28 technology risk analyst jobs at 21 companies in Everett, MA
1w
Save
Mark Applied
Hide
1w
Principal Technology Risk Analyst
Westlake or Merrimack or Smithfield
OnsiteFull Time
Fidelity Investments: Provides investment management, retirement planning, and brokerage services.
6+ YOEBachelor's or equivalent experience; 6+ years in cybersecurity/technology risk; strong AI governance, data privacy, and model governance knowledge; CISSP or CISA preferred; excellent written and verbal communication.
Rockland TrustNASDAQ: INDB: Provides commercial and retail banking and financial management services.
2+ YOEBachelor's preferred; 2+ years technology audit or IT risk assessment experience; familiarity with financial services/regulatory environments; ability to assess controls, test operating effectiveness, and document results; strong communication skills.
10+ YOE10+ years in IT risk/audit/GRC, experience with RCSAs/KRIs, vendor risk/SOC reviews, strong writing and communication, knowledge of NIST/COSO/COBIT and US/global regulations; professional certs a plus.
Washington or Boston or Dallas or Chicago or Miami or Denver or Orange or Los Angeles or Las Vegas or Sacramento or Phoenix or San Diego or United States
$130k-$160k/yrRemoteFull Time
DanaherNYSE: DHR: Develops scientific instruments and diagnostic tools for healthcare markets.
7+ YOE7+ years in third-party/vendor risk, enterprise risk, or vendor security; experience administering vendor questionnaires, reviewing SOC 2/ISO 27001 evidence, scoring at scale, reviewing cybersecurity contract provisions, and operating enterprise risk registers.
Data, AI and Emerging Technology Risk Principal Analyst
Johnston or Iselin or Westwood or Phoenix
HybridFull Time
Citizens Financial GroupNYSE: CFG: Provides retail, commercial, and private banking services to customers.
7+ YOE7+ years IT risk experience; deep expertise with CRI/NIST/COBIT/ITIL; experience with cloud, data platforms, analytics, and security tools; strong executive communication and mentoring skills.
First Tech Federal Credit Union: Member-owned financial cooperative providing banking and wealth management services.
8+ YOE8+ years ERM experience, bachelor\u0002s degree or equivalent experience, deep knowledge of enterprise/technology/operational risk, governance, risk methodologies, and regulatory support; preferred CRISC,CISA,CISSP,CGEIT,PMP,CERM.
Watts Water TechnologiesNYSE: WTS: Manufactures water flow control and water quality products.
3+ YOEBachelor's or equivalent; 3+ years IT compliance/internal audit/GRC experience; working knowledge of ITGCs and SOX; experience with GRC/audit platforms; strong communication and organizational skills.
Optro (AuditBoard), ServiceNow GRC, Archer, MetricStream, Jira, Microsoft Power Automate, SQL, Python, APIs
United States or San Francisco or San Jose or New York City or Chicago or Austin or Denver or Boston or Washington or Philadelphia or Portland or Seattle or Miami or California or Alaska or Delaware or Hawaii or Idaho or Iowa or Montana or Nebraska or North Dakota or Rhode Island or South Dakota or West Virginia
$165k-$233k/yrRemoteFull Time
Calendly: Scheduling automation platform for managing meetings and appointments.
5+ YOE5+ years in compliance/GRC in a technology/SaaS environment; SOC 2 and ISO 27001 experience; knowledge of NIST, GDPR, HIPAA; experience with compliance automation platforms and UARs; strong project management and communication.
WHOOP: Providing wearable health trackers and physiological performance analytics.
2+ YOE2+ years GRC experience, knowledge of ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS, bachelor’s degree, strong organizational and communication skills.
WHOOP: Wearable technology for personalized health and performance tracking.
6+ YOE6+ years in cybersecurity or enterprise risk; experience conducting structured cyber/IT risk assessments, maintaining risk registers, familiarity with security frameworks and AI risk; strong communication and analysis skills.
NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, NIST AI RMF, ISO/IEC 42001, FAIR
MACOMNASDAQ: MTSI: Designs and manufactures semiconductor products for communications infrastructure.
1+ YOEBachelor's in relevant field (or equivalent), 1–3 years information security/risk/compliance experience, knowledge of security frameworks, strong analytical and communication skills, and willingness to learn ServiceNow GRC.
ServiceNow GRC, NIST, ISO 27001, SOC2, CIS, ISO9001, ISO14001
QuanterixNASDAQ: QTRX: Developing digital immunoassay technology for ultra-sensitive protein detection.
5+ YOE5+ years IT compliance/risk, SOX/NIST/ISO knowledge; bachelor’s in IS/cybersecurity/accounting or related; strong documentation and audit support skills.
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
2+ YOE2+ years evaluating systems against the Risk Management Framework (RMF) using DoD policies, ISSO/ISSM experience, eMASS ATO package development, RMF documentation experience, Secret clearance, HS diploma/GED, and DoD 8140 certification.
Risk Management Framework (RMF), Enterprise Mission Assurance Support Service (eMASS), Security Technical Implementation Guides (STIGs), Security Content Automation Protocol (SCAP), Assured Compliance Assessment Solution (ACAS), Ports, Protocols, and Services Matrix, Vulnerability Remediation Asset Manager (VRAM), Host Based Security System (HBSS)
NetBrain: Provides AI-powered no-code network automation and visibility software.
4+ YOEBuild and operationalize a SaaS security and compliance program aligned to SOC 2, ISO 27001, NIST and GDPR; lead risk management, third-party risk, control testing and audit readiness; 4+ years security/compliance experience; cloud experience (AWS/Azure/GCP).
Boston Medical Center: Provides specialized medical care and academic healthcare training.
6+ YOE6+ years information security experience focused on governance, risk, and compliance; bachelor’s preferred; certifications such as CISA/CRISC/CISSP preferred; knowledge of NIST CSF 2.0, HIPAA/HITECH; strong data analysis and communication skills.
Microsoft Excel, Microsoft SharePoint, NIST CSF 2.0, HIPAA, HITECH
DigitalOceanNew York Stock Exchange: DOCN: Simplifies cloud infrastructure for developers, startups, and SMBs.
6+ YOE6+ years in detection & response, insider risk, or security engineering; hands-on UEBA/SIEM/DLP/UAM/SOAR; scripting with Python/Go/Bash; familiarity with macOS, Windows, Linux, Kubernetes and cloud; knowledge of MITRE ATT&CK and NIST.
Kansas City or St. Louis or Cleveland or Philadelphia or Chicago or San Francisco or New York or Boston or Atlanta or Minneapolis or Dallas or Richmond
$95k-$166k/yrHybridFull Time
Federal Reserve System: The central bank of the United States.
7+ YOEBachelor's degree required (Master's preferred), 7+ years vendor management/procurement experience, strong contract negotiation, risk management, analytics, and stakeholder communication skills.
IPG PhotonicsNASDAQ: IPGP: Designs and manufactures high-performance fiber laser systems.
7+ YOE7+ years cyber security experience; SIEM and incident response; Azure/M365 security and compliance; strong process documentation and risk focus; good communication and independent work skills.
Microsoft Defender, Microsoft Entra ID, Azure AD, M365, Purview, DLP, eDiscovery, Information Protection, Conditional Access, MFA