Executive Director, Chief of Staff to the Deputy Chief Information Security Officer CVS HealthExecutive Director, Chief of Staff to the Deputy Chief Information Security OfficerMassachusettsReporting to the Deputy CISO and working closely with the Chief Information Security Officer (CISO), this leader serves as a strategic partner and force multiplier for cybersecurity priorities, ensuring that key programs, budget commitments, strategic initiatives, and executive deliverables are coordinated, measurable, and delivered with impact. The Chief of Staff will help advance the Deputy CISO program by managing critical planning rhythms, supporting cybersecurity strategy, strengthening program governance, coordinating budget and resource planning, and enabling clear communication between the Deputy CISO, CISO, and enterprise stakeholders.
Chief Information Security Officer DLA PiperChief Information Security OfficerBoston, MA$550,000–$650,000 / yearExecutive-level knowledge of cybersecurity strategy, governance, risk, compliance, privacy, data protection, incident response, threat intelligence, vulnerability management, identity and access management, cloud and network security, application security, endpoint protection, email security, encryption, logging and monitoring, disaster recovery, business continuity, third-party risk, DevSecOps, modernized secure development practices including AI SDLC, and secure technology adoption. Operating as a trusted advisor to firm leadership, the Office of General Counsel, Information Technology, Information Governance, Risk Management, practice leadership, and global counterparts, the CISO ensures the confidentiality, integrity, and availability of client and firm information while enabling innovation, responsible AI adoption, operational resilience, and exceptional client service.
Information Security Risk and Compliance Analyst CarGurusInformation Security Risk and Compliance AnalystBoston, MassachusettsFull timeThe analyst works closely with security, engineering, legal, internal audit, privacy, finance, procurement and business stakeholders to build scalable processes, improve operational maturity and reduce organizational risk. The information security risk and compliance analyst supports the organization’s governance, risk, and compliance program by managing security risk, ensuring regulatory compliance and partnering across the business to strengthen the company’s security posture.
Information Security Analyst, AI Governance Form EnergyInformation Security Analyst, AI GovernanceSomerville, MAThis is a hands-on, cross-functional role that combines security judgment, IT operations discipline, and a genuine curiosity about how AI systems behave - bridging the gap between fast-moving AI capabilities and the guardrails Form Energy needs to adopt them safely and effectively. Define and enforce guardrails for agentic tools specifically - reviewing what actions an agent is authorized to take autonomously (e.g., sending communications, modifying records, executing code) and setting approval thresholds, logging, and rollback procedures.
Information Security Analyst Abacus TechnologyInformation Security AnalystHanscom AFB, MassachusettsProvide coordination and support to the Hanscom JWICS Site ISSM in all matters related to ICD 503 and RMF to ensure Hanscom JWICS maintains it Authorization to Operate (ATO) and high security posture. Serve as controlled equipment custodian COMSEC, key member of configuration management team site ops, planning, disaster recovery and network encryption.
Business Information Security Officer-VP State StreetBusiness Information Security Officer-VPQuincy, MassachusettsThe VP BISO leads a small team focused on providing cyber advisory services, building application- and service-level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business’s enhanced decision-making framework. The VP is a strong cyber controls analyst who can correlate the firm’s cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth in at least two focus areas.
Business Information Security Officer-Vp State Street CorporationBusiness Information Security Officer-VpQuincy, MA$120,000–$202,500 / yearThe VP BISO leads a small team focused on providing cyber advisory services, building application- and service-level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business's enhanced decision-making framework. The VP is a strong cyber controls analyst who can correlate the firm's cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth in at least two focus areas.
NewBusiness Information Security Officer State Street CorporationBusiness Information Security OfficerBoston, MA$120,000–$202,500 / yearThe VP BISO leads a small team focused on providing cyber advisory services, building application- and service-level threat models, executing a cyber book of work aligned to State Street business units, and delivering metrics and cyber-driven content that support the business's enhanced decision-making framework. The VP is a strong cyber controls analyst who can correlate the firm's cyber risk taxonomy to applicable business processes to conclude on the residual cyber risks aligned to business functions and critical business services, with practitioner-level depth in at least two focus areas.
Information Security Lead Click Therapeutics Inc.Information Security LeadBoston, MA$130,000–$200,000 / yearConsistently named a best place to work, Click fosters an inclusive, diverse workforce of innovators, clinicians, scientists, researchers, designers, technologists, engineers and more, united in a common mission to provide patients everywhere access to safe and effective prescription digital therapeutics. Click Therapeutics may at its business discretion decide to or refrain from obtaining, maintaining and/or extending the temporary visa status and/or sponsoring a colleague for permanent residency and /or employment eligibility, considering factors such as availability of qualified U.S. workers and the colleague's long-term prospects for securing lawful permanent residence, among other reasons.
Vice President, Information Security First Tech Federal Credit UnionVice President, Information SecurityMarlborough, MA$221,000–$276,500 / yearThe Vice President, Information Security provides executive leadership for the design, evolution, and operational oversight of security engineering capabilities that protect the organization's systems, data, and digital services. Lead and develop senior security engineering leaders and teams, fostering strong technical depth, accountability, and future leadership capability.
