1

Governance Risk Compliance Jobs in Boston, MA (NOW HIRING)

The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization. WHOOP is seeking a ...

The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...

Third-Party Risk Consultant

Boston, MA · On-site

$86K - $113K/yr

Third-Party Risk Consultant, ETX Governance, Risk & Compliance Team Full-Time, Springfield/Boston The Opportunity As a Third-Party Risk Consultant, you will play a crucial role in implementing the ...

IT Risk & Compliance Analyst

Andover, MA · On-site +1

$95K - $95K/yr

Three to five years of experience in IT compliance, IT audit, internal audit, risk management, controls, governance, risk and compliance (GRC), or information security compliance. * Working knowledge ...

next page

Showing results 1-20

Governance Risk Compliance information

See Boston, MA salary details

$34.2K

$74.7K

$121.7K

How much do governance risk compliance jobs pay per year?

As of Aug 7, 2026, the average yearly pay for governance risk compliance in Boston, MA is $74,670.00, according to ZipRecruiter salary data. Most workers in this role earn between $53,200.00 and $94,000.00 per year, depending on experience, location, and employer.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.
What are the most commonly searched types of Governance Risk Compliance jobs in Boston, MA? The most popular types of Governance Risk Compliance jobs in Boston, MA are:
What are popular job titles related to Governance Risk Compliance jobs in Boston, MA? For Governance Risk Compliance jobs in Boston, MA, the most frequently searched job titles are:
What cities near Boston, MA are hiring for Governance Risk Compliance jobs? Cities near Boston, MA with the most Governance Risk Compliance job openings:
Infographic showing various Governance Risk Compliance job openings in Boston, MA as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $74,670 per year, or $35.9 per hour.

Sr. Director, Governance, Risk & Compliance

Alnylam Pharmaceuticals

Cambridge, MA • On-site

$229K - $310K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 14 days ago


Job description

Overview
Alnylam is pioneering RNA interference (RNAi) therapeutics and scaling for impact to millions of patients. Our Cybersecurity organization is evolving to match that ambition, and we are seeking a Senior Director of Governance, Risk & Compliance (GRC) to define, lead, and mature the governance, risk management, and compliance capabilities that protect our science, enable our business, and meet global regulatory obligations.
Reporting directly to the VP/CISO, this leader will own Alnylam's enterprise cyber risk management, regulatory compliance, and security governance programs. The Senior Director will be accountable for establishing a scalable, risk-driven GRC operating model aligned with NIST CSF v2.0, Alnylam' enterprise risk management (ERM) program and applicable biotech and pharmaceutical regulations. This role balances strategic leadership with hands-on execution, partnering across the business and IT functions
This is a hybrid role primarily based in our Cambridge, MA office.
Responsibilities
  • Lead and evolve Alnylam's enterprise GRC program.
  • Define and execute a multi-year cyber risk and compliance maturity roadmap aligned to NIST CSF v2.0, enterprise risk management (ERM), regulatory requirements, and business priorities.
  • Own the cyber risk management lifecycle, including risk identification, assessment, prioritization, treatment, and executive-level reporting.
  • Establish and maintain security governance frameworks, policies, standards, and exception management processes.
  • Provide cybersecurity governance and risk oversight for GxP-regulated systems, ensuring alignment with data integrity, validation expectations, IT SDLC practices, and quality requirements across research, clinical, manufacturing, and quality operations.
  • Ensure security policies, standards, and risk decisions appropriately account for validated system constraints, change control requirements, and inspection readiness.
  • Oversee regulatory and compliance activities related to HIPAA, SOX, FDA-adjacent biotech regulations, computer system validation (CSV), privacy requirements, and emerging regulations (e.g., NIS2).
  • Lead internal and external audits, inspections, and assurance activities, including management of findings, remediation plans, and executive reporting.
  • Own and mature the third-party risk management (TPRM) program.
  • Embed cybersecurity risk considerations into system lifecycle and validation activities.
  • Define and track risk-based metrics and key risk indicators (KRIs) focused on outcomes, maturity, and remediation effectiveness rather than control volume.
  • Build and lead a high-performing GRC organization, fostering a culture of accountability, rigor, and strong cross-functional partnership.
  • Deliver clear, actionable executive- and board-level reporting

Qualifications
  • Bachelor's degree in a relevant field; advanced degree (MBA, Master's, JD) preferred.
  • 15+ years of progressive experience in cybersecurity, risk management, compliance, or audit.
  • 10+ years of leadership experience building and leading GRC, risk, or compliance teams.
  • Deep knowledge of NIST CSF, NIST 800-53, ISO 27001, and ERM frameworks.
  • Experience operating GRC programs in regulated environments such as biotech, pharma, healthcare, or life sciences.
  • Strong ability to translate complex risk topics for executive and board-level audiences.
  • Industry certifications such as CISSP, CISM, CRISC, or CISA strongly preferred.
  • Proven ability to influence across Security, IT, Legal, Audit, and business stakeholders.

#LI-MH1 #LI-Hybrid
U.S. Pay Range
$229,500.00 - $310,500.00
The pay range reflects the full-time base salary range we expect to pay for this role at the time of posting. Base pay will be determined based on a number of factors including, but not limited to, relevant experience, skills, and education. This role is eligible for an annual short-term incentive award (e.g., bonus or sales incentive) and an annual long-term incentive award (e.g., equity).
Alnylam's robust Total Rewards package is designed to support your overall health and well-being. We offer comprehensive benefits including medical, dental, and vision coverage, life and disability insurance, a lifestyle reimbursement program, flexible spending and health savings accounts and a 401(k)with a generous company match. Eligible employees enjoy paid time off, wellness days, holidays, and two company-wide recharge breaks. We also offer generous family resources and leave. Our commitment to your well-being reflects our belief that caring for our people fuels the impact we create together.
Learn more about these and additional benefits offered by Alnylam by visiting the Benefits section of the Careers website: https://www.alnylam.com/careers
About Alnylam
We are the leader in RNAi therapeutics - a revolutionary approach with the potential to transform the lives of people with rare and common diseases. Built on Nobel Prize-winning science, Alnylam has delivered the breakthroughs that made RNAi therapeutics possible and are just at the beginning of what's possible. Our deep pipeline, late-stage programs, and bold vision reflect our core values: fierce innovation, passion for excellence, purposeful urgency, open culture and commitment to people. We're proud to be a globally recognized top employer, where an authentic, inclusive culture and breakthrough thinking fuel one another.
At Alnylam, we commit to an inclusive recruitment process and equal employment opportunity. Qualified applicants will receive consideration for employment without regard to their sex, gender or gender identity, sexual orientation, race, color, ethnicity, national origin, ancestry, citizenship, religion, creed, physical or mental disability, pregnancy status or related conditions, genetic information, veteran or military status, marital or familial status, political affiliation, age, or any other factor protected by federal, state, or local law. Alnylam is an E-Verify Employer.