Demo

Cybersecurity Risk Analyst

Executive Office of Technology Services and Security
Boston, MA Contractor
POSTED ON 5/15/2026
AVAILABLE BEFORE 6/13/2026

About EOTSS

The Executive Office of Technology Services and Security (EOTSS) is the Commonwealth’s lead IT and cybersecurity organization, providing enterprise technology services to over 125 agencies and 43,000 employees. EOTSS delivers secure, reliable digital services that support residents, businesses, and state operations.


Position Summary

The Cybersecurity Risk Analyst supports the Enterprise Risk Management (ERM) program and contributes to Governance, Risk, and Compliance (GRC) activities across the Commonwealth. The incumbent performs risk assessment, compliance monitoring, audit support, and program coordination functions.

This role requires demonstrated experience in cybersecurity, IT risk, or compliance and the ability to manage multiple assignments in a collaborative, multi-agency environment.


The primary work location for this role will be at One Ashburton Place Boston, Massachusetts 02108. The work schedule for this position is Monday through Friday, 9:00AM – 5:00PM EST. This position is expected to follow a hybrid model of reporting to work that combines in-office workdays and work from home days as needed.


Duties and Responsibilities

  • Conduct cybersecurity and enterprise risk assessments, including identification of threats, vulnerabilities, and impacts
  • Document and track risk mitigation strategies and remediation activities
  • Evaluate and document control effectiveness aligned to established frameworks (e.g., NIST, CIS, ISO)
  • Execute ERM program processes, including third-party risk reviews and tabletop exercises
  • Track program deliverables, risks, issues, and dependencies across initiatives
  • Maintain risk registers, documentation, and reporting artifacts
  • Assist in development and maintenance of ERM policies, procedures, and templates
  • Prepare reports and communications for technical and non-technical stakeholders
  • Coordinate with agency stakeholders to support timely completion of risk and compliance activities
  • Support process improvement initiatives, including automation of manual workflows
  • Perform other duties as assigned


Required Qualifications

  • At least one (1) to three (3) years of experience in cybersecurity, information technology, risk management, compliance, or audit
  • Knowledge of enterprise risk management principles, with emphasis on cybersecurity risk
  • Familiarity with cybersecurity and control frameworks (e.g., NIST, CIS Controls, ISO 27001)
  • Understanding of IT environments, including applications, infrastructure, and third-party vendors
  • Ability to support audit and compliance activities, including control evaluation
  • Strong organizational skills and attention to detail
  • Ability to manage multiple assignments and meet deadlines
  • Effective written and verbal communication skills
  • Ability to work independently and as part of a team


Preferred Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or related field
  • Experience with ServiceNow IRM or other Governance, Risk, and Compliance (GRC) tools or platforms
  • Experience with third-party/vendor risk management processes
  • Experience working in a public sector or regulated environment


Competencies

  • Analytical Skills: Ability to assess risk, evaluate controls, and interpret data
  • Attention to Detail: Accuracy in documentation, tracking, and reporting
  • Communication: Clear and effective communication with technical and business stakeholders
  • Organizational Skills: Ability to prioritize and manage multiple tasks
  • Collaboration: Works effectively across teams and agencies
  • Adaptability: Adjusts to changing priorities and evolving risk environments

Salary : $70 - $78

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cybersecurity Risk Analyst?

Sign up to receive alerts about other jobs on the Cybersecurity Risk Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$149,432 - $188,965
Income Estimation: 
$179,455 - $227,077
Income Estimation: 
$99,793 - $130,112
Income Estimation: 
$125,027 - $157,872
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Executive Office of Technology Services and Security

  • Executive Office of Technology Services and Security Boston, MA
  • The Executive Office of Technology Services and Security (EOTSS) is the lead enterprise technology organization for the Commonwealth of Massachusetts. Char... more
  • 9 Days Ago


Not the job you're looking for? Here are some other Cybersecurity Risk Analyst jobs in the Boston, MA area that may be a better fit.

  • Agency Cybersecurity Boston, MA
  • About Agency Cybersecurity: Agency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance. Our softwa... more
  • 6 Days Ago

  • Agency Cybersecurity Boston, MA
  • About Agency Cybersecurity Agency Cybersecurity is fast growing ventured back startup that provides best-in-class cybersecurity and compliance. Our softwar... more
  • 6 Days Ago

AI Assistant is available now!

Feel free to start your new journey!