Business Information Security Officer-AVP State StreetBusiness Information Security Officer-AVPQuincy, MassachusettsThe AVP , Cyber Risk Advisor provides cyber risk advisory services focused on strengthening the firm's defensive cybersecurity posture through proactive risk management, cyber control oversight, vulnerability reduction, and security-by-design practices. As a member of the Business Information Security organization, the AVP Cyber Security Advisor partners closely with Security Operations, Vulnerability Management, Threat Intelligence, Engineering, Architecture, and AI Security teams to drive risk-informed decisions and measurable reductions in cyber exposure.
Senior Director, Chief Information Security Officer Scholar Rock Holding CorpSenior Director, Chief Information Security OfficerCambridge, MA$245,000–$325,000 / yearSummary of Position: Scholar Rock is seeking a Senior Director, Cybersecurity to serve as the company's Chief Information Security Officer, responsible for building and scaling enterprise cybersecurity capabilities that protect the organization's people, data, technology assets, intellectual property, and business operations. This role is ideal for a cybersecurity leader who has successfully led multiple cybersecurity functions and is ready to assume broader enterprise cybersecurity leadership responsibilities in a lean, high-growth biotechnology environment.
Sr. Manager, Information Security Identity And Access Management Operations BlueCross and BlueShield of MassachusettsSr. Manager, Information Security Identity And Access Management OperationsHingham, MA$113,940–$139,260 / yearSupport internal and external logical access audits Review processes and monitor quality assurance results to ensure audit and security controls are effective Assist in designing and managing the strategy for securing, monitoring, and managing privileged accounts and access. An employee's pay position within the salary range will be based on several factors including, but limited to, relevant education, qualifications, certifications, experience, skills, performance, shift, travel requirements, sales or revenue-based metrics, and business or organizational needs and affordability.
Manager of Information Security and Compliance iBoss CybersecurityManager of Information Security and ComplianceBoston, MAIn addition to managing internal security policies, this role will be the primary point of contact for client assessments and external audit engagements, ensuring all compliance obligations are met and supporting key security programs, including contingency planning, configuration management, security awareness, client assurance, and change management. The Director of Information Security & Compliance will develop and implement security policies and align organizational practices with industry frameworks such as ISO 27001, ISO 9001, SOC 1/2, Cyber Essentials, and FedRAMP to ensure continuous monitoring of security controls and incident response readiness.
Information Security Risk and Compliance Analyst CarGurus IncInformation Security Risk and Compliance AnalystBoston, MA$84,000–$106,000 / yearCome join us for the ride Role overview The information security risk and compliance analyst supports the organizations governance risk and compliance program by managing security risk ensuring regulatory compliance and partnering across the business to strengthen the companys security posture. What youll do Third Party Risk Management Customer Security Assurance Cyber Risk Management SOX Compliance Governance and Compliance What youll bring Experience with GRC platforms such as Auditboard SAFE Loopio or similar tools.
Information System Security Officer The Charles Stark Draper Laboratory IncInformation System Security OfficerCambridge, MA$75,000–$156,000 / yearDraper supports many programs to improve work-life balance including workplace flexibility, employee clubs ranging from photography to yoga, health and finance workshops, off site social events and discounts to local museums and cultural activities. Experience: 1-3 years year relevant industry experience is required, Preferred experience with RMF (NIST SP 800-53, JSIG, DAAG, ICD 503), IR, Vulnerability Management, SCAP, STIG, and Security-Relevant Tools.
Information Systems Security Manager (Issm) - SME AvintInformation Systems Security Manager (Issm) - SMEBedford, MA$165,000–$175,000 / yearIn this role, you’ll be part of a high-performing team responsible for implementing and overseeing all phases of the Risk Management Framework (RMF) while supporting day-to-day cybersecurity operations. Perform the Information System Security Engineer (ISSE) duties in an Information Assurance Workforce System Architecture and Engineering (IASAE) position as outlined in AFI 33-200, AFI 33-210 and AFMAN 33-285 for assigned systems.
Senior Information Security Analyst - Attack Surface Management Lead Mass General BrighamSenior Information Security Analyst - Attack Surface Management LeadSomerville, MassachusettsThis role will help lead the function into a risk-driven, validation-focused capability that identifies meaningful exposure, prioritizes remediation based on exploitability and business impact, and connects findings to detection engineering, threat hunting, threat intelligence, and broader Cyber Defense priorities. The Mass General Brigham Senior Information Security Analyst – Attack Surface Management Function Lead will be responsible for advancing and coordinating the MGB Attack Surface Management capability across vulnerability discovery, penetration testing, attack surface analysis, and attack simulation.
Chief Information Security Officer Verily Life Sciences LLCChief Information Security OfficerBoston, MADirect experience working with governance, risk, and compliance frameworks, including ISO 27001 and SOC 2. Direct experience with Okta, Crowdstrike, Wiz, Synk, or equivalent tools, and hands-on experience with hyperscaler platforms, Google Cloud Platform, Amazon Web Services, and/or Azure. Uniquely positioned at the intersection of technology, data science, and healthcare, Verily transforms multimodal health data into insights, models, and actions that make healthcare more personalized, predictive, and precise.
Head of Corporate and Information Security Layer HealthHead of Corporate and Information SecurityBoston, Massachusetts$180,000–$230,000 / yearDepending on the risks you identify, this may include areas such as cloud IAM and service accounts, network security, secrets and key management, vulnerability management, secure configuration, CI/CD and code security, logging and monitoring, or security architecture reviews. You should be comfortable reasoning about areas such as cloud IAM, networking, application and infrastructure security, data protection, secrets management, logging and detection, vulnerability management, and endpoint or identity security.