Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Manager, Information Security Compliance & Risk

$175k - $200k

Analysis Group

Overview Analysis Group is one of the largest international economics consulting firms, with more than 1,500 professionals across 15 offices in North America, Europe, and Asia. Since 1981, we have provided expertise in economics, finance, health care analytics, and strategy to top law firms, Fortune Global 500 companies, and government agencies worldwide. Our internal experts, together with our network of affiliated experts from academia, industry, and government, offer our clients exceptional breadth and depth of expertise. The Manager, Information Security Compliance and Risk is responsible for leading the firm’s Governance, Risk, and Compliance (GRC) program, including regulatory compliance, enterprise risk management, and assurance activities that support client requirements and regulatory obligations. This role also serves as the primary owner of Information Security AI governance, ensuring that the firm’s use of AI and machine learning technologies aligns with security, privacy, regulatory, and client expectations. The role manages a team of three Information Security Analysts and owns SOC 2 and ISO 27001 certification programs, while partnering closely with Legal, Compliance, Privacy, IT, and Security Engineering and Operations to ensure effective control design, evidence collection, risk management, and continuous improvement. Responsibilities Governance and Compliance Leadership Own and maintain the firm’s information security governance framework, including policies, standards, and procedures. Lead annual SOC 2 and ISO 27001 audit cycles, including audit readiness, evidence coordination, and remediation tracking. Ensure ongoing compliance with client, regulatory, and contractual information security requirements. Manage policy exceptions, risk acceptances, and documentation of compensating controls. Regulatory Authorization and Assurance Lead the renewal and ongoing maintenance of government and client security authorizations, attestations, and approvals required for regulated engagements. Coordinate cross-functional evidence collection and control validation to support authorization renewals and periodic reassessments. Track authorization requirements, renewal timelines, and control changes to ensure continuous eligibility for regulated work. AI Security Governance Lead the Information Security AI governance program, ensuring secure, responsible, and compliant use of AI technologies across the firm. Partner with Legal, Privacy, Compliance, and business stakeholders to define and maintain AI security requirements, risk assessments, and usage standards. Establish and maintain security controls for AI-enabled tools, including data handling, access controls, model usage restrictions, and third‑party AI risk. Support client and regulatory inquiries related to AI security posture and governance practices. Track emerging AI‑related regulatory and security requirements and assess their impact on firm policies and controls. Risk Management Maintain and mature the enterprise information security risk register. Facilitate periodic risk assessments, including risks associated with AI usage, data processing, and third‑party technologies. Develop and report meaningful risk metrics and dashboards for leadership review. Translate technical and operational risks into clear business‑impact language. Third‑Party and Emerging Risk Governance Oversee third‑party security risk management in partnership with Legal. Lead structured reviews of vendor security posture, including AI and SaaS providers. Track remediation plans and ongoing monitoring of third‑party and AI‑related risks. Audit and Assurance Coordination Serve as the primary liaison for internal and external audits related to information security. Coordinate evidence collection across IT, Security Engineering, Privacy, and business stakeholders. Track findings, corrective actions, and continuous improvement initiatives. Team Leadership Directly manage three Information Security Analysts. Set priorities, provide mentorship, and support professional development. Establish consistent processes, documentation standards, and performance expectations across the GRC function. Cross‑Functional Collaboration Partner closely with Security Engineering and Operations to align governance requirements with technical controls. Work with Legal, Compliance, Privacy, and Data Science teams on regulatory interpretation and AI governance requirements. Support client security inquiries, assessments, and due diligence requests. Expected Outcomes Sustained audit readiness for SOC 2 and ISO 27001 with minimal disruption. Clear, measurable visibility into information security and AI‑related risk posture. Consistent, scalable governance processes supporting firm growth and responsible AI adoption. Strong alignment between governance requirements and operational security controls. Qualifications & Skills Bachelor’s degree required; degree in information security, risk management, or a related field preferred. 7 to 10 years of experience in information security, GRC, audit, or risk management required. Prior experience managing SOC 2 and or ISO 27001 programs required. Demonstrated people management or team leadership experience. Professional certifications such as CISSP, CISM, CRISC, CGRC, or ISO 27001 Lead Implementer or Auditor. Experience with GRC platforms and risk management tooling. Experience supporting AI governance, data governance, or emerging technology risk programs. Experience supporting client‑driven security assessments in a professional services environment. An inclusive and growth‑oriented mindset, strong interpersonal skills, and an ability to work across differences. To the extent permitted by applicable law, eligible candidates must be authorized to work in the United States without sponsorship or restriction, now and in the future. Analysis Group embraces equal opportunity. We are committed to building teams that bring a variety of backgrounds, perspectives, and skills, as we believe that a strong and inclusive workforce directly supports our goal of providing the highest‑quality work. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other class protected under applicable federal, state, or local law, and we encourage candidates of all backgrounds to apply. Analysis Group offers competitive compensation and a comprehensive benefits package. The estimated salary range for this position is $175,000–$200,000. Compensation offered will be based on a number of factors including work experience, education, and skill level. This role is eligible for a discretionary annual bonus that is determined in large part by individual performance. To learn more about our benefit offerings, clickhere. #LI-Hybrid Privacy Notice For information about Analysis Group’s privacy practices, please refer to the applicable Analysis Groupprivacy policy. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities. Please view the EEOC’s “Know Your Rights” poster here. #J-18808-Ljbffr Analysis Group

