1

It Risk Management Jobs in Massachusetts (NOW HIRING)

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

IT Risk & Compliance Analyst

Andover, MA · On-site +1

$95K - $95K/yr

This position reports to the Manager, IT Risk & Compliance. This role is remote and may be based anywhere within the United States. Primary Job Duties and Responsibilities * Coordinate IT compliance, ...

next page

Showing results 1-20

It Risk Management information

See Massachusetts salary details

$56.2K

$121.8K

$185.7K

How much do it risk management jobs pay per year?

As of Aug 7, 2026, the average yearly pay for it risk management in Massachusetts is $121,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,300.00 and $140,900.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an IT risk management professional, and why are they important?

To thrive in IT Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, typically supported by a degree in information technology, cybersecurity, or a related field. Familiarity with risk management tools (such as RSA Archer or MetricStream), knowledge of ISO 27001, and certifications like CISSP or CISM are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets, ensuring compliance, and enabling informed decision-making regarding technology risks.

What are some common challenges faced by IT risk management professionals, and how can they effectively address them?

IT Risk Management professionals often encounter challenges such as rapidly evolving cyber threats, balancing compliance with operational efficiency, and communicating technical risks to non-technical stakeholders. Staying updated with the latest security trends and regulations is essential for effective risk assessment. Building strong cross-departmental relationships can help ensure that risk mitigation strategies are both practical and well-understood across the organization. Continuous learning and leveraging risk management frameworks, like NIST or ISO 27001, can also provide a solid foundation for addressing these challenges.

What is the difference between It Risk Management vs Cybersecurity Analyst?

AspectIt Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk assessment, compliance, and mitigation strategies across IT systemsFocus on monitoring, analyzing, and responding to security threats
Employer & Industry UsageUsed in organizations prioritizing risk management and complianceUsed in security operations centers and cybersecurity teams

While both roles involve IT security, It Risk Management emphasizes assessing and mitigating risks across IT systems, whereas Cybersecurity Analysts focus on detecting and responding to security threats. Understanding these differences helps organizations assign the right roles for their security needs.

What does an IT risk management do?

An IT risk management professional identifies, assesses, and prioritizes potential technology-related threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, ensuring data security and compliance with industry standards. This role often involves using risk assessment tools and maintaining awareness of emerging cybersecurity threats.

What is IT risk management?

IT Risk Management is the process of identifying, assessing, and mitigating risks related to information technology systems and data within an organization. This discipline aims to protect information assets from threats such as cyberattacks, data breaches, and system failures by implementing security controls and policies. Effective IT Risk Management helps organizations comply with regulations, minimize financial losses, and ensure business continuity. Professionals in this field continuously monitor and update risk strategies to adapt to evolving technological threats.

What are careers in it risk management?

Careers in IT risk management involve identifying, assessing, and mitigating technology-related security threats to protect organizational data and systems. Roles include IT risk analyst, cybersecurity manager, and compliance officer, often requiring knowledge of security frameworks, risk assessment tools, and relevant certifications like CISSP or CISM.
What are popular job titles related to It Risk Management jobs in Massachusetts? For It Risk Management jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching It Risk Management jobs in Massachusetts look for? The top searched job categories for It Risk Management jobs in Massachusetts are:
Infographic showing various It Risk Management job openings in Massachusetts as of August 2026, with employment types broken down into 80% Full Time, 15% Part Time, 1% Temporary, and 4% Contract. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $121,833 per year, or $58.6 per hour.

Director, Technology Risk

Geode Capital Management

Boston, MA • On-site

Full-time

Re-posted 3 days ago


Job description

Reporting to the Head of Risk, the Director of Technology Risk is responsible for technology risk management across the organization. This role involves identifying, assessing, monitoring, managing, mitigating, and reporting of relevant risks in a structured, coordinated, and consistent manner.

The Director of Technology Risk will help design, develop, refine, and implement risk management policies, procedures, and strategies to protect the organization and support Geode’s business objectives, strategy, and overall success.

This is a hybrid work environment opportunity located in Boston, Massachusetts with a weekly office schedule of Tuesdays, Wednesdays and Thursdays and remote work availability on Mondays and Fridays.


Primary Responsibilities:

  • Assist with design and lead the implementation of technology risk focused policies & procedures, including the company’s risk assessment framework as well as technology focused risk and control assessments.
  • Design, operationalize, and lead highly effective technology risk assessments and scenario analyses to evaluate the impact of identified risks.
  • Measure adherence to the company’s risk framework & industry standard IT control frameworks (e.g. COSO, COBIT, NIST) through periodic reporting to Senior Management & the Risk Oversight Committee.
  • Implement data and metrics-based analysis to help proactively monitor and report on technology risks through use of Key Risk Indicators (‘KRIs’).
  • Evolve Geode’s use of Governance, Risk, & Compliance (‘GRC’) tool, including adoption of IT risk management, business continuity & disaster recovery modules.
  • Help establish and maintain a risk taxonomy, technology controls inventory, and IT risk assessment related data within the GRC tool.
  • Partner with Technology & Information Security to identify control gaps and implement key controls for the Technology organization. Assist with remediation of errors and incidents.
  • Participate in strategic technology related initiatives, including IT architecture, systems implementation, cloud computing, data strategy & governance, artificial intelligence, etc. and advise on technology risk best practices.
  • Contribute to the development of the company’s Data Governance Strategy and assist with implementation of data governance procedures and controls.
  • Co-lead initial risk assessment and on-going due diligence of Geode’s key technology vendors to identify and assess any risks that may directly or indirectly impact the company.
  • Develop and implement crisis management plans to respond to emergencies and significant business disruptions, including restoration of data and systems.

Skills You Bring:

  • Minimum of 10+ years of professional experience in technology risk, information security, or IT audit, preferably with experience in the asset management industry.
  • Bachelor's degree (or above) preferably in computer science or related field.
  • IT risk, security, or auditing related certifications are preferred (e.g. CRISC, CISSP, CISM, CISA, etc.)
  • Mastery of IT risk management practices, regulatory requirements, IT Risk frameworks (e.g., NIST CSF, NIST RMF, COBIT, ISO, CSC, etc.), and the software development lifecycle (SDLC).
  • Knowledge of a cloud-services environment and associated best practices.
  • Proven success leveraging technology, data analytics, and other advanced techniques to deliver risk management best practices.
  • Ability to leverage and analyze data to inform critical decisions and make recommendations.
  • Excellent communication skills, both written and verbal with an ability to effectively interact and influence at all levels.
  • Strong relationship building, organization, and critical thinking skills.
  • Proficient time management skills with the ability to multi-task and meet deadlines.

Company Overview:

Founded in 2001, Geode is headquartered in Boston’s financial district, the center of one of the world’s most vibrant finance and technology hubs and employs approximately 170 employees.

Geode is an institutional asset manager providing core beta exposures across a range of equity and niche asset classes, with over $1 trillion in AUM as of September 30, 2024. With a robust infrastructure and experienced investment professionals, Geode offers the scale of a large asset management firm with the benefits of a smaller organization.
Geode is proud to be an equal opportunity employer and support a diversified work environment. Learn more about Geode at www.geodecapital.com/careers.