9 cybersecurity grc jobs at 8 companies in Boston, MA
4w
Save
Mark Applied
Hide
4w
Senior GRC Analyst
Boston, Massachusetts, United States
$130k-$170k/yrOnsiteFull Time
WHOOP: Wearable technology for personalized health and performance tracking.
6+ YOE6+ years in cybersecurity or enterprise risk; experience conducting structured cyber/IT risk assessments, maintaining risk registers, familiarity with security frameworks and AI risk; strong communication and analysis skills.
NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, NIST AI RMF, ISO/IEC 42001, FAIR
Boston Consulting Group: Global management consulting firm specializing in business strategy and transformation.
10+ YOE10+ years in cybersecurity/GRC with federal compliance (CMMC, NIST SP 800-171/53, FedRAMP), experience with assessments/audit defense, AI governance, executive communication, and ability to obtain U.S. Secret clearance.
UNFINYSE: UNFI: Distributors of natural, organic, and conventional food products.
12+ YOE5+ Mgmt12+ years cybersecurity experience,5+ years leadership,BS in CS or related,industry cybersecurity certification,experience with SOC,VM,GRC,incident command,and vendor/MSSP management.
NIST CSF, ISO 27001, FAIR, Zero Trust, SASE, VPN, MSSP, SaaS
Aqueduct Technologies: Provides managed IT services, cybersecurity, and cloud infrastructure solutions.
5+ YOE5+ years cybersecurity or solutions architecture experience; strong technical depth across SOC/MDR/SIEM, IAM, cloud (Azure,AWS,Microsoft M365), incident response, zero trust, and GRC; presales and customer-facing skills; relevant certifications preferred.
SOC, MDR, SIEM, IAM, Azure, AWS, Microsoft M365, Arctic Wolf, CrowdStrike, Palo Alto, Cisco, Fortinet, NIST, CIS, ISO
Sr. Technical Program Manager, Cybersecurity Remediation
Cambridge, Massachusetts, United States
$146k-$234k/yrHybridFull Time
ModernaNasdaq: MRNA: Develops and manufactures messenger RNA medicines and vaccines.
8+ YOE8+ years technical program or cybersecurity program management experience; experience leading cross-functional remediation programs, vulnerability management, incident/audit remediation, metrics and executive reporting.
vulnerability management platforms, GRC tools, NIST, ISO 27001, CIS
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
10+ YOEBachelor's degree required; 10+ years in cybersecurity, technology risk, GRC, or related fields; experience with cyber policy enforcement, risk governance, executive reporting, and enterprise stakeholder management.
Alnylam PharmaceuticalsNASDAQ: ALNY: Develops RNAi therapeutics to treat rare and common diseases.
15+ YOE10+ Mgmt15+ years in cybersecurity/risk/compliance, 10+ years leading GRC teams; Bachelor’s in a relevant field required; strong knowledge of NIST, ISO, ERM; CISSP/CISM/CRISC/CISA preferred.
NIST CSF v2.0, NIST 800-53, ISO 27001, ERM, GxP, HIPAA, SOX, FDA, Computer System Validation (CSV), NIS2, IT SDLC
QuanterixNASDAQ: QTRX: Developing digital immunoassay technology for ultra-sensitive protein detection.
5+ YOE5+ years IT compliance/risk, SOX/NIST/ISO knowledge; bachelor’s in IS/cybersecurity/accounting or related; strong documentation and audit support skills.
AlnylamNasdaq: ALNY: Developing and commercializing RNA interference (RNAi) therapeutics for diseases.
15+ YOE10+ MgmtBachelor's degree in a relevant field, 15+ years in cybersecurity/risk/compliance or audit, 10+ years leading GRC or risk teams, deep knowledge of NIST CSF, NIST 800-53, ISO 27001 and ERM; industry certifications (CISSP, CISM, CRISC, CISA) preferred.
NIST CSF v2.0, NIST 800-53, ISO 27001, Enterprise Risk Management (ERM), Computer System Validation (CSV), NIS2, GxP