1

It Risk Jobs in Massachusetts (NOW HIRING)

$16.25 - $21.75/hr

As a Risk Consulting Intern at RSM, you will work with various sized businesses spanning industries ... Information Technology controls testing in support of financial statement audits * Technical IT ...

Posted today

... technology, or IT risk), investment management, financial services, or technology. * Demonstrated ... knowledge of AI governance, AI risk management, machine learning, generative AI, intelligent ...

Showing results 41-60

It Risk information

See Massachusetts salary details

$15

$33

$80

How much do it risk jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for it risk in Massachusetts is $33.13, according to ZipRecruiter salary data. Most workers in this role earn between $21.25 and $42.26 per hour, depending on experience, location, and employer.

What is IT risk?

IT risk refers to the potential for losses or negative impacts to an organization resulting from the use of information technology. This includes threats such as data breaches, cyberattacks, system failures, and non-compliance with regulations. IT risk management involves identifying, assessing, and mitigating these risks to protect an organization’s information assets and ensure business continuity.

What are the key skills and qualifications needed to thrive as an IT risk professional, and why are they important?

To thrive as an IT Risk professional, you need a strong understanding of information security principles, risk management frameworks, and relevant regulations, typically supported by a degree in information technology or cybersecurity. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) systems, and certifications such as CISM or CISSP is highly valued. Analytical thinking, attention to detail, and effective communication are vital soft skills for identifying vulnerabilities and collaborating with stakeholders. These competencies are crucial for proactively managing threats and ensuring the organization's information assets remain secure and compliant.

What are some common challenges faced by IT risk professionals when working with cross-functional teams?

IT Risk professionals often collaborate with various departments such as IT, compliance, finance, and operations. A common challenge is effectively communicating technical risks in terms that non-technical stakeholders can understand, ensuring alignment on priorities and mitigation strategies. Navigating differing risk tolerances and balancing business needs with security requirements can also present difficulties. Building strong relationships and fostering ongoing dialogue are key to overcoming these challenges and ensuring successful risk management across the organization.

What is the difference between It Risk vs Cybersecurity Analyst?

AspectIt RiskCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, IT departments
Employer & Industry UsageFinancial, healthcare, and large enterprisesTech firms, finance, government agencies

It Risk professionals focus on identifying, assessing, and mitigating risks related to IT systems and compliance. Cybersecurity Analysts primarily monitor and respond to security threats and incidents. While both roles require similar certifications and work in overlapping environments, It Risk emphasizes risk management strategies, whereas Cybersecurity Analysts concentrate on security operations and threat response.

Do IT risk analysts make good money?

IT risk analysts typically earn competitive salaries that vary by experience, location, and industry. Entry-level positions may start around $60,000 annually, while experienced analysts can earn over $100,000, especially with certifications like CISSP or CISA. The role often involves working with cybersecurity tools and risk assessment frameworks.

Is risk analyst an IT job?

A risk analyst in the IT field evaluates technology-related risks, such as cybersecurity threats and system vulnerabilities, often using data analysis tools and risk management frameworks. The role typically requires knowledge of IT systems, security protocols, and relevant certifications like CISSP or CRISC.

What are the most commonly searched types of It Risk jobs in Massachusetts?

The most popular types of It Risk jobs in Massachusetts are:

Infographic showing various It Risk job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 12% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $68,913 per year, or $33.1 per hour.

Deputy Director of IT Risk and Compliance

Boston, MA • On-site

Massachusetts Bay Transportation Authority
5 - 10K employees

$128K - $140K/yr

Full-time

Posted 22 days ago


Key responsibilities

  • Oversee the risk management lifecycle for IT and OT systems, including identification, assessment, response, and monitoring.

  • Maintain and oversee the Risk Register, control testing, and issue management related to security risks.

  • Design and manage a Supply-Chain Risk Management (SCRM) program, including third-party assessments and ongoing performance monitoring.


Massachusetts Bay Transportation Authority rating

7.9

Company rating: 7.9 out of 10

Based on 27 frontline employees who took The Breakroom Quiz

48th of 101 rated public transport


Job description

At the MBTA, we envision a thriving region enabled by a best-in-class transit system. Our mission is to serve the public by providing safe, reliable, and accessible transportation. MBTA's core values are built around safety, service, equity, sustainability, culture, and accessibility, and each employee that works for the MBTA performs their roles based on our vision, mission, and values.

This includes attendance, participation, and contribution in local safety committee meetings as needed. Job Summary The Deputy Director of IT Risk & Compliance Management provides strategic and operational leadership over enterprise technology risk, compliance, and governance functions across the MBTA. The role safeguards information assets by operationalizing security and privacy control frameworks, orchestrating supply chain and vendor risk diligence, and translating risk posture between executive-level dashboards and actionable remediation plans.

