Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Analyst, Cyber Risk Quantification and GRC

$119k - $193k

Forrester

Senior Analyst

At Forrester, we're trusted to work on trailblazing, mission critical problems that business and technology leaders face today. That's why we're always looking to empower talented individuals to perform at their best every single day. We're proud of our community of smart people and vibrant voices who come together to do what's right by our clients and each other. Our success is driven by curiosity, courage and customer obsession. The confidence and drive to be bold at work. Join us and build an extraordinary future.

About This Role:

Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk management leaders and their teams. The ideal candidate has a strong understanding of risk management roles, responsibilities, and the most important security and risk trends and their business and technology implications; deep knowledge and experience with risk management practices and methods; deep knowledge and expertise in cyber risk quantification; and deep experience in developing, maintaining, and communicating risk management artifacts including risk standards, procedures, appetite, registry, and business strategy. Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired.

The successful candidate researches and uncovers the strategies, technologies, and best practices of risk management that create a resilient and opportunity-seeking business. The Senior Analyst delivers these insights and recommendations in written reports, presentations, inquiries, guidance sessions, and custom advisory for risk leaders across industries and geographies. Our research is aimed at helping enterprise clients solve business problems and improve business results by applying principles and best practices. We also advise vendors on their strategies, roadmaps, and messaging in line with our market insights and our recommendations for enterprise clients.

Job Description:

The Senior Analyst works as part of a high-performing team with a strong emphasis on collaborating with others in all aspects of the job. The Senior Analyst is expected to:

  • Develop a deep understanding of what Forrester clients require to be successful as risk management leaders and professionals with a focus on how they help their organizations develop risk management capabilities that enable a resilient and opportunity-seeking business.
  • Conduct primary research into risk management capabilities, practices, touchpoints, and artifacts in the context of supporting C-suite executives, business leaders, and appropriate committees.
  • Help define the future of risk management, including how risk leaders and professionals can work with other key business functions and support organizational success.
  • Work with different focus areas across Forrester research teams to develop a complete research portfolio on risk management, providing both input to others' research and writing reports incorporating expertise from across Forrester to provide a "big picture" view.
  • Partner as appropriate with other Forrester analysts on broader risk topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk.
  • Research/write/create approximately six to eight research projects per year — a mix of written reports, tools, webinars, videos, podcasts, infographics, and other intellectual property. Build visibility for their research and contribute to Forrester client communities.
  • Consult with clients to apply Forrester's research in the context of their specific business environment and help solve their problems through inquiry, guidance, and advisory engagements.
  • Establish an industry presence as an influential speaker and thinker; build relationships with journalists who cover the sector; and participate in vendor briefings and field press inquiries as necessary.
Job Requirements:
  • Five to seven years as a research analyst, consultant, or practitioner where you have led or been involved in risk management, with a focus on cyber risk quantification, or an equal amount of time as product manager for vendors that serve the market.
  • A deep intellectual curiosity about the effect of technology on the business landscape; solid business instincts and a practical understanding of what makes companies tick; and a creative view of markets, technologies, and attitudes combined with a fascination with the future.
  • Superior listening, critical thinking, and writing skills as well as compelling presentation skills.
  • The ability to take complex, disparate ideas and distill them into simple, provocative concepts — and be willing to take a stand on vendors and outcomes.
  • The ability to travel up to 20% of the time.

Base salary range: $119,000 - $193,000

Base salary range for Georgia: $106,000 - $174,000

Base salary range for New York City, NY: $136,000 – $222,000

Bonus target: 10%

The application deadline is July 31, 2026. Please refer to the job posting on Forrester.com careers page if the deadline has been extended.

Here at Forrester, we welcome people from all backgrounds and perspectives. Our aim is for all candidates to be able to fully participate in Forrester's recruitment process. If you would like to discuss a reasonable accommodation, please reach out to View email address on click.appcast.io.

Forrester Research, Inc. is an Equal Employment Opportunity Employer. As a federal contractor, Forrester encourages veterans and individuals with disabilities to apply for employment.

Vacancy posted 2 hours ago
Similar jobs that could be interesting for youBased on the Senior Analyst, Cyber Risk Quantification and GRC in Cambridge, MA vacancy
  • $95k - $110k

     ...Kite is the global leader in third-party cyber risk intelligence, trusted by more than 3,00...  ...from customers and industry analysts alike. WHY BLACK KITE We’re a fast...  ...right place. THE OPPORTUNITY The Senior GRC Analyst reports to the Director of Information... 
    Cyber
    Senior
    Worldwide
    Flexible hours

    Black Kite

    Boston, MA
    2 days ago
  •  ...Information Security Governance, Risk and Compliance (GRC) Analyst The ideal candidate is a self-starter with a passion for building relationships...  ...National Institute of Standards and Technology (NIST) Cyber Security Framework. Security requirements of the Payment... 
    Cyber

    Mindlance

    Boston, MA
    10 days ago
  •  ...Title: GRC Analyst Location MassDOT, 10 Park Plaza, Boston, MA 02116 Duration...  ...Information Security Governance, Risk and Compliance (GRC) Analyst The Massachusetts...  ...(GRC) Analyst! Join a great team of cyber security professionals and help us deliver... 
    Cyber
    For contractors
    Work at office
    Remote work
    Monday to Friday
    Flexible hours
    Shift work

    3B Staffing LLC

    Boston, MA
    5 days ago
  • $70 - $75 per hour

     ...Description We are seeking a ServiceNow professional to support the Cyber Risk Management and Governance team in managing and implementing...  ...controls within the ServiceNow Continuous Authorization and GRC modules while collaborating closely with application managers and... 
    Cyber
    Senior
    Contract work

    Vertex Pharmaceuticals

    Boston, MA
    5 days ago
  • $70 - $75 per hour

     ...a ServiceNow professional to manage application security controls within the Cyber Risk Management and Governance team. This role involves coding and validating controls in ServiceNow's GRC modules while collaborating with various application and technical teams. The... 
    Cyber
    Senior

    Vertex Pharmaceuticals

    Boston, MA
    5 days ago
  • $88k - $121k

    About the Role Flagship's GRC program has matured from build to operate. We have a functioning GRC system of record in Jira, active compliance...  ...infrastructure — someone who is as comfortable running a vendor risk assessment in Jira as they are prepping evidence packages for an... 
    Senior

    Flagship Pioneering

    Cambridge, MA
    4 days ago
  • $95k - $110k

    Blackkite in Boston seeks a Senior GRC Analyst to manage compliance platforms and customer security assessments. The ideal candidate will have 2-4 years in GRC or information security, paired with skills in SOC 2 and ISO 27001. You'll support FedRAMP ConMon reporting and... 
    Senior

    Blackkite

    Boston, MA
    4 days ago
  • Synchrony Financial is seeking a detail-oriented Sr. Business Analyst to join its GRC Risk Management Systems team in Boston, Massachusetts. This role involves advocating for GRC technology and working closely with various stakeholders to manage organizational risks effectively... 
    Senior

    Synchrony Financial

    Boston, MA
    1 day ago
  • $94.2k

     ...teams and other areas necessary to identify risks to the business and drive solutions...  ...Framework (HITRUST CSF), or the NIST 800-83 cyber security framework ~ Experience supporting...  ...experience ~ Governance Risk and Compliance (GRC) tool experience such as ARCHER ~ In-... 
    Cyber
    Senior
    For contractors
    Local area
    Remote work

    Highmark Health

    Boston, MA
    2 days ago
  •  ...The GRC Analyst will be responsible for supporting the development, implementation, and maintenance of the firm's governance, risk management, and compliance program. The ideal candidate will have...  .... ~ Strong drive to learn and grow in the cyber security field.... 
    Cyber
    Flexible hours

    RightWorks Inc

    Boston, MA
    4 days ago
  • $125k - $155k

     ...extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and...  ...across the organization. As a Senior Risk & Compliance Analyst, you will play a key role in supporting...  ..., and continued evolution of the cyber risk management program. In this... 
    Cyber
    Senior
    Full time
    Work at office
    Relocation

    Whoop

    Boston, MA
    18 days ago
  • $70k - $110k

     ...Job Description Job Description As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program. You will help manage risk reviews,...  ...bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferred.... 
    Cyber
    Full time
    Work at office
    Relocation

    Whoop

    Boston, MA
    26 days ago
  • $70 - $75 per hour

     ...Description: We are seeking a ServiceNow professional to support the Cyber Risk Management and Governance team in managing and implementing...  ...controls within the ServiceNow Continuous Authorization and GRC modules while collaborating closely with application managers... 
    Cyber
    Senior
    Full time
    Contract work
    Temporary work

    Vertex Pharmaceuticals

    Boston, MA
    1 day ago
  • $102.5k - $187.9k

     ...Join EY and help to build a better working world. Risk Consulting - Risk Technology - GRC/IRM Platforms - Senior Consultant The risk landscape is continuously...  ...widespread economic changes, regulatory reforms, and cyber threats. Organizations are increasingly seeking to... 
    Cyber
    Senior
    Work experience placement
    Summer holiday
    Work at office
    Flexible hours

    Ernst & Young Oman

    Boston, MA
    4 days ago
  • $102.79k - $141.36k

     ...Possible™. Learn more at and on LinkedIn and Twitter (X). Senior Analyst, Cybersecurity Risk & Compliance Risk Management & IT Compliance |...  ...Ensure organization-wide identification and mitigation of cyber and IT risks Support business continuity and regulatory... 
    Cyber
    Senior
    Permanent employment
    Work at office
    Flexible hours
    Shift work
    Day shift

    Analog Devices

    Wilmington, MA
    3 days ago
  • $87.8k - $160.9k

     ...opportunity   The objective of our consulting risk services is to provide clients with a...  ...by regulation or contract. For our Cyber Risk services, the ideal candidate will be...  ...present risk reports and dashboards to senior management and the board of directors.... 
    Cyber
    Senior
    Contract work
    Summer holiday
    Work at office
    Flexible hours

    EY

    Boston, MA
    3 days ago
  • A global investment firm in Boston is seeking a Cybersecurity GRC Associate to support cyber governance, risk, and compliance efforts. The role involves shaping cybersecurity policies, aiding in risk assessments, and reporting metrics to internal stakeholders. Ideal candidates... 
    Cyber

    Fynetra

    Boston, MA
    1 day ago
  • A leading global consulting firm is looking for a Senior Consultant to join their Risk Technology practice in Boston. In this role, you will assess, design, and implement integrated risk management solutions for diverse clients. Ideal candidates have a Bachelor’s in a... 
    Senior

    Ernst & Young Oman

    Boston, MA
    4 days ago
  • $75 per hour

     ...We're looking for a hands-on ServiceNow GRC Analyst to join a growing Security organization and support the implementation of an established...  ...regulations o Understanding of regulatory environments or risk frameworks is a plus • Prior experience documenting control exclusions... 

    Insight Global

    Boston, MA
    2 days ago
  • $91k - $321.5k

     ...Specialty/Competency: IFS - Risk & Quality (R&Q) Industry/Sector: Not Applicable...  ...Contract Specialist - Managed Services - Senior Manager, you will lead initiatives in enterprise...  ...maintenance application managed services, (3) cyber managed services, or (4) risk & regulatory... 
    Cyber
    Senior
    Full time
    Contract work
    H1b

    PwC

    Boston, MA
    9 days ago
  • Cybersecurity GRC Associate - Boston (Hybrid) Perm Hybrid We’re hiring an Associate to support cyber governance, risk, and compliance for a global investment firm. This role offers direct exposure to C-level leadership and cross-functional teams including Legal, Risk, and... 
    Cyber
    Permanent employment

    Fynetra

    Boston, MA
    15 hours ago
  • $75 per hour

    Insight Global is seeking a ServiceNow GRC Analyst in Boston to join a growing Security team. This role will be responsible for operationalizing security controls in ServiceNow across SaaS applications, working closely with system owners and technical leads. The ideal candidate... 

    Insight Global

    Boston, MA
    5 days ago
  • $88k - $121k

    Flagship Pioneering in Cambridge, MA, is seeking a GRC Specialist to own the execution of their GRC program. You will utilize Jira to manage compliance activities across frameworks like HITRUST and NIST. Ideal candidates have 3-6 years of relevant experience and are comfortable... 

    Flagship Pioneering

    Cambridge, MA
    4 days ago
  • $60k - $90k

    Whoop is searching for a GRC Analyst in Boston, MA, to enhance the Governance, Risk, and Compliance program. This role involves managing GRC intake processes, coordinating third-party risk reviews, and ensuring effective compliance operations. The ideal candidate will... 

    Whoop

    Boston, MA
    5 days ago
  • $84k - $126k

     ...GSS team (namely Security Risk and Trust, Security...  ...ABOUT THE ROLE: The Senior Technical Program Manager...  ...governance, and the data-driven cyber risk and control...  ...program tooling (security GRC, TPRM, continuous...  ..., CompTIA Cybersecurity Analyst or Certified Fraud Examiner... 
    Cyber
    Senior
    Flexible hours

    Klaviyo

    Boston, MA
    4 days ago
  • $75k - $150k

    Draper, an independent nonprofit research and development company in Cambridge, MA, is seeking a Senior System Security Engineer. The candidate will focus on guiding mission-system analysis and defining security requirements for critical technologies. The role requires... 
    Cyber
    Senior

    Draper

    Cambridge, MA
    4 days ago
  • $201.37k - $236.9k

     ...effectiveness of governance, compliance, risk management, and control process...  ...for IT & security audit as a senior leader within the global...  ...crypto, digital assets, cloud, cyber, AI, data privacy, and...  ...optimization of IA tooling (e.g., GRC platforms, Workiva/Archer).... 
    Cyber
    Senior
    Work at office
    Local area

    Coinbase

    Boston, MA
    3 days ago
  • A cutting-edge AI security firm in Boston is seeking a Tier 3 Security Analyst with over 5 years in cyber security operations. This role involves leading junior analysts and investigating incidents with a focus on understanding malicious activities. Candidates should have... 
    Cyber
    Senior

    Seven AI

    Boston, MA
    3 days ago
  • $144.05k - $206.78k

    A cybersecurity solutions provider is seeking a Senior Manager, Cyber Resilience Advisors to lead their US-based Cyber Resilience Team. The ideal candidate should have over 4 years of experience in cybersecurity operations and team management. Responsibilities include developing... 
    Cyber
    Senior
    Remote job
    Flexible hours

    Immersive

    Boston, MA
    4 days ago
  • Ernst & Young Oman is seeking a Cyber Triage and Forensics Incident Analyst to be a key member of the security incident response team. The role involves handling security incidents, performing forensic analysis, and coordinating remediation efforts. Ideal candidates should... 
    Cyber
    Senior

    Ernst & Young Oman

    Boston, MA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Analyst, Cyber Risk Quantification and GRC. Be the first to apply!