Deputy Director of IT Risk and Compliance
Massachusetts Bay Transportation Authority
The Deputy Director of IT Risk & Compliance Management provides strategic and operational leadership over enterprise technology risk, compliance, and governance functions across the MBTA. The role safeguards information assets by operationalizing security and privacy control frameworks, orchestrating supply chain and vendor risk diligence, and translating risk posture between executive-level dashboards and actionable remediation plans. The Deputy Director fosters a high-performance culture of security awareness, drives policy governance, and serves as a trusted advisor to senior leadership on emerging risks spanning legacy, cloud, DevOps, and Operational technology environments. Direct the risk management lifecycle—identification, assessment, response, monitoring—for IT and OT systems, ensuring alignment with NIST CSF, NIST800-53, ISO27001, CIS, and applicable privacy mandates (e.g., MA201CMR17.00, GDPR, CCPA). Maintain an authoritative inventory (Risk Register) of business, technology, regulatory, contractual, and organizational security related risks; oversee continuous control testing and issue management. Design and run a robust Supply-Chain Risk Management (SCRM) program, including third-party onboarding, due-diligence assessments (SOC2, ISO27001, PCIDSS, FedRAMP, CMMC), and ongoing performance monitoring. Coordinate with Procurement and Legal to embed security clauses and right-to-audit provisions in contracts. Develop, socialize, and maintain MBTA information security and privacy policies; drive adoption through targeted awareness campaigns, phishing simulations, and organization-wide training. Evangelize a Security-First mindset via townhalls, brownbag sessions, and executive briefings. Administer and optimize GRC portals (e.g., ServiceNow, Archer) for controlcatalogues, risk registers, exception management, and board-level metrics. Integrate vulnerability, incident, and asset data to deliver end-to-end traceability from findings to remediation and residual risk reporting. Produce concise, data-driven dashboards and briefings for the CISO, CIO, Board, and federal regulators (TSA, FTA, DHS/CISA). Present program status, risk trending, and budget justification in publics peaking forums, executive committees, and industry conferences. Lead, mentor, and develop a diverse team of risk analysts and compliance specialists; cultivate psychological safety, accountability, and continuous learning. Champion collaboration across Operations, Engineering, Legal, Audit, and Finance to embed security into MBTA’s technology and business roadmaps. Evaluate emerging threats, technologies, and regulatory changes; recommend process enhancements, automation, and tooling (e.g., IRM workflows, AI assisted control testing). Serve as primary interface for internal/external auditors and regulatory bodies; coordinate evidence collection, track remediation commitments, and attest to control effectiveness. Perform all other duties and projects that may be assigned. Additional responsibilities may include focus on one or more departments or locations. See applicable addendum for department or location specific functions. Supervision Manage a team of engineers and administrators. Bachelor’s degree from an accredited institution in Computer Science or a related field. Five (5)years of progressive IT risk, compliance, or cybersecurity governance experience within large, complex environments, Two (2)years of supervisory, managerial, and/or leadership experience. Demonstrated implementation of NIST800-53/CSF, ISO27001/27701, CISControls, ITIL, COBIT, and privacy regulations. Working knowledge of network, cloud (AWS/Azure), DevOps pipelines, legacy on-prem systems, security tooling (SIEM, EDR, IAM), and vulnerability management platforms. Handson administration of GRC suites (ServiceNow GRC, Archer, Origami, Armis, Nazomi) and phishing training platforms (KnowBe4, Proofpoint, Cofense). Exceptional verbal and written communication, publics peaking, and executive level presentation skills. At least one of: CRISC, CISM, CISSP, CISA; willingness to achieve additional certificates as needed. Substitutions A High School Diploma or GED with an additional seven (7) years of directly related experience substitutes for the bachelor’s degree requirement. An associate’s degree from an accredited institution and an additional three (3) years of directly related experience substitutes for the bachelor’s degree requirement. A master’s degree in a related subject substitutes for two (2) years of general experience. A nationally recognized certification, or statewide/professional certification in a related field substitutes for one year of experience. Seven (7) or more years of progressive IT risk, compliance, or cybersecurity governance experience within large, complex environments. Three (3)or more years in a supervisory/leadership capacity. Additional credentials (e.g., CGEIT, CCSP, ISO27001 Lead Auditor, PMP). Experience with federal critical infrastructure directives (TSA SD1580/82202201C, NISTSP80082). Exposure to operational technology (OT) environments and rail/transit systems. Record of thought leadership through conference speaking, publication, or standards body participation. Strategic thinker with a hands-on, results driven approach. Analytical mindset and quantitative skills; comfort with ambiguity and rapid change. Demonstrated integrity, ethical judgement, and commitment to public service. Ability to inspire teamwork, inclusivity, and a culture of continuous improvement. #J-18808-Ljbffr Massachusetts Bay Transportation Authority
- MBTA is seeking a Deputy Director of IT Risk & Compliance Management to provide strategic leadership over enterprise technology risk, compliance, and governance. The role ensures protection of information assets by implementing security controls, managing risk across IT...Suggested
- ...Director of Risk Management Boston, MA 02118 MUST HAVE: Master's degree in healthcare-related field or JD required. CPHRM is required within 6 months of hire, CPPS preferred, CPHQ optional. At least 5 years of direct clinical...Suggested
- Massachusetts Bay Transportation Authority (MBTA) seeks a Deputy Director of IT Risk & Compliance Management to provide strategic and operational leadership across enterprise technology risk, compliance, and governance functions. This role safeguards information assets...Suggested
$150k
...expertly crafted Commercial Insurance and Risk Management, Private Insurance and Risk... ...and risk management.Position Summary: The Director of Sales, Commercial Risk will be... ...team of sales professionals, and ensuring compliance with regulatory requirements.Primary Responsibilities...SuggestedFull timeContract workWork at office- ...Associate Chief Quality and Patient Safety Officer, the Senior Director of Risk Management and Patient Safety serves as a strategic leader... ...regarding malpractice claims and regulatory agencies for compliance and reporting. Beyond daily operations, this position drives...Suggested
$180k - $190k
...clients’ success.This position has a HYRBID schedule in our San Mateo, Boston, or New York office.About the DepartmentOur Investment Risk team safeguards the quality and performance of the firm’s fixed income strategies by providing quantitative insights, independent...Full timeWork at officeLocal area$175k - $225k
...The Director, Investment Risk will establish a centralized investment risk function within the Enterprise Data & Analytics team. Building upon... ...with investment professionals, Product Management, Legal & Compliance, Information Technology, and senior leadership to enhance...Work at officeLocal areaRemote work1 day per week- BlueHub Capital in Boston, MA is seeking a Director of Credit to lead the Lending team. Reporting to the Chief Credit Officer, you will oversee the credit approval and oversight process, ensuring consistency and integrity across BlueHub’s lending programs. The role requires...
$140k - $160k
Your role at DynatraceDynatrace is looking for an IT Compliance Lead to join our Business Systems organization. This position will run all... ...processesLead the IT Compliance Program activities that will include risk assessments, IT governance, internal/external audit...Work experience placementWork at officeRelocation2 days per week$150k
...expertly crafted Commercial Insurance and Risk Management, Private Insurance and Risk... ...and risk management. Position Summary The Director of Sales, Commercial Risk will be... ...team of sales professionals, and ensuring compliance with regulatory requirements. Primary Responsibilities...Contract workWork at officeLocal area- Cambridge Health Alliance seeks a Senior Director of Risk Management and Patient Safety to provide enterprise-wide strategic leadership for risk, safety, and regulatory compliance. Reporting to the Associate Chief Quality and Patient Safety Officer, this role drives a...
$77k - $214k
Industry/SectorNot ApplicableSpecialismIFS - Risk & Quality (R&Q)Management LevelSenior AssociateJob Description & SummaryAt PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients, providing advice, and solutions...Full timeH1b- ...investment management firm is seeking an experienced operational risk professional to join its high-performing Risk and Control team. In... ...policies, and delivering targeted training.Collaborate with IT and cybersecurity teams to assess technology-related risks, design...
$212.7k - $259.1k
...within our reach and yours as a WSP employee. Come join us and help shape the future!WSP is currently initiating a search for a Senior Risk Manager in Boston, MA. Your ImpactProvide risk leadership and act as the risk management subject matter expert on assigned project,...Contract workLocal areaFlexible hours$130k
...and may directing, the implementation and delivery of a range of risk services to support commissions and to provide line management... ...outcomes within our industry, while always aligning with our compliance obligations.Create Opportunity - For our people to excel: We champion...Full timePart timeFlexible hours$115k - $130k
...solutions that traditional providers cannot.ROLE OVERVIEWThe Manager, Risks Processes and Controls will take ownership of critical fund... ...activities, working cross-functionally with finance, legal, compliance, and operationsMaintain fund governance documentation and manage...Full timeWork at officeFlexible hours$180k - $190k
Investment Risk Manager - Taxable / Fixed Income | Hybrid | $180k-$190k | Boston, MA What You'll Do: Partner directly with portfolio managers and investment teams to provide independent risk analysis and quantitative insights Monitor portfolio risk exposures and deliver...Work at officeVisa sponsorship3 days per week$134k - $348.5k
...LevelDirectorJob Description & SummaryAt PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks... ...business growth and secure client satisfaction. As a Director, you will set the strategic direction, oversee multiple projects...Full timeTemporary workH1b$101k - $203k
...that’s why there’s nowhere like RSM.The ERP Risk and Automation Services (ERAS) Consulting... ...security and GRC (governance, risk and compliance) Proven experience managing project... ...Certifications: CPA, CIA, CISA, CFE or similar IT General Controls experience Prior...Full timeWork experience placementInternshipLocal area- ...their ability to drive real progress.The Group Head of Catastrophe Risk Analytics is responsible for leading Catastrophe risk analytics... ...requirements.Collaborate with underwriting, claims, actuarial, finance, and IT functions to deliver robust catastrophe risk insights that inform...Full timeWorldwide
$157.5k - $205k
...Transformation, you will help lead the reinvention of how Circle’s Global Risk Management (GRM) organization operates — moving it from today’s... ...AI transformation, you will partner with process owners across compliance, financial crime, security, financial risk, and enterprise risk...Flexible hoursShift work$128.55k - $222.82k
Job DescriptionThe Director, GWAM Business Risk Management, is a first line (Line 1B) risk management role responsible for supporting the implementation... ...leaders, process owners, and control owners to ensure compliance with enterprise risk management requirements.The Director...Full timeTemporary workLocal areaFlexible hours- ...cash incentive awards.Salary Range$120,400.00 - $198,700.00Target Openings1What Is the Opportunity?Travelers Enterprise Catastrophe Risk Management is seeking a Senior Manager to join our Actuarial and Analytics team. This team provides enterprise governance, analytical...Full timeLocal area
$220k - $330k
Job DescriptionThe Senior Director, Enterprise Third Party Risk Leader, will lead an expanded third-party risk management E2E process, including leading a Central Risk Management team and driving a holistic, effective and efficient third-party risk management approach for...Full timeSummer workImmediate startRemote workFlexible hours2 days per week$120.1k - $138.2k
...Under the direction of the Director of Patient Safety & Risk Management, the Risk Manager is a member of the Patient Safety & Risk Management team... ...level of quality care to the patients, ensuring regulatory compliance and mitigating malpractice risk through loss prevention....Work at office$78k - $113k
...The Risk Manager is responsible for the overall management of potential risks and liabilities within Boston Medical Center (BMC) and... ...Supports QA/RM databases for committee review Regulatory & Compliance Reporting Reports to external agencies (DPH, DMH, CMS, BOR, IM...Work experience placementWork at officeFlexible hours$97.5k - $141.5k
...POSITION SUMMARY : The Senior Risk Management Specialist provides leadership... ...care to the patients, ensuring regulatory compliance and mitigating malpractice risk through... ...leadership, the Chief Quality Officer, Director of Risk Management and the Director of Patient...Full timeFixed term contractWork at officeLocal areaImmediate startFlexible hours3 days per week- ...Operational Risk Manager (ORM) The Operational Risk Manager (ORM) serves as the regional leader for operational risk mitigation, safety, and compliance. This role is responsible for driving a culture of safety and risk awareness across field operations, ensuring contractual...Work at officeRemote work2 days per week
- ...Operational Risk Manager (ORM) The Operational Risk Manager (ORM) serves as the regional leader for operational risk mitigation, safety, and compliance. This role is responsible for driving a culture of safety and risk awareness across field operations, ensuring contractual...Work at officeLocal areaRemote work2 days per week
$115k
...$115,000 Job Overview - Operational Risk Manager Compensation: $115,000-$135,00... ...controls, audit readiness, and operational compliance within a financial services environment.... ...Experience: 6+ years of experience in IT audit, risk consulting, internal controls...Permanent employmentWork at officeMonday to Friday
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Deputy Director of IT Risk and Compliance. Be the first to apply!
- chief information officer Boston, MA
- information management officer Boston, MA
- IT director Boston, MA
- director of it audit Boston, MA
- cio Boston, MA
- director credit risk Boston, MA
- head of risk management Boston, MA
- risk management associate Boston, MA
- operational risk manager Boston, MA
- risk management specialist Boston, MA


