1

It Risk Jobs in Massachusetts (NOW HIRING)

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

IT Risk & Compliance Analyst

Andover, MA · On-site +1

$95K - $95K/yr

Scope of Position The IT Risk & Compliance Analyst, as part of the Information Security organization, is responsible for supporting the execution of Watts' IT compliance, audit readiness ...

Senior IT Audit Manager

Waltham, MA · On-site

$130 - $175/hr

... risk, and ensure timely execution of remediation efforts while enabling strategic technology ... Own and lead the ITGC and IT internal audit program, including planning, coordination, execution ...

Senior IT Audit Manager

Waltham, MA · On-site

$130 - $175/hr

... risk, and ensure timely execution of remediation efforts while enabling strategic technology ... Own and lead the ITGC and IT internal audit program, including planning, coordination, execution ...

next page

Showing results 1-20

It Risk information

See Massachusetts salary details

$15

$33

$80

How much do it risk jobs pay per hour?

As of Aug 18, 2026, the average hourly pay for it risk in Massachusetts is $33.13, according to ZipRecruiter salary data. Most workers in this role earn between $21.25 and $42.26 per hour, depending on experience, location, and employer.

What is IT risk?

IT risk refers to the potential for losses or negative impacts to an organization resulting from the use of information technology. This includes threats such as data breaches, cyberattacks, system failures, and non-compliance with regulations. IT risk management involves identifying, assessing, and mitigating these risks to protect an organization’s information assets and ensure business continuity.

What are the key skills and qualifications needed to thrive as an IT risk professional, and why are they important?

To thrive as an IT Risk professional, you need a strong understanding of information security principles, risk management frameworks, and relevant regulations, typically supported by a degree in information technology or cybersecurity. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) systems, and certifications such as CISM or CISSP is highly valued. Analytical thinking, attention to detail, and effective communication are vital soft skills for identifying vulnerabilities and collaborating with stakeholders. These competencies are crucial for proactively managing threats and ensuring the organization's information assets remain secure and compliant.

What are some common challenges faced by IT risk professionals when working with cross-functional teams?

IT Risk professionals often collaborate with various departments such as IT, compliance, finance, and operations. A common challenge is effectively communicating technical risks in terms that non-technical stakeholders can understand, ensuring alignment on priorities and mitigation strategies. Navigating differing risk tolerances and balancing business needs with security requirements can also present difficulties. Building strong relationships and fostering ongoing dialogue are key to overcoming these challenges and ensuring successful risk management across the organization.

What is the difference between It Risk vs Cybersecurity Analyst?

AspectIt RiskCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, IT departments
Employer & Industry UsageFinancial, healthcare, and large enterprisesTech firms, finance, government agencies

It Risk professionals focus on identifying, assessing, and mitigating risks related to IT systems and compliance. Cybersecurity Analysts primarily monitor and respond to security threats and incidents. While both roles require similar certifications and work in overlapping environments, It Risk emphasizes risk management strategies, whereas Cybersecurity Analysts concentrate on security operations and threat response.

Do IT risk analysts make good money?

IT risk analysts typically earn competitive salaries that vary by experience, location, and industry. Entry-level positions may start around $60,000 annually, while experienced analysts can earn over $100,000, especially with certifications like CISSP or CISA. The role often involves working with cybersecurity tools and risk assessment frameworks.

Is risk analyst an IT job?

A risk analyst in the IT field evaluates technology-related risks, such as cybersecurity threats and system vulnerabilities, often using data analysis tools and risk management frameworks. The role typically requires knowledge of IT systems, security protocols, and relevant certifications like CISSP or CRISC.

What are the most commonly searched types of It Risk jobs in Massachusetts?

The most popular types of It Risk jobs in Massachusetts are:

Infographic showing various It Risk job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 91% Full Time, 6% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $68,913 per year, or $33.1 per hour.

Senior IT Risk Analyst

Rockland Trust

Plymouth, MA • On-site

Full-time

Medical, Dental, Life, Retirement, PTO

Re-posted 6 days ago


Job description


Senior IT Risk Analyst (First Line of Defense)
Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program.
This is a hybrid role, 3 days Mon-Wed in the Plymouth office then remaining days working remotely.
This senior professional contributes to the identification, assessment, and mitigation of technology risks, providing informed recommendations to IT and business stakeholders. The role emphasizes accountability for high-quality risk assessments, strong judgment in interpreting results, and proactive contributions to process improvement and risk awareness across the organization.
This role serves as a resource and mentor to less-experienced colleagues, supporting development and consistent execution of sound risk management practices. The Senior IT Risk Analyst works closely with stakeholders across IT and business areas to ensure risks are adequately identified and managed, controls are designed and operating effectively, and necessary remediation activities are completed in a timely manner.
Key Responsibilities
IT Risk Assessment & Control Evaluation
  • Lead comprehensive IT risk assessments across applications, infrastructure, and IT processes, including inherent and residual risk evaluations.
  • Evaluate the design and operating effectiveness of controls, ensuring assessments are evidence-based and aligned with internal methodologies and regulatory requirements.
  • Conduct detailed walkthroughs and interviews with IT and business stakeholders to validate processes and risks, identify control gaps, and obtain and evaluate appropriate documentation and evidence.
  • Analyze risk and control data to identify trends, recurring issues, or systemic weaknesses to translate findings into actionable insights.
  • Maintain sufficient documentation of assessments performed, tests conducted, and issues noted in the Bank's systems of record, ensuring clarity, completeness, and alignment with Bank and regulatory methodology and requirements.

