1

Technology Risk Jobs in Boston, MA (NOW HIRING)

Senior IT Audit Manager

Waltham, MA ยท On-site

$130 - $175/hr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... risk, and ensure timely execution of remediation efforts while enabling strategic technology ... investments to be implemented with appropriate governance. As the organization grows toward its ...

Senior Principal, Internal Audit, IT

Bedford, MA ยท On-site

$88K - $110K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Develop and maintain the enterprise IT risk assessment framework and technology audit universe, ensuring coverage of critical risks across infrastructure, cloud platforms, ERP systems, cybersecurity ...

Senior Principal, Internal Audit, IT

Bedford, MA ยท On-site

$88K - $110K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Develop and maintain the enterprise IT risk assessment framework and technology audit universe, ensuring coverage of critical risks across infrastructure, cloud platforms, ERP systems, cybersecurity ...

Senior IT Audit Manager

Waltham, MA ยท On-site

$130 - $175/hr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... risk, and ensure timely execution of remediation efforts while enabling strategic technology ... investments to be implemented with appropriate governance. As the organization grows toward its ...

Sr Risk Analyst

Newton, MA ยท Hybrid

  • Medical

  • Dental

  • Vision

  • Retirement

TTGT) informs, influences and connects the world's technology buyers and sellers, to accelerate ... Conduct risk assessments for new technologies, systems, and business initiatives in partnership ...

New

Sr Risk Analyst

Newton, MA ยท On-site

  • Medical

  • Dental

  • Vision

  • Retirement

TTGT) informs, influences and connects the world's technology buyers and sellers, to accelerate ... Conduct risk assessments for new technologies, systems, and business initiatives in partnership ...

New

Senior IT Audit Manager

Waltham, MA ยท On-site

$130K - $175K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

This role will strengthen the company's control environment, reduce compliance and operational risk, and ensure timely execution of remediation efforts while enabling strategic technology investments ...

Showing results 41-60

Technology Risk information

See Boston, MA salary details

$15

$32

$80

How much do technology risk jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for technology risk in Boston, MA is $32.96, according to ZipRecruiter salary data. Most workers in this role earn between $21.15 and $42.07 per hour, depending on experience, location, and employer.

What is technology risk?

Technology risk refers to the potential for losses or disruptions in an organization due to failures, vulnerabilities, or misuse of technology systems and infrastructure. Professionals in technology risk assess, manage, and mitigate risks related to cybersecurity, data privacy, IT systems, and compliance with regulations. Their work is crucial for protecting sensitive information, ensuring business continuity, and maintaining trust with clients and stakeholders.

What are the key skills and qualifications needed to thrive in technology risk, and why are they important?

To thrive in Technology Risk, you need a solid understanding of IT systems, cybersecurity principles, risk management frameworks, and often a degree in information technology or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, vulnerability assessment software, and certifications such as CISA, CISSP, or CRISC are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess threats and convey complex risk issues to diverse stakeholders. These skills ensure organizations can proactively identify, assess, and mitigate technology risks to protect assets and maintain regulatory compliance.

What are some common challenges faced by professionals working in technology risk roles?

Professionals in Technology Risk often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring regulatory compliance across different jurisdictions, and effectively communicating technical risks to non-technical stakeholders. Balancing proactive risk mitigation with the need to support business innovation can also be demanding. Collaboration with IT, legal, and business units is essential to identify vulnerabilities and implement practical controls without hindering productivity.

What is the difference between Technology Risk vs Cybersecurity Analyst?

AspectTechnology RiskCybersecurity Analyst
Primary FocusIdentifying and managing technology-related risks to business operationsProtecting systems and data from cyber threats and attacks
CertificationsCRISC, CISSP, CISACISSP, CEH, Security+
Work EnvironmentRisk management teams, compliance departmentsSecurity operations centers, IT security teams
Industry UsageFinance, healthcare, technology firmsAny industry with digital assets, especially finance and government

Technology Risk professionals focus on assessing and mitigating risks associated with technology systems and processes, ensuring compliance and reducing potential disruptions. Cybersecurity Analysts primarily work to defend systems from cyber threats, focusing on security measures and incident response. While both roles involve technology and security, their core objectives and daily tasks differ significantly.

What are the most commonly searched types of Technology Risk jobs in Boston, MA?

The most popular types of Technology Risk jobs in Boston, MA are:

What are popular job titles related to Technology Risk jobs in Boston, MA?

For Technology Risk jobs in Boston, MA, the most frequently searched job titles are:

Infographic showing various Technology Risk job openings in Boston, MA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $68,551 per year, or $33 per hour.

Lead Security Governance & Risk Engineer

Klaviyo Inc.

Boston, MA โ€ข On-site

$156 - $234/hr

Other

Re-posted 5 days ago


Job description

Lead Security Governance & Risk Engineer

IT & Security

The STAR team assists the Global Security Services (GSS) organization in developing and refining information security policies, standards and strategy, enterprise risk management, creating metrics and reporting, coordinating cross-functional projects, and strategically aligning global information security initiatives with the broader CISO vision amongst other governance, risk and compliance efforts.

The Lead Security Governance & Risk Engineer is a senior, hands-on role at the point where security governance meets risk engineering. You will own the parts of the risk programme that turn policy and standards into measured, monitored, and automated risk decisions. Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 readiness, and build the automation that gives Klaviyo a continuously updated, quantified view of its risk posture.

You will work alongside the Trust and Compliance team who are the custodians of our security policies and standards, making sure each one connects to a specific risk it reduces and is enforced through operational controls rather than living as a document. You will partner closely with Engineering, Product, GTS, Legal, Internal Audit, the ARIA team, and Finance to make risk legible across the business, and you will challenge first-line teams credibly while keeping your independence. This is a role for an engineer who thinks like a risk professional: someone who automates repeatable assessment, instruments controls, quantifies risk in financial terms, and treats AI as foundational infrastructure rather than an afterthought.

How youโ€™ll have an impact:
  • Operate and maintain the risk register and taxonomy. Run the technology and third-party risk register on a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that risks aggregate, prioritise, and report meaningfully across the business.
  • Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and risk criteria, maintain the consolidated AI risk register against the K:AI inventory, and define AI risk treatment plans that map each risk to specific controls and treatment decisions. Drive ISO/IEC 42001 readiness (Clauses 6.1 and 8.2/8.3) toward the certification target, working with the Trust & Compliance and ARIA teams.
  • Drive third-party risk automation and risk scoring. Contribute vendor and application risk signals into the composite risk score, partnering with the TPRM lead who owns vendor onboarding automation and the TPRM process.
  • Perform the hands-on risk quantification. Apply cyber risk quantification (expected loss, probability, and cost of remediation versus acceptance) so leadership and the Technology Risk Committee can make rational investment and risk-acceptance decisions rather than relying on qualitative severity labels.
  • Support the risk governance cadence. Contribute to weekly risk huddles, monthly risk reviews, and the quarterly Technology Risk Committee (CIO, CISO, CTO), preparing accurate, succinct, decision-ready risk materials and translating high-severity findings into clear business impact.
  • Operate as a second line of defense. Provide independent oversight, credible challenge, and guidance to first-line teams, apply consistent risk taxonomies and reporting standards, and escalate risks that exceed established tolerance.
  • Partner cross-functionally and close the loop. Work with Engineering, Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk and audit findings affecting systems and processes, tracking findings and remediation through to closure with clear ownership.
Who you are:
  • 7+ years of experience in information security, technology risk, cyber risk, or operational risk within a large, complex, or high-growth organization, including hands-on risk engineering or quantitative risk work.
  • Strong command of cyber risk quantification, able to express risk in financial and business terms (FAIR, riskquant, or similar) rather than qualitative severity ratings alone.
  • Hands-on engineering ability: SQL, Python, and integrating with APIs to extract, transform, and load data between systems and to automate risk reporting.
  • Experience building and running a technology and/or third-party risk register and taxonomy, with the tooling and process automation behind it.
  • Working knowledge of security and AI frameworks (NIST CSF and RMF, ISO 27000 series, ISO 42001, SOC 2, PCI DSS, CIS Controls) and how they translate into credible control requirements.
  • Hands-on familiarity with modern risk and security tooling: third-party risk platforms, cyber risk quantification, vulnerability management, and endpoint and data-security telemetry, with a clear point of view on where AI augments versus replaces human judgement.
  • Experience authoring and maintaining security policies and standards, with a governance mindset that ties policy to the risk it reduces and to operational controls.
  • Able to operate independently as a second line of defense while engaging credibly with senior engineers, architects, and security teams.
  • Proficiency discussing complex, nuanced topics with technical and non-technical audiences alike, and translating technical risk into clear business impact.
  • Excellent ability to plan, prioritise, and execute work cross-functionally and on time.
Nice to have:
  • Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering-led, or AI-enabled risk capability.
  • AI governance, model risk, or responsible-AI programme experience, and ISO 42001 readiness or certification work.
  • Experience building metrics and dashboards (KPIs, KRIs, KCIs) using business intelligence or dashboarding tools like Tableau.
  • Experience in a regulated or high-trust environment (SOC 2, ISO 27000 series, ISO 42001, HIPAA, GDPR).
  • Threat modeling or secure design reviews, and experience designing or implementing technical security controls in AWS.
  • Experience securing web applications, Kubernetes clusters, and/or containers.
  • Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, an ISO 42001 / AI governance certification, or Open FAIR.

Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Our salary range reflects the cost of labor across various U.S. geographic markets. The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations. The base salary offered for this position is determined by several factors, including the applicantโ€™s job-related skills, relevant experience, education or training, and work location.

In addition to base salary, our total compensation package may include participation in the companyโ€™s annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing benefits based on eligibility.

Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process.

Base Pay Range For US Locations:

$156,000 โ€” $234,000 USD

This role may require up to 10% travel for purposes such as new hire onboarding, client or partner work if applicable, team meetings, and industry events. Travel is coordinated in advance.

#J-18808-Ljbffr