Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Risk Analyst

$110k - $130k
Full-time

Audax Group

Founded in 1999, Audax Group is a leading alternative investment manager with offices in Boston, New York, San Francisco, London and Hong Kong. With approximately $42 billion of assets under management and more than 475 employees, Audax is a leading capital partner for middle market companies, operating through three business lines: Audax Private Equity, Audax Private Debt, and Audax Strategic Capital.

For more information, visit or follow Audax Group on LinkedIn.

POSITION SUMMARY:

The Information Security Risk Analyst owns and executes the risk assessment activities that drive the ongoing maturity of the firm's information security risk program. This role independently performs risk assessments of vendors, applications, and internal systems, and maintains the supporting artifacts needed to track remediation and report risk in a consistent, repeatable way. The position also leads SOC 1 IT control evidence collection, audit coordination, due diligence questionnaires, and change management control validation.

The Risk Analyst partners closely with IT, Legal, Compliance, IR, and business stakeholders to ensure security risks are identified, documented, communicated, and addressed through practical mitigation plans. This role helps improve audit readiness, supports investor and customer assurance needs, and enables the business to operate efficiently while meeting governance and security expectations.

RESPONSIBILITIES:

  • Risk Assessment & Remediation
    • Perform independent information security risk assessments for vendors, applications, systems, and business processes.
    • Conduct application security vetting, including architecture reviews, control validation, and risk documentation.
    • Apply consistent risk rating methodology (likelihood, impact, inherent, residual) and document scoring rationale.
    • Partner with control owners to define practical remediation plans, including interim compensating controls.
    • Facilitate recurring risk review check-ins with control owners to validate progress on remediation plans.
    • Support risk exception and risk acceptance workflows (evidence collection, summaries, and tracking).
  • Governance, Policy & Strategy
    • Maintain and update risk registers, remediation tracking, and control mappings.
    • Map assessment results to common security and control frameworks (e.g., NIST CSF, ISO 27001, SOC 1 & SOC 2).
    • Contribute to policy, standard, and control development initiatives.
    • Identify process improvements and support continuous improvement of GRC tooling.
    • Contribute to documentation of SOPs, templates, and playbooks.
    • Develop risk narratives that translate technical controls into business-relevant language.
    • Support business continuity and resilience efforts (BIA input and tracking).
    • Partner with business stakeholders to reduce onboarding cycle time through repeatable processes.
  • Audit, Assurance & Investor Relations
    • Lead SOC 1 IT control evidence gathering across business units.
    • Coordinate internal and external audit requests and evidence collection.
    • Validate change management controls and ensure documentation supports audit requirements.
    • Improve audit preparedness and reduce last-minute evidence collection efforts.
    • Manage and respond to due diligence questionnaires (DDQs) from investors, customers, and partners.
    • Support initiatives that increase investor confidence in the security posture.
  • Monitoring & Investigations
    • Perform departing employee forensic reviews in collaboration with IT and HR.
    • Monitor and triage at-risk employee email and activity alerts.
    • Coordinate and track PII removal management activities, working with third-party providers and internal stakeholders.
    • Monitor and triage threat intelligence, digital risk protection (DRP) alerts, including brand impersonation, data exposure, and reputational threats, to identify new risks for assessment.

TECHNICAL QUALIFICATIONS:

  • Strong understanding of risk management frameworks (NIST CSF, ISO 27001, SOC 1/2 controls).
  • Experience performing third-party, application, and internal technology risk assessments using a consistent methodology (likelihood, impact, inherent, residual).
  • Working knowledge of control frameworks and mapping (e.g.: NIST CSF, ISO 27001, SOC 1 ITGC, SOC 2).
  • Familiarity with application security concepts, including architecture patterns and common control areas (IAM, logging, encryption, vulnerability management), and documenting security risks clearly.
  • Experience maintaining risk registers, remediation tracking, control mappings, and supporting evidence repositories.
  • Understanding of change management controls and how to validate required documentation and approvals.
  • Strong written risk documentation skills, including drafting risk narratives that translate technical control details into business impact.
  • Comfort handling security questionnaires and assurance requests (DDQs), including collecting inputs and validating supporting artifacts.
  • Baseline familiarity with security monitoring concepts and sources (SIEM alerts, EDR context, vulnerability scan outputs, threat intel summaries) to support triage and risk translation.

REQUIREMENTS:

  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or equivalent practical experience.
  • 3+ years of experience in information security risk, GRC, third-party risk, audit support, or security compliance.
  • Strong communication skills (written and verbal) with the ability to work across IT, Legal, Compliance, Privacy, HR, and business teams.
  • Demonstrated ability to manage multiple priorities, meet deadlines, maintain high-quality documentation, and follow through.
  • High attention to detail and comfort working with structured evidence, audit artifacts, and repeatable processes.
  • Ability to handle sensitive information with discretion and sound judgment.
  • Availability for on-call incident response outside of normal working hours including nights, weekends, and holidays.
  • Some domestic travel is required.
  • Preferred Certifications (not required): Security+, CRISC, CISA, ISO 27001 Foundation / Lead.

LOCATION: Boston, MA – Hybrid 4 days in-office. These in-office requirements may be adjusted based on the needs of the business.

For Massachusetts : The base salary range for this position is $110,000 - $130,000 . The base salary range represents the estimated low and high end for this position at the time of this posting. Consistent with applicable law, compensation may vary and will be determined based on but not limited to, the skills, qualifications, and experience of the applicant along with the requirements of the position, and Audax reserves the right to modify this pay range at any time. An employee may also be eligible for annual discretionary incentive compensation based on performance.

Audax offers a wide range of employee benefits, including health insurance, life insurance, disability insurance, paid time off (including sick leave, parental leave, volunteer leave, and vacation), charitable donation match, family support services (including Bright Horizons and Benefit Advocate Center), and a 401(k) in addition to other benefits.

This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities and activities may change or new ones may be assigned at any time with or without notice.

Audax Management Co. is an equal opportunity employer.

Please note that Audax Group and its affiliated entities do not accept unsolicited resumes from a third-party recruiting agency not currently under a signed agreement. Any unsolicited resume that is sent to directly to Audax Group or one of its affiliated entities, or its employees, including those submitted to hiring managers by a third-party recruiting agency not currently under a signed agreement, will be considered property of Audax Group. If a third-party recruiting agency submits a resume without an agreement, Audax Group or its affiliated entities explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the third-party recruiting agency. Any third-party recruiting agency should contact either a member of the Talent Acquisition or Human Resource team at Audax Group, in conjunction with a valid, fully executed contract for service based upon a specific job opening.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Security Risk Analyst in Boston, MA vacancy
  • $111k - $189k

     ...will transform complex threats into actionable intelligence for security operations, vulnerability management, and technology leaders,...  ...tools, and knowledge management practices.Communicate security risks and recommendations effectively to technical and non-technical... 
    Suggested
    Full time
    Local area
    Relocation package

    American Family Insurance

    Boston, MA
    3 days ago
  • $175k - $200k

    Security AnalystPosition SummaryAs a Security Analyst, you will be part of our growing Security & Compliance team, building security automations, creating baselines...  ...assessments to identify potential security risks.Work with DevOps, engineers, and system owners to remediate... 
    Suggested

    QuEra Computing

    Boston, MA
    1 day ago
  • $112k - $154k

     ...shape who you are.Position OverviewManages security operations tasks independently and...  ...Senior Security Operations Center (SOC) Analyst, you’ll take the lead on investigating and...  ...role will be focused around DLP and insider risk initiatives, which include incident analysis... 
    Suggested
    Full time
    Work at office
    Local area
    Visa sponsorship
    Flexible hours
    Shift work

    Zelis

    Boston, MA
    12 hours ago
  • Job-ID31409788Reference25-31660Title : SOC Analyst Location : New York City, Boston MA, Atlanta GA Shift : 3PM to 12AM EST Mon - Fri &...  ...SOC Analyst serves as the first line of defense for information security operationsmonitoring, investigating, and responding to... 
    Suggested
    Shift work

    Axelon

    Boston, MA
    4 days ago
  • $129k - $171k

     ...TEAMAnduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defense technologies...  ...a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing... 
    Suggested
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Boston, MA
    12 hours ago
  •  ...- $175000Posted: 2026-09-16We are seeking a Cybersecurity Analyst to join a growing organization focused on protecting critical...  ...infrastructure. This role offers exposure across security operations, risk management, compliance, and data protection initiatives. The... 

    Talener

    Boston, MA
    12 hours ago
  • $125k - $150k

     ...Technology Overview GovCIO is seeking a highly experienced Data Security Analyst - Master to lead the design, implementation, operation, and...  ...change requests according to established change-management, risk-review, and emergency-change processes. Perform regular... 
    Full time
    Remote work
    Flexible hours

    GovCIO

    Boston, MA
    1 day ago
  • $80k

     ...Senior Security Analyst, 2nd Shift, Quincy, MA - Mon-Fri 2-10 pm Country: United States of America It Starts Here: Santander is a global...  ...Benefits - 2026 Santander OnGoing/NH eGuide (foleon.com)]( Risk Culture: We embrace a strong risk culture and all of our professionals... 
    Hourly pay
    Full time
    Contract work
    Work experience placement
    Work at office
    Shift work
    Afternoon shift

    Banco Santander S.A.

    Quincy, MA
    9 days ago
  • $55 - $60 per hour

     ...Global Recruitment Center) at Akkodis Akkodis is seeking an IT Security Analyst for a Contract position with a client located in Quincy, MA....  ...to present and explain threat modelling; as well as institute risk detection and risk mitigation strategies to business and IT stakeholders... 
    Contract work
    Temporary work
    Work experience placement
    Local area
    Remote work
    Early shift

    Akkodis

    Quincy, MA
    4 days ago
  • Role: Security Analyst Duration: 6-12+ Months Contract Need Green Card or US Citizen Candidates Only Required Qualifications Bachelor's degree...  ...by conducting testing, internal control reviews, and risk assessments Maintain awareness of external regulations for new... 
    Contract work

    Cygnus Professionals Inc

    Boston, MA
    2 days ago
  • Form Energy in Somerville, MA is seeking an Information Security Analyst, AI Governance who will own the full lifecycle of AI tools: evaluating...  ...of AI tools, manage deployment, maintain an inventory and risk register, and define guardrails #J-18808-Ljbffr Form Energy
    Relocation package

    Form Energy

    Somerville, MA
    4 days ago
  • Mass General Brigham is seeking an Information Security Analyst I - Security Automation to support security operations through automation, scripting, and process improvement. You will help develop automated workflows that enhance threat detection, incident response, vulnerability... 

    Mass General Brigham

    Somerville, MA
    1 day ago
  •  ...SPECIFIC DUTIES - Partner with the BEST Team, SI, and product vendors, CTR and EOTSS to identify security requirements, using methods that may include risk and business impact assessments, including: provide operational support as defined by SLA requirements agreed... 
    Full time
    Work at office
    Work from home
    Flexible hours

    Volantsoft Inc

    Boston, MA
    1 day ago
  • $125k - $175k

    ## Information Security AnalystApplylocations: Bostontime type: Full timeposted on: Posted...  ...-100086**Position:**Information Security Analyst**Department:**511240 Information Tech (CIO...  ...security policy design and maintenance.* Risk management including vendor risk management... 

    Boston Partners Group

    Boston, MA
    4 days ago
  •  ...confidential search on behalf of a client - a well-established global IT services and business consulting firm - to place a Security & Compliance Analyst with one of their enterprise customers, a regulated organization based in South Carolina. This is a 6-month contract... 
    Contract work
    Remote work

    E-Frontiers

    Boston, MA
    4 days ago
  • $91.19k - $136.78k

     ...evaluate the effectiveness of the organization's security controls, detection capabilities, and response...  ...validate security investments, and reduce cyber risk. Reporting to the Cybersecurity Manager, the Security Analyst will work closely with IT teams across all threads... 
    Full time
    Work at office
    Work from home

    Point32Health

    Canton, MA
    12 hours ago
  •  ...Primary Responsibilities Perform information security risk assessments, control evaluations, and security reviews. Identify security risks, assess impact, and recommend mitigation strategies. Review security controls and ensure alignment with enterprise security... 
    Contract work

    PB consulting

    Woburn, MA
    27 days ago
  •  ...Job Title: Senior Information Security Analyst Location: Woburn, MA Work Arrangement: Hybrid / On-site as required Duration...  ...9 years of experience in information security, cybersecurity risk management, security engineering, or IT risk management ,... 
    Permanent employment
    Temporary work
    Local area
    Relocation

    Teamware Solutions

    Woburn, MA
    5 days ago
  • The Residential Rehabilitation Educator position is a great opportunity to work in the Human Services field. In this program, adults with mental illness share a home in the community. Our residential staff supports them to reach their goals by teaching them daily living...

    Calibre Inc

    Weymouth, MA
    5 days ago
  • $23.04 - $30.72 per hour

     ...cures for cancer. DESCRIPTION: Join our dedicated Global Security Operations Center (GSOC) team where you'll contribute to safeguarding...  ...and analysis • Strong knowledge of geopolitical and security risk assessment • Excellent verbal and written communication skills... 
    Hourly pay
    Temporary work
    Work at office
    Worldwide
    Shift work
    Night shift
    Day shift

    Gen Z Jobs

    Waltham, MA
    4 hours ago
  • Apply now: Security Operations Analyst , location is hybrid . The start date is ASAP for this 6 month contract position. Job Title: Security Operations Analyst Location-Type: Hybrid onsite in Needham, MA (Candidate must currently reside permanently local... 
    Contract work
    Local area
    Immediate start
    Relocation

    Mondo

    Needham, MA
    4 hours ago
  •  ...Job Description Job Description BEST Program Security Analyst Location: Boston, MA Duration: 6 Months Position Summary The BEST...  ...collaborate with the BEST PMO, Phase 2 Technical Lead, Phase 2 Risk and Compliance Lead, CTR Risk Management Team, product vendors... 
    Work at office

    Compu-Vision - IT

    Quincy, MA
    1 day ago
  •  ...100% remote. Our direct client has a new opening for a Lead Security Analyst 141809 This job is 14 months to start, and the client is located in Augusta, ME Please send your rate and resume. Top 3 Skills... 
    Local area
    Remote work

    FHR

    East Boston, MA
    12 hours ago
  •  ...Interim Assignment Position: Position Overview The Interim Security Analyst will provide hands-on security operations and technical...  ...incident response activities. Escalate significant or high-risk security events to appropriate leadership and stakeholders.... 
    Permanent employment
    Temporary work
    Interim role
    Monday to Friday
    Flexible hours

    AXA Professionals

    Boston, MA
    2 days ago
  •  ...American Operations Corporation (AOC) is seeking a Information Security Analyst to support the BLITS 3.0 program at Hanscom Air Force Base,...  ...status reports on vulnerability status, patch compliance, and risk posture for leadership and compliance reviews. • Collaborate... 
    Temporary work

    American Operations Corporation

    Lexington, MA
    4 hours ago
  •  ...diversity and inclusion.SummaryAt Leader Bank, the Information Security Analyst is responsible for the daily operational monitoring of events...  ...intrusion detection, threat detection/analysis, or information risk management preferred.Experience with SIEM systems is a plus.... 
    Temporary work
    Work at office
    Local area

    LEADER BANK

    Arlington, MA
    3 days ago
  •  ...prevention platforms, system logs, and other sources Investigate security events and remediate or escape them Monitor the ticketing system...  ...intrusion detection, threat detection/analysis, or information risk management preferred Experience with SIEM systems is a plus GIAC... 

    Jobtailor

    Arlington, MA
    1 day ago
  • $90k - $180k

     ...solutions, tailored to the unique return and risk objectives of institutional clients in...  ...of our clients.THE POSITIONThe Risk Analyst, Fixed Income position is part of the global...  ...portfolio oversight, risk measurement, and security analytics processes across our broad... 
    Full time
    Remote work
    Flexible hours
    1 day per week

    Wellington Management

    Boston, MA
    4 days ago
  • $76.3k - $92.1k

     ...Overview The Information Security Analyst is a key team member in Dana-Farber Cancer Institute’s Information Security program. Reporting...  ...program operations, including routine security investigations, risk management support, training and awareness, and policy... 
    Full time

    Dana-Farber Cancer Institute

    Boston, MA
    21 hours ago
  • $160k - $180k

     ...join their Boston-based Technology Governance Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst. In this newly created role, the Technology Senior...  ...& access, change/release, resiliency/DR, cloud security, data protection, and vulnerability management.... 
    Temporary work
    Flexible hours

    Berkshire Hathaway Specialty Insurance

    Boston, MA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Risk Analyst. Be the first to apply!