Sr Risk Analyst
Newton, MA - USA
Job Summary
This role is based in our Newton MA office.
We are seeking an experienced and strategic Senior Cyber Risk Analyst to join our team. This role requires deep expertise in enterprise cybersecurity risk management with responsibility for identifying assessing and mitigating cyber risks across the organization. You will lead enterprise risk assessments partner with engineering and security teams on strategic initiatives and provide executive-level reporting on the organizations cyber risk posture. This position also includes emerging responsibilities in AI governance and technology risk as part of a comprehensive enterprise risk management approach.
Key Responsibilities
Enterprise Risk Assessment & Management
- Lead comprehensive enterprise-wide cyber risk assessments across all business operations systems and infrastructure
- Identify analyze and evaluate cybersecurity risks including threats vulnerabilities and potential business impacts
- Develop and maintain enterprise risk registers ensuring all cyber risks are properly documented prioritized and monitored
- Create and implement risk treatment plans and mitigation strategies to reduce organizational exposure
- Conduct risk assessments for new technologies systems and business initiatives in partnership with engineering and product teams
- Utilize risk management frameworks (NIST CSF ISO 27005 FAIR) to quantify and communicate risk
Cloud Security & Infrastructure Risk
- Assess security risks associated with cloud environments (AWS Azure GCP) and hybrid infrastructure
- Evaluate cloud architecture designs and configurations for security and compliance risks
- Partner with cloud engineering teams to implement security controls and risk mitigation measures
- Review and assess risks related to cloud migration projects and infrastructure changes
Vulnerability & Threat Management
- Oversee vulnerability management program effectiveness and risk prioritization
- Analyze vulnerability scan results and penetration test findings to assess enterprise risk exposure
- Work with IT and security teams to ensure timely remediation of critical vulnerabilities
- Monitor threat intelligence and assess potential impact to the organization
- Evaluate the effectiveness of security controls in mitigating identified vulnerabilities
Third-Party & Vendor Risk Management
- Conduct cybersecurity risk assessments of third-party vendors suppliers and business partners
- Review vendor security questionnaires certifications and audit reports
- Assess risks associated with vendor access to systems and data
- Monitor ongoing third-party risk and ensure compliance with security requirements
- Support vendor risk remediation efforts and contract security requirements
Governance Compliance & Policy
- Ensure compliance with relevant cybersecurity regulations standards and frameworks (SOC 2 ISO 27001 NIST Sox etc.)
- Support the development and maintenance of cybersecurity policies standards and procedures
- Participate in internal and external audits related to cybersecurity and risk management
- Monitor regulatory changes and assess impact on organizational risk posture
- Contribute to the organizations cybersecurity governance structure and risk committee activities
Executive Reporting & Metrics
- Prepare comprehensive cyber risk reports and presentations for executive leadership board of directors and key stakeholders
- Develop and maintain cyber risk dashboards with Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)
- Communicate complex cybersecurity risks in business terms to non-technical executive audiences
- Provide regular updates on risk trends threat landscape and mitigation progress
- Present risk-based recommendations to support strategic business decisions
Strategic Partnership & Advisory
- Partner with engineering IT security and product teams on new initiatives and technology implementations
- Provide expert cybersecurity risk guidance during project planning and system design phases
- Advise business units on cyber risk implications of strategic decisions and initiatives
- Collaborate with cross-functional teams including legal compliance privacy and internal audit
Emerging Technology & AI Governance
- Assess cybersecurity and privacy risks associated with AI/ML systems and emerging technologies
- Support the development of AI governance frameworks and responsible AI practices
- Evaluate risks related to AI implementation including data privacy model security and ethical considerations
- Stay current with emerging technology risks and evolving regulatory requirements
Required Qualifications
Education & Experience
- Bachelors degree in Cybersecurity Information Security Risk Management Computer Science Information Technology or related field
- 5-8 years of progressive experience in cybersecurity risk management information security or IT risk
- Proven track record of conducting enterprise-level cyber risk assessments in complex technology environments
- Experience with cloud security risk assessment and cloud platforms (AWS Azure GCP)
- Demonstrated experience in third-party risk management and vendor security assessments
Professional Certifications
Required (at least one):
- CRISC (Certified in Risk and Information Systems Control)
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
Preferred:
- CISA (Certified Information Systems Auditor)
- CGRC (Certified in Governance Risk and Compliance)
- CCSP (Certified Cloud Security Professional)
- Additional relevant cybersecurity or risk management certifications
Cybersecurity & Technical Skills
- Deep understanding of cybersecurity principles threats vulnerabilities and attack vectors
- Strong knowledge of risk management frameworks (NIST ISO 27001 Soc2 Sox)
- Experience with vulnerability management tools and processes
- Understanding of cloud security architecture and controls (AWS Azure GCP)
- Knowledge of security controls defense-in-depth strategies and compensating controls
- Familiarity with compliance frameworks (SOC 2 ISO 27001 NIST 800-53)
- Experience with GRC (Governance Risk and Compliance) platforms
- Understanding of network security application security and infrastructure security
Qualifications :
Professional Skills
- Exceptional analytical and critical thinking skills with strong attention to detail
- Excellent written and verbal communication skills particularly for executive audiences
- Ability to translate technical cybersecurity concepts into business risk language
- Strong stakeholder management and influence skills across all organizational levels
- Proficiency in data analysis and visualization tools
- Project management capabilities and ability to manage multiple priorities
Preferred Qualifications
- Masters degree in Cybersecurity Information Security Risk Management or related field
- Background in information security operations or security engineering
- Knowledge of security architecture and secure design principles
- Experience with security incident response and business continuity planning
- Familiarity with AI/ML security risks and emerging technology governance
- Understanding of privacy regulations (GDPR CCPA PIPEDA)
Key Competencies
- Strategic risk thinking and business acumen
- Proactive risk identification and problem-solving
- Executive presence and communication
- Stakeholder influence and relationship building
- Adaptability to evolving threat landscape
- Ethical judgment and integrity
- Continuous learning and professional development
- Collaboration and cross-functional partnership
Additional Information :
TechTarget Inc. doing business as Informa TechTarget including its subsidiaries is an equal opportunity employer and complies with all applicable federal state and local fair employment practices laws. We strictly prohibit and do not tolerate discrimination against employees applicants or any other covered persons because of race color sex (including pregnancy) age national origin or ancestry ethnicity religion creed sexual orientation gender identity or expression status as a veteran and basis of disability or any other federal state or local protected class. This policy applies to all terms and conditions of employment including but not limited to hiring training promotion discipline compensation benefits and termination of employment. If you would like to request reasonable adjustments or accommodations to assist your participation in the hiring process and or in the advertised position please inform the appropriate Talent Acquisition Partner for the role once they have been in touch. Your request will be reviewed and considered in confidence.
Informa TechTarget complies with the Americans with Disabilities Act (ADA) as amended by the ADA Amendments Act and all applicable federal state or local law.
We believe that great things happen when people connect face-to-face. Thats why we work in-person with each other or with customers and partners three days a week or more. When youre not spending time together in one of our offices or other workplaces like at an Informa event you get the flexibility and support to work from home or remotely.
Our benefits include:
- Great community: a welcoming culture with in-person and online social events our fantastic Walk the World charity day and active colleague groups and networks promoting a positive supportive and collaborative work environment
- Broader impact: take up to four days per year to volunteer with a philanthropic organization
- Career opportunity: the opportunity to develop your career with bespoke training and learning mentoring platforms and on-demand access to thousands of courses on LinkedIn Learning. When its time for the next step we encourage and support internal job moves
- Time out: Open Vacation plus 10 national holidays and the chance to work from (almost!) anywhere for up to four weeks a year
- Competitive benefits including a 401k match health vision and dental insurance parental leave and an ESPP offering company shares at a minimum 15% discount
- Strong wellbeing support through EAP assistance mental health first aiders free access to a wellness app and more
- Recognition for great work with global awards and kudos programs
- As an international company the chance to collaborate with teams around the world
The salary range for this role is $150K-$170K/YR based on experience.
This posting will automatically expire on September 4 2026.
Remote Work :
No
Employment Type :
Full-time
About Company
Informa is a leading international events, digital services and academic research group. We're here to champion the specialist. Through hundreds of brands and a range of products and services, we connect businesses and professionals with the knowledge they need to learn more, know m ... View more