1

Security Risk Management Jobs in Massachusetts (NOW HIRING)

This role sets the strategic direction for the firm's Information Security Management System, security governance, risk management, incident response, third-party security, data protection, and ...

Ensure Information Security Risk Management Process (ISRMP) requirements are maintained for assigned applications. * Ensure appropriate Data Stewards are assigned and that Data Governance and Data ...

New

Showing results 41-60

Security Risk Management information

See Massachusetts salary details

$11

$55

$76

How much do security risk management jobs pay per hour?

As of Sep 7, 2026, the average hourly pay for security risk management in Massachusetts is $55.05, according to ZipRecruiter salary data. Most workers in this role earn between $44.62 and $65.62 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.

What are popular job titles related to Security Risk Management jobs in Massachusetts?

For Security Risk Management jobs in Massachusetts, the most frequently searched job titles are:

What job categories do people searching Security Risk Management jobs in Massachusetts look for?

The top searched job categories for Security Risk Management jobs in Massachusetts are:

Infographic showing various Security Risk Management job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 78% Full Time, 16% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 82% Physical, 3% Hybrid, and 15% Remote job distribution, with an average salary of $114,507 per year, or $55.1 per hour.

Business Information Security Officer-AVP

State Street Global Advisors

Boston, MA โ€ข On-site

$90K - $157K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 19 days ago


Job description

AVP, Cyber Risk Advisor

The AVP, Cyber Risk Advisor provides cyber risk advisory services focused on strengthening the firm's defensive cybersecurity posture through proactive risk management, cyber control oversight, vulnerability reduction, and security-by-design practices. The role serves as a trusted advisor to technology, infrastructure, application, and business teams, ensuring cybersecurity risks are identified, assessed, and managed in alignment with enterprise standards, regulatory expectations, and risk appetite.

As a member of the Business Information Security organization, the AVP Cyber Security Advisor partners closely with Security Operations, Vulnerability Management, Threat Intelligence, Engineering, Architecture, and AI Security teams to drive risk-informed decisions and measurable reductions in cyber exposure. The successful candidate combines strong technical cybersecurity knowledge with the ability to influence stakeholders and translate complex cyber risks into actionable business guidance.

Cyber Risk Advisory & Oversight

  • Assess cyber risks associated with infrastructure, applications, cloud services, third party supply chain, and emerging technologies.

  • Assess network designs, material changes, and new initiatives for security risk; review architecture artifacts and control implementations.

  • Provide expert guidance on risk acceptance decisions, exception handling, and residual risk posture related to network controls.

  • Support execution of enterprise cyber risk management objectives and control improvement initiatives across Saas platforms in support of client deliverables.

Security Architecture & Design Influence

  • Partner with network and cloud engineering teams to embed securitybydesign and resilience principles across onprem, cloud, and hybrid networks.

  • Review and influence network segmentation, trust boundaries, ingress/egress controls, and monitoring strategies.

  • Influence the alignment with security patterns with enterprise standards, zero trust principles, and regulatory obligations while working with cyber threat intel to build models.

  • Partner with GCS Security Guardians to ensure current network security principals and guidance are updated and documented.

Vulnerability and Exposure Management

  • Partner with vulnerability management teams to prioritize remediation activities based on risk.

  • Analyze vulnerability trends, systemic control weaknesses, and emerging threat exposures.

  • Provide advisory support on patch management, configuration management, and security hardening efforts.

  • Assist business and technology teams in developing sustainable remediation strategies.

Risk Assessment & Control Governance

  • Lead or support network security risk assessments, control gap analysis, and prioritization aligned to enterprise risk frameworks.

  • Track remediation of identified control gaps and provide transparent risk reporting and escalation as needed.

  • Support internal audits, regulatory reviews, and risk committees by articulating network security posture and key risks.

Threat and Incident Advisory

  • Provide advisory support during cyber incidents and events, including impact analysis, containment strategy guidance, and participate in playbook refinement.

  • Partner with threat intelligence teams, cyber defense center, and vulnerability management teams to interpret emerging threats, model exposure, and appropriate remediation.

Qualifications and Experience

  • Strong technical understanding of enterprise networking concepts and security controls.

  • Strong experience with network security technologies, secure cloud, Secure SDLC practices

  • Experience in securing Software-as-a-Service delivery models (Identity, Data Protection, Monitoring, and Governance)

  • Ability to assess architecture diagrams and design documents for security risk.

  • Experience in cyber risk assessment, control evaluation, and remediation tracking.

  • Strong written and verbal communication skills; able to influence without direct authority.

  • Experience in regulated financial services or similarly complex environments.

  • Exposure to regulatory expectations (e.g., FFIEC, NIST, ISO, SOC, or equivalent frameworks).

  • Experience supporting audits, regulators, or executive risk forums.

Salary Range:

$90,000 - $157,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.