×
Register Here to Apply for Jobs or Post Jobs. X

Deputy Director of IT Risk and Compliance

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: MBTA
Full Time position
Listed on 2026-09-09
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 190000 USD Yearly USD 120000.00 190000.00 YEAR
Job Description & How to Apply Below

At the MBTA, we envision a thriving region enabled by a best-in-class transit system. Our mission is to serve the public by providing safe, reliable, and accessible transportation. MBTA’s core values are built around safety, service, equity, sustainability, culture, and accessibility, and each employee that works for the MBTA performs their roles based on our vision, mission, and values. This includes attendance, participation, and contribution in local safety committee meetings as needed.

Job Summary

The Deputy Director of IT Risk & Compliance Management provides strategic and operational leadership over enterprise technology risk, compliance, and governance functions across the MBTA. The role safeguards information assets by operationalizing security and privacy control frameworks, orchestrating supply chain and vendor risk diligence, and translating risk posture between executive-level dashboards and actionable remediation plans. The Deputy Director fosters a high-performance culture of security awareness, drives policy governance, and serves as a trusted advisor to senior leadership on emerging risks spanning legacy, cloud, Dev Ops, and Operational technology environments.

Duties & Responsibilities
  • Direct the risk management lifecycle—identification, assessment, response, monitoring for IT and OT systems, ensuring alignment with NIST CSF, NIST 800-53, ISO 27001, CIS, and applicable privacy mandates (e.g., MA 201 CMR 17.00, GDPR, CCPA).
  • Maintain an authoritative inventory (Risk Register) of business, technology, regulatory, contractual, and organizational security related risks; oversee continuous control testing and issue management.
  • Design and run a robust Supply-Chain Risk Management (SCRM) program, including third-party onboarding, due-diligence assessments (SOC 2, ISO 27001, PCI DSS, FedRAMP, CMMC), and ongoing performance monitoring.
  • Coordinate with Procurement and Legal to embed security clauses and right-to-audit provisions in contracts.
  • Develop, socialize, and maintain MBTA information security and privacy policies; drive adoption through targeted awareness campaigns, phishing simulations, and organization-wide training.
  • Evangelize a Security-First mindset via townhalls, brownbag sessions, and executive briefings.
  • Administer and optimize GRC portals (e.g., Service Now, Archer) for control catalogues, risk registers, exception management, and board-level metrics.
  • Integrate vulnerability, incident, and asset data to deliver end-to-end traceability from findings to remediation and residual risk reporting.
  • Produce concise, data
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary