Manager, Information Security Compliance & Risk
$175k - $200kAnalysis Group
Overview Analysis Group is one of the largest international economics consulting firms, with more than 1,500 professionals across 15 offices in North America, Europe, and Asia. Since 1981, we have provided expertise in economics, finance, health care analytics, and strategy to top law firms, Fortune Global 500 companies, and government agencies worldwide. Our internal experts, together with our network of affiliated experts from academia, industry, and government, offer our clients exceptional breadth and depth of expertise. The Manager, Information Security Compliance and Risk is responsible for leading the firm's Governance, Risk, and Compliance (GRC) program, including regulatory compliance, enterprise risk management, and assurance activities that support client requirements and regulatory obligations. This role also serves as the primary owner of Information Security AI governance, ensuring that the firm's use of AI and machine learning technologies aligns with security, privacy, regulatory, and client expectations. The role manages a team of three Information Security Analysts and owns SOC 2 and ISO 27001 certification programs, while partnering closely with Legal, Compliance, Privacy, IT, and Security Engineering and Operations to ensure effective control design, evidence collection, risk management, and continuous improvement. Responsibilities: Governance and Compliance Leadership
- Own and maintain the firm's information security governance framework, including policies, standards, and procedures.
- Lead annual SOC 2 and ISO 27001 audit cycles, including audit readiness, evidence coordination, and remediation tracking.
- Ensure ongoing compliance with client, regulatory, and contractual information security requirements.
- Manage policy exceptions, risk acceptances, and documentation of compensating controls.
- Lead the renewal and ongoing maintenance of government and client security authorizations, attestations, and approvals required for regulated engagements.
- Coordinate cross-functional evidence collection and control validation to support authorization renewals and periodic reassessments.
- Track authorization requirements, renewal timelines, and control changes to ensure continuous eligibility for regulated work.
- Lead the Information Security AI governance program, ensuring secure, responsible, and compliant use of AI technologies across the firm.
- Partner with Legal, Privacy, Compliance, and business stakeholders to define and maintain AI security requirements, risk assessments, and usage standards.
- Establish and maintain security controls for AI-enabled tools, including data handling, access controls, model usage restrictions, and third-party AI risk.
- Support client and regulatory inquiries related to AI security posture and governance practices.
- Track emerging AI-related regulatory and security requirements and assess their impact on firm policies and controls.
- Maintain and mature the enterprise information security risk register.
- Facilitate periodic risk assessments, including risks associated with AI usage, data processing, and third-party technologies.
- Develop and report meaningful risk metrics and dashboards for leadership review.
- Translate technical and operational risks into clear business-impact language.
- Oversee third-party security risk management in partnership with Legal.
- Lead structured reviews of vendor security posture, including AI and SaaS providers.
- Track remediation plans and ongoing monitoring of third-party and AI-related risks.
- Serve as the primary liaison for internal and external audits related to information security.
- Coordinate evidence collection across IT, Security Engineering, Privacy, and business stakeholders.
- Track findings, corrective actions, and continuous improvement initiatives.
- Directly manage three Information Security Analysts.
- Set priorities, provide mentorship, and support professional development.
- Establish consistent processes, documentation standards, and performance expectations across the GRC function.
- Partner closely with Security Engineering and Operations to align governance requirements with technical controls.
- Work with Legal, Compliance, Privacy, and Data Science teams on regulatory interpretation and AI governance requirements.
- Support client security inquiries, assessments, and due diligence requests.
- Sustained audit readiness for SOC 2 and ISO 27001 with minimal disruption.
- Clear, measurable visibility into information security and AI-related risk posture.
- Consistent, scalable governance processes supporting firm growth and responsible AI adoption.
- Strong alignment between governance requirements and operational security controls.
- Bachelor's degree required; degree in information security, risk management, or a related field preferred.
- 7 to 10 years of experience in information security, GRC, audit, or risk management required.
- Prior experience managing SOC 2 and or ISO 27001 programs required.
- Demonstrated people management or team leadership experience.
- Professional certifications such as CISSP, CISM, CRISC, CGRC, or ISO 27001 Lead Implementer or Auditor.
- Experience with GRC platforms and risk management tooling.
- Experience supporting AI governance, data governance, or emerging technology risk programs.
- Experience supporting client-driven security assessments in a professional services environment.
- An inclusive and growth-oriented mindset, strong interpersonal skills, and an ability to work across differences.
- To the extent permitted by applicable law, eligible candidates must be authorized to work in the United States without sponsorship or restriction, now and in the future.
- Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities.
- Please view the EEOC's "Know Your Rights" poster here.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Manager, Information Security Compliance & Risk in Boston, MA vacancy
- ...Description & Requirements The Senior Director, Global Information Security and Risk is the senior-most leader accountable for the... ...s enterprise-wide information security posture, risk management, and compliance maturity. Reporting to the CIO, this role provides...RiskWork at officeLocal areaFlexible hours3 days per week
$175k - $200k
Analysis Group, Inc. seeks a Manager for Information Security Compliance and Risk in Boston, MA. The role involves leading the Governance, Risk, and Compliance program, managing a team of analysts, and overseeing information security governance, including AI compliance...Risk$128.1k - $239.6k
...fueled by vast amounts of information. Data is more valuable... ...in EY Information Security has a critical role to... ...Information Security we blend risk strategy, digital... ...Security Portfolio Compliance Enablement function, you... ...these pillars: Risk Management and Reduction: Assisting...RiskWork experience placementSummer holidayLocal areaFlexible hours$185k - $277k
...Overview The Senior Manager of Enterprise Security is a technical people leader... ...SecDevOps and continuous compliance programs, and leads a living... ..., Legal, and Governance, Risk, and Compliance, this... ...~ Work with the information security GRC function to adapt...RiskWork at officeRemote work$95k - $110k
...in third-party cyber risk intelligence, trusted... ...organizations worldwide. We give security and business leaders a... ...cyber, financial, and compliance signals into clear,... ...-party cyber risk management programs in an... ...reports to the Director of Information Security and owns three...RiskWorldwideFlexible hours$130k - $140k
...Job Description Role: Manager, Security Operations Location: United... ...reviews Vulnerability and risk tracking Ensure... ...working with Legal, Privacy, or Compliance teams during security incidents... ...annual incentive program, and information on benefits offered is here....RiskFull time$118.45k - $260.59k
...Position Summary The Senior Manager - Zero Trust is a senior... ...a dedicated team of security engineers, managing the implementation... ...with IT, security, compliance, and various business... ...protection fundamentals and risk‑based approach to information security. Preferred...RiskHourly payFull timeTemporary workWork experience placementLocal areaRemote work- ...Sr. Business Information Security Officer (Sr. BISO) – Consumer Technology... ...BISO) – Consumer and Wealth Management Technology will be a member... ...specialized information security risk-based discussions. This... ...wider risk management and compliance programs • Monitors...RiskWork at officeShift workDay shift
$147k - $185k
...leader in healthcare data management and interoperability,... ..., availability, and security are non-negotiable.... ...engineering, architecture, compliance, and operations... ...Communicate progress, risks, and decisions to support... ...countries worldwide. For more information, please visit...RiskTemporary workWorldwide$195k - $300k
..., while providing strategic oversight of regulatory risk management and corporate compliance function. The role will serve as a key advisor to the... ...governance and credible challenge for the firm’s information security program in partnership with the CISO. Own privacy governance...RiskContract work- ...zone Contentful strives to build a secure and safe service and commits... ...Security team supports organization-wide information security management programs and collaborates closely with... ...initiatives, and ensure comprehensive risk mitigation while minimizing impact on...RiskFull timeWork at officeLocal areaRemote workWorldwide
$100.5k - $122.1k
...looking for a Technical Program Manager with experience managing Information Security projects, resources, and timelines... ...resource planning and assignments, risk monitoring, and project... ...configurations. Security & Compliance: Coordinate with security teams to...RiskFlexible hours- ...Cybersecurity and Privacy Risk Advisor About the Company... ...spearhead the advancement of its Information Security Governance and Risk... ...leading the team to ensure compliance and continuous control monitoring... ...in solving complex IT-risk management issues, with a strong...RiskWork experience placement
$117k - $210.6k
...with cutting-edge web security platforms? Do you love... ...problems? Join our global Information Security team We are seeking a Manager of Information Security... ...managing dependencies, risks, and cross-functional... ...of relevant security compliance experience and a...RiskPermanent employmentWork experience placementWork at officeWork from homeWorldwideFlexible hours$81.15k - $83.57k
...Information Technology Manager/Information Security Officer - Career Centers Department: Education, Training, and... ...sites Information Security & Compliance Serve as the designated Information... ...Monitor and respond to security risks and incidents in coordination...RiskPermanent employmentFull timeLocal areaRemote work$84k - $126k
...opportunity within the Security Strategy and... ...developing and refining information security strategy, creating... ...team (namely Security Risk and Trust, Security Product... ...Technical Program Manager is an expert-level technical... ...third-party risk, compliance and audit readiness,...RiskFlexible hours- A nonprofit research and development company in Cambridge seeks a Supply Chain Risk Manager to oversee operations and ensure compliance with Department of Defense programs. The role requires leading cross-functional teams, strong knowledge of supply chain risk management...Risk
$90k - $115k
BRG is seeking an IT Risk and Compliance Analyst in Boston, MA. This client-facing role works closely with Legal and Business Unit stakeholders to assess and monitor compliance with information security standards. You'll provide risk and compliance advice, maintain policies...Risk- Wayfair is seeking a Global Security Operations Center (GSOC) Manager to innovate, lead and... ...executive security, regulatory compliance, business continuity, and... ...responsive to evolving risks while advancing global... ...evaluate potential risks and inform mitigation strategies....RiskWork at officeLocal area
$84k - $105k
...Description POSITION: Enterprise Risk Reporting Analyst Position... ...operates within Enterprise Risk Management (ERM) and is responsible for providing... ...with Finance, Credit, Compliance/BSA, Data, Operations, Information Security, Technology, as well as key Business...RiskFull timeVisa sponsorshipWork visaFlexible hours$148k - $296k
...Summary We are seeking a Senior Manager, Security Operations to join K&L... ...security while maintaining compliance standards, and manage security... ...and safeguard against risks from various sources. Oversee... ...in computer science, information security, cybersecurity, or...RiskTemporary workWork at officeRemote workRelocationFlexible hours- ...Information Security Governance, Risk and Compliance (GRC) Analyst The ideal candidate is a self-starter with a passion for building relationships and... ...practical experience in Information Security Risk Management Strong work ethic, great time management, and highly...Risk
- ...Position: Junior Information Security Analyst Location: Boston, MA (Hybrid... ...responsible for ensuring compliance with industry regulations,... ...of clients' Governance Risk and Compliance (GRC) technology... ...in Compliance and Risk Management ~ Bachelor's Degree or equivalent...RiskContract workTemporary workFor contractorsLocal area
$100k - $135k
...Description Operational Risk Manager - Cybersecurity Work Arrangement Hybrid... ...oversight, review, and challenge of information security and technology related risks. The colleague... ...activities to assess corporate wide compliance. The role may be co-located as...RiskLocal areaRemote workMonday to FridayFlexible hours$110.5k - $202.7k
...objective of our Consulting risk services is to provide... ...be responsible for managing multiple client... ...evaluate, and enhance information systems facilitating the... ...technology control and security engagements. Skills... ...risks and maintaining compliance. To qualify for the...RiskContract workSummer holidayWork at officeImmediate startFlexible hours- ...Notes: . 37.5 Hours a week. hybrid Information Security Governance, Risk and Compliance (GRC) Analyst The Massachusetts Department of... ...alignment of IT activities to business goals and the management of information security risks. Our GRC program needs...RiskFor contractorsWork at officeRemote workMonday to FridayFlexible hoursShift work
- Position: Junior Information Security Analyst Location: Boston, MA (Hybrid... ...is responsible for ensuring compliance with industry regulations,... ...implementation of clients' Governance Risk and Compliance (GRC)... ...in Compliance and Risk Management Bachelor's Degree or equivalent...RiskContract workFor contractorsLocal area
$170k - $230k
...Of Cyber & Technology Risk At BBH, partnership... ...career. Enterprise Risk Management is hiring a Head of... ...guidance that enables secure delivery. You'll bring... ...; partner with Legal, Compliance, and Risk teams to... ...Technology. Partner with Information Security to refresh...RiskLocal area- ...implementation, and maintenance of the firm's governance, risk management, and compliance program. The ideal candidate will have a strong... ...regulatory requirements, risk management frameworks, and information security. They will have experience performing third-party risk...RiskFlexible hours
$108.88k - $163.32k
...Technology and more. Overview The ADUSA Security Manager oversees the Security Patching team,... ...Corporate locations) from security cyber risks. Establishes and executes the... ...Technical Undergraduate degree. Knowledge of information systems and security controls, of attack...RiskFull timeWork experience placementWork at officeRemote workFlexible hoursWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Manager, Information Security Compliance & Risk. Be the first to apply!
Related searches
- senior director information security Boston, MA
- surveillance manager Boston, MA
- security engineering manager Boston, MA
- security systems manager Boston, MA
- director global security Boston, MA
- physical security manager Boston, MA
- security manager Boston, MA
- corporate security manager Boston, MA
- director information security Boston, MA
- security operations manager Boston, MA

