网络安全量化风险经理- 远程
Manager, Cybersecurity, Quantitative Risk - Remote
工作灵活性:优先考虑居住在东部或中部时区的候选人。
作为网络安全经理,量化风险,您将领导开发和应用量化方法,以衡量、建模并传达企业范围内的网络安全风险。您将与网络安全GRC、网络安全战略、安全运营、企业风险管理、财务和业务领导人合作,以确定投资重点、控制有效性、网络安全战略和高管风险报告。
您将负责:
• 领导企业网络安全量化项目,建立一致且可衡量的网络安全风险暴露视图。
• 将量化风险洞察转化为对高管领导层和治理论坛的建议。
• 与安全、技术、财务、审计、合规、企业风险和业务职能合作,支持基于风险的决策。
技术职责:
• 开发和维护量化网络安全风险评估方法、风险模型和评分方法。
• 测量和分析各业务单元、产品、技术和第三方环境中的网络安全风险暴露。
• 进行基于情景的风险分析、损失估算、蒙特卡洛分析和控制有效性评估。
• 应用FAIR或其他类似方法进行网络安全量化项目。
• 开发网络安全仪表板、关键风险指标、量化报告能力和高管报告机制。
• 通过风险降低分析评估网络安全投资和修复项目。
• 进行涉及网络威胁、漏洞和控制环境的新兴风险评估和趋势分析。
• 通过量化风险洞察支持监管、审计、治理和网络安全战略要求。
知识和能力:
• 将网络安全框架、风险管理原则、统计建模和治理流程应用于企业风险分析。
• 将复杂的量化信息提炼为简洁的沟通内容,供高管和高级管理层使用。
• 在保持一致的风险测量实践的同时,优先处理多个分析、报告需求和截止日期。
您需要具备:
必要资格
• 网络安全、风险管理、统计学、数学、数据科学、信息系统、金融、工程或相关领域的学士学位。
• 至少8年相关工作经验。
查看英文原文
Work Flexibility: RemotePreference will be given to candidates residing in the Eastern or Central time zones.
As a Manager, Cybersecurity, Quantitative Risk, you will lead the development and application of quantitative methods that measure, model, and communicate cybersecurity risk across the enterprise. You will partner with Cyber GRC, Cyber Strategy, Security Operations, Enterprise Risk Management, Finance, and business leaders to inform investment priorities, control effectiveness, cybersecurity strategy, and executive risk reporting.
What you will do:
• Lead enterprise cyber risk quantification initiatives and establish a consistent, measurable view of cybersecurity risk exposure.
• Translate quantitative risk insights into recommendations for executive leadership and governance forums.
• Partner across security, technology, finance, audit, compliance, enterprise risk, and business functions to support risk-informed decisions.
Technical Responsibilities:
• Develop and maintain quantitative cyber risk assessment methodologies, risk models, and scoring approaches.
• Measure and analyze cyber risk exposure across business units, products, technologies, and third-party environments.
• Perform scenario-based risk analyses, loss estimation, Monte Carlo analysis, and control effectiveness evaluations.
• Apply FAIR or similar methodologies to cyber risk quantification initiatives.
• Develop cyber risk dashboards, key risk indicators, quantitative reporting capabilities, and executive reporting mechanisms.
• Evaluate cybersecurity investments and remediation initiatives through risk reduction analyses.
• Conduct emerging risk assessments and trend analyses involving cyber threats, vulnerabilities, and control environments.
• Support regulatory, audit, governance, and cybersecurity strategy requirements through quantitative risk insights.
Knowledge and Capabilities:
• Apply cybersecurity frameworks, risk management principles, statistical modeling, and governance processes to enterprise risk analyses.
• Synthesize complex quantitative information into concise communications for executive and senior leadership audiences.
• Prioritize concurrent analyses, reporting needs, and deadlines while maintaining consistent risk measurement practices.
What You Need:
Required Qualifications
• Bachelor's degree in Cybersecurity, Risk Management, Statistics, Mathematics, Data Science, Information Systems, Finance, Engineering, or a related discipline.
• Minimum 8 years of professional experience in information technology or cybersecurity.
• Minimum 5 years of experience in cybersecurity risk management, quantitative risk analysis, enterprise risk, data analytics, or a related discipline.
• Experience conducting cyber risk assessments and control effectiveness evaluations.
• Experience developing risk models, risk scoring methodologies, quantitative reporting capabilities, and using data analytics or visualization tools.
Preferred Qualifications
• Training in quantitative risk analysis, statistical modeling, enterprise risk management, or cybersecurity risk management.
• Experience with FAIR, Monte Carlo analysis, risk modeling techniques, or similar methodologies.
• CRISC, CISSP, CISM, FAIR, Financial Risk Manager (FRM), or equivalent certification.
United States of America Pay Ranges:
- USN: $135,600 - $225,900 USD Annual
- US5: $142,400 - $237,200 USD Annual
- US10: $149,200 - $248,500 USD Annual
- US15: $155,900 - $259,800 USD Annual
- US20: $162,700 - $271,100 USD Annual
- US30: $176,300 - $293,700 USD Annual
View the U.S. work location and transparency guide to find the pay range for your location.
Travel Percentage: NoneStryker Corporation is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected veteran status. Stryker is an EO employer – M/F/Veteran/Disability.Stryker Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information.Originally posted on Himalayas