Cybersecurity Risk Manager
Listed on 2026-02-17
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Cybersecurity Risk Manager
Date: Feb 13, 2026
Location: Lexington, MA, US
Company: MIT Lincoln Laboratory
Who are we?MIT Lincoln Laboratory is a Federally Funded Research and Development Center (FFRDC) whose mission is research in support of National Security.
Mission - The Security Services Department's (SSD) overall mission is to identify and counter security threats to the MIT Lincoln Laboratory's (MIT LL) mission of development of game‑changing technology in support of national security, including guarding against compromise by foreign intelligence agencies and insider threats.
Culture - We foster an inclusive, opportunity‑filled environment of empowered team members from diverse backgrounds.
Reporting directly to the Laboratory's Chief Information Security Officer (CISO), you will have enterprise‑level responsibility for managing and sustaining organizational efforts for the Laboratory's Cyber Maturity Model Certification (CMMC) program compliance, to include planning for future implementation of additional regulatory and contractual requirements.
- You will directly lead and oversee daily operations of the Laboratory's Cybersecurity Risk Management Team (CRMT), a team of cybersecurity professionals who are the core component of the Laboratory's Enterprise Risk Management Program, providing daily technical and operational supervision, mentoring, and performance oversight for Cybersecurity Risk Analysts and Cybersecurity Risk Managers.
- Participate in personnel retention efforts for staff, schedule and conduct candidate screening and interviews for team vacancies.
- Define team strategy, goals, action plans, and metrics aligned with Laboratory, Cybersecurity and Security Department strategic initiatives.
- Assist in staff goal setting and performance appraisals, identify opportunities for professional development.
- Develop, administer and predict team budgets and schedules in accordance with established organization strategy.
- Assess technologies, systems, and components to identify cybersecurity risks and conduct security impact analyses.
- Work closely with the IT department in collaboration of enterprise activities and security requirements.
- Conduct security impact analysis of emerging technologies and components intended for use across the Laboratory enterprise.
- Serve as Product Owner for the Laboratory's Governance, Risk, and Compliance (GRC) tool, ensuring alignment with mission objectives and strong user adoption.
- Evaluate and understand complex system environments and determine whether the appropriate level of security measures are enforced based on applicable security best practices and/or governing policies and regulations.
- Assist in planning, organizing and leading enterprise‑level IT security projects related to network, system and data security, enterprise information security reporting, auditing, as well as system risk management and mitigation, to include Cyber Maturity Model Certification (CMMC), Zero Trust Architecture and others.
- Participate in ongoing meetings with Laboratory management and present briefings and reports regarding risk assessments and evaluations of emerging technology.
- Participate in corporate policy and procedure development, maintain Cybersecurity Risk Management Team operating procedures.
- Develop and maintain cybersecurity policies, processes, and procedures aligned with requirements and industry best practices.
- Must be a U.S. citizen.
- Education:
Bachelor's degree in Computer Science, Information Technology, Computer Information Systems, or related field is required. - Experience:
Seven (7) or more years of management experience in a Defense Industrial Base (DIB) setting is desired, with related work in the following areas:
Security Control Assessor, Information Assurance, Risk Assessment, IT Security, or equivalent combination of education and experience. - Leadership:
Demonstrated capability in leading cross‑functional teams and presenting ideas both in writing and orally within a collaborative team environment. - Thorough understanding of NIST Special Publications 800‑171, 800‑171a, 800‑172, 800‑172a, FISMA processes, and the FedRAMP…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).