1

It Risk Management Jobs in Massachusetts (NOW HIRING)

The IT Internal Auditor supports the execution of the Company's Internal Audit plan, with ... governance and risk management practices, and helps enhance the overall control environment.

The IT Internal Auditor supports the execution of the Company's Internal Audit plan, with ... governance and risk management practices, and helps enhance the overall control environment.

Senior IT Audit Manager

Waltham, MA · On-site

$130 - $175/hr

Minimum of 8 years of progressive experience in external audit, internal audit, IT compliance, IT risk management, or SOX advisory, with significant focus on IT General Controls and enterprise ...

New

Senior IT Audit Manager

Waltham, MA · On-site

$130 - $175/hr

Minimum of 8 years of progressive experience in external audit, internal audit, IT compliance, IT risk management, or SOX advisory, with significant focus on IT General Controls and enterprise ...

Senior IT Audit Manager

Waltham, MA · On-site

$130K - $175K/yr

Minimum of 8 years of progressive experience in external audit, internal audit, IT compliance, IT risk management, or SOX advisory, with significant focus on IT General Controls and enterprise ...

$130K - $175K/yr

Minimum of 8 years of progressive experience in external audit, internal audit, IT compliance, IT risk management, or SOX advisory, with significant focus on IT General Controls and enterprise ...

Senior IT Audit Manager

Waltham, MA · On-site

$130K - $175K/yr

Minimum of 8 years of progressive experience in external audit, internal audit, IT compliance, IT risk management, or SOX advisory, with significant focus on IT General Controls and enterprise ...

Senior Principal, Internal Audit, IT

Bedford, MA · On-site

$88K - $110K/yr

Deep knowledge of technology risk management, IT general controls, cybersecurity, cloud ... environments, ERP platforms, data governance, and emerging technology risks. * Experience ...

Governance Analyst

Boston, MA · On-site

$49 - $65.25/hr

Drawing on a background in technology audit, risk management, and information security, the analyst bridges the gap between technical operations and regulatory compliance, ensuring that ...

Showing results 21-40

It Risk Management information

See Massachusetts salary details

$56.2K

$121.8K

$185.7K

How much do it risk management jobs pay per year?

As of Aug 7, 2026, the average yearly pay for it risk management in Massachusetts is $121,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,300.00 and $140,900.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an IT risk management professional, and why are they important?

To thrive in IT Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, typically supported by a degree in information technology, cybersecurity, or a related field. Familiarity with risk management tools (such as RSA Archer or MetricStream), knowledge of ISO 27001, and certifications like CISSP or CISM are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets, ensuring compliance, and enabling informed decision-making regarding technology risks.

What are some common challenges faced by IT risk management professionals, and how can they effectively address them?

IT Risk Management professionals often encounter challenges such as rapidly evolving cyber threats, balancing compliance with operational efficiency, and communicating technical risks to non-technical stakeholders. Staying updated with the latest security trends and regulations is essential for effective risk assessment. Building strong cross-departmental relationships can help ensure that risk mitigation strategies are both practical and well-understood across the organization. Continuous learning and leveraging risk management frameworks, like NIST or ISO 27001, can also provide a solid foundation for addressing these challenges.

What is the difference between It Risk Management vs Cybersecurity Analyst?

AspectIt Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk assessment, compliance, and mitigation strategies across IT systemsFocus on monitoring, analyzing, and responding to security threats
Employer & Industry UsageUsed in organizations prioritizing risk management and complianceUsed in security operations centers and cybersecurity teams

While both roles involve IT security, It Risk Management emphasizes assessing and mitigating risks across IT systems, whereas Cybersecurity Analysts focus on detecting and responding to security threats. Understanding these differences helps organizations assign the right roles for their security needs.

What does an IT risk management do?

An IT risk management professional identifies, assesses, and prioritizes potential technology-related threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, ensuring data security and compliance with industry standards. This role often involves using risk assessment tools and maintaining awareness of emerging cybersecurity threats.

What is IT risk management?

IT Risk Management is the process of identifying, assessing, and mitigating risks related to information technology systems and data within an organization. This discipline aims to protect information assets from threats such as cyberattacks, data breaches, and system failures by implementing security controls and policies. Effective IT Risk Management helps organizations comply with regulations, minimize financial losses, and ensure business continuity. Professionals in this field continuously monitor and update risk strategies to adapt to evolving technological threats.

What are careers in it risk management?

Careers in IT risk management involve identifying, assessing, and mitigating technology-related security threats to protect organizational data and systems. Roles include IT risk analyst, cybersecurity manager, and compliance officer, often requiring knowledge of security frameworks, risk assessment tools, and relevant certifications like CISSP or CISM.
What are popular job titles related to It Risk Management jobs in Massachusetts? For It Risk Management jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching It Risk Management jobs in Massachusetts look for? The top searched job categories for It Risk Management jobs in Massachusetts are:
Infographic showing various It Risk Management job openings in Massachusetts as of August 2026, with employment types broken down into 80% Full Time, 15% Part Time, 1% Temporary, and 4% Contract. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $121,833 per year, or $58.6 per hour.

IT Internal Auditor

Unifirst

Wilmington, MA • Hybrid

Full-time

Medical, Life, Retirement, PTO

Posted 22 days ago


UniFirst rating

6.5

Company rating: 6.5 out of 10

Based on 133 frontline employees who took The Breakroom Quiz

144th of 250 rated facilities management


Job description

*This is a hybrid role with a 50% on-site requirement in Wilmington, MA*

The IT Internal Auditor supports the execution of the Company's Internal Audit plan, with responsibilities covering Sarbanes-Oxley (SOX) IT General Controls (ITGC) testing, IT operational audits, IT compliance audits, and system development life cycle (SDLC) assessments. This role evaluates the design and operating effectiveness of technology controls, identifies opportunities to strengthen governance and risk management practices, and helps enhance the overall control environment.

Working closely with Internal Audit leadership, business stakeholders, technology teams, and external auditors, the IT Internal Auditor participates in all phases of the audit cycle, including planning, risk assessment, fieldwork/testing, reporting, and follow-up activities. The position supports the assessment of risks related to information technology, cybersecurity, system implementations, cloud-based environments, third-party service providers, regulatory compliance, and technology-enabled business processes.

The successful candidate will apply analytical and problem-solving skills to assess controls, document test procedures and results, communicate observations and recommendations, and contribute to continuous improvement initiatives within the Internal Audit function. This role offers significant exposure to business and IT operations while providing opportunities for professional growth and development.

Responsibilities: 

  • Support the Company's ongoing compliance with the Sarbanes-Oxley Act (SOX) by participating in scoping, planning, walkthroughs, control testing, issue tracking, status reporting, and coordination with external auditors

  • Execute SOX IT General Controls (ITGC) testing, including assessments of user access management, change management, computer operations, logical security, and other key technology controls

  • Assist in evaluating the design and operating effectiveness of IT controls and identifying opportunities to strengthen the 

    Company's control environment, risk management practices, and operational effectiveness.

  • Support audits and assessments of technology-related risks, including cybersecurity, cloud computing, third-party service providers, data governance, and other emerging technology risks, as assigned.

  • Participate in System Development Life Cycle (SDLC) reviews and system implementation assessments to evaluate project governance, change management, testing, security, and overall control effectiveness.

  • Execute audit procedures in accordance with established audit programs, methodologies, and professional standards, while preparing clear, well-organized, and comprehensive audit workpapers.

