Senior Analyst, Cyber Risk Quantification and GRC
$119k - $193kForrester
At Forrester, we’re trusted to work on trailblazing, mission critical problems that business and technology leaders face today. That’s why we’re always looking to empower talented individuals to perform at their best every single day. We’re proud of our community of smart people and vibrant voices who come together to do what’s right by our clients and each other. Our success is driven by curiosity, courage and customer obsession. The confidence and drive to be bold at work. Join us and build an extraordinary future.
About This Role:
Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk management leaders and their teams. The ideal candidate has a strong understanding of risk management roles, responsibilities, and the most important security and risk trends and their business and technology implications; deep knowledge and experience with risk management practices and methods; deep knowledge and expertise in cyber risk quantification; and deep experience in developing, maintaining, and communicating risk management artifacts including risk standards, procedures, appetite, registry, and business strategy. Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired.
The successful candidate researches and uncovers the strategies, technologies, and best practices of risk management that create a resilient and opportunity-seeking business. The Senior Analyst delivers these insights and recommendations in written reports, presentations, inquiries, guidance sessions, and custom advisory for risk leaders across industries and geographies. Our research is aimed at helping enterprise clients solve business problems and improve business results by applying principles and best practices. We also advise vendors on their strategies, roadmaps, and messaging in line with our market insights and our recommendations for enterprise clients.
Job Description:
The Senior Analyst works as part of a high-performing team with a strong emphasis on collaborating with others in all aspects of the job. The Senior Analyst is expected to:
Develop a deep understanding of what Forrester clients require to be successful as risk management leaders and professionals with a focus on how they help their organizations develop risk management capabilities that enable a resilient and opportunity-seeking business.
Conduct primary research into risk management capabilities, practices, touchpoints, and artifacts in the context of supporting C-suite executives, business leaders, and appropriate committees.
Help define the future of risk management, including how risk leaders and professionals can work with other key business functions and support organizational success.
Work with different focus areas across Forrester research teams to develop a complete research portfolio on risk management, providing both input to others’ research and writing reports incorporating expertise from across Forrester to provide a “big picture” view.
Partner as appropriate with other Forrester analysts on broader risk topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk.
Research/write/create approximately six to eight research projects per year — a mix of written reports, tools, webinars, videos, podcasts, infographics, and other intellectual property. Build visibility for their research and contribute to Forrester client communities.
Consult with clients to apply Forrester’s research in the context of their specific business environment and help solve their problems through inquiry, guidance, and advisory engagements.
Establish an industry presence as an influential speaker and thinker; build relationships with journalists who cover the sector; and participate in vendor briefings and field press inquiries as necessary.
Job Requirements:
Five to seven years as a research analyst, consultant, or practitioner where you have led or been involved in risk management, with a focus on cyber risk quantification, or an equal amount of time as product manager for vendors that serve the market.
A deep intellectual curiosity about the effect of technology on the business landscape; solid business instincts and a practical understanding of what makes companies tick; and a creative view of markets, technologies, and attitudes combined with a fascination with the future.
Superior listening, critical thinking, and writing skills as well as compelling presentation skills.
The ability to take complex, disparate ideas and distill them into simple, provocative concepts — and be willing to take a stand on vendors and outcomes.
The ability to travel up to 20% of the time.
Please note that the base salary range indicated here is inclusive of all applicable US geographies listed in this requisition, with the exception of New York City and Georgia. This salary range is based upon the position as described in the job listing. The offered compensation may vary within this range and is dependent upon the successful candidate’s primary work location, experience, training, education, and credentials.
Base salary range: $119,000 - $193,000
Base salary range for Georgia: $106,000 - $174,000
Base salary range for New York City, NY: $136,000 – $222,000
For employees based in Washington State, the percentage listed here is an estimated bonus target as a percentage of base salary, in accordance with the Forrester Employee Bonus plan. Individual and company performance, as well as other eligibility criteria, will determine the actual incentive amount.
Bonus target: 10%
For information on benefits, please visit:
The application deadline is July 31, 2026. Please refer to the job posting on Forrester.com careers page if the deadline has been extended.
#LI-JM1
We’re a network of knowledge and experience leading to richer, fuller careers. Here, we’re always learning. Whether you want to hone your strengths or discover new ones, Forrester is the place to go for it. It’s a place where everyone is given the tools, support, and runway they need to go far. We’ll be right there beside you, every step of the way.
Let’s be bold, together.
Explore #ForresterLife on:
Instagram (
Glassdoor (
FLSA Status:
Exempt
Here at Forrester, we welcome people from all backgrounds and perspectives. Our aim is for all candidates to be able to fully participate in Forrester’s recruitment process. If you would like to discuss a reasonable accommodation, please reach out to View email address on click.appcast.io .
Forrester Research, Inc. is an Equal Employment Opportunity Employer. As a federal contractor, Forrester encourages veterans and individuals with disabilities to apply for employment.
Benefits at a Glance (
Benefits at a Glance - Cambridge
- ...A dynamic cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work closely with senior members to strengthen client cybersecurity and compliance programs. You'll be involved in assessing controls,...CyberRemote work
$50 - $56 per hour
...An international law firm is looking for a Senior Analyst, Cyber Risk to join their security group. The Firm has more than 1,300 lawyers and has... ...CRISC, CISM, CISA, ISO 27001 Lead Auditor/Implementor - GRC tooling experience - Metrics & Awareness experience...CyberSeniorWork at office$172k - $202.5k
...Gartner is seeking a Senior Director Analyst in Cybersecurity, Governance, Risk & Compliance (Remote US). This role entails providing thought leadership, developing... .... The ideal candidate should have 12+ years in Cyber GRC/Information Security with proven leadership...CyberSeniorRemote work- ...RegScale is hiring a Senior Content Marketing Manager to lead the brand voice and content strategy, generating awareness and demand across... ...in B2B SaaS content marketing, preferably in cybersecurity or GRC. Responsibilities include developing a full editorial calendar,...CyberSenior
- ...join us. The Role Rogo is hiring a GRC Analyst to support our customer trust, security... ...-market teams to ensure Rogo's controls, risk posture, and security practices are clearly... ...2, ISO 27001, ISO 42001, EU AI Act, UK Cyber Essentials, and GDPR, including evidence...Cyber
$95k - $105k
...Subsplash is looking for a GRC Analyst to join its Remote team in the United States. In this role, you'll be a strategic lead in advancing security and risk operations by identifying gaps and implementing best practices. With a salary range of $95,000-$105,000/yr, you'...SeniorRemote work- ...A cutting-edge technology firm in the United States is seeking a Senior GRC Analyst. The role requires 5+ years of experience in risk management, compliance, and governance. You will support the organization's GRC program, maintain security compliance frameworks, and...SeniorRemote work
$130k - $160k
...Alumni Ventures is seeking a Senior GRC Analyst to operate and mature governance, risk, compliance, and audit readiness programs. This role involves collaboration across departments to ensure effective compliance practices. Ideal candidates have 5+ years in GRC and experience...SeniorRemote workFlexible hours- ...Neier Inc. is seeking an Experienced or Senior GRC Analyst to lead cybersecurity and compliance initiatives. This full-time, remote position will focus on risk assessments, developing compliance programs, and mentoring junior analysts. The ideal candidate has over 5 years...SeniorFull timeRemote work
- ...Radar Senior GRC Analyst Radar is the global leader in geolocation, with geofencing SDKs, maps APIs, and AI-enabled solutions for marketing... ...and compliance programs, with a focus on third-party risk and modern SaaS governance. You'll partner with Engineering...SeniorWork at officeRemote work
$95k - $110k
...Blackkite is looking for a Senior GRC Analyst to oversee compliance efforts and support customer security assessments in the United States. This role requires expertise in compliance frameworks like SOC 2 and ISO 27001, along with strong communication skills. The successful...SeniorFlexible hours$130k - $160k
...Location U.S Remote Employment Type Full time Department Engineering Team & Role As a Senior GRC Analyst at Benepass, you will help operate and mature the governance, risk, compliance, audit readiness, and customer assurance programs that support our business, customers...SeniorFull timeWork at officeRemote workWork from homeFlexible hours$135k - $190k
...employees who prefer to work in an office some or all of the time. About your role As a Senior GRC Analyst, you are responsible for supporting the organization's governance, risk management, and compliance (GRC) program. The ideal candidate will have a strong understanding...SeniorFull timeWork at officeLocal areaRemote workWork from homeFlexible hours- Radar is hiring a Senior GRC Analyst in New York City to enhance security and compliance programs, focusing on third-party risk and SaaS governance. You will work with various teams to evaluate vendors, shape security strategies, and improve workflows, reporting to the...Senior
- A leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves... ...with various departments to implement governance and risk management processes. The ideal candidate has a Bachelor’s...Senior
- ...A dynamic consulting firm in the United States seeks a Senior Associate for its Cyber Security & Data Privacy (CSDP) group. This role involves leading... ...knowledge of compliance frameworks. Experience with GRC tools is also essential. The firm values collaboration, mentorship...CyberSenior
$161.6k - $202k
...that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You'll join the Security... ...security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk...SeniorWork from homeFlexible hours$63.8k - $90.8k
...Senior Analyst - Cyber Risk Advisory AGRC What if your cyber risk expertise shaped enterprise-wide decisions-not just technical reports? Looking to combine analytics, governance, and financial insight in one role? Step into a career where cyber risk translates...CyberSeniorFull timeTemporary workPart timeWork experience placementWork at officeLocal areaRemote work$150k - $185k
...Actuary / Senior Actuary New York, New York, United States Actuary / Senior Actuary... ...the ground up to help businesses tackle cyber risk head on. By combining industry-leading... ...growing team of actuaries and actuarial analysts of diverse backgrounds and report to our...CyberSenior$76 per hour
The Cake is looking for an experienced cyber risk analyst to conduct assessments and support governance documentation in New York City. The role requires 5+ years in cyber risk or security governance and the ability to translate technical risks into business language....Cyber$200.7k - $229.1k
...Senior Manager, Cyber Risk and Analysis Capital One is one of the fastest growing organizations in the world today, powered by our passion... ...technical audiences ~5+ years of experience applying risk quantification methodologies and rolling out risk framework changes ~4...CyberSeniorFull timePart timeLocal area$91.57k - $110k
...REACHABLE ON THE CYBERSECURITY ANALYST CIVIL SERVICE LIST ARE... ...Services plays a leading role in risk-based assessments of the Department... ...position will report to the Cyber Security IT Audit Manager in the... ..., Risk and Compliance (GRC) best practices, methodologies...CyberSeniorPermanent employmentWork at office- ...exclusive features. Position Title: Senior Actuary - Medicare Strategy... ...with product, finance, and risk adjustment teams to ensure financial... ..., Professional Liability & Cyber Pricing United States $121,000... ...1 week ago REMOTE - Actuarial Analyst II (ACA) - R9791 United States...CyberSeniorFull timeWork at officeRemote work
$94.2k
...teams and other areas necessary to identify risks to the business and drive solutions... ...Framework (HITRUST CSF), or the NIST 800-83 cyber security framework Experience supporting... ...experience Governance Risk and Compliance (GRC) tool experience such as ARCHER In-depth...CyberSeniorLocal areaRemote work$109k - $124.4k
Senior Business Analyst - Technology Risk Management Join to apply for the Senior Business Analyst - Technology Risk Management role at Capital One Senior... ...with very senior stakeholders in our Technology, Cyber and Product risk organizations. You will help deliver on...CyberSeniorFull timeTemporary workPart timeWork at officeLocal area- ...Priority" for Liberty Mutual? The NAS Financial Lines and Cyber team is looking for a dedicated individual to lead pricing... ...premium over the next five years. We are open to fill as a Senior Actuarial Analyst (Grade 16) or an Actuary (Grade 18) depending on candidate...CyberSeniorLocal area
$95.17k - $156.36k
...Senior Analyst - Cyber Risk & Control Monitoring Position Summary Do you want to be part of a collaborative Cybersecurity Governance team... ..., technology risk, control testing/assurance, audit, or GRC Hands-on experience coordinating audits/assessments (...CyberSeniorFull timeWork at officeVisa sponsorshipWork visaFlexible hours3 days per week- A global consulting firm is seeking a Senior Consultant in Risk Technology to support client engagements in SAP Security and GRC solutions. You'll help design and implement security measures while collaborating in diverse teams to enhance client operations. Candidates...SeniorFlexible hours
$90k - $160k
...IT RISK & CONTROL SENIOR ANALYST WHAT IS THE OPPORTUNITY? The IT Risk Senior Analyst is a subject-area specialist with specialized training,... ...analytic techniques to create recommendations and directions for cyber risk mitigation in a complex technical environment. ITRM...CyberSeniorRemote work- Capital One is seeking a Senior Associate - Cyber Risk & Analysis in New York City to join its Tech Audit team. This role will focus on cybersecurity risks and critical technology audits, allowing for personal and professional growth in a collaborative environment. The...CyberSenior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Analyst, Cyber Risk Quantification and GRC. Be the first to apply!
- transaction risk analyst New York, NY
- operational risk consultant New York, NY
- governance risk & compliance analyst New York, NY
- it risk analyst New York, NY
- quantitative risk analyst New York, NY
- risk analyst intern New York, NY
- information risk analyst New York, NY
- risk compliance officer New York, NY
- operational risk specialist New York, NY
- risk analyst New York, NY

