1

Information Risk Jobs in Massachusetts (NOW HIRING)

Knowledge of (information) risk management related standards or frameworks such as COSO, ISO 2700x, CobiT, ISO 24762, BS 25999, NIST, ISF Standard of Good Practice and ITIL Knowledge of OWASP, SDLC ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

IT Risk & Compliance Analyst

Andover, MA · On-site +1

$95K - $95K/yr

Scope of Position The IT Risk & Compliance Analyst, as part of the Information Security organization, is responsible for supporting the execution of Watts' IT compliance, audit readiness ...

next page

Showing results 1-20

Information Risk information

See Massachusetts salary details

$32.7K

$113.4K

$186.1K

How much do information risk jobs pay per year?

As of Sep 11, 2026, the average yearly pay for information risk in Massachusetts is $113,435.00, according to ZipRecruiter salary data. Most workers in this role earn between $87,967.00 and $137,851.00 per year, depending on experience, location, and employer.

What are the most commonly searched types of Information Risk jobs in Massachusetts?

The most popular types of Information Risk jobs in Massachusetts are:

Infographic showing various Information Risk job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 70% Full Time, 24% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $113,435 per year, or $54.5 per hour.

Application Security Specialist

Cambridge, MA • On-site

Contractor

Re-posted 12 days ago


Job description

Company Description

Engineering

Job Description

Title: Application Security Specialist
Location: Cambridge, MA

Duration: 6 Months(Extendable)
Roles & Responsibilities:
Creating application security related policies & processes
    Creating RFP for selecting a service provide for application security
    Analysing RFP results and presenting to stakeholders
    Coordinate vendor product demonstrations and presentations
    Analysing application security products from various vendors
    Conducting pilot or POC with selected vendors for threat modelling, architecture reviews , code scanning and penetration testing
    Collaborating with cross functional teams and getting their buy in Managed project deadlines.
Skills:
Good mediation and facilitation skills
    Good knowledge of IT Project Management
    Experience with compliance and security requirements[AR1] related to medical devices, including data privacy.
    Knowledge of (information) risk management related standards or frameworks such as COSO, ISO 2700x, CobiT, ISO 24762, BS 25999, NIST, ISF Standard of Good Practice and ITIL
    Knowledge of OWASP, SDLC, Encryption, Identity and Access Management, data integrity measures
    capability to design application security related policies and processes deep knowledge of integration between Security and system development life cycle Experience:10+ years of working experience
    3+ years as an IT security expert
    Broad and in-depth technical, analytical and conceptual skills
    Experience in reporting to and communicating with senior level management
    Excellent written and verbal communication and presentation skills; interpersonal and collaborative skills; and the ability to communicate information risk-related concepts to technical as well as nontechnical audiences, and to audiences with a risk management profile as well as those with a less outspoken risk management profile.
    Excellent understanding and knowledge of general IT infrastructure technology, systems and management processes
Proven experience to create new processes or improve existing process Applicaiton Security Application Architecture MS-Office
Understanding of OWASP top 10 and SANS 25
Professional information security certification, such as CISSP, CISM or ISO 27001 auditor / practitioner is preferred.
Professional (information system) risk or audit certification such as CIA, CISA or CRISC is preferred.

Qualifications

Undergrad in Computer Science or relevant is required: Masters degree is preferred

Additional Information

All your information will be kept confidential according to EEO guidelines.