Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Risk Management and Governance

STEM Solutions

Managing Director, Cyber Risk Management & Governance

The Managing Director, Cyber Risk Management & Governance will lead a team responsible for the design, execution, and oversight of the cyber risk management and governance framework. This role ensures cyber risk is consistently identified, assessed, governed, and reported in alignment with the Enterprise Risk Framework, regulatory expectations, and the firm's risk appetite. The role serves as a central coordination point, with a strong focus on framework governance, risk management, findings oversight and management, and executive-level reporting.

Key Responsibilities:

  • Own and evolve the Cyber Risk Management Framework, ensuring alignment with the Enterprise Risk Framework and regulatory expectations.
  • Govern cyber risk taxonomies, risk appetite statements, risk metrics, and assessment methodologies.
  • Support embedding cyber risk practices across the L3 Cyber risk methodology and support functional and business risk owners in their efforts to improve and sustain cyber risk posture.
  • Provide oversight of control assurance and remediation execution and quality, including challenge, escalation, and consistency.
  • Ensure consistent linkage between assessment outcomes, risk appetite, and remediation priorities.
  • Enable and guide Enterprise Process Owner (EPO) / Metric Owners with challenges related to processes area / Key Risk Indicator improvement, ensuring clear accountability and effective operation.
  • Support the second line of defense in defining, maintaining, and overseeing Cyber Key Risk Indicators (KRIs) and thresholds, ensuring they provide meaningful insight into risk posture and trends.
  • Coordinate cyber risk matters for management-level and executive Risk Committees, including agenda development, materials, and escalation.
  • Produce and oversee executive-level cyber risk reporting, including risk posture, trends, material issues, and emerging risks.
  • Ensure reporting is concise, decision-oriented, and aligned with enterprise and Board risk governance expectations.
  • Serve as the primary cyber risk interface with Technology Risk Advisors (TRAs), coordinating inputs, challenge, outcomes, and follow-through.
  • Oversee LOD and legal entity cyber risk reporting, ensuring a consistent Global Cybersecurity view.
  • Coordinate with Cyber Compliance teams to provide accurate data sharing for regulatory engagement and legal entities.
  • Provide governance oversight for issues that impact cyber risk, including intake, severity assessment, challenge, escalation, and closure monitoring.
  • Oversee cyber risk acceptance governance, ensuring decisions are risk-informed, appropriately documented, time-bound, and approved at the correct level.
  • Ensure alignment between issues, risk acceptances, and risk appetite.
  • Lead the intake and governance of cyber findings from audits, regulatory reviews, assessments, and testing activities.
  • Ensure findings are consistently risk-rated, challenged where appropriate, and tracked through remediation to closure.
  • Monitor remediation progress, aging, and systemic themes, escalating concerns as needed to governance/management committees.

Required Qualifications:

  • 10+ years of experience in cybersecurity risk management, technology risk, or enterprise risk governance, with significant experience at a senior leadership level.
  • Bachelor's degree in information systems, computer science, data analytics, cybersecurity or related field (or equivalent experience).
  • Deep understanding of cyber risk frameworks, enterprise risk management, and regulatory expectations within a large, complex financial services or regulated environment.
  • Proven experience with risk governance, control assurance and assessments, KRIs, issue management, and executive reporting.
  • Strong ability to build relationships across the three lines of defense and influence at executive and Board levels.
  • Exceptional communication skills, with the ability to translate technical and risk concepts into executive-level insights.
  • Experience leading highly successful teams in achieving objectives and key results.

Preferred Skills:

  • Cybersecurity Certifications such as: CISSP, CISM or equivalent.
  • Experience implementing automated and/or continuous controls monitoring in cloud and hybrid environments.
  • Strong analytical mindset with the ability to translate ambiguous risk or control questions into measurable metrics and repeatable tests.
  • Clear written and verbal communication skills, including the ability to explain complex technical findings and trends to leadership.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the GRC Risk Management and Governance in Boston, MA vacancy
  • $70 - $75 per hour

     ...Pharmaceuticals in Boston is seeking a ServiceNow professional to manage application security controls within the Cyber Risk Management and Governance team. This role involves coding and validating controls in ServiceNow's GRC modules while collaborating with various application... 
    Suggested

    Vertex Pharmaceuticals

    Boston, MA
    4 days ago
  •  ...leading staffing and recruiting firm in Boston is seeking a seasoned cybersecurity compliance professional to strengthen risk management and governance. This role involves advising on security and compliance frameworks and conducting risk assessments while interfacing... 
    Suggested
    Remote job
    Flexible hours

    ExperTech Inc.

    Boston, MA
    3 days ago
  •  ...to unify their stack and expose it as a governed layer through golden paths for...  ...re looking for you We’re looking for a GRC Program Manager to drive Port’s FedRAMP authorization and...  ...Drata, Tugboat Logic, Vanta, OneTrust). Risk Management. Background in technical security... 
    Suggested
    Flexible hours

    Port.io

    Boston, MA
    4 days ago
  •  ...Our customer base is expanding, the regulatory and risk landscape is getting more complex, and the business needs a GRC function that can keep pace. As the GRC Manager at CloudZero, you’ll own and scale our governance, risk, and compliance programs across the organization... 
    Suggested
    Contract work
    Work at office
    2 days per week
    3 days per week

    CloudZero

    Boston, MA
    3 days ago
  • ## Senior Manager, Risk OperationsApplylocations: Boston, MAtime type: Full timeposted on: Posted...  ...audit management process, using Archer GRC risk platforms. Supports and coordinates...  ...status of Operational Controls and Governance, along with action plans to address and... 
    Suggested

    Soteria Reinsurance Ltd.

    Boston, MA
    2 days ago
  • $150k - $165k

     ...the COO is responsible for building and managing the systems, people, finances, and processes...  ...organization is financially strong, well-governed, efficiently run, and built for growth....  ...leadership pathways # Facilities, Capital & Risk Lead long-term facilities strategy... 
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Afternoon shift

    Vilna Shul

    Boston, MA
    3 days ago
  •  ...executive oversight of construction operations including project management, field execution, estimating, preconstruction, scheduling, and...  ...performance metrics including profitability, productivity, and risk exposure. Partner with project executives and operations... 
    Contract work

    Wainwright Talent Partners

    Boston, MA
    3 days ago
  • A global investment firm in Boston is seeking a Cybersecurity GRC Associate to support cyber governance, risk, and compliance efforts. The role involves shaping cybersecurity policies, aiding in risk assessments, and reporting metrics to internal stakeholders. Ideal candidates... 

    Fynetra

    Boston, MA
    5 days ago
  • $110k - $207.5k

     ...single point of accountability for program governance. This role is the governance authority...  ...integrated program plan and performance management approachMaintains heat maps and...  ...forums clearly reflects program reality, risks, and trade‑offs3. Risk, Issues & EscalationOwns... 
    Temporary work
    Flexible hours

    STATE STREET CORPORATION

    Boston, MA
    5 days ago
  • $110k - $207.5k

    STATE STREET CORPORATION in Boston seeks a PMO Lead to ensure effective governance across program domains. The role requires accountability for program planning, performance insight, risk management, and producing client-facing reports, amongst other responsibilities.... 

    STATE STREET CORPORATION

    Boston, MA
    5 days ago
  • $151.2k - $226.8k

    Overview The Tech Program Manager II leads complex, multi workstream programs that deliver...  ...while coordinating teams, mitigating risks, and driving execution across the program...  ...outcomes through disciplined coordination, governance, and execution. Our flexible/hybrid... 
    Full time
    Work experience placement
    Work at office
    Flexible hours

    ViziRecruiter,LLC.

    Quincy, MA
    4 days ago
  • Cybersecurity GRC Associate - Boston (Hybrid) Perm Hybrid We’re hiring an Associate to support cyber governance, risk, and compliance for a global investment firm. This role offers...  ...Liaise with teams across legal, vendor management, and enterprise risk Assist in audits... 
    Permanent employment

    Fynetra

    Boston, MA
    5 days ago
  • $201.37k - $236.9k

     ...to objectively evaluate and audit the effectiveness of governance, compliance, risk management, and control process. The in-house Coinbase Internal Audit...  ...and partnering on the optimization of IA tooling (e.g., GRC platforms, Workiva/Archer). Contribute to Board and... 
    Work at office
    Local area

    Coinbase

    Boston, MA
    7 days ago
  •  ...Lead based in Boston, MA. This role is crucial for program governance and involves authority over framework and quality gates. The...  ...like JIRA and Confluence. High-impact communication skills and risk management expertise are essential for success. #J-18808-Ljbffr State... 

    State Street

    Boston, MA
    5 days ago
  • $177k - $278.08k

     ...shine? Join us as a Director, Global Program Management, NS TAU in our Cambridge, MA office. At...  ...proactive management and mitigation of development risks, and ensuring appropriate communication and interface with internal governance. Works closely with the Global Program... 
    Minimum wage
    Full time
    Temporary work
    For contractors
    Work at office
    Local area
    Remote work

    Initial Therapeutics, Inc.

    Boston, MA
    3 days ago
  • $240k - $350k

     ...Information Security strategy and policy, manages the Information Security program,...  ...executive of Identity & Access Management (IAM) Governance serves as the enterprise authority for identity governance strategy, policy, and risk management within Global Information Security... 
    Shift work
    Day shift

    Koitecc Solutions

    Boston, MA
    1 day ago
  • $110k - $315k

     ...seeking a skilled professional to lead enterprise technology risk and governance. This critical role involves establishing risk frameworks...  ...candidate will have extensive experience in technology risk management, a solid understanding of governance processes, and... 

    Arrowstreet Capital, Limited Partnership

    Boston, MA
    2 days ago
  • $60k - $90k

    Whoop is searching for a GRC Analyst in Boston, MA, to enhance the Governance, Risk, and Compliance program. This role involves managing GRC intake processes, coordinating third-party risk reviews, and ensuring effective compliance operations. The ideal candidate will have... 

    Whoop

    Boston, MA
    4 days ago
  • $180k - $210k

     ...Description: Pathstone is a growing wealth management firm serving ultra-high net worth...  ...across key areas such as tax strategy, risk management guidance, wealth and estate planning...  ..., philanthropic planning, and family governance — helping clients navigate complexity and... 
    Work experience placement
    Work at office
    Flexible hours

    Pathstone

    Boston, MA
    14 days ago
  • $70k - $90k

     ...Description: Pathstone is a growing wealth management firm serving ultra-high net worth...  ...across key areas such as tax strategy, risk management guidance, wealth and estate planning...  ..., philanthropic planning, and family governance helping clients navigate complexity and... 
    Internship
    Work at office
    Flexible hours

    PathStone

    Boston, MA
    7 days ago
  •  ...insurer located in Boston is seeking an Associate Director of AI Governance to operationalize its AI Governance strategy. The role...  ...coordinating with various departments, and ensuring compliance and risk management in AI initiatives. Ideal candidates will have over 10 years... 

    Blue Cross and Blue Shield of Massachusetts Inc.

    Boston, MA
    1 day ago
  • $50k - $65k

     ...This role, reporting to the Program Team Manager in Membership Services, operates at the intersection...  ..., creating reusable templates, SOPs, and governance artifacts that serve as the single source...  ...at every touchpoint. Drive proactive risk & issue management, and escape blockers... 
    Full time

    WHOOP

    Boston, MA
    3 days ago
  •  ...over 15 years of cybersecurity experience, focusing on the governance and security of AI technologies. You will strategize AI initiatives...  ...in cybersecurity and a strong understanding of AI risk management. This position is essential in guiding secure AI adoption across... 

    NTT Data Americas, Inc.

    Boston, MA
    5 days ago
  • $55k - $75k

     ...Description: Pathstone is a growing wealth management firm serving ultra-high net worth...  ...across key areas such as tax strategy, risk management guidance, wealth and estate planning...  ..., philanthropic planning, and family governance — helping clients navigate complexity and... 
    Work at office
    Flexible hours

    Pathstone

    Boston, MA
    7 days ago
  • $60k - $90k

    As a GRC Analyst, Operations & Risk, you will support the WHOOP Governance, Risk, and Compliance program by helping manage GRC intake, coordinate third-party risk activities, strengthen operational workflows, and improve visibility across risk and compliance work. This... 
    Full time
    Work at office
    Relocation

    Whoop

    Boston, MA
    1 day ago
  • $139.12k - $208.68k

     ...related areas for ADUSA Finance; the overall data strategy, governance and management of critical financial data - to include master data - and...  ...-to-understand way to colleagues and other stakeholders Risk Management - Ability to proactively identify and mitigate process... 
    Local area

    Peapod Digital Labs

    Quincy, MA
    2 days ago
  • $99k - $252.45k

     ...reliability of this information with a variety of stakeholders. They evaluate compliance with regulations including assessing governance and risk management processes and related controls. Those in data, analytics and technology solutions at PwC will assist clients in... 
    Full time
    H1b

    PwC

    Boston, MA
    5 days ago
  •  ...candidate will be responsible for financial operational strategy and execution, team leadership and management, and will have a strong background in regulatory and risk management, particularly in the context of banking and AML technology. Applicants for the COO position... 

    Confidential

    Boston, MA
    5 days ago
  • $170k - $282.5k

    State Street Investment Management (“State Street IM”, formerly State Street Global Advisors...  ...Head of Architecture and Engineering Governance to lead the firm’s enterprise-wide architecture...  ..., balancing delivery velocity with risk, resilience, and control expectations.Platform... 
    Temporary work
    Flexible hours

    STATE STREET CORPORATION

    Boston, MA
    1 day ago
  •  ...GRC Program Operations Specialist Support day-to-day GRC program operations – manage and triage GRC intakes and accurate tracking through resolution. Perform and support third-party risk management activities, including vendor reviews, reassessments, partner coordination... 

    WHOOP

    Boston, MA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Risk Management and Governance. Be the first to apply!