disposition decisions, and manage quality remediation of serious issues
-
Maintain audit-ready quality records and support regulatory inspections and internal audits of the product development process
-
2-4 years of direct experience conducting FMEA or another structured risk assessment methodology in medical devices, aerospace, automotive, industrial, or another regulated industry where you were responsible for identifying failure modes, evaluating severity and probability, and defining controls.
-
Practical experience managing elements of a formal QMS: document control, change management, audit preparation, supplier qualification, nonconformance or CAPA handling; industry does not matter as long as you have worked inside a real quality system rather than just alongside one.
-
Software literacy sufficient to read a requirements document, understand a system architecture diagram, and evaluate whether a risk control measure is implemented and tested appropriately; this can come from engineering experience, a technical degree, or a background in DevSecOps or security engineering.
-
Familiarity with ISO 14971 or a closely analogous risk management framework; you understand the structure of hazard analysis and how risk control measures are documented and verified.
-
Strong written communication; you can produce clear, specific, well-reasoned risk and quality documentation that stands up to regulatory scrutiny.
-
Familiarity with ISO 13485 quality management systems and FDA QMSR.
-
Experience withIEC 62304medical device software lifecycle processes: software safety classification, required documentation by class, and how development and verification activities trace to risk controls
-
Experience withAAMI SW96,IEC 81001-5-1, or cybersecurity risk management in another regulated context
-
Familiarity with CVSS or other methods of scoring security vulnerabilities.
-
Experience in Threat Modeling using STRIDE
For a software-driven implantable device, the quality system and the risk management file are not bureaucratic overhead—they are the engineering artifacts that determine what gets built, what gets tested, and what the FDA will accept as evidence that the product is safe. The person in this role is directly responsible for the integrity of that record.
Your risk assessments will drive requirements, and you will work closely with smart people on a small team. Your QMS management will determine what goes into the design history file that supports our regulatory submissions. The decisions you make will affect whether the product reaches patients, and whether it does so safely.
If you want risk and quality work that has direct, traceable consequences—this is it.
About Socket
Sourced by ZipRecruiter
Industry
Network security
Company size
1 - 10 Employees
Headquarters location
San Francisco, CA, US