Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 ...
Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 ...
Senior Technical Program Manager, Information Security
$140K - $170K/yr
Run risk analysis, contingency planning, and trade-off conversations with senior stakeholders ... Manage the Information Security Risk Management lifecycle by partnering with engineering and ...
Quick apply
Senior Technical Program Manager, Information Security
$140K - $170K/yr
Run risk analysis, contingency planning, and trade-off conversations with senior stakeholders ... Manage the Information Security Risk Management lifecycle by partnering with engineering and ...
Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0. The IT Security Risk ...
Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0. The IT Security Risk ...
The leader oversees physical security, incident response, and risk management while partnering closely with the Corporate Security Center of Excellence (CoE) to align on enterprise standards and best ...
The leader oversees physical security, incident response, and risk management while partnering closely with the Corporate Security Center of Excellence (CoE) to align on enterprise standards and best ...
Technology Risk and Governance
Boston, MA · On-site
$110K - $315K/yr
Job Overview The position reports to the Chief Information Security Officer and leads the ... This role is a key contributor to enterprise risk management, partnering with the Chief Compliance ...
Technology Risk and Governance
Boston, MA · On-site
$110K - $315K/yr
Job Overview The position reports to the Chief Information Security Officer and leads the ... This role is a key contributor to enterprise risk management, partnering with the Chief Compliance ...
Technology Risk and Governance
Boston, MA · On-site
$110K - $315K/yr
Job Overview The position reports to the Chief Information Security Officer and leads the ... This role is a key contributor to enterprise risk management, partnering with the Chief Compliance ...
Technology Risk and Governance
Boston, MA · On-site
$110K - $315K/yr
Job Overview The position reports to the Chief Information Security Officer and leads the ... This role is a key contributor to enterprise risk management, partnering with the Chief Compliance ...
Security Compliance Manager
Boston, MA · Remote
$140K - $170K/yr
Risk management program execution: Recommend and implement improvements to the information security risk management program; develop and maintain the risk register, risk ownership, and workflows for ...
Quick apply
Security Compliance Manager
Boston, MA · Remote
$140K - $170K/yr
Risk management program execution: Recommend and implement improvements to the information security risk management program; develop and maintain the risk register, risk ownership, and workflows for ...
Senior Manager, Risk Operations
Boston, MA · On-site
$147K - $157K/yr
Modernizes risk management and tests using data investigation. Builds risk management reporting ... Risk Please be advised that Fidelity's business is governed by the provisions of the Securities ...
Senior Manager, Risk Operations
Boston, MA · On-site
$147K - $157K/yr
Modernizes risk management and tests using data investigation. Builds risk management reporting ... Risk Please be advised that Fidelity's business is governed by the provisions of the Securities ...
Senior Manager, Risk Operations
Boston, MA · On-site
$147K - $157K/yr
Modernizes risk management and tests using data investigation. Builds risk management reporting ... Risk Please be advised that Fidelity's business is governed by the provisions of the Securities ...
Senior Manager, Risk Operations
Boston, MA · On-site
$147K - $157K/yr
Modernizes risk management and tests using data investigation. Builds risk management reporting ... Risk Please be advised that Fidelity's business is governed by the provisions of the Securities ...
Working with the Project Manager, Business Users and Infrastructure team you will have a hands on ... Information Security * Experience with project and/or program management, whether business ...
Working with the Project Manager, Business Users and Infrastructure team you will have a hands on ... Information Security * Experience with project and/or program management, whether business ...
Risk Management - Capital Markets
Boston, MA · On-site
$125K - $180K/yr
... manager portfolios, including analysis of margin levels, stress scenario results, and exposure ... securities on an ad-hoc basis; and maintain and update collateral schedules for State Street ...
Risk Management - Capital Markets
Boston, MA · On-site
$125K - $180K/yr
... manager portfolios, including analysis of margin levels, stress scenario results, and exposure ... securities on an ad-hoc basis; and maintain and update collateral schedules for State Street ...
Risk Management - Capital Markets
Boston, MA · Hybrid
$125K - $180K/yr
... manager portfolios, including analysis of margin levels, stress scenario results, and exposure ... securities on an ad-hoc basis; and maintain and update collateral schedules for State Street ...
Risk Management - Capital Markets
Boston, MA · Hybrid
$125K - $180K/yr
... manager portfolios, including analysis of margin levels, stress scenario results, and exposure ... securities on an ad-hoc basis; and maintain and update collateral schedules for State Street ...
Accomplished background in brokerage, insurance, investment adviser, and general securities matters ... Experience with Governance, Risk Management, and Compliance (GRC) platforms, preferably Archer.
Accomplished background in brokerage, insurance, investment adviser, and general securities matters ... Experience with Governance, Risk Management, and Compliance (GRC) platforms, preferably Archer.
First Line Risk Sr Manager
Boston, MA · On-site
Accomplished background in brokerage, insurance, investment adviser, and general securities matters ... Experience with Governance, Risk Management, and Compliance (GRC) platforms, preferably Archer.
First Line Risk Sr Manager
Boston, MA · On-site
Accomplished background in brokerage, insurance, investment adviser, and general securities matters ... Experience with Governance, Risk Management, and Compliance (GRC) platforms, preferably Archer.
Security Compliance Specialist
Lexington, MA · On-site
NIST SP 800-53 / Risk Management Framework (RMF) * NIST SP 800-171 * NISPOM (32 CFR Part 117 ... Security+ CE * CASP * CISSP * CISA * CCP/CCA or other industry-recognized cybersecurity ...
Security Compliance Specialist
Lexington, MA · On-site
NIST SP 800-53 / Risk Management Framework (RMF) * NIST SP 800-171 * NISPOM (32 CFR Part 117 ... Security+ CE * CASP * CISSP * CISA * CCP/CCA or other industry-recognized cybersecurity ...
Lead Product Security Engineer
Danvers, MA · On-site
Experience with security risk management techniques and tactics. * Experience working in a regulated environment, FDA-regulated preferred. * Demonstrated organizational skills, attention to detail ...
Lead Product Security Engineer
Danvers, MA · On-site
Experience with security risk management techniques and tactics. * Experience working in a regulated environment, FDA-regulated preferred. * Demonstrated organizational skills, attention to detail ...
... securities finance, brokerage services, and sales and trading in foreign exchange markets. What you ... Contribute to enhancing CCR limit framework and risk management systems to support new business ...
... securities finance, brokerage services, and sales and trading in foreign exchange markets. What you ... Contribute to enhancing CCR limit framework and risk management systems to support new business ...
Counterparty Credit Risk Manager, Prime Brokerage & Clearing, VP
Boston, MA · On-site
$120K - $202K/yr
... securities finance, brokerage services, and sales and trading in foreign exchange markets. What you ... Contribute to enhancing CCR limit framework and risk management systems to support new business ...
Counterparty Credit Risk Manager, Prime Brokerage & Clearing, VP
Boston, MA · On-site
$120K - $202K/yr
... securities finance, brokerage services, and sales and trading in foreign exchange markets. What you ... Contribute to enhancing CCR limit framework and risk management systems to support new business ...
... securities finance, brokerage services, and sales and trading in foreign exchange markets. What you ... Contribute to enhancing CCR limit framework and risk management systems to support new business ...
... securities finance, brokerage services, and sales and trading in foreign exchange markets. What you ... Contribute to enhancing CCR limit framework and risk management systems to support new business ...
Partner in the development, implementation, and ongoing management of scalable security control frameworks, policies, standards, and security awareness programs, third-party risk assessment, SDLC ...
Partner in the development, implementation, and ongoing management of scalable security control frameworks, policies, standards, and security awareness programs, third-party risk assessment, SDLC ...
Security Risk Manager information
See Massachusetts salary details
$15.23 - $19.05
17% of jobs
$20.03 is the 25th percentile. Wages below this are outliers.
$19.05 - $22.86
32% of jobs
The median wage is $23.17 / hr.
$22.86 - $26.68
20% of jobs
$29.33 is the 75th percentile. Wages above this are outliers.
$26.68 - $30.50
9% of jobs
$30.50 - $34.32
5% of jobs
$34.32 - $38.14
6% of jobs
$38.14 - $41.96
3% of jobs
$41.96 - $45.78
4% of jobs
$45.78 - $49.59
1% of jobs
$49.59 - $53.41
1% of jobs
$53.41 - $57.23
1% of jobs
$15
$28
$57
How much do security risk manager jobs pay per hour?
How much does a risk manager get paid?
What is the difference between Security Risk Manager vs Security Analyst?
| Aspect | Security Risk Manager | Security Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CISSP (optional) |
| Work Environment | Strategic, managerial, policy-focused | Operational, monitoring, incident response |
| Employer & Industry Usage | Organizations with risk management frameworks | IT departments, cybersecurity teams |
The Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and frameworks. In contrast, the Security Analyst handles day-to-day security monitoring, incident response, and vulnerability assessments. Both roles require cybersecurity certifications, but the Risk Manager's role is more strategic, while the Analyst's role is more technical and operational.
What are some common challenges Security Risk Managers face when implementing new security policies within an organization?
What are the key skills and qualifications needed to thrive as a Security Risk Manager, and why are they important?
What is the highest salary for a risk manager?
What does a security risk manager do?
Can I make $200,000 a year in cyber security?

Job description
An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services. This is achieved by providing a robust and secure technology foundation to do great work. We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment.
The STAR team assists the Global Security Services (GSS) organization in developing and refining information security policies, standards and strategy, enterprise risk management, creating metrics and reporting, coordinating cross-functional projects, and strategically aligning global information security initiatives with the broader CISO vision amongst other governance, risk and compliance efforts. The STAR team is highly collaborative and cross-functional, working closely with various functions within the GSS team (namely Security Product and Development and Security Intelligence Operations), Global Technology Solutions (GTS) team and the broader Klaviyo organization.
About the role:The Lead Security Governance & Risk Engineer is a senior, hands-on role at the point where security governance meets risk engineering. You will own the parts of the risk programme that turn policy and standards into measured, monitored, and automated risk decisions. Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 readiness, and build the automation that gives Klaviyo a continuously updated, quantified view of its risk posture.
You will work alongside the Trust and Compliance team who are the custodians of our security policies and standards, making sure each one connects to a specific risk it reduces and is enforced through operational controls rather than living as a document. You will partner closely with Engineering, Product, GTS, Legal, Internal Audit, the ARIA team, and Finance to make risk legible across the business, and you will challenge first-line teams credibly while keeping your independence. This is a role for an engineer who thinks like a risk professional: someone who automates repeatable assessment, instruments controls, quantifies risk in financial terms, and treats AI as foundational infrastructure rather than an afterthought.
How you'll have an impact:- Operate and maintain the risk register and taxonomy. Run the technology and third-party risk register on a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that risks aggregate, prioritise, and report meaningfully across the business.
- Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and risk criteria, maintain the consolidated AI risk register against the K:AI inventory, and define AI risk treatment plans that map each risk to specific controls and treatment decisions. Drive ISO/IEC 42001 readiness (Clauses 6.1 and 8.2/8.3) toward the certification target, working with the Trust & Compliance and ARIA teams.
- Drive third-party risk automation and risk scoring. Contribute vendor and application risk signals into the composite risk score, partnering with the TPRM lead who owns vendor onboarding automation and the TPRM process.
- Perform the hands-on risk quantification. Apply cyber risk quantification (expected loss, probability, and cost of remediation versus acceptance) so leadership and the Technology Risk Committee can make rational investment and risk-acceptance decisions rather than relying on qualitative severity labels.
- Support the risk governance cadence. Contribute to weekly risk huddles, monthly risk reviews, and the quarterly Technology Risk Committee (CIO, CISO, CTO), preparing accurate, succinct, decision-ready risk materials and translating high-severity findings into clear business impact.
- Operate as a second line of defense. Provide independent oversight, credible challenge, and guidance to first-line teams, apply consistent risk taxonomies and reporting standards, and escalate risks that exceed established tolerance.
- Partner cross-functionally and close the loop. Work with Engineering, Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk and audit findings affecting systems and processes, tracking findings and remediation through to closure with clear ownership.
- 7+ years of experience in information security, technology risk, cyber risk, or operational risk within a large, complex, or high-growth organization, including hands-on risk engineering or quantitative risk work.
- Strong command of cyber risk quantification, able to express risk in financial and business terms (FAIR, riskquant, or similar) rather than qualitative severity ratings alone.
- Hands-on engineering ability: SQL, Python, and integrating with APIs to extract, transform, and load data between systems and to automate risk reporting.
- Experience building and running a technology and/or third-party risk register and taxonomy, with the tooling and process automation behind it.
- Working knowledge of security and AI frameworks (NIST CSF and RMF, ISO 27000 series, ISO 42001, SOC 2, PCI DSS, CIS Controls) and how they translate into credible control requirements.
- Hands-on familiarity with modern risk and security tooling: third-party risk platforms, cyber risk quantification, vulnerability management, and endpoint and data-security telemetry, with a clear point of view on where AI augments versus replaces human judgement.
- Experience authoring and maintaining security policies and standards, with a governance mindset that ties policy to the risk it reduces and to operational controls.
- Able to operate independently as a second line of defense while engaging credibly with senior engineers, architects, and security teams.
- Proficiency discussing complex, nuanced topics with technical and non-technical audiences alike, and translating technical risk into clear business impact.
- Excellent ability to plan, prioritise, and execute work cross-functionally and on time.
- Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering-led, or AI-enabled risk capability.
- AI governance, model risk, or responsible-AI programme experience, and ISO 42001 readiness or certification work.
- Experience building metrics and dashboards (KPIs, KRIs, KCIs) using business intelligence or dashboarding tools like Tableau and so on.
- Experience in a regulated or high-trust environment (SOC 2, ISO 27000 series, ISO 42001, HIPAA, GDPR).
- Threat modeling or secure design reviews, and experience designing or implementing technical security controls in AWS.
- Experience securing web applications, Kubernetes clusters, and/or containers.
- Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, an ISO 42001 / AI governance certification, or Open FAIR.
About Klaviyo
Sourced by ZipRecruiter
Industry
Marketing
Company size
1,001 - 5,000 Employees
Headquarters location
Boston, MA, US
Year founded
2012