1

Vendor Risk Jobs in Massachusetts (NOW HIRING)

Governance Analyst

Boston, MA ยท On-site

$49 - $65.25/hr

Act as the technical vendor relationship manager for selected third-party technology and infrastructure partners. Technology Risk & Information Security * Conduct technical risk assessments on ...

New

Complete vendor risk assessments in accordance with approved methodologies, client requirements, and internal quality standards * Communicate findings and recommendations to clients in clear ...

Complete vendor risk assessments in accordance with approved methodologies, client requirements, and internal quality standards * Communicate findings and recommendations to clients in clear ...

Complete vendor risk assessments in accordance with approved methodologies, client requirements, and internal quality standards * Communicate findings and recommendations to clients in clear ...

Complete vendor risk assessments in accordance with approved methodologies, client requirements, and internal quality standards * Communicate findings and recommendations to clients in clear ...

Director, Business Applications (Boston)

Boston, MA ยท On-site

$247K/yr

Partner with Security, Legal, and Compliance teams to implement and maintain enterprise standards for identity and access management, data governance, vendor risk management, regulatory compliance ...

Showing results 21-40

Vendor Risk information

What is the difference between Vendor Risk vs Vendor Compliance?

AspectVendor RiskVendor Compliance
FocusIdentifying and mitigating risks associated with vendorsEnsuring vendors meet regulatory and contractual requirements
CertificationsRisk management certifications (e.g., CRISC, FAIR)Compliance certifications (e.g., ISO 27001, SOC 2)
Work EnvironmentRisk assessment teams, procurement, security departmentsLegal, compliance, audit teams
Industry UsageFinancial, healthcare, technology sectorsFinancial services, healthcare, regulated industries

Vendor Risk and Vendor Compliance roles often overlap but serve different purposes. Vendor Risk focuses on identifying and mitigating potential risks posed by vendors, while Vendor Compliance ensures vendors adhere to legal and contractual standards. Both are essential for managing vendor relationships effectively and maintaining organizational security and compliance.

What are the most commonly searched types of Vendor Risk jobs in Massachusetts? The most popular types of Vendor Risk jobs in Massachusetts are:
What cities in Massachusetts are hiring for Vendor Risk jobs? Cities in Massachusetts with the most Vendor Risk job openings:
Infographic showing various Vendor Risk job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Governance Analyst

SMART TECH SKILLS LLC

Boston, MA โ€ข On-site

$49 - $65.25/hr

Full-time

Posted 3 days ago

New


Job description

Benefits:
  • Competitive salary

Location
Boston, MA
Experience Level
Senior Level (5 to 8 or more years of experience)
Role Overview
The Senior Technology Governance Analyst oversees the enterprise technology governance framework, lifecycle management processes, and IT compliance policies. This role designs, implements, and maintains IT standards and procedures while ensuring all technology assets are tracked from procurement to retirement. Drawing on a background in technology audit, risk management, and information security, the analyst bridges the gap between technical operations and regulatory compliance, ensuring that infrastructure remains secure, resilient, and fully aligned with business requirements. This is a contract position for 6 or more months.
Key Responsibilities
Standards, Policies, & Procedures

• Draft, review, and update comprehensive IT policies, procedures, and technical standards to align with industry frameworks such as ISO, COBIT, NIST, and ITIL.
• Drive organization-wide adoption of technology standards through training, structured documentation, and clear knowledge sharing.
• Evaluate existing technology governance, compliance, and risk processes regularly to identify gaps, operational inefficiencies, and opportunities for process optimization.
Technology Lifecycle Management (TLM)
• Manage the end-to-end lifecycle of hardware, software, and enterprise applications, tracking asset health, support status, and obsolescence risks.
• Maintain the definitive Software Asset Management (SAM) data and the hardware Configuration Management Database (CMDB).
• Collaborate with Engineering, Finance, and Vendor Risk Management teams to plan and execute system upgrades, data migrations, and decommissioning of legacy platforms.
• Act as the technical vendor relationship manager for selected third-party technology and infrastructure partners.
Technology Risk & Information Security
• Conduct technical risk assessments on existing infrastructure, newly proposed technologies, and automated release pipelines.
• Partner with Information Security teams to validate that data security policies meet strict data protection regulations.
• Identify vulnerability patterns and integrate secure baselines into the deployment lifecycle, supporting review and approval gates within a Secure Software Development Lifecycle (SSDLC).
• Develop risk mitigation strategies and maintain central registries of known risks, acceptance criteria, and periodic renewal and closure timelines in coordination with Enterprise Risk.
Audit Collaboration & Identity Governance
• Act as the primary liaison for internal and external technology audit teams, gathering, validating, and organizing audit evidence.
• Track audit findings and remediation plans, ensuring technical teams resolve identified control deficiencies on schedule.
• Perform pre-audit readiness assessments to proactively identify, test, and resolve compliance gaps.
• Assist in executing and enhancing Access Management processes, supporting user access requests, and coordinating periodic access reviews for user and operational accounts.
Required Qualifications
• 5 to 8 or more years of professional experience in IT governance, technology audit, information security, or IT risk management.
• In-depth knowledge of NIST, ISO/IEC 27001, COBIT, and ITIL frameworks.
• Hands-on experience utilizing ITAM and ITSM tools (such as ServiceNow, Jira, or Flexera) to manage directories and configurations.
• Solid understanding of internal audit standards, risk testing, and control validation methodologies.
• Experience implementing review and approval gates within a Secure Software Development Lifecycle (SSDLC), including automated processes within CI/CD pipelines.
• Bachelor's or Master's degree in Computer Science, Information Systems, Cyber Security, or a related technical field.
Preferred Qualifications
• Professional certifications, such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Security Professional (CISSP).
• Prior experience managing compliance, ITAM registries, or audit remediations within highly regulated environments (such as financial services or investment management).
• Experience directly coordinating third-party vendor risk assessments and contract management frameworks.
Core Skills & Attributes
• Exceptional written and verbal communication skills, with a proven ability to translate complex technical concepts into clear, accessible policy language.
• Strong critical thinking, problem-solving, and analytical capabilities with high attention to regulatory and procedural details.
• Outstanding organizational and relationship-building skills to collaborate productively across cross-functional engineering, finance, and security teams.
• Self-motivated with a disciplined approach to tracking milestones, resolving audit findings, and managing timelines.

Flexible work from home options available.