1

Security Risk Manager Jobs in Massachusetts (NOW HIRING)

Experience with security risk management techniques and tactics. * Experience working in a regulated environment, FDA-regulated preferred. * Demonstrated organizational skills, attention to detail ...

Security Technical Implementation Guides (STIGs), NIST 800-53/Risk Management Framework (RMF), CNSSI 1253, and DOD Manual 5205.07 Volumes 1-4, NIST SP 800-171 and DAAPM 2.0. The IT Security Risk ...

Security and innovation treated as mutually reinforcing priorities * Define a new function at the ... Strong judgment and risk assessment capability * Experience working cross-functionally with IT and ...

They are seeking a Senior Security Compliance Engineer to design and optimize automated compliance ... into risk management workflows • Implement and customize compliance automation platforms (e.g.

next page

Showing results 1-20

Security Risk Manager information

See Massachusetts salary details

$15

$28

$57

How much do security risk manager jobs pay per hour?

As of Jul 21, 2026, the average hourly pay for security risk manager in Massachusetts is $28.37, according to ZipRecruiter salary data. Most workers in this role earn between $19.95 and $32.02 per hour, depending on experience, location, and employer.

How much does a risk manager get paid?

A Security Risk Manager's average salary in the United States ranges from $80,000 to $130,000 annually, depending on experience, certifications, and industry. Senior roles or those with specialized skills can earn higher salaries, often exceeding $150,000. Compensation may also include bonuses and benefits related to security and risk management tools.

What is the difference between Security Risk Manager vs Security Analyst?

AspectSecurity Risk ManagerSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP (optional)
Work EnvironmentStrategic, managerial, policy-focusedOperational, monitoring, incident response
Employer & Industry UsageOrganizations with risk management frameworksIT departments, cybersecurity teams

The Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and frameworks. In contrast, the Security Analyst handles day-to-day security monitoring, incident response, and vulnerability assessments. Both roles require cybersecurity certifications, but the Risk Manager's role is more strategic, while the Analyst's role is more technical and operational.

What are some common challenges Security Risk Managers face when implementing new security policies within an organization?

Security Risk Managers often encounter challenges such as resistance to change from employees, balancing security needs with business operations, and ensuring compliance with industry regulations. Gaining buy-in from various stakeholders requires strong communication and education efforts, as some team members may perceive new protocols as disruptive. Additionally, Security Risk Managers must continuously assess evolving threats while adapting policies to keep the organization protected without hindering productivity.

What are the key skills and qualifications needed to thrive as a Security Risk Manager, and why are they important?

To thrive as a Security Risk Manager, you need a solid understanding of risk assessment, security protocols, and regulatory compliance, typically supported by a degree in cybersecurity, information security, or a related field. Familiarity with risk management frameworks (like ISO 27001 or NIST), security information and event management (SIEM) systems, and certifications such as CISSP or CISM are commonly required. Strong analytical thinking, communication, and leadership skills help you effectively identify vulnerabilities and collaborate with stakeholders. These competencies are crucial for proactively managing threats, ensuring organizational resilience, and maintaining regulatory compliance.

What is the highest salary for a risk manager?

The highest salary for a Security Risk Manager can exceed $150,000 annually, especially for those with extensive experience, advanced certifications like CISSP or CISM, and leadership roles in large organizations. Salaries vary based on industry, location, and the complexity of security environments managed.

What does a security risk manager do?

A security risk manager assesses and identifies potential security threats to an organization’s information systems and physical assets. They develop strategies, implement policies, and oversee security measures to mitigate risks, often using tools like risk assessment frameworks and security audits. Strong analytical skills and relevant certifications such as CISSP or CISM are typically required.

Can I make $200,000 a year in cyber security?

Security Risk Managers with extensive experience, advanced certifications, and specialized skills can potentially earn $200,000 or more annually, especially in high-demand industries or senior roles. Salary levels depend on factors such as location, company size, and individual expertise, with senior positions often offering higher compensation.
What cities in Massachusetts are hiring for Security Risk Manager jobs? Cities in Massachusetts with the most Security Risk Manager job openings:
Infographic showing various Security Risk Manager job openings in Massachusetts as of July 2026, with employment types broken down into 83% Full Time, 13% Part Time, 3% Temporary, and 1% Contract. Highlights an 92% Physical, 4% Hybrid, and 4% Remote job distribution, with an average salary of $59,015 per year, or $28.4 per hour.
Lead Product Security Engineer

Lead Product Security Engineer

Johnson & Johnson

Danvers, MA • Hybrid

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 25 days ago


Johnson & Johnson rating

8.2

Company rating: 8.2 out of 10

Based on 110 frontline employees who took The Breakroom Quiz

29th of 74 rated pharmaceutical


Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Solution Architecture

Job Category:

Scientific/Technology

All Job Posting Locations:

Danvers, Massachusetts, United States of America, Raritan, New Jersey, United States of America

Job Description:

J&J Heart Recovery is redefining team-driven success while reshaping heart recovery. Here, new ideas are welcomed and encouraged, learning is constant, and our dynamic setting enables positive people to do profoundly important work.

As the solutions we provide to patients and health care providers evolve from a technological standpoint, we must remain vigilant in our cybersecurity efforts to ensure we are providing the highest quality devices. We accomplish this by incorporating cybersecurity activities across the total-product-lifecycle of our solutions and integrating these processes with our Quality Management System.

Are you passionate about security and interested in joining a community of collaborative colleagues working in a Patient First! culture If that's you, heart recovery has an immediate opportunity for a Product Security Analyst to join the newly formed Product Security team to help ensure security is implemented by design for this top-performing medical device company. This is an exciting opportunity to impact development initiatives that will shape future product development and industry standards. You will own the Product Security process that includes both pre-market and post-market processes engineering teams leverage throughout the product development lifecycle. If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives, this could be perfect for you.

Primary Duties And Responsibilities:

  • Partner with engineering and other cross-functional teams (cloud, console, pump, etc.) to drive successful adherence to J&J Heart Recovery's product security program.
  • Deliver documentation for pre-market development activities including security plans, architecture and data flow diagrams, threat models, requirements, SBOM, and risk documentation.
  • Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
  • Monitor and drive post-market vulnerability management activities, with adherence to strict timelines.
  • Support compliance certification activities, such as SOC2, FedRAMP, ISO 27001, etc.
  • Identify, research, evaluate, and integrate new compliance requirements and industry standards/trends into the product security program.
  • Guide teams to make decisions that balance business needs with security objectives.
  • Thinks across organizational boundaries and empathizes with customers, both internal and external.
  • Perform other related duties and responsibilities, as assigned.

Job Qualifications:

  • Bachelor's degree in Computer Science, Information Systems, or related field.
  • 4+ years industry experience in Information Security.
  • Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR).
  • Experience with security risk management techniques and tactics.
  • Experience working in a regulated environment, FDA-regulated preferred.
  • Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be able to meet assigned deadlines.
  • Committed to working with a sense of urgency and embracing new challenges.
  • Strong communication and interpersonal skills.

Other:

  • Up to 20% travel.

#LI-Hybrid

#JNJTECH

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants' needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.

Required Skills:

Preferred Skills:

The anticipated base pay range for this position is :

The anticipated base pay range for this position is: $94,000- $151,800

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees and/or eligible dependents are eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance. Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, Employees are eligible for the following time off benefits: Vacation -120 hours per calendar year Sick time - 40 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year Holiday pay, including Floating Holidays -13 days per calendar year Work, Personal and Family Time - up to 40 hours per calendar year Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child Condolence Leave - 30 days for an immediate family member: 5 days for an extended family member Caregiver Leave - 10 days Volunteer Leave - 4 days Military Spouse Time-Off - 80 hours Additional information can be found through the link below. https://www.careers.jnj.com/employee-benefits

What Johnson & Johnson employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom