Lead the transition of risk management from a cyber-centric model to an enterprise-wide framework - expanding scope beyond cybersecurity to operational, financial, regulatory, and third-party risk ...
Lead the transition of risk management from a cyber-centric model to an enterprise-wide framework - expanding scope beyond cybersecurity to operational, financial, regulatory, and third-party risk ...
Lead the transition of risk management from a cyber-centric model to an enterprise-wide framework -- expanding scope beyond cybersecurity to operational, financial, regulatory, and third-party risk ...
Quick apply
Lead the transition of risk management from a cyber-centric model to an enterprise-wide framework -- expanding scope beyond cybersecurity to operational, financial, regulatory, and third-party risk ...
Manager, Risk Adjustment
Worcester, MA · On-site
We are looking for a Manager of Risk Managment to oversee Mass Advantages's full suite of Risk ... model (including V24 -V28 transition management). * Evaluate current vendor performance ...
Manager, Risk Adjustment
Worcester, MA · On-site
We are looking for a Manager of Risk Managment to oversee Mass Advantages's full suite of Risk ... model (including V24 -V28 transition management). * Evaluate current vendor performance ...
Manager, Risk Adjustment
Worcester, MA · On-site
We are looking for a Manager of Risk Managment to oversee Mass Advantages's full suite of Risk ... model (including V24 -V28 transition management). * Evaluate current vendor performance ...
Quick apply
Manager, Risk Adjustment
Worcester, MA · On-site
We are looking for a Manager of Risk Managment to oversee Mass Advantages's full suite of Risk ... model (including V24 -V28 transition management). * Evaluate current vendor performance ...
Manager, Risk Adjustment
Worcester, MA · On-site
$90K/yr
We are looking for a Manager of Risk Managment to oversee Mass Advantages's full suite of Risk ... model (including V24 -V28 transition management). * Evaluate current vendor performance ...
Manager, Risk Adjustment
Worcester, MA · On-site
$90K/yr
We are looking for a Manager of Risk Managment to oversee Mass Advantages's full suite of Risk ... model (including V24 -V28 transition management). * Evaluate current vendor performance ...
The Manager will ensure that supplier risk identification, assessment, and mitigation are ... Define and operationalize trigger-based models that initiate risk assessments based on supplier ...
The Manager will ensure that supplier risk identification, assessment, and mitigation are ... Define and operationalize trigger-based models that initiate risk assessments based on supplier ...
The Manager will ensure that supplier risk identification, assessment, and mitigation are ... Define and operationalize trigger-based models that initiate risk assessments based on supplier ...
The Manager will ensure that supplier risk identification, assessment, and mitigation are ... Define and operationalize trigger-based models that initiate risk assessments based on supplier ...
Support credit model oversight and governance, including monitoring performance and identifying potential limitations in coordination with Model Risk Management * Participate in regulatory exams ...
Support credit model oversight and governance, including monitoring performance and identifying potential limitations in coordination with Model Risk Management * Participate in regulatory exams ...
Risk Management - Capital Markets
Boston, MA · Hybrid
$125K - $180K/yr
... manager portfolios, including analysis of margin levels, stress scenario results, and exposure ... risk dashboard and models; review prospect portfolios as well as existing client portfolios in ...
Risk Management - Capital Markets
Boston, MA · Hybrid
$125K - $180K/yr
... manager portfolios, including analysis of margin levels, stress scenario results, and exposure ... risk dashboard and models; review prospect portfolios as well as existing client portfolios in ...
Senior Credit Risk Management Analyst, Chelmsford, MA or Hillsboro, OR, Hybrid Full-Time
Chelmsford, MA · On-site
Support credit model oversight and governance, including monitoring performance and identifying potential limitations in coordination with Model Risk Management * Participate in regulatory exams ...
Senior Credit Risk Management Analyst, Chelmsford, MA or Hillsboro, OR, Hybrid Full-Time
Chelmsford, MA · On-site
Support credit model oversight and governance, including monitoring performance and identifying potential limitations in coordination with Model Risk Management * Participate in regulatory exams ...
Risk Management - Capital Markets
Boston, MA · On-site
$125K - $180K/yr
... manager portfolios, including analysis of margin levels, stress scenario results, and exposure ... risk dashboard and models; review prospect portfolios as well as existing client portfolios in ...
Risk Management - Capital Markets
Boston, MA · On-site
$125K - $180K/yr
... manager portfolios, including analysis of margin levels, stress scenario results, and exposure ... risk dashboard and models; review prospect portfolios as well as existing client portfolios in ...
Bachelor's degree or equivalent practical experience. * 4+ years of experience in AI governance, data privacy, security risk management, compliance and controls, AI product risk, model risk ...
Bachelor's degree or equivalent practical experience. * 4+ years of experience in AI governance, data privacy, security risk management, compliance and controls, AI product risk, model risk ...
The Opportunity As a Risk Management - Contract Specialist - Managed Services - Senior Manager, you will lead initiatives in enterprise risk management, focusing on business continuity, risk model ...
The Opportunity As a Risk Management - Contract Specialist - Managed Services - Senior Manager, you will lead initiatives in enterprise risk management, focusing on business continuity, risk model ...
Actuary - Financial Projection Modeling (Modeling Center of Excellence)
Springfield, MA · On-site
$116K - $136K/yr
Support model governance and model risk management, including documentation of methodologies, controls and limitations Collaboration & Technology * Collaborate with FP&A, Valuation, ERM, Treasury ...
Actuary - Financial Projection Modeling (Modeling Center of Excellence)
Springfield, MA · On-site
$116K - $136K/yr
Support model governance and model risk management, including documentation of methodologies, controls and limitations Collaboration & Technology * Collaborate with FP&A, Valuation, ERM, Treasury ...
Manage and lead within a matrix of dedicated and assigned resources across a hybrid centralized and federated risk management operating model. * Work with HR and Communications team to coordinate and ...
Manage and lead within a matrix of dedicated and assigned resources across a hybrid centralized and federated risk management operating model. * Work with HR and Communications team to coordinate and ...
Manage and lead within a matrix of dedicated and assigned resources across a hybrid centralized and federated risk management operating model. * Work with HR and Communications team to coordinate and ...
Manage and lead within a matrix of dedicated and assigned resources across a hybrid centralized and federated risk management operating model. * Work with HR and Communications team to coordinate and ...
Manager - Digital Assets Enterprise Strategy, Risk and Operating Model Design Enterprise Operatio...
Boston, MA · On-site
Manager - Digital Assets Enterprise Strategy, Risk and Operating Model Design Enterprise Operations & Risk Ready for a fast-paced exciting career? Have a passion for helping your clients reduce risk ...
Manager - Digital Assets Enterprise Strategy, Risk and Operating Model Design Enterprise Operatio...
Boston, MA · On-site
Manager - Digital Assets Enterprise Strategy, Risk and Operating Model Design Enterprise Operations & Risk Ready for a fast-paced exciting career? Have a passion for helping your clients reduce risk ...
Manager - Digital Assets Enterprise Strategy, Risk and Operating Model Design Enterprise Operatio...
Boston, MA · On-site
Manager - Digital Assets Enterprise Strategy, Risk and Operating Model Design Enterprise Operations & Risk Ready for a fast-paced exciting career? Have a passion for helping your clients reduce risk ...
Manager - Digital Assets Enterprise Strategy, Risk and Operating Model Design Enterprise Operatio...
Boston, MA · On-site
Manager - Digital Assets Enterprise Strategy, Risk and Operating Model Design Enterprise Operations & Risk Ready for a fast-paced exciting career? Have a passion for helping your clients reduce risk ...
Senior AI Risk Advisor
Boston, MA · On-site +1
The Senior AI Risk Advisor, under the direction of the Manager of Risk Operations, sits at the ... Lead AI risk assessments across the full model lifecycle - evaluating third-party AI vendors ...
Senior AI Risk Advisor
Boston, MA · On-site +1
The Senior AI Risk Advisor, under the direction of the Manager of Risk Operations, sits at the ... Lead AI risk assessments across the full model lifecycle - evaluating third-party AI vendors ...
... Model and reinforce professional and technical standards (e.g. refer to specific - PwC tax and ... The Opportunity As a Risk Management - Contract Specialist - Advisory Consulting Services - Senior ...
... Model and reinforce professional and technical standards (e.g. refer to specific - PwC tax and ... The Opportunity As a Risk Management - Contract Specialist - Advisory Consulting Services - Senior ...
Model Risk Manager information
See Massachusetts salary details
$56.2K - $68K
4% of jobs
$68K - $79.8K
6% of jobs
$79.8K - $91.5K
11% of jobs
$96K is the 25th percentile. Wages below this are outliers.
$91.5K - $103.3K
11% of jobs
The median wage is $112.7K / yr.
$103.3K - $115.1K
23% of jobs
$115.1K - $126.8K
13% of jobs
$134.6K is the 75th percentile. Wages above this are outliers.
$126.8K - $138.6K
12% of jobs
$138.6K - $150.4K
8% of jobs
$150.4K - $162.1K
6% of jobs
$162.1K - $173.9K
4% of jobs
$173.9K - $185.7K
2% of jobs
$56.2K
$121.8K
$185.7K
How much do model risk manager jobs pay per year?
What are some common challenges a Model Risk Manager faces when validating complex financial models?
What is the difference between Model Risk Manager vs Quantitative Analyst?
| Aspect | Model Risk Manager | Quantitative Analyst |
|---|---|---|
| Required Credentials | Advanced degrees in finance, statistics, or mathematics; certifications like FRM or CFA | Degree in finance, economics, mathematics, or related fields; often CFA or CQF |
| Work Environment | Focus on risk management teams within financial institutions; regulatory compliance | Analytical roles within trading, investment, or banking divisions; model development |
| Employer & Industry Usage | Financial institutions, banks, asset managers | Investment firms, hedge funds, banks, financial services |
The Model Risk Manager primarily oversees and mitigates risks associated with financial models, ensuring compliance and accuracy. In contrast, Quantitative Analysts develop and implement models to support trading, investment, or risk strategies. While both roles require strong quantitative skills and similar credentials, their focus areas differ—risk management versus model development and analysis.
What are the key skills and qualifications needed to thrive as a Model Risk Manager, and why are they important?
What does a Model Risk Manager do?

Job description
About the team:
An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services. This is achieved by providing a robust and secure technology foundation to do great work. We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment.
The STAR team assists the Global Security Services (GSS) organization in developing and refining information security policies, standards and strategy, enterprise risk management, creating metrics and reporting, coordinating cross-functional projects, and strategically aligning global information security initiatives with the broader CISO vision amongst other governance, risk and compliance efforts. The STAR team is highly collaborative and cross-functional, working closely with various functions within the GSS team (namely Security Product and Development and Security Intelligence Operations), Global Technology Solutions (GTS) team and the broader Klaviyo organization.
About the role:
The Senior Manager, Security Risk Engineering is a senior information security and risk leader responsible for evolving risk management at Klaviyo from a traditional, cyber-centric, compliance-driven model into a real-time, business-aligned, engineering-led risk intelligence capability. Reporting into the Director of Security Trust and Risk, you will lead the Security Risk Engineering team as a second line of defense - owning technology risk management, third-party risk, risk quantification, and the risk intelligence and automation capability that turns disparate security signals into a single, decision-enabling view of risk.
You will operate as a credible, hands-on risk authority who can challenge and partner with engineering and security teams while maintaining independence from first-line delivery. You will build a team that thinks like risk engineers rather than traditional analysts - automating repeatable assessment, instrumenting controls, and applying AI as foundational infrastructure. You will partner with Engineering, Product, GTS, Legal, Audit, Finance, and the wider GSS organization to make risk legible across the business and to move Klaviyo's risk posture measurably forward.
How you'll have an impact:
- Lead the transition of risk management from a cyber-centric model to an enterprise-wide framework - expanding scope beyond cybersecurity to operational, financial, regulatory, and third-party risk, with integrated remediation tracking and clear ownership of outcomes
- Own the risk register and taxonomy, establishing a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that aggregation, prioritisation, and reporting become meaningful
- Quantify risk in financial terms - expected loss, probability, and cost of remediation versus acceptance - so leadership can make rational investment and risk-acceptance decisions rather than relying on qualitative severity labels
- Set and continuously refine the risk cadence: weekly risk huddles with business functions, monthly risk reviews, and a quarterly Enterprise Risk Committee, connecting day-to-day execution to GSS and Klaviyo-level objectives
- Build the risk intelligence and automation capability - partnering closely with the team's risk intelligence lead, whose remit is risk intelligence and building automations using AI - to surface a continuously updated, quantified view of risk posture drawn from the live security tool estate (vulnerability, endpoint, third-party, data movement, and cyber risk quantification sources)
- Drive the risk scoring programme: integrate third-party risk, application inventory, and cyber risk quantification platforms so that applications and vendors carry a composite, evidence-based risk score that drives tiered, automated decision-making
- Unlock third-party risk automation through a tiered vendor model - fast-tracking low-risk vendors while ensuring high-risk vendors receive deep due diligence, business reviews, and continuous monitoring
- Evaluate and govern risks associated with AI/ML deployments, LLM integrations, and cloud data pipelines, embedding AI risk assessment into the internal and third-party risk programs
- Operate as a second line of defense - providing independent oversight, challenge, and guidance to first-line teams, applying consistent risk taxonomies and reporting standards, and escalating risks that exceed established tolerance
- Act as custodian of the relevant security risk policies and standards, owning the review and update cycle and ensuring each policy connects to a specific risk it reduces
- Partner with Legal and Internal Audit on regulatory horizon scanning and on audit findings affecting systems and processes, tracking findings through to closure
- Maintain authoritative risk materials for GSS leadership, monthly KPI updates, and quarterly Board contributions - accurate, succinct, and decision-ready - translating high-severity findings into clear business impact
- Lead, mentor, and grow the team, developing risk engineers and specialists and building a culture of adversarial thinking, business empathy, and technical rigour
- 10+ years of experience in information security, cybersecurity, technology risk, or operational risk within a large, complex, or high-growth organization, with demonstrable depth of information security expertise and a track record of operating at a senior level
- Proven experience operating in or alongside a second line of defense function within a Three (or Four) Lines of Defense model, able to engage credibly with senior engineers, architects, and security teams while maintaining independence from first-line delivery ownership
- Demonstrated leadership of a risk or security team, with a track record of mentoring and developing people, and the ability to manage conflicting priorities and multiple concurrent initiatives
- Strong command of risk quantification - able to express risk in financial and business terms, not just qualitative severity ratings - and of enterprise risk management beyond cybersecurity alone
- Working knowledge of security frameworks - NIST, ISO 27001, SOC 2, ISO 42001, PCI DSS, CIS Controls - and how they translate into credible control requirements and delivery plans
- Hands-on familiarity with modern risk and security tooling: third-party risk platforms, cyber risk quantification, vulnerability management, endpoint, and data-security telemetry, with a clear point of view on where AI augments versus replaces human judgement
- Experience building and tracking security KPIs and metrics to measure success and drive continuous improvement
- A strong communicator and problem-solver who balances persuasion with active listening, with exceptional stakeholder management skills to engage engineering leaders and executives and translate complex, technical risk into clear business impact
- Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering-led, or AI-enabled risk capability
- Experience in a regulated or high-trust environment (e.g. SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR) and familiarity with the regulatory expectations affecting technology and cybersecurity risk
- Exposure to AI governance, model risk, or responsible-AI program work
- Familiarity with operational resilience and third-party risk beyond cybersecurity alone
- Experience with Python, SQL, and REST APIs to build automated data ingestion pipelines, query security telemetry, and programmatically orchestrate risk reporting
- Hands-on experience in SecOps, AppSec, or Security Architecture - with a focus on threat modeling, Zero Trust architecture, and data governance
- Experience working with security and risk tooling in cloud infrastructure, hosting, and platform contexts
- Relevant professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or ISO 27001 Lead Auditor / Lead Implementer
Massachusetts Applicants:It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Our salary range reflects the cost of labor across various U.S. geographic markets. The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations. The base salary offered for this position is determined by several factors, including the applicant's job-related skills, relevant experience, education or training, and work location.
In addition to base salary, our total compensation package may include participation in the company's annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing benefits based on eligibility.
Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process.
Base Pay Range For US Locations:
$180,000-$270,000 USD
This role may require up to 10% travel for purposes such as new hire onboarding, client or partner work if applicable, team meetings, and industry events. Travel is coordinated in advance.
Get to Know Klaviyo
We're Klaviyo (pronounced clay-vee-oh). We empower creators to own their destiny by making first-party data accessible and actionable like never before. We see limitless potential for the technology we're developing to nurture personalized experiences in ecommerce and beyond. To reach our goals, we need our own crew of remarkable creators-ambitious and collaborative teammates who stay focused on our north star: delighting our customers. If you're ready to do the best work of your career, where you'll be welcomed as your whole self from day one and supported with generous benefits, we hope you'll join us.
AI fluency at Klaviyo includes responsible use of AI (including privacy, security, bias awareness, and human-in-the-loop). We provide accommodations as needed.
By participating in Klaviyo's interview process, you acknowledge that you have read, understood, and will adhere to our Guidelines for using AI in the Klaviyo interview Process. For more information about how we process your personal data, see our Job Applicant Privacy Notice.
Klaviyo is committed to a policy of equal opportunity and non-discrimination. We do not discriminate on the basis of race, ethnicity, citizenship, national origin, color, religion or religious creed, age, sex (including pregnancy), gender identity, sexual orientation, physical or mental disability, veteran or active military status, marital status, criminal record, genetics, retaliation, sexual harassment or any other characteristic protected by applicable law.
IMPORTANT NOTICE: Our company takes the security and privacy of job applicants very seriously. We will never ask for payment, bank details, or personal financial information as part of the application process. All our legitimate job postings can be found on our official career site. Please be cautious of job offers that come from non-company email addresses (@klaviyo.com), instant messaging platforms, or unsolicited calls.
By clicking "Submit Application" you consent to Klaviyo processing your Personal Data in accordance with our Job Applicant Privacy Notice. If you do not wish for Klaviyo to process your Personal Data, please do not submit an application. You can find our Job Applicant Privacy Notice here and here (FR).
About Klaviyo
Sourced by ZipRecruiter
Industry
Marketing
Company size
1,001 - 5,000 Employees
Headquarters location
Boston, MA, US
Year founded
2012