The Deputy Director fosters a high-performance culture of security awareness, drives policy governance, and serves as a trusted advisor to senior leadership on emerging risks spanning legacy, cloud, DevOps, and Operational technology environments. Duties & Responsibilities Direct the risk management lifecycle-identification, assessment, response, monitoring-for IT and OT systems, ensuring alignment with NIST CSF, NIST 800-53, ISO 27001, CIS, and applicable privacy mandates (e.g., MA 201 CMR 17.00, GDPR, CCPA). Maintain an authoritative inventory (Risk Register) of business, technology, regulatory, contractual, and organizational security related risks; oversee continuous control testing and issue management

Design and run a robust Supply-Chain Risk Management (SCRM) program, including third-party onboarding, due-diligence assessments (SOC 2, ISO 27001, PCI DSS, FedRAMP, CMMC), and ongoing performance monitoring. Coordinate with Procurement and Legal to embed security clauses and right-to-audit provisions in contracts. Develop, socialize, and maintain MBTA information security and privacy policies; drive adoption through targeted awareness campaigns, phishing simulations, and organization-wide training.

Evangelize a Security-First mindset via townhalls, brownbag sessions, and executive briefings. Administer and optimize GRC portals (e.g., ServiceNow, Archer) for control catalogues, risk registers, exception management, and board-level metrics. Integrate vulnerability, incident, and asset data to deliver end-to-end traceability from findings to remediation and residual risk reporting

Produce concise, data-driven dashboards and briefings for the CISO, CIO, Board, and federal regulators (TSA, FTA, DHS/CISA). Present program status, risk trending, and budget justification in publics peaking forums, executive committees, and industry conferences. Lead, mentor, and develop a diverse team of risk analysts and compliance specialists; cultivate psychological safety, accountability, and continuous learning.

Champion collaboration across Operations, Engineering, Legal, Audit, and Finance to embed security into MBTA's technology and business roadmaps. Evaluate emerging threats, technologies, and regulatory changes; recommend process enhancements, automation, and tooling (e.g., IRM workflows, AI assisted control testing). Serve as primary interface for internal/external auditors and regulatory bodies; coordinate evidence collection, track remediation commitments, and attest to control effectiveness

Perform all other duties and projects that may be assigned. Additional responsibilities may include focus on one or more departments or locations. See applicable addendum for department or location specific functions.

Supervision Manage a team of engineers and administrators. Minimum Requirements & Qualifications Bachelor's degree from an accredited institution in Computer Science or a related field. Five (5) years of progressive IT risk, compliance, or cybersecurity governance experience within large, complex environments, Two (2) years of supervisory, managerial, and/or leadership experience.

Demonstrated implementation of NIST 800-53/CSF, ISO 27001/27701, CIS Controls, ITIL, COBIT, and privacy regulations. Working knowledge of network, cloud (AWS/Azure), DevOps pipelines, legacy on-prem systems, security tooling (SIEM, EDR, IAM), and vulnerability management platforms. Handson administration of GRC suites (ServiceNow GRC, Archer, Origami, Armis, Nazomi) and phishing training platforms (KnowBe4, Proofpoint, Cofense).

Exceptional verbal and written communication, publics peaking, and executive level presentation skills. At least one of: CRISC, CISM, CISSP, CISA; willingness to achieve additional certifications as needed. Substitutions A High School Diploma or GED with an additional seven (7) years of directly related experience substitutes for the bachelor's degree requirement.

An associate's degree from an accredited institution and an additional three (3) years of directly related experience substitutes for the bachelor's degree requirement. A master's degree in a related subject substitutes for two (2) years of general experience. A nationally recognized certification, or statewide/professional certification in a related field substitutes for one year of experience.

Preferred Experience & Skills Seven (7) or more years of progressive IT risk, compliance, or cybersecurity governance experience within large, complex environments. Three (3) or more years in a supervisory/leadership capacity. Additional credentials (e.g., CGEIT, CCSP, ISO 27001 Lead Auditor, PMP)

Experience with federal critical infrastructure directives (TSA SD 1580/82202201C, NIST SP 80082). Exposure to operational technology (OT) environments and rail/transit systems. Record of thought leadership through conference speaking, publication, or standards body participation.

Strategic thinker with a hands-on, results driven approach. Analytical mindset and quantitative skills; comfort with ambiguity and rapid change. Demonstrated integrity, ethical judgement, and commitment to public service.

Ability to inspire teamwork, inclusivity, and a culture of continuous improvement. Job Conditions: Ability to effectively read, comprehend, communicate, and respond to instructions, orders, signs, notices, inquiries, etc. in English.