  • Analyze audit results, identify control deficiencies and process improvement opportunities, and assist in developing practical, value-added recommendations

  • Assist in the preparation of Internal Audit reports, including documenting audit scope, objectives, observations, risk assessments, recommendations, and management action plans
  • Collaborate with IT and business stakeholders to obtain information, discuss audit results, validate findings, and monitor remediation efforts.
  • Maintain a working knowledge of Internal Audit methodologies, professional standards, regulatory requirements, and industry best practices.
  • Exceptional organizational skills and ability to manage time effectively and efficiently to ensure assigned work is completed within established time frames
  • Contribute to departmental initiatives, training programs, knowledge-sharing activities, and continuous improvement efforts designed to enhance the effectiveness and maturity of the Internal Audit function
  • Perform other audit-related responsibilities, special projects, and ad hoc reviews as assigned
     

Requirements: 

  • 1-3 years of experience in IT Audit, Internal Audit, SOX compliance, public accounting, IT risk management, IT compliance, cybersecurity, or a related internal controls function
  • Foundational knowledge of IT General Controls (ITGCs), including user access management, change management, computer operations, and logical security controls.
  • Exposure to IT operational audits, IT compliance assessments, system development life cycle (SDLC) processes, application controls, or technology risk management is preferred
  • Demonstrated commitment to professional development, including pursuit of relevant certifications such as Certified Information Systems Auditor (CISA) or Certified Internal Auditor (CIA)
  • Experience with Optro (formerly AuditBoard) or other audit management software is a plus
  • Strong verbal and written communication skills, with the ability to effectively document audit procedures, communicate observations, and interact with stakeholders across all levels of the organization 
  • Strong analytical, critical thinking, and problem-solving skills with a high degree of attention to detail and professional skepticism
  • Self-motivated and results-oriented, with the ability to manage multiple priorities, meet deadlines, and deliver high-quality work in a fast-paced environment with limited supervision 
  • Collaborative team partner who contributes to a positive and inclusive work environment and demonstrates the ability to build effective working relationships with diverse stakeholders 
  • Proficient with Microsoft Office applications (Excel, PowerPoint, Outlook, Word) and comfortable learning and using technology
  • Willingness and ability to travel up to 15% as required. 
  • Ability to handle sensitive and confidential information with the highest level of integrity, professionalism, and discretion.

Education:

  • Bachelor's degree in Information Systems, Information Technology, Computer Science, Cybersecurity, Computer Engineering, Management Information Systems (MIS), Accounting, Finance, or a related field.
  • Relevant professional certifications, including Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certified Public Accountant (CPA), or Certified Information Systems Security Professional (CISSP), are preferred or expected to be pursued based on experience level.
     

The estimated compensation for this position ranges from $74,000-$104,000. This range reflects various factors, including but not limited to the applicant's skills, qualifications, and previous work experience. Additionally, geographic differentials may apply based on the location where the position is ultimately filled, which could affect the final compensation. Please note that there is no application deadline for this role, and the recruitment process will continue until the position is filled.

Benefits & Perks:

401K with Company Match, Profit Sharing, Health Insurance, Employee Assistance Program, Life Insurance, Paid Time Off, Tuition Reimbursement, 30% Employee Discount, Employee Referral Bonuses.

UniFirst is an international leader in garment & Uniform services industry. We currently employ over 14,000 team partners who serve 300,000 business customer locations throughout the U.S., Canada, and Europe.

We were included in the top 10 of Selling Power magazine's "Best Companies to Sell For" list and recognized on Forbes magazine's "Platinum 400 - Best Big Companies" list. As an 80-year old company focused on annual growth, there's never been a better time to join our team. 


What UniFirst employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


UniFirst logo

About UniFirst

Sourced by ZipRecruiter

The year was 1936 and Aldo Croatti had a vision: to serve the men and women who put in a hard day’s work. He founded a laundry business to clean clothes of factory workers and others in the heavy-soil business. With UniFirst, he created an entirely new concept: uniform rental services. This business concept gained popularity because it delivered on a key customer need: helping businesses work safer and smarter while presenting a better business image. Aldo’s vision spurred the growth of an entire industry. Since then, UniFirst has evolved into a leader in the uniform rental services industry. With headquarters located in Wilmington, MA, UniFirst operates 260-plus facilities throughout North and Central America and Europe. We serve over 300,000 customers and outfit over 2 million workers across a variety of industries—from automotive to transportation and warehousing, construction, and everything in between. We proudly serve nearly half of Fortune 500 companies and their hardworking employees.

Industry

Manufacturing

Company size

10,000+ Employees

Headquarters location

Wilmington, MA, US

Year founded

1936