1

It Risk Management Jobs in Massachusetts (NOW HIRING)

Senior Manager, IT Internal Audit

Needham, MA · On-site

$98K - $134K/yr

Our what is concrete: we facilitate the enterprise risk management program, execute risk-based ... As Senior Manager, IT Internal Audit, you'll work that full mandate and carry its technical depth.

... risk management practices for the ETX (Information Technology) organization. We work closely with our business and technology partners and succeed together by designing practical and effective ...

Third-Party Risk Consultant

Boston, MA · On-site

$86K - $113K/yr

... risk management practices for the ETX (Information Technology) organization. We work closely with our business and technology partners and succeed together by designing practical and effective ...

Showing results 41-60

It Risk Management information

See Massachusetts salary details

$56.2K

$121.8K

$185.7K

How much do it risk management jobs pay per year?

As of Aug 7, 2026, the average yearly pay for it risk management in Massachusetts is $121,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,300.00 and $140,900.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an IT risk management professional, and why are they important?

To thrive in IT Risk Management, you need a strong understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, typically supported by a degree in information technology, cybersecurity, or a related field. Familiarity with risk management tools (such as RSA Archer or MetricStream), knowledge of ISO 27001, and certifications like CISSP or CISM are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets, ensuring compliance, and enabling informed decision-making regarding technology risks.

What are some common challenges faced by IT risk management professionals, and how can they effectively address them?

IT Risk Management professionals often encounter challenges such as rapidly evolving cyber threats, balancing compliance with operational efficiency, and communicating technical risks to non-technical stakeholders. Staying updated with the latest security trends and regulations is essential for effective risk assessment. Building strong cross-departmental relationships can help ensure that risk mitigation strategies are both practical and well-understood across the organization. Continuous learning and leveraging risk management frameworks, like NIST or ISO 27001, can also provide a solid foundation for addressing these challenges.

What is the difference between It Risk Management vs Cybersecurity Analyst?

AspectIt Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentFocus on risk assessment, compliance, and mitigation strategies across IT systemsFocus on monitoring, analyzing, and responding to security threats
Employer & Industry UsageUsed in organizations prioritizing risk management and complianceUsed in security operations centers and cybersecurity teams

While both roles involve IT security, It Risk Management emphasizes assessing and mitigating risks across IT systems, whereas Cybersecurity Analysts focus on detecting and responding to security threats. Understanding these differences helps organizations assign the right roles for their security needs.

What does an IT risk management do?

An IT risk management professional identifies, assesses, and prioritizes potential technology-related threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, ensuring data security and compliance with industry standards. This role often involves using risk assessment tools and maintaining awareness of emerging cybersecurity threats.

What is IT risk management?

IT Risk Management is the process of identifying, assessing, and mitigating risks related to information technology systems and data within an organization. This discipline aims to protect information assets from threats such as cyberattacks, data breaches, and system failures by implementing security controls and policies. Effective IT Risk Management helps organizations comply with regulations, minimize financial losses, and ensure business continuity. Professionals in this field continuously monitor and update risk strategies to adapt to evolving technological threats.

What are careers in it risk management?

Careers in IT risk management involve identifying, assessing, and mitigating technology-related security threats to protect organizational data and systems. Roles include IT risk analyst, cybersecurity manager, and compliance officer, often requiring knowledge of security frameworks, risk assessment tools, and relevant certifications like CISSP or CISM.
What are popular job titles related to It Risk Management jobs in Massachusetts? For It Risk Management jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching It Risk Management jobs in Massachusetts look for? The top searched job categories for It Risk Management jobs in Massachusetts are:
Infographic showing various It Risk Management job openings in Massachusetts as of August 2026, with employment types broken down into 80% Full Time, 15% Part Time, 1% Temporary, and 4% Contract. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $121,833 per year, or $58.6 per hour.

IT Audit, Cybersecurity & Risk Director

Baker Tilly International

Tewksbury, MA • On-site

$215.44 - $359.06/hr

Other

Posted 2 days ago

New


Baker Tilly rating

8.7

Company rating: 8.7 out of 10

Based on 33 frontline employees who took The Breakroom Quiz

4th of 22 rated bookkeepers and accountants


Job description

## IT Audit, Cybersecurity & Risk DirectorApplylocations: USA MA Tewksburytime type: Full timeposted on: Posted Todayjob requisition id: JR107255# **Overview**Baker Tilly is a leading advisory, tax and assurance firm, providing clients with a genuine coast-to-coast and global advantage in major regions of the U.S. and in many of the world’s leading financial centers – New York, London, San Francisco, Los Angeles, Chicago and Boston. Baker Tilly Advisory Group, LP and Baker Tilly US, LLP (Baker Tilly) provide professional services through an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable laws, regulations and professional standards. Baker Tilly US, LLP is a licensed independent CPA firm that provides attest services to its clients. Baker Tilly Advisory Group, LP and its subsidiary entities provide tax and business advisory services to their clients. Baker Tilly Advisory Group, LP and its subsidiary entities are not licensed CPA firms.Baker Tilly Advisory Group, LP and Baker Tilly US, LLP, trading as Baker Tilly, are independent members of Baker Tilly International, a worldwide network of independent accounting and business advisory firms in 141 territories, with 43,000 professionals and a combined worldwide revenue of $5.2 billion. Visit bakertilly.com or join the conversation on LinkedIn, Facebook and Instagram.Please discuss the work location status with your Baker Tilly talent acquisition professional to understand the requirements for an opportunity you are exploring.*Baker Tilly is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability or protected veteran status, gender identity, sexual orientation, or any other legally protected basis, in accordance with applicable federal, state or local law.**Any unsolicited resumes submitted through our website or to Baker Tilly Advisory Group, LP, employee e-mail accounts are considered property of Baker Tilly Advisory Group, LP, and are not subject to payment of agency fees. In order to be an authorized recruitment agency ("search firm") for Baker Tilly Advisory Group, LP, there must be a formal written agreement in place and the agency must be invited, by Baker Tilly's Talent Attraction team, to submit candidates for review via our applicant tracking system.*# **Job Description:**ResponsibilitiesAre you interested in joining one of the fastest growing consulting and accounting firms in the country? Would you like the ability to join a highly dynamic team focused on providing exceptional client service in the area of informational technology risk advisory? If yes, consider joining Baker Tilly (BT) as an **IT Audit, Cybersecurity &** **Risk Director**! Our Risk Advisory practice provides a full spectrum of services to help our clients assess their risks, develop strategies to compete in an ever-changing business environment, and achieve their goals and objectives. All of this is accomplished through deep industry knowledge of risk, governance, internal audit, compliance, IT, and cybersecurity best practices. As one of the fastest growing firms in the nation, BT has the ability to offer you upward career trajectory, flexibility in how and where you get your work done and meaningful relationships with clients, teammates and leadership who truly care about you and your development.**Does this describe you?*** You want to continue to expand your work experiences and hone your skills as an IT risk professional in the areas of compliance, cybersecurity, and internal controls* You crave the opportunity to be part of a fast growing, entrepreneurial risk consulting practice where your hard work and creativity will be rewarded* You do your best work when you are part of a talented, down-to-earth team that thrives in collaboration and truly enjoys working together* You feel valued when you are provided the resources and support to continually sharpen your technical skills and build your career ***now, for tomorrow*****What you will do:*** Our cybersecurity team plays an integral role in helping our clients proactively manage their cybersecurity risks by assessing their IT and security capabilities and developing strategies to deliver operational improvements and increase the effectiveness of their cybersecurity investments.* As a Director, you'll work as part of a team helping to evaluate client risks and solve complex issues from strategy to execution. Your role will include:* Overseeing the delivery of our cybersecurity advisory services, including cybersecurity risk assessments, technology due diligence assessments, technical IT internal audit assistance, and penetration testing and vulnerability scanning* Supporting the development of team members through sharing your knowledge and experience and contributing to the growth and development of the cybersecurity practice* Coordinating project delivery activities and maintaining the quality of cybersecurity services delivered by the team* Directly interacting with key client stakeholders and leadership to ensure alignment on project objectives and activities, delivery schedules, and overall project management activities* Supporting business development activities, including attending networking events and drafting proposals and engagement letters* Initiating open and candid coaching conversations at all levels, encouraging everyone to have a voice* Anticipating stakeholder needs and developing and discussing potential solutions, even before the stakeholder realizes they are required* Initiating and leading open conversations with teams, clients and stakeholders to build trust* Applying knowledge of industry regulations and information security frameworks and standards (e.g., NIST CSF, ISO 27001/2, PCI DSS, etc.)Qualifications* Bachelor’s degree in management/computer information systems, computer science, accounting information systems, or related program* CISSP, CISA or CPA certification required* 12+ year(s) experience with cybersecurity consulting* Experience with NIST CSF, ISO 27001/2, or other related cyber frameworks* Experience with reviewing penetration testing and vulnerability scanning reports* Experience as a client serving professional for a consulting firm required* Excellent analytical, technical and problem-solving skills, with strong attention to detail* Exceptional verbal and written communication, collaboration, and time management skills, problem solving skills, with strong attention to detailThe compensation range for this role is $211,500 to $359,060. Actual compensation is influenced by a variety of factors including but not limited to skills, experience, qualifications, and geographic location.#LI-LF2#LI-hybrid #J-18808-Ljbffr

What Baker Tilly employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom