1

Governance Risk Compliance Jobs in Boston, MA (NOW HIRING)

Experience with governance, risk, and compliance (GRC) processes. Core Skills Security Governance | Cybersecurity Documentation | Process Analysis | Technical Writing | NIST CSF | CIS Controls | ISO ...

Showing results 41-60

Governance Risk Compliance information

See Boston, MA salary details

$34.2K

$74.7K

$121.7K

How much do governance risk compliance jobs pay per year?

As of Sep 3, 2026, the average yearly pay for governance risk compliance in Boston, MA is $74,670.00, according to ZipRecruiter salary data. Most workers in this role earn between $53,200.00 and $94,000.00 per year, depending on experience, location, and employer.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What are the most commonly searched types of Governance Risk Compliance jobs in Boston, MA?

The most popular types of Governance Risk Compliance jobs in Boston, MA are:

What are popular job titles related to Governance Risk Compliance jobs in Boston, MA?

For Governance Risk Compliance jobs in Boston, MA, the most frequently searched job titles are:

What job categories do people searching Governance Risk Compliance jobs in Boston, MA look for?

The top searched job categories for Governance Risk Compliance jobs in Boston, MA are:

What cities near Boston, MA are hiring for Governance Risk Compliance jobs?

Cities near Boston, MA with the most Governance Risk Compliance job openings:

Infographic showing various Governance Risk Compliance job openings in Boston, MA as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 12% Part Time, and 5% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $74,670 per year, or $35.9 per hour.

Director, Technology Risk

Geode Capital Management

Boston, MA • On-site

Full-time

Re-posted 23 hours ago


Job description

Reporting to the Head of Risk, the Director of Technology Risk is responsible for technology risk management across the organization. This role involves identifying, assessing, monitoring, managing, mitigating, and reporting of relevant risks in a structured, coordinated, and consistent manner. 

The Director of Technology Risk will help design, develop, refine, and implement risk management policies, procedures, and strategies to protect the organization and support Geode’s business objectives, strategy, and overall success. 

This is a hybrid work environment opportunity located in Boston, Massachusetts with a weekly office schedule of Tuesdays, Wednesdays and Thursdays and remote work availability on Mondays and Fridays.


 
Primary Responsibilities:

  • Assist with design and lead the implementation of technology risk focused policies & procedures, including the company’s risk assessment framework as well as technology focused risk and control assessments.
  • Design, operationalize, and lead highly effective technology risk assessments and scenario analyses to evaluate the impact of identified risks. 
  • Measure adherence to the company’s risk framework & industry standard IT control frameworks (e.g. COSO, COBIT, NIST) through periodic reporting to Senior Management & the Risk Oversight Committee. 
  • Implement data and metrics-based analysis to help proactively monitor and report on technology risks through use of Key Risk Indicators (‘KRIs’). 
  • Evolve Geode’s use of Governance, Risk, & Compliance (‘GRC’) tool, including adoption of IT risk management, business continuity & disaster recovery modules. 
  • Help establish and maintain a risk taxonomy, technology controls inventory, and IT risk assessment related data within the GRC tool. 
  • Partner with Technology & Information Security to identify control gaps and implement key controls for the Technology organization. Assist with remediation of errors and incidents. 
  • Participate in strategic technology related initiatives, including IT architecture, systems implementation, cloud computing, data strategy & governance, artificial intelligence, etc. and advise on technology risk best practices. 
  • Contribute to the development of the company’s Data Governance Strategy and assist with implementation of data governance procedures and controls. 
  • Co-lead initial risk assessment and on-going due diligence of Geode’s key technology vendors to identify and assess any risks that may directly or indirectly impact the company.
  • Develop and implement crisis management plans to respond to emergencies and significant business disruptions, including restoration of data and systems. 

Skills You Bring:

  • Minimum of 10+ years of professional experience in technology risk, information security, or IT audit, preferably with experience in the asset management industry.
  • Bachelor's degree (or above) preferably in computer science or related field.
  • IT risk, security, or auditing related certifications are preferred (e.g. CRISC, CISSP, CISM, CISA, etc.)
  • Mastery of IT risk management practices, regulatory requirements, IT Risk frameworks (e.g., NIST CSF, NIST RMF, COBIT, ISO, CSC, etc.), and the software development lifecycle (SDLC).
  • Knowledge of a cloud-services environment and associated best practices.
  • Proven success leveraging technology, data analytics, and other advanced techniques to deliver risk management best practices. 
  • Ability to leverage and analyze data to inform critical decisions and make recommendations.
  • Excellent communication skills, both written and verbal with an ability to effectively interact and influence at all levels.
  • Strong relationship building, organization, and critical thinking skills.
  • Proficient time management skills with the ability to multi-task and meet deadlines.

 Company Overview:

 Founded in 2001, Geode is headquartered in Boston’s financial district, the center of one of the world’s most vibrant finance and technology hubs and employs approximately 170 employees.
 

Geode is an institutional asset manager providing core beta exposures across a range of equity and niche asset classes, with over $1 trillion in AUM as of September 30, 2024. With a robust infrastructure and experienced investment professionals, Geode offers the scale of a large asset management firm with the benefits of a smaller organization.  
 
Geode is proud to be an equal opportunity employer and support a diversified work environment. Learn more about Geode at www.geodecapital.com/careers.