1

Director Cyber Risk Management Jobs (NOW HIRING)

Position Overview The Director, Cyber Risk leads Asurion's cyber and technology risk management discipline and is accountable for a consistent, outcome-driven program the business can rely on for ...

Position Overview The Director, Cyber Risk leads Asurion's cyber and technology risk management discipline and is accountable for a consistent, outcome-driven program the business can rely on for ...

The ideal candidate brings deep expertise in cybersecurity strategy and risk management, a strong ... Advise investors on cyber risks that may impact valuation, deal structure, integration strategy, or ...

The ideal candidate brings deep expertise in cybersecurity strategy and risk management, a strong ... Advise investors on cyber risks that may impact valuation, deal structure, integration strategy, or ...

The ideal candidate brings deep expertise in cybersecurity strategy and risk management, a strong ... Advise investors on cyber risks that may impact valuation, deal structure, integration strategy, or ...

$200 - $250/hr

Director, Cyber Strategy and Risk Advisory, vCISO Cybersecurity Cybersecurity | New York, NY ... Support executive management teams in cyber crisis preparation, tabletop exercises, incident ...

The ideal candidate brings deep expertise in cybersecurity strategy and risk management, a strong ... Advise investors on cyber risks that may impact valuation, deal structure, integration strategy, or ...

The ideal candidate brings deep expertise in cybersecurity strategy and risk management, a strong ... Advise investors on cyber risks that may impact valuation, deal structure, integration strategy, or ...

$250/hr

Department Overview The Senior Director of Cyber Third-Party Risk Management (TPRM) is accountable for leading and modernizing McDonald's global third-party cyber risk management capability across a ...

next page

Showing results 1-20

Director Cyber Risk Management information

See salary details

$54K

$143.2K

$260K

How much do director cyber risk management jobs pay per year?

As of Sep 9, 2026, the average yearly pay for director cyber risk management in the United States is $143,185.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,500.00 and $167,500.00 per year, depending on experience, location, and employer.

What does a director of cyber risk management do?

A Director of Cyber Risk Management is responsible for overseeing an organization's strategies and programs to identify, assess, and mitigate cyber risks. This role involves developing risk management frameworks, leading incident response efforts, and ensuring compliance with cybersecurity regulations. The director collaborates with other departments to implement security best practices and often reports on risk posture to senior leadership. Their goal is to minimize potential threats to the company's information assets and ensure business continuity.

What are the key skills and qualifications needed to thrive as a director of cyber risk management, and why are they important?

To thrive as a Director of Cyber Risk Management, you need deep expertise in information security, risk assessment, regulatory compliance, and typically a bachelor's or master's degree in cybersecurity or a related field. Familiarity with frameworks like NIST, ISO 27001, and tools such as risk management software and security incident response platforms is crucial, as are certifications like CISSP, CISM, or CRISC. Strong leadership, strategic thinking, and effective communication skills set top candidates apart by enabling them to influence stakeholders and guide multidisciplinary teams. These capabilities are essential to proactively identify, assess, and mitigate cyber threats, ensuring organizational resilience and regulatory compliance.

What are some common challenges faced by a director of cyber risk management when aligning security initiatives with business objectives?

A Director of Cyber Risk Management often encounters the challenge of balancing robust security measures with the need for business agility and innovation. It's essential to effectively communicate cyber risks in business terms so that leadership can make informed decisions without stifling growth. Additionally, aligning disparate stakeholders—including IT, legal, compliance, and executive teams—requires strong collaboration and negotiation skills. Managing evolving threats while maintaining regulatory compliance and supporting business goals is a dynamic, ongoing challenge in this role.

What is the difference between Director Cyber Risk Management vs Cybersecurity Manager?

AspectDirector Cyber Risk ManagementCybersecurity Manager
CertificationsCISSP, CISM, CRISCCISSP, Security+
Work EnvironmentStrategic, executive-level, cross-departmentalOperational, team-focused, technical
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, tech firms, mid-sized companies

The main difference is that the Director Cyber Risk Management focuses on strategic risk oversight and policy development, while the Cybersecurity Manager handles day-to-day security operations and technical implementation. Both roles require relevant certifications and are vital in protecting organizational assets, but they differ in scope and level of responsibility.

What cities are hiring for Director Cyber Risk Management jobs?

Cities with the most Director Cyber Risk Management job openings:

What states have the most Director Cyber Risk Management jobs?

States with the most job openings for Director Cyber Risk Management jobs include:

What are popular job titles related to Director Cyber Risk Management jobs?

For Director Cyber Risk Management jobs, the most frequently searched job titles are:

Infographic showing various Director Cyber Risk Management job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $143,185 per year, or $68.8 per hour.
Asurion
IT Services • 10K+ employees

Full-time

Re-posted 11 days ago


Key responsibilities

  • Own and continuously improve the cyber and technology risk management framework, methodology, taxonomy, and lifecycle.

  • Lead enterprise cyber risk assessments and establish a cyber risk quantification capability to inform prioritization and investment decisions.

  • Own issues and remediation management, including intake, prioritization, tracking, and escalation of aging items.


Asurion rating

7.2

Company rating: 7.2 out of 10

Based on 84 frontline employees who took The Breakroom Quiz

138th of 226 rated it services


Job description

Position Overview

The Director, Cyber Risk leads Asurion's cyber and technology risk management discipline and is accountable for a consistent, outcome-driven program the business can rely on for decision-making. This strategic, cross-functional leader owns the end-to-end cyber risk lifecycle-identification, assessment, quantification, treatment, acceptance, monitoring, and reporting-along with the cyber risk register, risk appetite and tolerance framework, control assurance, and issues management. The Director partners closely with first-line control owners across security and technology, Portfolio Information Security Officers (PISOs), and key stakeholders in Enterprise Risk Management, Internal Audit, Legal, and Privacy. This role sets the standard for sound risk judgment, develops a high-performing team, and translates complex cyber risk into clear, defensible narratives for senior leadership and the board. This is a salaried, leadership role with enterprise impact, guiding a multi-year maturity uplift from ad hoc practices to scalable, evidence-based risk management.

Key Responsibilities
  • Own and continuously improve the cyber and technology risk management framework, methodology, taxonomy, and lifecycle aligned to NIST CSF 2.0, ISO 27001/27005, and applicable regulatory obligations.
  • Define standards, procedures, and rating scales for consistent enterprise-wide risk identification, assessment, and reporting; partner with the PISO model to ensure common language and practices across portfolios.
  • Lead enterprise cyber risk assessments across technology, business, regulatory, and emerging-risk domains to produce consistent, defensible determinations.
  • Establish and operate a cyber risk quantification capability (e.g., FAIR-based) to express risk in business and financial terms and inform prioritization and investment decisions.
  • Maintain the enterprise cyber risk register; ensure risks are well-described, owned, rated, and tracked to acceptable residual levels; develop and manage KRI/KCI programs for forward-looking posture.
  • Operationalize the risk appetite and tolerance framework with the CISO and senior leadership; own risk acceptance and exception governance with clear, auditable documentation and time-bound approvals.
  • Govern cyber risk policy structure, ownership, review cadence, and exception handling; chair or support cyber risk forums and escalate decisions to appropriate authority levels.
  • Lead second-line, risk-based assurance over design and operating effectiveness of key cyber controls in coordination with first-line and Internal Audit; identify thematic weaknesses and drive structural remediation.
  • Own issues and remediation management-intake, prioritization, owner assignment, tracking to closure, and escalation of aging items.
  • Define and report outcome-focused metrics (e.g., residual risk trends, out-of-appetite reduction, early-versus-late finding ratios, incidents tied to accepted risk) in executive- and board-ready formats.
  • Serve as primary point of contact for cyber risk in regulatory exams, audits, and carrier-partner due diligence.
  • Integrate cyber risk into Enterprise Risk Management to ensure consistency in enterprise risk reporting and governance; partner with Legal, Privacy, Procurement, and technology leaders to embed risk-informed decisions.
  • Oversee vendor/third-party risk within the cyber risk portfolio to ensure supply-chain risk is governed in line with enterprise practices.
  • Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance, and scale capacity through process improvement, tooling, and appropriate AI-assisted workflows.
Education and Experience
  • Bachelor's degree in a related field or equivalent professional experience.
  • 10+ years in cybersecurity, IT/technology risk, or GRC, including 5+ years leading managers or multiple teams/domains.
  • Proven experience designing, leading, or substantially maturing an end-to-end enterprise cyber/IT risk management program.
  • Deep knowledge of NIST CSF 2.0, ISO 27001/27005, relevant regulatory regimes, and the three-lines-of-defense model.
  • Experience operating a risk register, risk appetite/tolerance framework, and risk acceptance/exception governance.
  • Hands-on experience with GRC/IRM platforms (e.g., ServiceNow IRM, Archer, OneTrust, or comparable).
  • Excellent executive communication skills with a track record of briefing senior leadership and boards.
  • Strong cross-functional influence partnering across security, technology, legal, privacy, and business teams.
  • Preferred: CRISC, CISSP, CISM, or CISA; FAIR-based quantification experience; background in regulated or consumer-facing environments; experience with ERM integration and executive/board risk committees; Master's degree in a related field.
Knowledge, Skills, and Abilities
  • Strategic risk leadership with the ability to connect cyber risk to business outcomes and investment decisions.
  • Sound, defensible judgment under uncertainty; skilled in risk trade-offs and acceptance decisions.
  • Expertise in risk quantification, KRI/KCI design, and outcome-based program metrics.
  • Strong governance and policy acumen, including appetite/tolerance, exceptions, and escalation pathways.
  • Proficiency in second-line control assurance and issues management, driving thematic remediation.
  • Exceptional written and verbal communication; translates complex risk into clear, actionable narratives for executives and the board.
  • Team leadership and talent development; builds high-performance teams and next-level leaders.
  • Change agent mindset with process improvement, tooling, and automation competencies, including appropriate use of AI-assisted workflows.
  • Collaboration and influence across ERM, Internal Audit, Legal, Privacy, Procurement, and technology organizations.
Travel Requirements

N/A

Physical Demands
  • Stationary Position: Frequently
  • Vision: 20/20 corrected vision
  • Hearing: Receive detailed information if spoken to

What Asurion employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Asurion logo

About Asurion

Sourced by ZipRecruiter

As the world's leading tech care company, Asurion eliminates the fears and frustrations associated with technology, to ensure our 300 million customers get the most out of their devices, appliances and connections. We provide insurance, repair, replacement, installation and 24/7 support for everything from cellphones to laptops and household appliances. Our experts are available online, on the phone, at one of our more than 700 stores, or can even come to you.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Nashville, TN, US

Social media