The Senior Governance & Risk Analyst will conduct comprehensive risk assessments, manage a risk register, collaborate with teams for compliance, and prepare risk reports.
ZS is a place where passion changes lives. As a management consulting and technology firm focused on improving life and how we live it, we transform ideas into impact by bringing together data, science, technology and human ingenuity to deliver better outcomes for all. Here you'll work side-by-side with a powerful collective of thinkers and experts shaping life-changing solutions for patients, caregivers and consumers, worldwide. ZSers drive impact by bringing a client-first mentality to each and every engagement. We partner collaboratively with our clients to develop custom solutions and technology products that create value and deliver company results across critical areas of their business. Bring your curiosity for learning, bold ideas, courage and passion to drive life-changing impact to ZS.
Senior Governance & Risk Analyst
ZS IT Support teams are aligned with the company's business strategy and operating model and aims to provide its 4000 plus employees and their clients the right tools and information for high performance. The IT organization focuses on providing products and services to ZS to ensure successful business outcomes. This involves providing a scalable, sustainable and reliable IT infrastructure, customized applications, messaging and collaboration products, Business Intelligence and Database administration support along with a reliable 24*7 uninterrupted high-quality technology support services.
What You'll Do:
We are seeking applicants for the position of Senior Analyst - Governance and Risk team to join our US IT Governance, Risk and Compliance team. The position will support various management directed, IT risk governance initiatives which include following job requirements:
The primary responsibility of this role is to perform comprehensive risk assessments, including vendor due diligence, process/project security risk assessments, and maintaining the risk register. The successful candidate will possess a strong understanding of IT risk management principles and will play a crucial role in identifying, assessing, and mitigating risks to ensure the security and stability of our organizational infrastructure. It requires strong analytical skills, familiarity with security domains, and the ability to communicate risk insights clearly and effectively.
Risk Assessments:
VRA Execution & Risk Register Management:
Compliance & Controls:
Reporting & Communication:
What You'll Bring:
How You'll Grow:
Hybrid Working Model:
ZS is committed to a Flexible and Connected way of working. ZSers are on-site at clients or ZS offices three days a week. Combined flexibility to work remotely two days a week is also available. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Perks & Benefits:
ZS offers a comprehensive total rewards package including health and well-being, financial planning, annual leave, personal growth and professional development. Our robust skills development programs, multiple career progression options and internal mobility paths and collaborative culture empowers you to thrive as an individual and global team member.
We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Travel:
Travel is a requirement at ZS for client facing ZSers; business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.
Considering applying?
At ZS, we honor the visible and invisible elements of our identities, personal experiences, and belief systems-the ones that comprise us as individuals, shape who we are, and make us unique. We believe your personal interests, identities, and desire to learn are integral to your success here. We are committed to building a team that reflects a broad variety of backgrounds, perspectives, and experiences. Learn more about our inclusion and belonging efforts and the networks ZS supports to assist our ZSers in cultivating community spaces and obtaining the resources they need to thrive.
If you're eager to grow, contribute, and bring your unique self to our work, we encourage you to apply.
ZS is an equal opportunity employer and is committed to providing equal employment and advancement opportunities without regard to any class protected by applicable law.
To complete your application:
Candidates must possess or be able to obtain work authorization for their intended country of employment. An on-line application, including a full set of transcripts (official or unofficial), is required to be considered.
NO AGENCY CALLS, PLEASE.
Find Out More At:
www.zs.com
Salary: $110,000.00 - $120,000.00
Senior Governance & Risk Analyst
ZS IT Support teams are aligned with the company's business strategy and operating model and aims to provide its 4000 plus employees and their clients the right tools and information for high performance. The IT organization focuses on providing products and services to ZS to ensure successful business outcomes. This involves providing a scalable, sustainable and reliable IT infrastructure, customized applications, messaging and collaboration products, Business Intelligence and Database administration support along with a reliable 24*7 uninterrupted high-quality technology support services.
What You'll Do:
We are seeking applicants for the position of Senior Analyst - Governance and Risk team to join our US IT Governance, Risk and Compliance team. The position will support various management directed, IT risk governance initiatives which include following job requirements:
The primary responsibility of this role is to perform comprehensive risk assessments, including vendor due diligence, process/project security risk assessments, and maintaining the risk register. The successful candidate will possess a strong understanding of IT risk management principles and will play a crucial role in identifying, assessing, and mitigating risks to ensure the security and stability of our organizational infrastructure. It requires strong analytical skills, familiarity with security domains, and the ability to communicate risk insights clearly and effectively.
Risk Assessments:
- Perform assessments for vendors, processes, and projects to identify security gaps and recommend controls.
- Evaluate risks across IT systems, applications, infrastructure, and third-party engagements.
- Document assessment findings with clear rationale and actionable recommendations.
VRA Execution & Risk Register Management:
- Perform vendor risk assessments to evaluate third-party security posture, document findings, and recommend mitigation strategies aligned with organizational standards.
- Maintain and update the risk register, ensuring accurate classification, ownership mapping, and closure tracking across all active and draft risks.
- Collaborate with internal teams (e.g., security, legal, procurement) and external stakeholders to ensure risk documentation is complete, validated, and aligned with business priorities.
- Conduct periodic risk hygiene activities, including archival of outdated risks, evidence collection, and exception tracking.
- Ensure all risk-related documentation is clear, complete, and accessible for stakeholders, supporting decision-making and compliance readiness.
Compliance & Controls:
- Apply knowledge of regulatory standards (e.g., ISO, NIST, GDPR) to assess and document compliance.
- Support the implementation of security policies and control frameworks across business functions.
- Monitor control effectiveness and suggest improvements where needed.
Reporting & Communication:
- Prepare risk reports with summaries of findings, impact analysis, and mitigation plans.
- Share updates on risk trends, exceptions, and closure progress on a regular cadence.
- Communicate technical risk concepts in a clear, accessible format for non-technical audiences
What You'll Bring:
- Bachelor's degree in Computer Science, Information Systems, or a related field (master's degree is a plus).
- Minimum of 4-6 of years' experience in IT risk management, IT governance or related field.
- Strong understanding and knowledge of IT risk assessment methodologies, frameworks industry best practices and regulatory requirements (GDPR, HIPAA, PCI DSS).
- Strong experience with vendor risk management and security risk assessments.
- High proficiency in using risk assessment tools and technologies.
- Excellent analytical and problem-solving skills.
- Strong written and verbal communication skills, with the ability to effectively communicate technical concepts to both technical and non-technical audiences.
- Strong organizational and time management skills, with the ability to manage multiple priorities and deadlines.
- Relevant certifications such as Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), or Certified Information Security Manager (CISM) are preferred, ISO 27001.
- Professional appearance and demeanor, with ability to exercise good judgment and discretion.
- Proven ability to work creatively and analytically in a problem-solving environment.
How You'll Grow:
- Cross-functional skills development & custom learning pathways
- Milestone training programs aligned to career progression opportunities
- Internal mobility paths that empower growth via s-curves, individual contribution and role expansions
Hybrid Working Model:
ZS is committed to a Flexible and Connected way of working. ZSers are on-site at clients or ZS offices three days a week. Combined flexibility to work remotely two days a week is also available. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Perks & Benefits:
ZS offers a comprehensive total rewards package including health and well-being, financial planning, annual leave, personal growth and professional development. Our robust skills development programs, multiple career progression options and internal mobility paths and collaborative culture empowers you to thrive as an individual and global team member.
We are committed to giving our employees a flexible and connected way of working. A flexible and connected ZS allows us to combine work from home and on-site presence at clients/ZS offices for the majority of our week. The magic of ZS culture and innovation thrives in both planned and spontaneous face-to-face connections.
Travel:
Travel is a requirement at ZS for client facing ZSers; business needs of your project and client are the priority. While some projects may be local, all client-facing ZSers should be prepared to travel as needed. Travel provides opportunities to strengthen client relationships, gain diverse experiences, and enhance professional growth by working in different environments and cultures.
Considering applying?
At ZS, we honor the visible and invisible elements of our identities, personal experiences, and belief systems-the ones that comprise us as individuals, shape who we are, and make us unique. We believe your personal interests, identities, and desire to learn are integral to your success here. We are committed to building a team that reflects a broad variety of backgrounds, perspectives, and experiences. Learn more about our inclusion and belonging efforts and the networks ZS supports to assist our ZSers in cultivating community spaces and obtaining the resources they need to thrive.
If you're eager to grow, contribute, and bring your unique self to our work, we encourage you to apply.
ZS is an equal opportunity employer and is committed to providing equal employment and advancement opportunities without regard to any class protected by applicable law.
To complete your application:
Candidates must possess or be able to obtain work authorization for their intended country of employment. An on-line application, including a full set of transcripts (official or unofficial), is required to be considered.
NO AGENCY CALLS, PLEASE.
Find Out More At:
www.zs.com
Salary: $110,000.00 - $120,000.00
Top Skills
Gdpr
Hipaa
Iso
Nist
Pci Dss
Risk Assessment Tools
ZS Boston, Massachusetts, USA Office

One Boston Place, 28th Floor, Boston, MA, United States, 02108
Similar Jobs at ZS
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Manage projects focused on technology solutions for healthcare, enhancing delivery systems and ensuring regulatory compliance while leading teams and mentoring individuals.
Top Skills:
Cloud PlatformsData AnalyticsData ManagementElectronic Health RecordsPythonSQL
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
The Strategy Insights & Planning Consultant will lead project execution, conduct analyses, synthesize findings, provide recommendations, and mentor junior team members to improve client outcomes in medical affairs.
Top Skills:
DataScienceTechnology
Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
The Enterprise Architect will co-lead tech advisory, manage client relationships, drive new business, mentor junior consultants, and oversee large transformations.
Top Skills:
AICloudComputer ApplicationsDataDigitalOn-PremProject Management ToolsSecurity
What you need to know about the Boston Tech Scene
Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories


