1

Senior Technology Risk Management Jobs in Boston, MA

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior IT Risk Analyst (First Line of Defense) Rockland Trust is seeking a Senior IT Risk Analyst to advance the Bank's First Line of Defense IT Risk Management Program. This is a hybrid role, 3 days ...

Senior Principal, Internal Audit, IT

Bedford, MA · On-site

$88K - $110K/yr

Senior Principal, Internal Audit, IT Here at Entegris, we use advanced science to enable ... Deep knowledge of technology risk management, IT general controls, cybersecurity, cloud ...

Senior Principal, Internal Audit, IT

Bedford, MA · On-site

$88K - $110K/yr

Senior Principal, Internal Audit, IT Here at Entegris, we use advanced science to enable ... Deep knowledge of technology risk management, IT general controls, cybersecurity, cloud ...

next page

Showing results 1-20

Senior Technology Risk Management information

See Boston, MA salary details

$24.4K

$128.5K

$228.1K

How much do senior technology risk management jobs pay per year?

As of Jul 26, 2026, the average yearly pay for senior technology risk management in Boston, MA is $128,476.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,800.00 and $157,500.00 per year, depending on experience, location, and employer.

What does a technology risk manager do?

A technology risk manager identifies, assesses, and mitigates risks related to information technology and cybersecurity within an organization. They develop policies, implement controls, and monitor systems to ensure data security and compliance, often using tools like risk assessment frameworks and security protocols. Strong analytical skills and knowledge of industry standards such as ISO 27001 or NIST are essential for this role.

How much does a senior technology risk analyst make at Fidelity?

A senior technology risk analyst at Fidelity typically earns between $90,000 and $130,000 annually, depending on experience, location, and certifications. The role often requires knowledge of risk assessment tools and regulatory compliance standards.

What is the highest salary for a risk manager?

Senior Technology Risk Management professionals can earn salaries up to $150,000 or higher annually, depending on experience, certifications, and the size of the organization. Top earners in this field often have advanced skills in cybersecurity, compliance, and risk assessment, and may receive bonuses or other incentives.

How does a Senior Technology Risk Management professional typically collaborate with other departments within an organization?

A Senior Technology Risk Management professional regularly works with teams across IT, compliance, internal audit, and business units to identify, assess, and mitigate technology-related risks. This collaboration often involves participating in cross-functional meetings, providing guidance on risk controls, and ensuring that technology initiatives align with the overall risk appetite of the organization. Strong communication skills are essential, as the role requires translating complex technical risks into actionable recommendations for non-technical stakeholders. Building solid relationships with various departments is crucial to effectively manage and respond to emerging risks.

What are the key skills and qualifications needed to thrive as a Senior Technology Risk Management professional, and why are they important?

To thrive as a Senior Technology Risk Management professional, you need a deep understanding of IT risk frameworks, cybersecurity principles, and regulatory requirements, often supported by a degree in information security or related fields and certifications like CISA, CISSP, or CRISC. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and incident management systems is typically required. Strong analytical thinking, communication skills, and stakeholder management abilities help professionals excel in this role. These skills and qualities are vital for effectively identifying, assessing, and mitigating technology risks to protect organizational assets and ensure regulatory compliance.

What is the difference between Senior Technology Risk Management vs Cybersecurity Analyst?

AspectSenior Technology Risk ManagementCybersecurity Analyst
Required CredentialsCertifications like CRISC, CISSP, CISACertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability assessment
Employer & Industry UsageFinancial, healthcare, large enterprisesIT firms, government agencies, tech companies

While both roles focus on security, Senior Technology Risk Management emphasizes strategic risk assessment and mitigation planning, whereas Cybersecurity Analysts focus on technical security operations and incident response. The roles often collaborate but differ in scope and daily responsibilities.

What is the highest paying risk management job?

In risk management, senior roles such as Chief Risk Officer (CRO) or Director of Risk Management tend to have the highest salaries, often exceeding six figures annually. These positions require extensive experience, advanced certifications like FRM or CRM, and strong leadership skills, especially in financial services, insurance, or large corporations.

What is Senior Technology Risk Management?

Senior Technology Risk Management refers to a leadership role responsible for identifying, assessing, and mitigating technology-related risks within an organization. Professionals in this position develop risk management strategies, ensure compliance with regulations, and oversee the implementation of security controls to protect information systems. They collaborate with IT, business, and compliance teams to address vulnerabilities and respond to emerging threats. Their work helps safeguard critical assets and supports the organization's overall risk management framework.
What are the most commonly searched types of Technology Risk Management jobs in Boston, MA? The most popular types of Technology Risk Management jobs in Boston, MA are:
What are popular job titles related to Senior Technology Risk Management jobs in Boston, MA? For Senior Technology Risk Management jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Senior Technology Risk Management jobs in Boston, MA look for? The top searched job categories for Senior Technology Risk Management jobs in Boston, MA are:
What cities near Boston, MA are hiring for Senior Technology Risk Management jobs? Cities near Boston, MA with the most Senior Technology Risk Management job openings:
Infographic showing various Senior Technology Risk Management job openings in Boston, MA as of July 2026, with employment types broken down into 87% Full Time, 10% Part Time, 1% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $128,476 per year, or $61.8 per hour.
Principal/Senior Technology Risk Analyst

Principal/Senior Technology Risk Analyst

Berkshire Hathaway Specialty Insurance

Boston, MA • On-site

$160K - $180K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago


Job description

Who are we?


A strategic and trusted insurance partner, Berkshire Hathaway Specialty Insurance (BHSI), provides a broad range of commercial property, casualty and specialty insurance coverages and outstanding service to customers and brokers around the world. Part of Berkshire Hathaway’s insurance operations, we bring our solutions to market with our stellar brand name, top-rated balance sheet, and the expertise of our global team of professionals, who exude excellent capabilities and strong character.


We are a values-based organization where respect, integrity, excellence, collaboration, and passion define who we are and how we do business. We value diversity of backgrounIds, experience, and perspectives and strive to foster an inclusive environment that enables all our team members to bring their best selves to work. We are one team committed to building a culture where every teammate has the opportunity to contribute and be recognized. Want to be part of the team building the finest property, casualty and specialty lines insurance company in the world?


Learn more about our unique culture and history.


Job Opportunity:

Berkshire Hathaway Specialty Insurance (BHSI) has an exciting opportunity for a new team member to join their Boston-based Technology Governance Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst. In this newly created role, the Technology Senior Risk Analyst will support and mature the Technology Risk Management pillar, ensuring technology risks are proactively identified, assessed, communicated, and monitored across the enterprise. This role will build strong partnerships with Technology leadership and collaborate closely with teams across BHSI to evaluate our Technology risk posture, provide independent challenge, and recommend practical risk‑reducing actions aligned with our established risk appetite. If you're passionate about elevating enterprise Technology risk practices, driving meaningful change, and growing your career as a key contributor to our evolving global IT risk program, we’re interested in speaking with you.


Duties & Responsibilities:

  • Lead risk identification, risk assessment, and ongoing monitoring; maintain the Technology risk register and ensure risks map to business objectives and risk appetite/tolerances.
  • Drive Risk and Control Self‑Assessments (RCAs) with different risk and control owners; advise on control design for identity & access, change/release, resiliency/DR, cloud security, data protection, and vulnerability management.
  • Define and socialize KRIs/KPIs, risk dashboards, trends, and heat maps; deliver clear status to Technology leadership, and key stakeholders.
  • Partner with Vendor Risk Management Team to evaluate critical vendors (including AI‑enabled services), review SOC reports/certifications, assess control gaps, and track remediation/compensating controls through closure.
  • Track risk issues, action plans, and target dates; validate remediation and retest where needed; participate in lessons‑learned and scenario exercises.
  • Provide support to our offices from both a U.S. and global perspective (i.e., Asia, Middle East, UK, Europe, Australasia, etc.) regarding the fulfillment of Technology risk related requests and obligations.
  • Assess AI/automation use cases for explainability, privacy, security, and bias risk; ensure appropriate documentation, monitoring, and governance are in place.
  • Educate teams on risk expectations, evidence quality, and the “why” behind controls; help embed risk thinking into delivery and operations.
  • Attend/participate in e-learning training sessions to increase background knowledge of the ever-evolving Technology regulatory landscape.

Qualifications, Skills and Experience:

  • 10+ years of experience in Technology risk, Technology audit/compliance, or cyber GRC.
  • Experience running RCSAs, defining KRIs/KPIs, and presenting risk insights to senior stakeholders.
  • Strong documentation skills, including writing risk narratives, control designs, control matrices, testing procedures, and remediation plans.
  • Effective communication and partnership skills; able to challenge constructively and receive challenge professionally.
  • Experience conducting vendor risk reviews, including SOC 2 analysis, control gap identification, and remediation follow‑up.
  • Solid background knowledge of major risk and control frameworks (Technology, Cyber, Enterprise), such as NIST CSF, COSO ERM, COBIT, etc.
  • Working knowledge of U.S. Technology regulations (e.g., SOX, CCPA/CPRA, PCI, NY‑DFS) is recommended.
  • Familiarity with global regulatory frameworks (e.g., GDPR, CBI, DORA, MAS, APRA, BaFin) is preferred but not required.
  • Ability to work in a team-based environment and communicate effectively and efficiently with others domestically and globally.
  • Experience with GRC tools such as Workiva, AuditBoard, ServiceNow, Drata, Vanta, or similar platforms is a plus.
  • AI experience is a plus, including an understanding of AI risks, responsible AI concepts, or emerging AI regulatory requirements.
  • Professional certifications such as CRISC, CISA, CISM, CISSP, or ISO/IEC 27001 Lead Implementer/Lead Auditor (or equivalent) are a plus.


BHSI Offers:


  • A competitive package and exciting growth opportunities for career-oriented teammates.
  • A dynamic, action oriented, and thoughtful environment centered on always doing the right thing for our customers, teammates and our other stakeholders.
  • A purposely non-bureaucratic organization that embraces simplicity over complexity and emphasizes individual excellence in a team framework.
  • Benefits that support your life and well-being, which include:
    • Comprehensive Health, Dental and Vision benefits.
    • Disability Insurance (both short-term and long-term).
    • Life Insurance (for you and your family).
    • Accidental Death & Dismemberment Insurance (for you and your family).
    • Flexible Spending Accounts.
    • Health Reimbursement Account.
    • Employee Assistance Program.
    • Retirement Savings 401(k) Plan with Company Match.
    • Generous holiday and Paid Time Off.
    • Tuition Reimbursement.
    • Paid Parental Leave.


The base salary range for this position in Boston is $160,000.00 to $180,000.00, along with annual bonus eligibility. Total compensation for a candidate is determined by their relevant skills, location, and experience. We value our teammates – both their capabilities and character – as demonstrated by our amazing culture.


NOTE: Compensation will be commensurate with experience. This job description is not intended to be all-inclusive. Team Member may perform other related duties as negotiated to meet the ongoing needs of the organization.