1

Security Risk Management Jobs in Massachusetts (NOW HIRING)

As a key member of the Security Risk & Audit team, the Technology Risk & Continuity Analyst supports the firm's security risk, business continuity, and incident management programs, contributing ...

As a key member of the Security Risk & Audit team, the Technology Risk & Continuity Analyst supports the firm's security risk, business continuity, and incident management programs, contributing ...

As a key member of the Security Risk & Audit team, the Technology Risk & Continuity Analyst supports the firm's security risk, business continuity, and incident management programs, contributing ...

Work with the Department of Revenue's (DOR's) Risk Management team to identify business impact of ... Strong knowledge of security frameworks and standards (e.g., NIST, ISO 27001, COBIT). * Experience ...

next page

Showing results 1-20

Security Risk Management information

See Massachusetts salary details

$11

$55

$76

How much do security risk management jobs pay per hour?

As of Jun 30, 2026, the average hourly pay for security risk management in Massachusetts is $55.05, according to ZipRecruiter salary data. Most workers in this role earn between $44.62 and $65.62 per hour, depending on experience, location, and employer.

What are the typical challenges faced by professionals in Security Risk Management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

Can I make $200,000 a year in cyber security?

Security Risk Management professionals can potentially earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and roles in high-demand industries or senior leadership positions. Salary levels vary based on location, company size, and individual expertise, but high-level cybersecurity roles often offer compensation in this range.

Can you make $500,000 a year in cyber security?

Security Risk Management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or within large organizations. Achieving this income typically requires extensive experience, advanced certifications like CISSP or CISM, and expertise in high-demand areas such as threat intelligence or security architecture.

Is security risk management a good career?

Security risk management is a viable career that involves identifying, assessing, and mitigating security threats to organizations. It often requires certifications such as CISSP or CISM and skills in risk analysis, security policies, and incident response. The field offers opportunities across various industries with increasing demand for cybersecurity expertise.

What is Security Risk Management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in Security Risk Management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

Is SOC 1 entry level?

SOC 1 (Service Organization Control 1) reports are audit reports used to evaluate internal controls at a service organization and are not job roles. In the context of security risk management, entry-level positions typically require foundational knowledge of security principles, certifications like CompTIA Security+ or CISSP, and experience with risk assessment tools, but SOC 1 itself is not an entry-level role.
What are popular job titles related to Security Risk Management jobs in Massachusetts? For Security Risk Management jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching Security Risk Management jobs in Massachusetts look for? The top searched job categories for Security Risk Management jobs in Massachusetts are:
Infographic showing various Security Risk Management job openings in Massachusetts as of June 2026, with employment types broken down into 90% Full Time, 7% Part Time, 1% Temporary, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $114,507 per year, or $55.1 per hour.

Senior Manager - Security Risk Engineering

Venturefizz Product Management Community

Boston, MA • On-site

Other

Posted 12 days ago


Key responsibilities

  • Lead the transition of risk management from a cyber-centric model to an enterprise-wide framework, expanding scope beyond cybersecurity to operational, financial, regulatory, and third-party risk.

  • Own the risk register and taxonomy, establishing consistent standards for aggregation, prioritization, and reporting of risk.

  • Build the risk intelligence and automation capability to provide a continuously updated, quantified view of risk posture from security tool sources.


Job description

Senior Manager – Security Risk Engineering

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you're a close but not exact match with the description, we hope you'll still consider applying. Want to learn more about life at Klaviyo? Visit klaviyo.com/careers to see how we empower creators to own their own destiny.

An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services. This is achieved by providing a robust and secure technology foundation to do great work. We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment.

The STAR team assists the Global Security Services (GSS) organization in developing and refining information security policies, standards and strategy, enterprise risk management, creating metrics and reporting, coordinating cross-functional projects, and strategically aligning global information security initiatives with the broader CISO vision amongst other governance, risk and compliance efforts. The STAR team is highly collaborative and cross-functional, working closely with various functions within the GSS team (namely Security Product and Development and Security Intelligence Operations), Global Technology Solutions (GTS) team and the broader Klaviyo organization.

The Senior Manager, Security Risk Engineering is a senior information security and risk leader responsible for evolving risk management at Klaviyo from a traditional, cyber-centric, compliance-driven model into a real-time, business-aligned, engineering-led risk intelligence capability. Reporting into the Director of Security Trust and Risk, you will lead the Security Risk Engineering team as a second line of defense — owning technology risk management, third-party risk, risk quantification, and the risk intelligence and automation capability that turns disparate security signals into a single, decision-enabling view of risk.

You will operate as a credible, hands-on risk authority who can challenge and partner with engineering and security teams while maintaining independence from first-line delivery. You will build a team that thinks like risk engineers rather than traditional analysts — automating repeatable assessment, instrumenting controls, and applying AI as foundational infrastructure. You will partner with Engineering, Product, GTS, Legal, Audit, Finance, and the wider GSS organization to make risk legible across the business and to move Klaviyo's risk posture measurably forward.

Lead the transition of risk management from a cyber-centric model to an enterprise-wide framework — expanding scope beyond cybersecurity to operational, financial, regulatory, and third-party risk, with integrated remediation tracking and clear ownership of outcomes

Own the risk register and taxonomy, establishing a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that aggregation, prioritisation, and reporting become meaningful

Quantify risk in financial terms — expected loss, probability, and cost of remediation versus acceptance — so leadership can make rational investment and risk-acceptance decisions rather than relying on qualitative severity labels

Set and continuously refine the risk cadence: weekly risk huddles with business functions, monthly risk reviews, and a quarterly Enterprise Risk Committee, connecting day-to-day execution to GSS and Klaviyo-level objectives

Build the risk intelligence and automation capability — partnering closely with the team's risk intelligence lead, whose remit is risk intelligence and building automations using AI — to surface a continuously updated, quantified view of risk posture drawn from the live security tool estate (vulnerability, endpoint, third-party, data movement, and cyber risk quantification sources)

Drive the risk scoring programme: integrate third-party risk, application inventory, and cyber risk quantification platforms so that applications and vendors carry a composite, evidence-based risk score that drives tiered, automated decision-making

Unlock third-party risk automation through a tiered vendor model — fast-tracking low-risk vendors while ensuring high-risk vendors receive deep due diligence, business reviews, and continuous monitoring

Evaluate and govern risks associated with AI/ML deployments, LLM integrations, and cloud data pipelines, embedding AI risk assessment into the internal and third-party risk programs

Operate as a second line of defense — providing independent oversight, challenge, and guidance to first-line teams, applying consistent risk taxonomies and reporting standards, and escalating risks that exceed established tolerance

Act as custodian of the relevant security risk policies and standards, owning the review and update cycle and ensuring each policy connects to a specific risk it reduces

Partner with Legal and Internal Audit on regulatory horizon scanning and on audit findings affecting systems and processes, tracking findings through to closure

Maintain authoritative risk materials for GSS leadership, monthly KPI updates, and quarterly Board contributions — accurate, succinct, and decision-ready — translating high-severity findings into clear business impact

Lead, mentor, and grow the team, developing risk engineers and specialists and building a culture of adversarial thinking, business empathy, and technical rigour

10+ years of experience in information security, cybersecurity, technology risk, or operational risk within a large, complex, or high-growth organization, with demonstrable depth of information security expertise and a track record of operating at a senior level

Proven experience operating in or alongside a second line of defense function within a Three (or Four) Lines of Defense model, able to engage credibly with senior engineers, architects, and security teams while maintaining independence from first-line delivery ownership

Demonstrated leadership of a risk or security team, with a track record of mentoring and developing people, and the ability to manage conflicting priorities and multiple concurrent initiatives

Strong command of risk quantification — able to express risk in financial and business terms, not just qualitative severity ratings — and of enterprise risk management beyond cybersecurity alone

Working knowledge of security frameworks — NIST, ISO 27001, SOC 2, ISO 42001, PCI DSS, CIS Controls — and how they translate into credible control requirements and delivery plans

Hands-on familiarity with modern risk and security tooling: third-party risk platforms, cyber risk quantification, vulnerability management, endpoint, and data-security telemetry, with a clear point of view on where AI augments versus replaces human judgement

Experience building and tracking security KPIs and metrics to measure success and drive continuous improvement

A strong communicator and problem-solver who balances persuasion with active listening, with exceptional stakeholder management skills to engage engineering leaders and executives and translate complex, technical risk into clear business impact

Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering-led, or AI-enabled risk capability

Experience in a regulated or high-trust environment (e.g. SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR) and familiarity with the regulatory expectations affecting technology and cybersecurity risk

Exposure to AI governance, model risk, or responsible-AI program work

Familiarity with operational resilience and third-party risk beyond cybersecurity alone

Experience with Python, SQL, and REST APIs to build automated data ingestion pipelines, query security telemetry, and programmatically orchestrate risk reporting

Hands-on experience in SecOps, AppSec, or Security Architecture — with a focus on threat modeling, Zero Trust architecture, and data governance

Experience working with security and risk tooling in cloud infrastructure, hosting, and platform contexts

Relevant professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or ISO 27001 Lead Auditor / Lead Implementer

Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Our salary range reflects the cost of labor across various U.S. geographic markets. The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations. The base salary offered for this position is determined by several factors, including the applicant's job-related skills, relevant experience, education or training, and work location.

In addition to base salary, our total compensation package may include participation in the company's annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing benefits based on eligibility.

Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process.

Base Pay Range For US Locations: $18