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Manager, Information Security Compliance & Risk in Boston, MA vacancy
  • $180k - $270k

     ...exciting opportunity within the Security Trust and Risk (STAR) team whose mission...  ...developing and refining information security policies,...  ...strategy, enterprise risk management, creating metrics and reporting...  ...other governance, risk and compliance efforts. The STAR team is... 
    Risk

    Klaviyo

    Boston, MA
    8 days ago
  • $175k - $200k

    Analysis Group, Inc. seeks a Manager for Information Security Compliance and Risk in Boston, MA. The role involves leading the Governance, Risk, and Compliance program, managing a team of analysts, and overseeing information security governance, including AI compliance... 
    Risk

    Analysis Group, Inc.

    Boston, MA
    1 day ago
  • $172k - $250k

     ...Grant Thornton is seeking a Director of Information Security Audit & Compliance to join the team. Approved office...  ...global delivery centers, managing internal and external audits, and ensuring...  ...and remediation plans. Governance, Risk & Control Framework Align the information... 
    Risk
    Internship
    Seasonal work
    Work at office
    Local area
    Flexible hours
    3 days per week

    Grant Thornton

    Boston, MA
    3 days ago
  • $128.1k - $239.6k

     ...fueled by vast amounts of information. Data is more valuable...  ...in EY Information Security has a critical role to...  ...Information Security we blend risk strategy, digital...  ...Security Portfolio Compliance Enablement function, you...  ...these pillars: Risk Management and Reduction: Assisting... 
    Risk
    Work experience placement
    Summer holiday
    Local area
    Flexible hours

    Ernst & Young Oman

    Boston, MA
    1 day ago
  • $185k - $277k

     ...Overview The Senior Manager of Enterprise Security is a technical people leader...  ...SecDevOps and continuous compliance programs, and leads a living...  ..., Legal, and Governance, Risk, and Compliance, this...  ...~ Work with the information security GRC function to adapt... 
    Risk
    Work at office
    Remote work

    Relativity

    Boston, MA
    5 days ago
  • $130k - $140k

     ...Job Description Role: Manager, Security Operations Department: Cybersecurity...  ...reviews Vulnerability and risk tracking Ensure consistent,...  ...working with Legal, Privacy, or Compliance teams during security...  ...annual incentive program, and information on benefits offered is here.... 
    Risk
    Full time

    Pearson

    Boston, MA
    1 day ago
  • $95k - $110k

     ...in third‑party cyber risk intelligence, trusted...  ...organizations worldwide. We give security and business leaders a...  ...cyber, financial, and compliance signals into clear,...  ...‑party cyber risk management programs in an...  ...reports to the Director of Information Security and owns three... 
    Risk
    Worldwide
    Flexible hours

    Blackkite

    Boston, MA
    5 days ago
  •  ...Cybersecurity and Privacy Risk Advisor About the Company Prestigious...  ...the advancement of its Information Security Governance and Risk...  ...leading the team to ensure compliance and continuous control monitoring...  ...in solving complex IT-risk management issues, with a strong... 
    Risk
    Work experience placement