Be at least eighteen (18) years of age, except if participating in an approved high school internship / co-op program. Ability to commute to assigned work locations in the Boston, MA metro area, as required by the role. Ability to provide internal and external customers with courteous and professional experiences.

Ability to work effectively, independently, and as part of a diverse workforce team (or supervise, if required). Ability to uphold the rights and interests of the MBTA while building and maintaining effective relationships with employees and co-workers. Ability to adhere to rules, regulations, collective bargaining agreements (if applicable), and policies of the MBTA, including the EEO, anti-discrimination, anti-harassment, and anti-retaliation policies.

Have a satisfactory work record for the two (2) years immediately prior to the closing date of this posting (unless if current student or recent graduate), including overall employment, job performance, discipline, and safety records (infractions and/or offenses occurring after the closing of the posting and before the filling of a vacancy may preclude a candidate from consideration for selection). Ability to pass a Criminal Offender Record Information (CORI) check, comprehensive background screening, and / or medical Clinic screening, potentially including physical examination and drug and alcohol screenings. Ability to work all shifts and / or locations assigned, directed, or necessary for this position, including (for some transit / operations roles) up to twenty-four (24) hours per day, seven (7) days per week as necessary to accommodate severe weather conditions, emergencies, or any other circumstances that may potentially impact service or the safety of service.

Intern / co-op staff must be enrolled full or part-time in an accredited educational program and maintain a cumulative GPA of at least 2.5 for the entire duration of the internship / co-op. Additionally, interns / co-ops must have valid work authorization and U.S. Social Security Number prior to starting pre-employment screenings / pre-boarding, working in their positions, and throughout the duration of their program

Disclaimers and Definitions: General Disclaimer: The statements contained in this job description are intended to describe a summary, general nature, and complexity of typical job functions and do not represent an exhaustive list of all duties, tasks, and responsibilities required of staff assigned to this position. Application Completion: It is each applicant's responsibility to ensure application details are entered completely and correctly, including updated work and education histories (past and current). Incomplete applications may not be considered.

Attachments do not substitute for application fields. The recruitment team does not have access to existing employee data / history. Application Deadlines: Applicants should apply as soon as possible, as the MBTA may stop considering applicants after a sufficiently large applicant pool is established.

Work Environment: The physical demands and work environment characteristics described here-in are representative of those an employee may encounter while performing the essential functions of this job. Reasonable accommodations can be made to enable individuals with disabilities to perform essential functions. See job description for role-specific requirements.

Work Eligibility: All employees must be legally authorized to work in the United States and on an unrestricted basis. The MBTA does not have an employer work sponsorship program. However, if you have unrestricted work authorization, or are sponsored by a separate entity, you are welcome to apply.

Further, all persons hired will require a U.S. Social Security Number prior to starting the position and employees will be required to complete a Form I-9 to verify their identity and eligibility to work in the U.S. Interviews: Candidates should ensure they arrive on time, are prepared, can remain for the duration, and if remote, are in a quiet place without distraction, for the interview

Candidates who do not attend their interview without advance authorization, including an email confirmation of a rescheduled time/date from Human Resources, will be considered a no-show and disqualified from consideration for the position. Related to rescheduling, on a one-time basis, and due to something emergent, you may be allowed to reschedule the interview. In addition, Human Resources may require documentation supporting the request.

However, should you need to reschedule, you will need to contact your Recruiter directly by email. Safety Sensitive Positions: Employees working in this classification will be subject to periodic physical examinations plus random drug and alcohol testing. On-call or 24/7 Positions: Employees working in this classification must be available to respond to page / text / call and report to work as determined by assigned department or the Authority.

Essential / Emergency Staff: During declared "states of emergency," employees working in this classification are required to report to work for their assigned work hours or as directed by management. ADA Accommodations: The MBTA makes reasonable accommodations for applicants with disabilities. If you require an accommodation during this process, please contact the MBTA's ADA Unit at 617-222-5751 or hradaaa@mbta.com

Diversity, Equity, and Inclusion: The MBTA is an Equal Employment Opportunity Employer. For terms, descriptions, and definitions related to diversity, equity, inclusion, veteran status, and immediate family members that you may find on the application form, please visit mbta.com/careers-app-definitions. Intern / Co-Op Benefits: Employees taking part in an internship or co-op at the MBTA are eligible to receive accrued paid sick leave as well as a monthly transportation pass, based on the city from which the intern / co-op commutes to work, at no cost

However, no additional benefits are currently offered for interns or co-ops.


What Massachusetts Bay Transportation Authority employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom