网络安全、指标与报告高级经理 - 远程
Senior Manager, Cybersecurity, Metrics & Reporting - Remote
工作灵活性:远程办公
优先考虑居住在东部或中部时区的候选人。
作为高级经理,网络安全、度量与报告,您将领导企业网络安全绩效测量、分析和报告的战略、治理和执行。您将与网络安全、技术、风险、审计、合规和业务部门的高级领导合作,提供对网络风险、项目有效性、运营表现、韧性及投资成果的清晰可见性。
您将负责:
• 根据组织目标和网络安全风险重点,定义、实施并持续演进企业网络安全度量、报告和分析策略。
• 作为企业网络安全度量与报告的领导者,将数据驱动的分析转化为对高级管理层的战略见解和建议。
• 通过高级分析和绩效报告,影响网络安全战略、投资优先级和企业风险管理决策。
• 建立报告成熟度路线图和持续改进计划,提升企业网络安全度量能力。
技术职责:
• 建立并管理网络安全关键绩效指标、关键风险指标、绩效衡量标准、度量定义、数据质量标准、报告控制和生命周期管理实践。
• 领导编写针对网络安全风险、性能、韧性及项目有效性的高管、董事会、审计委员会和监管机构的报告。
• 衡量网络安全控制的有效性、运营表现、网络韧性、风险降低成果和网络安全投资回报。
• 分析性能趋势、新兴威胁、风险指标和结果,以识别改进机会并推荐缓解策略。
• 领导推动网络安全报告自动化的项目,扩展仪表板、数据可视化、预测分析、风险预测、基于遥测的自动化和AI驱动的分析能力。
• 整合并管理来自企业安全平台、云环境、身份系统和新兴AI安全能力的网络安全遥测数据,以支持自动化报告、高级分析和运营决策。
领导力与人员管理职责:
• 领导团队、项目和企业倡议
查看英文原文
Work Flexibility: Remote
Preference will be given to candidates residing in the Eastern or Central time zones.
As a Senior Manager, Cybersecurity, Metrics and Reporting, you will lead the enterprise strategy, governance, and execution of cybersecurity performance measurement, analytics, and reporting. You will partner with senior leaders across Cybersecurity, Technology, Risk, Audit, Compliance, and business functions to provide clear visibility into cyber risk, program effectiveness, operational performance, resilience, and investment outcomes.
What you will do:
•Define, implement, and continuously evolve the enterprise cybersecurity metrics, reporting, and analytics strategy in alignment with organizational objectives and cyber risk priorities.
•Serve as the enterprise leader for cybersecurity measurement and reporting, translating data-driven analysis into strategic insights and recommendations for senior leadership.
•Influence cybersecurity strategy, investment prioritization, and enterprise risk management decisions through advanced analytics and performance reporting.
•Establish reporting maturity roadmaps and continuous improvement programs that advance enterprise cybersecurity measurement capabilities.
Technical Responsibilities:
•Establish and govern cybersecurity key performance indicators, key risk indicators, performance measures, metric definitions, data quality standards, reporting controls, and lifecycle management practices.
•Lead the development and delivery of executive, board, audit committee, and regulatory reporting on cybersecurity risk, performance, resilience, and program effectiveness.
•Measure cybersecurity control effectiveness, operational performance, cyber resilience, risk reduction outcomes, and returns on cybersecurity investments.
•Analyze performance trends, emerging threats, risk indicators, and outcomes to identify improvement opportunities and recommend mitigation strategies.
•Lead initiatives that automate cybersecurity reporting and expand dashboard, data visualization, predictive analytics, risk forecasting, telemetry-driven automation, and AI-enabled analytics capabilities.
•Integrate and govern cybersecurity telemetry from enterprise security platforms, cloud environments, identity systems, and emerging AI security capabilities to support automated reporting, advanced analytics, and operational decisions.
Leadership & People Management Responsibilities:
•Lead teams, programs, and enterprise initiatives responsible for cybersecurity metrics, analytics, governance, and reporting.
•Guide cross-functional initiatives and align cybersecurity, technology, risk, audit, compliance, and business stakeholders around enterprise measurement priorities.
Knowledge and Capabilities:
•Synthesize complex cybersecurity, risk, and performance information into concise executive, board, audit committee, and regulatory communications.
•Apply analytical and quantitative reasoning to cybersecurity measurement, risk analytics, business intelligence, and performance reporting.
•Prioritize concurrent reporting, analytics, and strategic initiatives while meeting established deadlines.
What You Need:
Required Qualifications
•Bachelor's degree in Cybersecurity, Information Systems, Data Analytics, Computer Science, Engineering, Business Analytics, or a related discipline.
•Minimum 10 years of experience in information technology, cybersecurity, or product security.
•Minimum 8 years of experience in cybersecurity, technology risk, business intelligence, data analytics, or performance reporting.
•Experience developing and governing enterprise cybersecurity metrics, key performance indicators, key risk indicators, and performance measurement frameworks.
•Experience delivering executive, board, or regulatory reporting that supports strategic decision-making.
•Leadership experience managing teams, programs, or enterprise initiatives.
Preferred Qualifications
•Experience with Power BI, Tableau, ServiceNow, Archer, or equivalent data visualization and reporting platforms.
•CISSP, CRISC, CISM, Security+, Certified Data Analyst, or equivalent certification.
United States of America Pay Ranges:
- USN: $155,900 - $259,700 USD Annual
- US5: $163,700 - $272,700 USD Annual
- US10: $171,500 - $285,700 USD Annual
- US15: $179,300 - $298,700 USD Annual
- US20: $187,100 - $311,600 USD Annual
- US30: $202,700 - $337,600 USD Annual
View the U.S. work location and transparency guide to find the pay range for your location.
Travel Percentage: NoneStryker Corporation is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected veteran status. Stryker is an EO employer – M/F/Veteran/Disability.Stryker Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information.Originally posted on Himalayas