    Confidential

    Boston, MA
    3 days ago
  • $105.79k - $141.05k

     ...connected ecosystem. We enable secure, high‑performance...  ...us today. The Role The Manager of Information Security—Cyber Threat Exposure...  ...prioritizes, and reduces cyber risk across a rapidly evolving digital...  ...mean time to remediate, SLA compliance, exception trends, asset... 
    Risk
    Full time
    Temporary work
    Remote work

    Lumen

    Cambridge, MA
    2 days ago
  •  ...Insight Global in Boston seeks a Cyber Security Analyst to develop and maintain...  ...procedures. Responsibilities include risk assessments, compliance reviews, and monitoring compliance with...  ...field and 2-5 years' experience in information security, along with strong... 
    Risk

    Insight Global

    Boston, MA
    5 hours ago
  • A nonprofit research and development company in Cambridge seeks a Supply Chain Risk Manager to oversee operations and ensure compliance with Department of Defense programs. The role requires leading cross-functional teams, strong knowledge of supply chain risk management... 
    Risk

    Draper

    Cambridge, MA
    2 days ago
  • $90k - $115k

    BRG is seeking an IT Risk and Compliance Analyst in Boston, MA. This client-facing role works closely with Legal and Business Unit stakeholders to assess and monitor compliance with information security standards. You'll provide risk and compliance advice, maintain policies... 
    Risk

    BRG

    Boston, MA
    1 day ago
  • $148k - $296k

     ...Summary We are seeking a Senior Manager, Security Operations to join K&L...  ...security while maintaining compliance standards, and manage security...  ...and safeguard against risks from various sources. Oversee...  ...in computer science, information security, cybersecurity, or... 
    Risk
    Temporary work
    Work at office
    Remote work
    Relocation
    Flexible hours

    K&L Gates

    Boston, MA
    3 days ago
  • $81.15k - $83.57k

     ...Compensation: $81,154 - $83,574 / year Information Technology Manager & Information Security Officer The Information...  ...all sites Information Security & Compliance Serve as the designated Information...  ...Monitor and respond to security risks and incidents in coordination with... 
    Risk
    Local area
    Remote work

    Action For Boston Community Development

    Boston, MA
    4 days ago
  • $110.5k - $202.7k

     ...objective of our Consulting risk services is to provide...  ...be responsible for managing multiple client...  ...evaluate, and enhance information systems facilitating the...  ...technology control and security engagements.    Skills...  ...risks and maintaining compliance. To qualify for the... 
    Risk
    Contract work
    Summer holiday
    Work at office
    Immediate start
    Flexible hours

    EY

    Boston, MA
    1 day ago
  •  ...Notes: . 37.5 Hours a week. hybrid Information Security Governance, Risk and Compliance (GRC) Analyst The Massachusetts Department of...  ...alignment of IT activities to business goals and the management of information security risks. Our GRC program needs... 
    Risk
    For contractors
    Work at office
    Remote work
    Monday to Friday
    Flexible hours
    Shift work

    3B Staffing LLC

    Boston, MA
    3 days ago
  • $170k - $230k

     ...business and relationships. Enterprise Risk Management is hiring a Head of Cyber &...  ...activities; partner with Internal Audit, Compliance, and Legal. Policies, standards & enablement...  ...and control training; partner with Information Security to refresh security awareness content... 
    Risk
    Local area

    Brown Brothers Harriman & Co.

    Boston, MA
    2 days ago
  • $100k - $135k

     ...Citizens currently has an opening for a Manager on our Operational Risk Management Oversight team focused...  ..., review, and challenge of information security and technology related risks. The...  ...activities to assess corporate-wide compliance. The role may be co-located as needed... 
    Risk
    Local area
    Monday to Friday
    Flexible hours

    Citizens

    Boston, MA
    3 days ago
  • $121k - $148k

     ...leader in healthcare data management and interoperability ,...  ...availability and security are non‑negotiable requirements...  ...security challenges, compliance requirements, and...  ...Threat Modeling and Risk Mitigation: Collaborate...  ...product management or information security (e.g., CISSP,... 
    Risk
    Temporary work

    Mass Digital Health

    Boston, MA
    2 days ago
  • $108.88k - $163.32k

     ...Technology and more. Overview The ADUSA Security Manager oversees the Security Patching team,...  ...Corporate locations) from security cyber risks. Establishes and executes the...  ...Technical Undergraduate degree. Knowledge of information systems and security controls, of attack... 
    Risk
    Full time
    Work experience placement
    Work at office
    Remote work
    Flexible hours
    Weekend work

    ViziRecruiter,LLC.

    Quincy, MA
    4 days ago
  • $90k - $115k

     ...Job Summary IT Risk and Compliance Analyst position is a highly visible, client‑facing role...  ...reports to the IT Risk and Compliance Manager. This role is responsible for...  ...risk and compliance with applicable information security standards and frameworks, industry best... 
    Risk
    Work experience placement
    Local area

    Brg Corp

    Boston, MA
    1 day ago
  •  ...thrive when empowered with better information. Teradata Autonomous Knowledge Platform...  ...with AI. What You’ll Do The Manager / Sr. Manager of Strategic Security Programs leads the identification,...  ...security initiatives that reduce risk, advance security maturity, and align... 
    Risk
    Permanent employment
    Flexible hours

    Teradata Corporation (SE)

    Boston, MA
    2 days ago
  • $110.5k - $202.7k

     ...reliable overview of their risk landscape. Our...  ...will be responsible for managing multiple client engagement...  ...evaluate, and enhance information systems facilitating...  ...control and security engagements. Skills and...  ...risks and maintaining compliance. To qualify for the role... 
    Risk
    Contract work
    Summer holiday
    Work at office
    Immediate start
    Flexible hours

    Ernst & Young Oman

    Boston, MA
    3 days ago
  • $70k - $80k

     ...you will play a pivotal role securing our clients’ infrastructure...  ...leader, like a Chief Information Security Officer (CISO). We...  ...leadership in Governance, Risk, and Compliance (GRC) directly to our clients...  ...components of a good cybersecurity management program, including: Leading... 
    Risk
    Full time
    Work at office

    Fractional CISO

    Newton, MA
    1 day ago
  • Director, Information Security 1 General Overview Functional Area: Information Technology (ITM) Career Stream: IT Risk & Compliance (RAC) Role: Director (DR1) Job Title: Director, Information...  ...like Data Security Posture Management (DSPM) and Data Rights Management... 
    Risk
    Work at office

    Celestica Inc.

    Boston, MA
    3 days ago
  •  ...Director, Security Compliance Known for being a great place to work and build a career...  ...specialist-level knowledge of risk, compliance, and information security controls to develop and execute...  ...and challenging the status quo; manage and review those team members'... 
    Risk
    Temporary work
    H1b
    Local area

    Kpmg India

    Boston, MA
    2 days ago
  • $99k - $232k

     ...Requirements: Up to 60% At PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients, providing advice, and...  ...certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified... 
    Risk
    Full time
    H1b

    PwC

    Boston, MA
    4 days ago
  •  ...Position Overview The Senior Manager, Cybersecurity...  ...implement, and maintain security operations processes,...  ...industry groups to stay informed on emerging threats...  ...platforms. Conduct regular risk assessments,...  ...leadership. Support audit and compliance activities related to... 
    Risk
    Contract work
    Local area
    Remote work

    US LBM

    Boston, MA
    3 days ago
  • $200k - $210k

     ...Opportunity: As the Director of Security Risk Engineering, you will serve...  ...operational resilience, managing a highly impactful program...  ...DevOps, Product, Program, Risk/Compliance, and IT leaders to...  ...Compliance Frameworks: Maintain an information security framework that... 
    Risk
    Full time
    Local area
    Immediate start
    Shift work

    Flywire

    Boston, MA
    6 days ago
  • $190k - $220k

     ...Director, Information Security WHOOP Boston, MA, US Full-Time IT...  ...of Information Security will manage an existing security team, oversee...  ...grows and regulatory and risk requirements change...  ...PCI, and emerging AI-related compliance requirements ~ Experience... 
    Risk
    Full time
    Work at office
    Relocation

    Softbank Investment Advisers

    Boston, MA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Manager, Information Security Compliance & Risk. Be the first to apply!