Risk Communication & Issue Resolution
  • Communicate findings, risk implications, control gaps, or other such issues to stakeholders in a professional, credible, and constructive manner.
  • Support, advise, and challenge remediation plans to ensure proposed actions effectively mitigate identified risks.
  • Coordinate responses to audit, regulatory, or other internal inquiries, ensuring timely and accurate resolution of outstanding issues.
  • Track and monitor remediation efforts and key milestones to facilitate risk closure, proactively identifying potential bottlenecks or emerging risks.

Program Support & Mentorship
  • Provide guidance and informal coaching to junior team members, reviewing work products to ensure adherence to risk assessment standards and quality expectations.
  • Contribute to continuous improvement initiatives for IT risk assessment methodologies, reporting practices, and other opportunities.
  • Serve as a trusted resource for IT and business teams on risk-related topics, fostering a risk-aware culture and promoting best practices.
  • Stay current with regulatory guidance, industry standards, and emerging risks to support program maturity and long-term risk management effectiveness.

Required Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Finance, or a related field with equitable risk and controls experience.
  • Minimum of 5 years of professional experience in IT risk management, technology audit, or control testing, including execution of risk assessments, control evaluation, and reporting.
  • Must be able to work the hybrid schedule: 3 days Mon-Wed in the Plymouth office then remaining days work remotely.
  • Experience with GRC platforms (e.g., Archer) and risk reporting tools (e.g., PowerBI dashboards).
  • Familiarity with risk and control frameworks such as NIST, CIS, COBIT, FFIEC, or ISO.
  • Demonstrated ability to effectively communicate, both written and verbally, complex IT risk and control concepts effectively to technical and non-technical stakeholders.
  • Experience navigating highly regulated or matrixed environments, interacting with audit, compliance, and/ or regulatory stakeholders.
  • Strong analytical skills, attention to detail, and ability to make independent, informed decisions.
  • Proven ability to influence outcomes and drive follow-through on risk identification and mitigation activities.

Highly preferred:
  • Professional certifications: CISA, CRISC, CISM, CISSP, or equivalent.
  • Financial services industry experience.

Responsibilities
Key Responsibilities
IT Risk Assessment & Control Evaluation
  • Lead comprehensive IT risk assessments across applications, infrastructure, and IT processes, including inherent and residual risk evaluations.
  • Evaluate the design and operating effectiveness of controls, ensuring assessments are evidence-based and aligned with internal methodologies and regulatory requirements.
  • Conduct detailed walkthroughs and interviews with IT and business stakeholders to validate processes and risks, identify control gaps, and obtain and evaluate appropriate documentation and evidence.
  • Analyze risk and control data to identify trends, recurring issues, or systemic weaknesses to translate findings into actionable insights.
  • Maintain sufficient documentation of assessments performed, tests conducted, and issues noted in the Bank's systems of record, ensuring clarity, completeness, and alignment with Bank and regulatory methodology and requirements.

Risk Communication & Issue Resolution
  • Communicate findings, risk implications, control gaps, or other such issues to stakeholders in a professional, credible, and constructive manner.
  • Support, advise, and challenge remediation plans to ensure proposed actions effectively mitigate identified risks.
  • Coordinate responses to audit, regulatory, or other internal inquiries, ensuring timely and accurate resolution of outstanding issues.
  • Track and monitor remediation efforts and key milestones to facilitate risk closure, proactively identifying potential bottlenecks or emerging risks.

Program Support & Mentorship
  • Provide guidance and informal coaching to junior team members, reviewing work products to ensure adherence to risk assessment standards and quality expectations.
  • Contribute to continuous improvement initiatives for IT risk assessment methodologies, reporting practices, and other opportunities.
  • Serve as a trusted resource for IT and business teams on risk-related topics, fostering a risk-aware culture and promoting best practices.
  • Stay current with regulatory guidance, industry standards, and emerging risks to support program maturity and long-term risk management effectiveness.

Qualifications
Required Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Accounting, Finance, or a related field with equitable risk and controls experience.
  • Minimum of 5 years of professional experience in IT risk management, technology audit, or control testing, including execution of risk assessments, control evaluation, and reporting.
  • Must be able to work the hybrid schedule: 3 days Mon-Wed in the Plymouth office then remaining days work remotely.
  • Experience with GRC platforms (e.g., Archer) and risk reporting tools (e.g., PowerBI dashboards).
  • Familiarity with risk and control frameworks such as NIST, CIS, COBIT, FFIEC, or ISO.
  • Demonstrated ability to effectively communicate, both written and verbally, complex IT risk and control concepts effectively to technical and non-technical stakeholders.
  • Experience navigating highly regulated or matrixed environments, interacting with audit, compliance, and/ or regulatory stakeholders.
  • Strong analytical skills, attention to detail, and ability to make independent, informed decisions.
  • Proven ability to influence outcomes and drive follow-through on risk identification and mitigation activities.

Highly preferred:
  • Professional certifications: CISA, CRISC, CISM, CISSP, or equivalent.
  • Financial services industry experience.

Our goal is to offer our colleagues the most generous benefits package possible. We strive to provide colleagues with a comprehensive benefits package and an environment that supports a healthy work-life balance. Benefits include: Competitive compensation with performance incentive awards, Health Insurance, Dental Insurance, a 401K and DC Plan for your retirement, LTD & Life Insurance, Vacation Time, Day Care Reimbursement, Tuition Assistance for graduate and undergraduate programs, an Award Winning Wellness program and much more!
At Rockland Trust you'll find a respectful and inclusive environment where everyone is given the chance to succeed. We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.