1

Cybersecurity Risk Management Jobs in Cambridge, MA

Showing results 41-60

Cybersecurity Risk Management information

See Cambridge, MA salary details

$62.8K

$146.5K

$204.9K

How much do cybersecurity risk management jobs pay per year?

As of Aug 11, 2026, the average yearly pay for cybersecurity risk management in Cambridge, MA is $146,485.00, according to ZipRecruiter salary data. Most workers in this role earn between $122,300.00 and $165,300.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.
What job categories do people searching Cybersecurity Risk Management jobs in Cambridge, MA look for? The top searched job categories for Cybersecurity Risk Management jobs in Cambridge, MA are:
What cities near Cambridge, MA are hiring for Cybersecurity Risk Management jobs? Cities near Cambridge, MA with the most Cybersecurity Risk Management job openings:

Risk Management Framework (RMF) Subject Matter Expert (SME)

Abacus Technology

Hanscom Air Force Base, MA โ€ข Remote

$149K - $167K/yr

Other

Medical, Dental, Life, Retirement, PTO

Re-posted 2 days ago


Job description

Overview

Abacus Technology is seeking a Risk Management Framework (RMF) Subject Matter Expert (SME) to support the Wing Cyberspace Office (WCSO) in managing and executing DoD Risk Management Framework processes at Hanscom AFB.ย  This is a full-time position.

Responsibilities
  • Serve as the lead RMF Subject Matter Expert supporting the Wing Cyberspace Office (WCSO) for all systems and enclaves within the base enterprise.
  • Lead the management, implementation, and execution of the Risk Management Framework (RMF) lifecycle (Categorize, Select, Implement, Assess, Authorize, and Monitor) for supported systems.
  • Develop, maintain, and validate RMF artifacts within Enterprise Mission Assurance Support Service (eMASS) to ensure completeness, accuracy, and compliance with DoD and Air Force requirements.
  • Provide expert guidance to ISSMs, ISSOs, and system owners on ATO packages, reauthorization efforts, and continuous monitoring strategies.
  • Ensure continuous compliance with DoD, Air Force, NSA, and NIST cybersecurity policies and directives, including NIST SP 800-53 and DoDI 8510.01.
  • Conduct risk assessments and security control evaluations, recommending mitigation strategies to reduce risk to acceptable levels.
  • Review and validate Security Technical Implementation Guides (STIGs), vulnerability alerts, and cybersecurity directives for implementation across supported systems.
  • Support Authorization to Operate (ATO), Authority to Connect (ATC), and Interim Authorization (IATT) processes as required.
  • Develop and manage Plans of Action & Milestones (POA&Ms) and track remediation efforts to closure.
  • Provide direct support during cybersecurity inspections and audits (e.g., CCRI, IG, SAV), including preparation, execution, and remediation.
  • Advise on system architecture, boundary definitions, and control inheritance to improve RMF efficiency and cybersecurity posture.
  • Collaborate with network, system, and cybersecurity teams to ensure secure integration and sustainment of systems.
  • Analyze and report cybersecurity posture metrics and trends, providing recommendations for continuous improvement.
  • Mentor and provide RMF training and knowledge transfer to cybersecurity staff and stakeholders across the Wing.
Qualifications

10+ years experience in cyber security, with a strong emphasis on Risk Management Framework (RMF) within the DoD or Federal environment.ย  Bachelor's degree in a related field.ย  Additional years of experience may be substituted for degree requirements.ย  Must be Security+ certified.ย  CISSP certification preferred.ย  Extensive experience with DoD RMF processes, ATO lifecycle management, and continuous monitoring.ย  Demonstrated expertise in eMASS and RMF package development and management.ย  Strong knowledge of Air Force, DoD, and Federal cyber security directives, policies, and instructions.ย  Hands-on experience conducting security control assessments, vulnerability management, and POA&M tracking.ย  Experience supporting cyber security inspections (e.g., CCRI, IG inspections, SAVs).ย  Able to interpret and implement STIGs, security guidance, and vulnerability remediation requirements.ย  Strong ability to work independently and collaboratively, providing technical leadership across multiple stakeholders.ย  Excellent communication skills, with the ability to translate complex cyber security concepts into actionable guidance.ย  Must be a US citizen and hold a current Secret clearance.

The projected compensation range for this position is $149,000-$167,100. There are multiple factors that can impact a final salary, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (if remote or different from the stated location for this position), education and certifications as well as Federal Government Contract Labor categories. In addition, Abacus Technology offers a benefits package that includes: Health and Dental Insurance; 401(k) and Matching; Life Insurance; Short- and Long-Term Disability; Paid Time Off; Paid Holidays; and Professional Membership, Technical Training, Certification, and Education Assistance.

Applicants selected will be subject to a U.S. government security investigation and must meet eligibility requirements for access to classified information.

EOE/M/F/Vet/Disabled

Employment Type: OTHER