They must understand threats and risk mitigations, perform cyber risk assessments at the ... Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that ...
They must understand threats and risk mitigations, perform cyber risk assessments at the ... Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that ...
Analyze provided documentation: network diagrams, risk assessments, audit reports, penetration test results, and security controls inventories. Conduct interviews with key personnel (security, IT ...
Analyze provided documentation: network diagrams, risk assessments, audit reports, penetration test results, and security controls inventories. Conduct interviews with key personnel (security, IT ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate
Boston, MA · On-site
$77K - $202K/yr
... Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus ... assessments to enhance internal controls - Conducting compliance audits and reviews to confirm ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate
Boston, MA · On-site
$77K - $202K/yr
... Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus ... assessments to enhance internal controls - Conducting compliance audits and reviews to confirm ...
... risk, vulnerability, and security impact assessments Experience maintaining RMF artifacts (SSP, POA&Ms, SARs, control documentation) Ability to assess and document security impacts of system changes ...
... risk, vulnerability, and security impact assessments Experience maintaining RMF artifacts (SSP, POA&Ms, SARs, control documentation) Ability to assess and document security impacts of system changes ...
They must understand threats and risk mitigations, perform cyber risk assessments at the ... Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that ...
They must understand threats and risk mitigations, perform cyber risk assessments at the ... Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that ...
Analyze provided documentation: network diagrams, risk assessments, audit reports, penetration test results, and security controls inventories. Conduct interviews with key personnel (security, IT ...
Analyze provided documentation: network diagrams, risk assessments, audit reports, penetration test results, and security controls inventories. Conduct interviews with key personnel (security, IT ...
The candidate should be able to assess blockchain and digital asset risk in a practical way, including tokenization, custody, wallet security, Hardware Security Modules (HSMs), transaction signing ...
The candidate should be able to assess blockchain and digital asset risk in a practical way, including tokenization, custody, wallet security, Hardware Security Modules (HSMs), transaction signing ...
The candidate should be able to assess blockchain and digital asset risk in a practical way, including tokenization, custody, wallet security, Hardware Security Modules (HSMs), transaction signing ...
The candidate should be able to assess blockchain and digital asset risk in a practical way, including tokenization, custody, wallet security, Hardware Security Modules (HSMs), transaction signing ...
Minimum 3 years of experience Enterprise IT security risk assessments and related frameworks (e.g., ISO 27000 series, NIST 800 Series, COBIT, IT General Controls, etc.) * Bachelor's degree or ...
New
Minimum 3 years of experience Enterprise IT security risk assessments and related frameworks (e.g., ISO 27000 series, NIST 800 Series, COBIT, IT General Controls, etc.) * Bachelor's degree or ...
New
Minimum 3 years of experience Enterprise IT security risk assessments and related frameworks (e.g., ISO 27000 series, NIST 800 Series, COBIT, IT General Controls, etc.) * Bachelor's degree or ...
New
Minimum 3 years of experience Enterprise IT security risk assessments and related frameworks (e.g., ISO 27000 series, NIST 800 Series, COBIT, IT General Controls, etc.) * Bachelor's degree or ...
New
These teams work continuously to engage and assess member firm and market risk. * Intelligence ... Deep understanding of securities markets, broker-dealer operations, and regulatory frameworks
These teams work continuously to engage and assess member firm and market risk. * Intelligence ... Deep understanding of securities markets, broker-dealer operations, and regulatory frameworks
Principal Technician (Cyber Security) for NATO with security clearance
Norfolk, MA · On-site
$65 - $100/hr
Applying and maintaining security measures set by policy and local risk assessment * Working access controls for firewalls and endpoint security solutions * Running routine vulnerability assessments ...
Principal Technician (Cyber Security) for NATO with security clearance
Norfolk, MA · On-site
$65 - $100/hr
Applying and maintaining security measures set by policy and local risk assessment * Working access controls for firewalls and endpoint security solutions * Running routine vulnerability assessments ...
Information Systems Security Manager with Security Clearance
Quincy, MA · On-site
$164K - $194K/yr
Conduct security risk assessments, vulnerability assessments, and audits to identify and mitigate threats. * Recommend and implement security solutions, such as IDS/IPS, encryption protocols, and ...
New
Information Systems Security Manager with Security Clearance
Quincy, MA · On-site
$164K - $194K/yr
Conduct security risk assessments, vulnerability assessments, and audits to identify and mitigate threats. * Recommend and implement security solutions, such as IDS/IPS, encryption protocols, and ...
New
Cloud Security Engineer
Waltham, MA · On-site
Additionally, the Cloud Security Engineer assists in the development of cyber security requirements, conducts security risk assessments, evaluates security services and technologies, and reviews and ...
Cloud Security Engineer
Waltham, MA · On-site
Additionally, the Cloud Security Engineer assists in the development of cyber security requirements, conducts security risk assessments, evaluates security services and technologies, and reviews and ...
Cyber Security Technician (Endpoint, Firewall and Vulnerability) for NATO with security clearance
Norfolk, MA · On-site
$70 - $100/hr
Applying and maintaining security measures set by policy and local risk assessment * Working access controls for firewalls and endpoint security solutions * Running routine vulnerability assessments ...
Cyber Security Technician (Endpoint, Firewall and Vulnerability) for NATO with security clearance
Norfolk, MA · On-site
$70 - $100/hr
Applying and maintaining security measures set by policy and local risk assessment * Working access controls for firewalls and endpoint security solutions * Running routine vulnerability assessments ...
Partner in the development, implementation, and ongoing management of scalable security control frameworks, policies, standards, and security awareness programs, third-party risk assessment, SDLC ...
Partner in the development, implementation, and ongoing management of scalable security control frameworks, policies, standards, and security awareness programs, third-party risk assessment, SDLC ...
Insider Risk Investigator
Boston, MA · On-site
$245K - $305K/yr
The Insider Risk Team works cross-functionally to deter, identify, investigate and mitigate risks ... Provide rapid-turnaround security assessments to support business operations * Support education ...
Insider Risk Investigator
Boston, MA · On-site
$245K - $305K/yr
The Insider Risk Team works cross-functionally to deter, identify, investigate and mitigate risks ... Provide rapid-turnaround security assessments to support business operations * Support education ...
Information Systems Security Manager
Quincy, MA · On-site
$164K - $194K/yr
Conduct security risk assessments, vulnerability assessments, and audits to identify and mitigate threats. * Recommend and implement security solutions, such as IDS/IPS, encryption protocols, and ...
New
Information Systems Security Manager
Quincy, MA · On-site
$164K - $194K/yr
Conduct security risk assessments, vulnerability assessments, and audits to identify and mitigate threats. * Recommend and implement security solutions, such as IDS/IPS, encryption protocols, and ...
New
Fractional CISO Consultant
Boston, MA · On-site
Experience conducting security due diligence and risk assessments for acquisitions. * Strong communication skills with the ability to train and educate stakeholders on compliance and risk management.
Fractional CISO Consultant
Boston, MA · On-site
Experience conducting security due diligence and risk assessments for acquisitions. * Strong communication skills with the ability to train and educate stakeholders on compliance and risk management.
Security Guardian -VP
$120K - $217K/yr
... security risk through deep engagement with product teams, rigorous architecture and application ... Conduct hands-on security assessments at the application, platform, and system levels using threat ...
Security Guardian -VP
$120K - $217K/yr
... security risk through deep engagement with product teams, rigorous architecture and application ... Conduct hands-on security assessments at the application, platform, and system levels using threat ...
Freelance Security Risk Assessment information
See Boston, MA salary details
$25.56 is the 25th percentile. Wages below this are outliers.
$16.19 - $27.78
31% of jobs
The median wage is $34.92 / hr.
$27.78 - $39.36
31% of jobs
$39.36 - $50.95
4% of jobs
$61.09 is the 75th percentile. Wages above this are outliers.
$50.95 - $62.53
10% of jobs
$62.53 - $74.12
9% of jobs
$74.12 - $85.71
5% of jobs
$85.71 - $97.29
0% of jobs
$97.29 - $108.88
8% of jobs
$108.88 - $120.46
0% of jobs
$120.46 - $132.05
0% of jobs
$132.05 - $143.63
1% of jobs
$16
$51
$143
How much do freelance security risk assessment jobs pay per hour?
What is the difference between Freelance Security Risk Assessment vs Security Consultant?
| Aspect | Freelance Security Risk Assessment | Security Consultant |
|---|---|---|
| Credentials | Certifications like CISSP, CISA, or CEH often required | Similar certifications, often with additional experience requirements |
| Work Environment | Independent, project-based, often remote or on-site at client locations | Typically employed by firms or consulting agencies, may work on multiple projects |
| Industry Usage | Used by organizations seeking independent risk assessments | Engaged for broader security strategy, policy development, and consulting |
While both roles involve assessing security risks, Freelance Security Risk Assessments focus on independent, project-specific evaluations, whereas Security Consultants often provide ongoing security advice and strategy within organizations or consulting firms.
What are the most commonly searched types of Security Risk Assessment jobs in Boston, MA?
The most popular types of Security Risk Assessment jobs in Boston, MA are:
What are popular job titles related to Freelance Security Risk Assessment jobs in Boston, MA?
For Freelance Security Risk Assessment jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Freelance Security Risk Assessment jobs in Boston, MA look for?
The top searched job categories for Freelance Security Risk Assessment jobs in Boston, MA are:
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 5 days ago
Job description
Who We Are Looking For
TheAssistant Vice President, Business Information Security Officer (BISO)provides cyber risk management oversight to lines of business and legal entities within State Street, sitting within the first line of defense. The AVP - BISO integrates into small team focused on providing cyber advisory services, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business's enhanced decision-making framework.
BISO roles and responsibilities span multiple domains, including Information Security and Risk Management, Cyber Incident and Response Management, Cyber Controls Analysis, and Cyber Reporting.
The Non-Technical Dimension: Trusted Advisor & Change Agent
The AVP - BISO is a change agent and thought leader. They must build trust through information and transparency with senior executives, be able to present to the highest levels of leadership, with the appropriate blend of technical and business detail. As a critical partner to senior business leaders in the first line of defense, the incumbent must be skilled atinfluencing changeto lead teams to further adopt cyber controls while reducing overall residual risk to their businesses.
The Technical Dimension
This role requires a strong technical background and the ability to understand emerging technologies, their purpose, security requirements, and benefits to a large financial firm. The AVP is a strong cyber controls analyst who can correlate the firm's cyber risk taxonomy to applicable business processes to conclude on theresidual cyber risksaligned to business functions and critical business services, with practitioner-level depth in at least two focus areas. They must understand threats and risk mitigations, perform cyber risk assessments at the application, platform, and system levels, and recommend solutions that protect the bank and strengthen its cyber resiliency and incident-response preparedness.
Why this role is important to us
Global Cybersecurity (GCS) manages cyber risk across State Street's business entities by delivering timely, actionable insights that enable informed decision-making and strengthen the firm's cyber risk culture. Within GCS, the Business Information Security Officer (BISO) function is the trusted advisor that embeds security within the business, serving as the conduit between GCS and the business units - providing guidance on policy, standard, and control compliance, and promoting cyber awareness across the organization.
What You Will Be Responsible For
Partner with senior business and technology leaders through timely data delivery to enable informed decision-making, prioritization, and risk-based trade-offs.
Oversee and actively manage risks in line with risk appetite through continuous business unit engagement, escalating open risk items to aligned business leadership.
Collaborate with key stakeholders to identify information assets and assess the protection needs requirements for the entire line of business and legal entity.
Perform cyber risk assessments at the application / platform / system levels to identify vulnerabilities and potential threats, analyze impacts to the bank, and determine protections required via GCS standards.
Represent the global cybersecurity organization as a member of business control committees, risk committees, and specialized forums.
Prepare and deliver executive-ready presentations and briefings on protection-needs outcomes, threat models, and control results to mid- and senior-level leadership.
Report significant changes in information security risk to the appropriate level of management on both a periodic and an event-driven basis.
Technical Judgment & Knowledge
Aligned to the GCS BISO cyber technical skills model, the AVP should demonstrate practitioner-level depth across at least two of the domains below and be able to answer probing questions and coach others. Assess each area against the proficiency scale at the end of this document.
Core Technologies
Cloud & modern platform security (Azure, AWS, or cloud principles; hybrid and multi-cloud)
Networking and network security
Security architecture fundamentals and control design effectiveness
Operating systems
Supporting Processes
Cryptography, encryption, and key management
Patching and vulnerability management
Cyber resiliency, incident response, and recovery (tabletop exercises, playbooks, after-action reviews)
Data classification and data protection
Secure communication protocols
Identity and Access Management (IAM) / Privileged Access concepts
Secure SDLC, secure engineering, and DevSecOps
Third-party & supply chain security (vendor assessments, shared responsibility models)
Security operations & monitoring (SOC / SIEM awareness, KPIs, posture reporting)
Emerging Technology & AI
The BISO function upskills talent to manage current and emerging cyber risk, including evolving frontier-model AI risk. Candidates should be able to:
Articulate the risks associated with Generative AI, and the differences between Generative AI, Agentic AI, and traditional Machine Learning.
Demonstrate an understanding of model risk, frontier models, and the risk management around them.
Risk Management
Understands how to measure risk, discuss trade-offs, and support risk-acceptance decisions in line with risk appetite.
Familiarity with recognized standards and frameworks (e.g., NIST CSF 2.0, NIST SP 800-53, ISO 27001).
Understanding of issue management, triage, remediation tracking, and residual-risk scoring.
What We Value
These skills will help you succeed in this role:
Establish key relationships with business risk executives, third-party management, client relations, global technology services, second and third lines of defense, and internal regulatory teams.
Translate technical risk into clear, actionable business terms for both technical and non-technical audiences.
Experience working with dashboards and data-mining tools to build cyber risk profiles.
Demonstrates continuous learning; stays current on emerging threats, technologies, and trends, and can explain how they keep up to date.
Knows when to admit knowledge gaps and can describe how they would go about obtaining the needed information.
Education & Preferred Qualifications
Bachelor's degree in computer science, or a related technical field - or equivalent work-aligned experience.
CISSP or CISM strongly preferred.CRISC, CISA, SSCP, CCSP, CEH, or GIAC certifications highly valued.
Eight or more years of progressive cybersecurity and risk leadership, including governance, risk, and compliance preferably within regulated financial services. Technical cybersecurity background i.e. SOC, operations, networking, engineering, etc. preferred.
Demonstrated ability to influence executives, translate technical risk into business language, and operate across audit, regulatory, and third-party risk domains. Strong analytical and strong interpersonal skills including active listening, dependability, and teamwork.
Salary Range:
$90,000 - $157,500 AnnualThe range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.
About State StreetAcross the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
About State Street Global Advisors
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
1,001 - 5,000 Employees
Headquarters location
Boston, MA, US
Year founded
1978