1

Cybersecurity Risk Management Jobs in Boston, MA

... cybersecurity, risk management, and project management processes while ensuring alignment with organizational policies, security requirements, and regulatory obligations. • Adhere to agreed project ...

Identify opportunities to apply AI-enabled solutions to compliance, cybersecurity, risk management, and project management processes while ensuring alignment with organizational policies, security ...

The ideal candidate brings deep expertise in cybersecurity strategy and risk management, a strong network within the private equity ecosystem, and a proven track record of leading high-performing ...

Why this role is important to us The Managing Director is a trusted executive partner who translates cybersecurity risk into business terms, influences enterprise decision-making, and drives a ...

Why this role is important to us The Managing Director is a trusted executive partner who translates cybersecurity risk into business terms, influences enterprise decision-making, and drives a ...

Showing results 21-40

Cybersecurity Risk Management information

See Boston, MA salary details

$61.9K

$144.4K

$202K

How much do cybersecurity risk management jobs pay per year?

As of Sep 11, 2026, the average yearly pay for cybersecurity risk management in Boston, MA is $144,432.00, according to ZipRecruiter salary data. Most workers in this role earn between $120,600.00 and $162,900.00 per year, depending on experience, location, and employer.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are popular job titles related to Cybersecurity Risk Management jobs in Boston, MA?

For Cybersecurity Risk Management jobs in Boston, MA, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management jobs in Boston, MA look for?

The top searched job categories for Cybersecurity Risk Management jobs in Boston, MA are:

What cities near Boston, MA are hiring for Cybersecurity Risk Management jobs?

Cities near Boston, MA with the most Cybersecurity Risk Management job openings:

Infographic showing various Cybersecurity Risk Management job openings in Boston, MA as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 16% Part Time, and 2% Contract. Highlights an 82% Physical, 3% Hybrid, and 15% Remote job distribution, with an average salary of $144,442 per year, or $69.4 per hour.

Design, Process, and Software Quality Risk Specialist

Cambridge, MA • On-site

Socket.dev
Network Security • 1 - 10 employees

Other

Posted 9 days ago


Key responsibilities

  • Own and conduct design risk assessments (dFMEA).

  • Manage process risk assessments (pFMEA) and software risk assessments (SRA).

  • Track and manage changes to software requirements and design documents, and support regulatory inspections and internal audits.


Job description

About Axoft

Axoft is building a new class of implantable neural interface-ultra-flexible, minimally reactive, and designed to remain functional for decades inside the human brain. Our software connects that hardware to the world: acquisition firmware, embedded configuration tools, clinical monitoring applications, and the cloud infrastructure that ties them together. Every release we ship ultimately affects a patient.

We are a small, technical team building compliant medical device systems the right way: risk-driven, Agile, and grounded in the international standards that govern product development, quality systems, and medical device software globally. We are looking for someone to help own the organizational risk management infrastructure that makes that possible, with software risk as the immediate priority.

The Role

We are hiring a Design, Process, and Software Quality Risk Specialist to help own Axoft’s organizational risk management system across product design, development processes, and software. The immediate priority will be software risk, but the role is intended to support risk management more broadly across the organization as our device and quality system mature.

The ideal candidate has hands-on experience with FMEA or structured risk assessment from any regulated industry, some grounding in quality systems, and enough software literacy to engage credibly with engineers. If you have a cybersecurity engineering background and are looking to apply it to medical device safety, this role is a natural transition—we will teach you the medical device regulatory framework, and your security expertise will be immediately valuable as we establish our secure product development framework.

What You Will Own
  • Design risk assessments (dFMEA)

  • Process risk assessments (pFMEA)

  • Software Risk Assessment (SRA)

  • Cybersecurity Risk Analysis (CRA)

Additional Responsibilities
  • Software QMS management. Track and manage changes to software requirements and design documents.

  • Phase review coordination.

  • Cybersecurity threat modeling.

  • Software complaint management.

  • Triage anomalies for safety and cybersecurity impact, drive disposition decisions, and manage quality remediation of serious issues.

  • Maintain audit-ready quality records and support regulatory inspections and internal audits of the product development process.

  • Software Complaint management: Triage anomalies for safety and cybersecurity impact, drive disposition decisions, and manage quality remediation of serious issues

  • Maintain audit-ready quality records and support regulatory inspections and internal audits of the product development process

What You Bring Required
  • 2-4 years of direct experience conducting FMEA or another structured risk assessment methodology in medical devices, aerospace, automotive, industrial, or another regulated industry where you were responsible for identifying failure modes, evaluating severity and probability, and defining controls.

  • Practical experience managing elements of a formal QMS: document control, change management, audit preparation, supplier qualification, nonconformance or CAPA handling; industry does not matter as long as you have worked inside a real quality system rather than just alongside one.

  • Software literacy sufficient to read a requirements document, understand a system architecture diagram, and evaluate whether a risk control measure is implemented and tested appropriately; this can come from engineering experience, a technical degree, or a background in DevSecOps or security engineering.

  • Familiarity with ISO 14971 or a closely analogous risk management framework; you understand the structure of hazard analysis and how risk control measures are documented and verified.

  • Strong written communication; you can produce clear, specific, well-reasoned risk and quality documentation that stands up to regulatory scrutiny.

Preferred
  • Familiarity with ISO 13485 quality management systems and FDA QMSR.

  • Experience withIEC 62304medical device software lifecycle processes: software safety classification, required documentation by class, and how development and verification activities trace to risk controls

  • Experience withAAMI SW96,IEC 81001-5-1, or cybersecurity risk management in another regulated context

  • Familiarity with CVSS or other methods of scoring security vulnerabilities.

  • Experience in Threat Modeling using STRIDE

Why This Role

For a software-driven implantable device, the quality system and the risk management file are not bureaucratic overhead—they are the engineering artifacts that determine what gets built, what gets tested, and what the FDA will accept as evidence that the product is safe. The person in this role is directly responsible for the integrity of that record.

Your risk assessments will drive requirements, and you will work closely with smart people on a small team. Your QMS management will determine what goes into the design history file that supports our regulatory submissions. The decisions you make will affect whether the product reaches patients, and whether it does so safely.

If you want risk and quality work that has direct, traceable consequences—this is it.

#J-18808-Ljbffr