Senior Cybersecurity Analyst (GRC)
$89.5k - $130kBoston Medical Center
POSITION SUMMARY
The Senior Cybersecurity Analyst (Governance, Risk, and Compliance) plays an important role in building and maturing Boston Medical Center Health System’s GRC program. This role will be key to developing and improving human-driven processes before enterprise tooling is in place, and will make that work visible, auditable, and ready to scale. Position Senior Cybersecurity Analyst Department Information Security Schedule Full TimeESSENTIAL RESPONSIBILITIES / DUTIES
Lead execution of GRC program initiatives, contributing design input on processes, workflows, and work products as the program matures toward enterprise tooling adoption. Maintain and operationalize risk registers, control frameworks, and maturity assessments aligned to NIST CSF 2.0, HIPAA/HITECH, and applicable federal and state security and privacy regulations. Drive compliance monitoring activities and recommend updates to security policies, standards, and procedures that balance regulatory rigor with operational practicality. Coordinate the third-party risk management process, including vendor risk assessments and ongoing vendor risk workflows. Apply risk scoring methodologies to support framework maturity tracking and quantified risk metrics, incorporating business continuity and disaster recovery considerations. Manage structured GRC work products in spreadsheet and document-based environments (e.g., Excel, SharePoint), keeping them accurate, accessible, and audit-ready on an ongoing basis. Translate technical findings into clear, actionable written and verbal reporting for executive and non-technical audiences. Partner with stakeholders across IT and non-IT business functions to advance new standards and workflows, influencing adoption without direct authority. Prioritize multiple concurrent workstreams to deliver accurate results on schedule in a fast-paced, evolving environment. (The above statements in this job description are intended to depict the general nature and level of work assigned to the employee(s) in this job. The above is not intended to represent an exhaustive list of accountable duties and responsibilities required)JOB REQUIREMENTS
REQUIRED EDUCATION AND EXPERIENCE
Bachelor's degree in Cybersecurity, Computer Science, Information Management, or a related field preferred A minimum of six years of experience in information security or related discipline, with a strong focus on governance, risk, and compliance programs in complex or regulated environments. Or equivalent combination of education and experience.PREFERRED EDUCATION AND EXPERIENCE
Demonstrated experience building or significantly maturing a GRC function, including the design of processes and workflows prior to enterprise tooling adoption.CERTIFICATIONS, LICENSES, REGISTRATIONS PREFERRED
Professional certifications such as CISA, CRISC, CISSP, or equivalent are highly desirable. KNOWLEDGE, SKILLS & ABILITIES (KSAs) Demonstrated experience in data mining, analysis and report development required. Strong knowledge of information systems security concepts and current information security/privacy trends and practices. Knowledge of Federal and State security and privacy-related regulatory requirements. Excellent written and oral communication skills, interpersonal skills, and effective leadership skills to support privacy programs. Must be able to prepare formal reports and presentations as needed. Must be detailed oriented and possess the ability to prioritize tasks so work is completed in an accurate, timely manner. Strong business and technical skills in the planning, administration, and management of information systems, operational and technical security controls; and security risk analysis and management. Self-starter with the ability to work independently, prioritize, multi-task, and maintain flexibility in fast-paced, changing environment. Ability to confront conflict and difficult issues in a professional, assertive, and proactive manner. Ability to build strong working relationships at all levels, internal and/or external to the organization. Knowledge about medical records and other medical information, patient privacy and confidentiality, and release of information. Academic medical center and/or health care consulting experience preferred. Compensation Range $89,500.00- $130,000.00 This range offers an estimate based on the minimum job qualifications. However, our approach to determining base pay is comprehensive, and a broad range of factors is considered when making an offer. This includes education, experience, skills, and certifications/licensures as they directly relate to position requirements; as well as business/organizational needs, internal equity, and market-competitiveness. In addition, BMCHS offers generous total compensation that includes, but is not limited to, benefits (medical, dental, vision, pharmacy), discretionary annual bonuses and merit increases, Flexible Spending Accounts, 403(b) savings matches, paid time off, career advancement opportunities, and resources to support employee and family well-being. NOTE: This range is based on Boston-area data, and is subject to modification based on geographic location. Equal Opportunity Employer/Disabled/Veterans #J-18808-Ljbffr Boston Medical CenterVacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Senior Cybersecurity Analyst (GRC) in Boston, MA vacancy
$70k - $80k
...As a GRC Cybersecurity Analyst (CA), you will play a pivotal role securing our clients’ infrastructure, data and software. Beyond helping our clients... ...not quite large enough yet to hire a full-time “C-level” senior security leader, like a Chief Information Security Officer...SuggestedFull timeWork at office- Children's Hospital Corporation dba Boston Children's Hospital in Boston, MA is seeking a Cyber Security Analyst IV to develop solutions for security operations and lead investigations of security events. The position allows for remote work within the US and requires a...SeniorRemote job
- ...strengthen the ERM and audit program, conducting cybersecurity and IT audits, risk assessments, and... ..., produce comprehensive reports, inform senior management of risks, and track issues to closure, collaborating with ERM risk analysts and departments across the organization....Senior
- Madison-Davis, LLC is seeking a Senior Cybersecurity Analyst in Boston, Massachusetts. The role involves enhancing security controls, managing risks, and supporting incident responses across a modern technology landscape. The ideal candidate will have over 5 years of cybersecurity...Senior
- A clinical trials technology firm in Boston is seeking a Senior Security Compliance Analyst to enhance its compliance programs. The role focuses on GRC, managing audits, and ensuring adherence to industry regulations like ISO 27001 and HIPAA. Ideal candidates will have...Senior
$80.5k - $159.3k
...help shape the future of our industry. Job Description: As a Cybersecurity Senior Consultant , you will help organizations navigate an evolving... ...across domains such as governance, risk, and compliance (GRC) and business resiliency. Serve as an extension of client teams...SeniorLocal areaWorldwide- DigitalOcean is looking for a Senior GRC Analyst who will architect our expanding ISO ecosystem. Responsibilities include leading the maturation of our compliance framework with key ISO standards and managing risk assessments and compliance certifications. The ideal candidate...SeniorRemote job
- A consulting firm is seeking a Senior GRC Archer Application Lead in Boston, MA. This hybrid position requires deep expertise in RSA Archer, with responsibilities including leading solution design, development, and implementation of enterprise risk management solutions...SeniorLong term contract
$130k - $170k
...Senior GRC Analyst At WHOOP, we are on a mission to unlock human performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization...SeniorFull timeWork at officeRelocation$120k - $180k
Klaviyo is seeking a Senior Security Compliance Engineer to join our Security Trust & Compliance team in Boston. This role involves designing automated compliance workflows, enhancing control monitoring, and partnering with engineering and legal teams. The ideal candidate...Senior$82.3k - $220k
...necessary for true innovation. Job Description Summary The Cybersecurity Risk Analyst is a member of Draper’s Cybersecurity Risk Management team,... ...environments. This team serves as the Governance Risk and Compliance (GRC) tool product owner, performs compliance and risk analyses,...For contractorsFlexible hours- Form Energy, based in Somerville, is looking for a Director of Cybersecurity & GRC to lead cybersecurity and IT governance. This hybrid role requires onsite work for at least 3 days a week and offers relocation assistance. Candidates will oversee the security program and...Relocation package3 days per week
- We have an immediate requirement for Senior GRC Archer Application Lead role. (both W2 and C2C are accepted) Job Title: Senior GRC Archer Application Lead Location: Hybrid/Boston, MA (2-3 days in office) Length of assignment: Long term Contract Job Description We are...SeniorLong term contractWork at officeImmediate start
- Gravity Engineering Services Pvt Ltd. is seeking a Security and Compliance Analyst based in Cambridge, Massachusetts. The role involves conducting security audits, managing compliance programs, and integrating security practices into cloud platforms. Ideal candidates will...Senior
$119k - $193k
...extraordinary future.About This Role:Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk... ...in compliance management, internal or external audit, and GRC platforms is strongly desired.The successful candidate...SeniorFor contractors- Crowe in Boston is seeking a Cybersecurity Senior Consultant to help organizations navigate a complex regulatory environment and effectively manage cybersecurity risks. The role requires a Bachelor’s degree and at least 2 years of relevant experience in cybersecurity or...SeniorFlexible hours
- ...and effective. Coordinate with ERM risk analysts to ensure internal reviews include current... ...or improvements Proactively inform senior management of significant risks or exposures... ...least five (5) years of experience in cybersecurity audit, IT audit, risk management, or compliance...For contractorsLocal area
- Berkshire Hathaway Specialty Insurance is seeking a Technology Senior Risk Analyst to advance the GRAC program, coordinating risk identification, assessment, and continuous monitoring across enterprise IT risk practices. The role involves defining and socializing KRIs/KPIs...Senior
- ...specialized recruitment agency in Boston is seeking an Experienced Recruitment Consultant to manage the full recruiting process for mid to senior-level roles. The role entails developing new business and nurturing existing client relationships in governance, risk, and...Senior
$90k - $157.5k
...Overview State Street is seeking a Cybersecurity Analyst to operate vulnerability scanning and management tools, analyze results, and provide relevant reporting to stakeholders. The role requires organizational, analytic, and technical expertise to protect the bank’s assets...- Forrester Research, based in Cambridge, MA, is seeking a Senior Analyst to deliver strategic advice and conduct research for risk management leaders. The ideal candidate will possess strong knowledge of risk practices, cyber risk quantification, and excellent communication...Senior
- EY is looking for a highly motivated Senior Associate for their Risk Technology practice in Boston. This role focuses on SAP application risk management and technology enablement while managing client engagements across various sectors. You will leverage SAP experience...Senior
$229.5k - $310.5k
Alnylam Pharmaceuticals, Inc. is seeking a Senior Director of Governance, Risk & Compliance to define, lead, and mature governance,... ...programs. The ideal candidate will have 15+ years of experience in cybersecurity with strong leadership skills. A comprehensive benefits...Senior- A leading staffing and recruiting firm in Boston is seeking a seasoned cybersecurity compliance professional to strengthen risk management and governance. This role involves advising on security and compliance frameworks and conducting risk assessments while interfacing...SeniorRemote jobFlexible hours
$87k - $109k
InterSystems in Boston, Massachusetts, is seeking a Cybersecurity Analyst to join their Cybersecurity Department. This role involves providing risk management and assurance support, collaborating with various teams to manage cybersecurity risks effectively. The ideal candidate...- Cognizant is looking for a Junior Cybersecurity Analyst in Englewood, CO. This full-time role involves supporting security operations and IAM, providing a foundation for growth into various security engineering positions. The ideal candidate will have a Bachelor's degree...Full time
- Trellix is seeking a Competitive Intelligence Analyst located in Boston, MA. This role involves transforming market data into actionable... ...product management. Candidates should have deep expertise in cybersecurity and experience in Competitive Intelligence or Market Research....
$65k
...Years Employment Type: Full-Time Role Summary: The Junior Cybersecurity Analyst - Cloud, Network, Infrastructure Security & IAM supports:... ...operational execution, monitoring, and support under the guidance of senior IAM engineers while building strong foundational...Hourly payFull timeTemporary workWork at officeShift work- ...Eacademy Sanofi is seeking a Senior Principal Scientist I in Cambridge, MA, to lead a team developing functional biomarkers and immunophenotyping panels. The role requires a Ph.D. and extensive experience in flow cytometry, assay design, and managing teams. This position...Senior
- 7AI is seeking a Senior Security Engineer to join our Boston team, focusing on defining security workflows and incident response strategies... ...a passion for tackling security challenges. Join us at this exciting stage of AI-driven cybersecurity innovation. #J-18808-Ljbffr 7AISenior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Cybersecurity Analyst (GRC). Be the first to apply!
Related searches
- cyber security specialist Boston, MA
- cyber security consultant Boston, MA
- senior trade analyst Boston, MA
- senior app developer Boston, MA
- senior customer service advisor Boston, MA
- senior international account manager Boston, MA
- senior product manager mobile Boston, MA
- senior magento developer Boston, MA
- senior quantitative risk analyst Boston, MA
- senior business development director Boston, MA

