1

Information Risk Manager Jobs in Massachusetts (NOW HIRING)

Knowledge of (information) risk management related standards or frameworks such as COSO, ISO 2700x, CobiT, ISO 24762, BS 25999, NIST, ISF Standard of Good Practice and ITIL Knowledge of OWASP, SDLC ...

Prepare risk reports, management information, dashboards, and metrics to support business management and governance committees. * Provide guidance and assistance to process owners and business ...

The Team Leader, Risk Management (TLRM) works with the Commercial Lines teams to assist our larger ... For further information, please review the Know Your Rights notice from the Department of Labor.

Risk Management Specialist

Boston, MA ยท On-site

$78K - $113K/yr

The Risk Manager is responsible for the overall management of potential risks and liabilities ... Ability to collect event information and organize into a coherent narrative. Basic command of data ...

Data Validation Risk - Manager

Boston, MA ยท On-site

$99K - $232K/yr

Responsibilities - Leading data validation and risk management initiatives to support client ... Accounting, Engineering, Data Processing/Analytics/Science, Computer and Information Science ...

EHS Risk Manager, FTR

North Reading, MA ยท On-site

$85K - $115K/yr

Perform safety risk assessments and develop hazard mitigation strategies for contractor and vendor ... more information. If the country/region you're applying in isn't listed, please contact your ...

Showing results 21-40

Information Risk Manager information

See Massachusetts salary details

$56.2K

$121.8K

$185.7K

How much do information risk manager jobs pay per year?

As of Sep 11, 2026, the average yearly pay for information risk manager in Massachusetts is $121,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,300.00 and $140,900.00 per year, depending on experience, location, and employer.

What does an information risk manager do?

An Information Risk Manager is responsible for identifying, assessing, and mitigating risks related to an organization's information assets. They develop and implement risk management policies, conduct regular risk assessments, and ensure compliance with relevant standards and regulations. Their role often involves collaborating with IT, security, and business teams to protect sensitive data and support business continuity. By proactively managing information risks, they help organizations minimize the potential impact of security threats and data breaches.

What are the key skills and qualifications needed to thrive as an information risk manager?

To thrive as an Information Risk Manager, you need expertise in risk assessment, information security principles, and regulatory compliance, often supported by a degree in information technology or cybersecurity and relevant certifications like CISSP or CISM. Familiarity with risk management tools, governance frameworks (such as ISO 27001), and security incident management systems is typical. Strong analytical thinking, communication, and stakeholder management skills help set top performers apart. These capabilities are crucial for proactively identifying, assessing, and mitigating information risks to protect organizational assets and ensure compliance.

What are some common challenges information risk managers face when implementing new risk mitigation strategies?

Information Risk Managers often encounter resistance to change from employees and stakeholders when introducing new risk mitigation strategies. Balancing security requirements with business objectives can also be challenging, as overly restrictive controls may hinder productivity. Additionally, staying updated with evolving cyber threats and ensuring compliance with various regulatory standards requires continuous learning and adaptation. Successful Information Risk Managers proactively communicate the value of risk initiatives and foster collaboration across departments to achieve buy-in.

What is the difference between Information Risk Manager vs Cybersecurity Analyst?

AspectInformation Risk ManagerCybersecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISMCISSP, CompTIA Security+, CEH
Work EnvironmentRisk assessment, policy development, compliance managementSecurity monitoring, incident response, vulnerability assessment
Employer & IndustryFinancial, healthcare, government, large enterprisesIT firms, security service providers, corporate IT teams

The main difference is that an Information Risk Manager focuses on identifying, assessing, and managing overall information risks and compliance strategies, while a Cybersecurity Analyst primarily handles security monitoring, threat detection, and incident response. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

Sr. Risk Manager, Cyber & Technology Risk Management

Boston, MA โ€ข On-site

Brown Brothers Harriman & Co.
Finance and Insuranceย โ€ขย 1 - 5K employees

$140K - $190K/yr

Other

Posted 15 days ago


Job description

At BBH, Partnership is more than a form of ownershipโ€”itโ€™s our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for whatโ€™s next, this is the right place to build a fulfilling career.

Cyber & Technology Risk Management is an independent second-line risk function within Enterprise Risk Management (ERM). The group is aligned to the Firmโ€™s global Systems/Technology organization and provides risk oversight across a complex financial services environment.

The Senior Risk Manager will serve as a trusted second-line advisor, leading a team of cyber and technology risk professionals responsible for identifying, assessing, and helping manage cyber and technology risks that impact the Firm. The Senior Risk Manager is expected to bring broad technical knowledge with expertise in cyber risk management and related regulatory frameworks including information security, cyber resilience, data protection, and regulatory compliance across the Firm's technology environment.

This is a senior, highly visible role that partners closely with Systems/Technology management, Application and Data Owners, control owners, Compliance, Internal Audit, Line of Business leadership, and peer leaders across Cyber & Technology Risk Management and ERM to promote sound risk decisions, strong governance, and practical outcomes.

RESPONSIBILITIES

What Youโ€™ll Do Partner with technology, security, and operations teams to identify, assess, and manage cyber and technology risks. Provide independent second-line advisory and effective challenge, translating risk considerations into clear, practical guidance. Lead and/or support risk and control assessments, including cyber risk reviews, RCSAs, application risk assessments, external assurance reviews, and related governance activities. Evaluate control gaps, risk acceptances, exceptions, and remediation plans; assist stakeholders prioritize actions based on business impact, risk appetite, and regulatory expectations. Analyze new and emerging risks, including related regulatory requirements and supervisory guidance to identify risk implications and potential gaps; collaborate with control owners on control design, implementation, and measurement. Support the continued build-out of a new IT governance platform to improve integration, transparency, and execution across Cyber & Technology Risk Management programs.

QUALIFICATIONS

What Youโ€™ll Bring Bachelorโ€™s degree, equivalent work experience, specialized training in information technology, cybersecurity, risk management, audit, or related discipline. 10+ years of experience in cyber risk, technology risk, information security, IT audit, operational risk, third-party risk, or a related control function. Demonstrated experience assessing cyber risk programs, cybersecurity controls, and information security governance frameworks within a regulated financial institution or similarly regulated environment. Ability to analyze complex risk issues, balance business objectives with control expectations, and communicate practical recommendations to both technical and non-technical audiences. Strong understanding of cyber and technology risk concepts, control assessment, issue management, remediation tracking, risk acceptance, and risk reporting practices. Strong knowledge of cybersecurity regulatory requirements and industry frameworks, including NYDFS Part 500, NIST Cybersecurity Framework, ISO 27001, and other applicable cybersecurity or operational resilience standards. Familiarity with DORA, global operational resilience requirements, and other emerging cyber regulatory frameworks. Working knowledge of technology environments, including networks, operating platforms, cloud services, application security, and third-party hosted solutions. Certifications such as CISSP, CISM, and/or CRISC are a plus.

This role can be based in either our Boston or Jersey City locations and will be a hybrid role, with a minimum of three (3) days in office.

Salary Range NJ / MA: $140,000 - $190,000 base salary + annual target bonus BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck - providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being.

We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasnโ€™t followed a traditional path, includes alternative experiences, or doesnโ€™t meet every qualification or skill listed in the job description, please do go ahead and apply.

About BBH:

Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. Delivering for our clients and each other energizes us. We believe that how we do our work is just as important as what we do. We are relentless problem solvers who know our best ideas come from collective debate and development - so we are never possessive about our ideas. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice - creating success that lasts. No matter where you sit in the organization, everyone is empowered to contribute their ideas. BBHers can pick up the phone and call any colleague, and they are happy to help. Expanding your impact beyond your daily role is part of how we operate as trusted partners to one another. We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often - pushing the boundaries of innovation. As a private partnership, we are uniquely built to put clients first and create success that lasts. We believe our success starts with yours. At BBH, partnership is more than just a form of ownershipโ€”itโ€™s our approach to business and relationships. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice. Across Investor Services and

#J-18808-Ljbffr