1

Quantitative Cyber Risk Jobs (NOW HIRING)

The Senior Associate conducts qualitative and quantitative cyber risk assessments, develops executive-ready risk recommendations, and supports strategic initiatives including the enterprise Crown ...

The Senior Associate conducts qualitative and quantitative cyber risk assessments, develops executive-ready risk recommendations, and supports strategic initiatives including the enterprise Crown ...

Own zerohash's cyber risk framework: risk methodology, risk appetite metrics, and scenario library ... Hands-on experience with quantitative risk modeling - FAIR methodology or equivalent * Familiarity ...

Senior GRC Analyst

Boston, MA · On-site

$130K - $170K/yr

Support and help mature quantitative cyber risk analysis approaches such as FAIR to improve how risk is measured and communicated * Prepare materials and analysis to support the Cyber Risk Committee ...

This role is responsible for building risk frameworks, conducting quantitative analysis, monitoring ... operational, compliance, cyber, and strategic risk categories • Identify emerging risks ...

Provide subject matter expertise in enterprise risk management, operational risk, cyber risk, and ... Conduct qualitative and quantitative risk analyses to support program decision-making. * Maintain ...

Provide subject matter expertise in enterprise risk management, operational risk, cyber risk, and ... Conduct qualitative and quantitative risk analyses to support program decision-making. * Maintain ...

The Insider Risk team, in partnership with the Information Security Data Operations team, is ... The role partners closely with Cyber, HR, Legal, Compliance, Anti‐Fraud, and Enterprise ...

Apply FAIR or comparable quantitative methods for high-impact vendor decisions, expressing cyber risk in loss-exposure terms that resonate with senior leadership. * Advise IT, Engineering and ...

next page

Showing results 1-20

Quantitative Cyber Risk information

See salary details

$98K

$169.7K

$259.5K

How much do quantitative cyber risk jobs pay per year?

As of Aug 27, 2026, the average yearly pay for quantitative cyber risk in the United States is $169,729.00, according to ZipRecruiter salary data. Most workers in this role earn between $134,500.00 and $199,000.00 per year, depending on experience, location, and employer.

What is quantitative cyber risk?

Quantitative cyber risk involves using mathematical models and statistical techniques to measure and predict the financial impact of cyber threats on an organization. Unlike qualitative approaches that rely on subjective judgments, quantitative methods assign numerical values to risks, helping companies understand potential losses in dollar terms. This allows organizations to make more informed decisions about cybersecurity investments, insurance, and risk mitigation strategies.

What are some common challenges faced by professionals in quantitative cyber risk roles and how can they be addressed?

Professionals in Quantitative Cyber Risk roles often encounter challenges such as translating complex cyber threats into measurable financial terms and obtaining reliable data for risk modeling. Collaborating closely with IT security teams and business stakeholders is essential to bridge gaps in understanding and ensure risk assessments are both technically accurate and aligned with organizational goals. Staying current with evolving threat landscapes and regulatory requirements also demands continuous learning and adaptation. Leveraging industry-standard frameworks and advanced analytics tools can help address these challenges effectively.

What are the key skills and qualifications needed to thrive as a quantitative cyber risk professional, and why are they important?

To thrive as a Quantitative Cyber Risk professional, you need strong analytical skills, expertise in statistics or mathematics, and a background in cybersecurity or risk management, often supported by relevant degrees or certifications. Familiarity with risk modeling tools, programming languages like Python or R, and frameworks such as FAIR (Factor Analysis of Information Risk) is highly valued. Exceptional problem-solving, communication, and stakeholder management skills help translate complex risk data into actionable business insights. These competencies are critical for accurately assessing cyber risks, informing decision-making, and enhancing an organization's overall security posture.

What is the difference between Quantitative Cyber Risk vs Cyber Risk Analyst?

AspectQuantitative Cyber RiskCyber Risk Analyst
Required CredentialsCertifications like CRCM, CISSP, or CISA; strong quantitative backgroundCertifications such as CISA, CRISC; focus on risk assessment skills
Work EnvironmentFinancial institutions, cybersecurity firms, large corporationsFinancial services, consulting firms, government agencies
Industry UsageFocuses on modeling and quantifying cyber risks using data analysisEvaluates and reports on cyber risks, develops mitigation strategies

While both roles involve cybersecurity, Quantitative Cyber Risk specialists focus on modeling and quantifying risks using data and mathematical methods. Cyber Risk Analysts assess, analyze, and communicate cyber threats and vulnerabilities. The former is more data-driven and modeling-oriented, whereas the latter emphasizes risk evaluation and strategic recommendations.

More about Quantitative Cyber Risk jobs

What cities are hiring for Quantitative Cyber Risk jobs?

Cities with the most Quantitative Cyber Risk job openings:

What states have the most Quantitative Cyber Risk jobs?

States with the most job openings for Quantitative Cyber Risk jobs include:

Infographic showing various Quantitative Cyber Risk job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $169,729 per year, or $81.6 per hour.

Sr Analyst, Risk Management

On-site


Newell Brands
Manufacturing • 10K+ employees

7.3

Company rating: 7.3 out of 10

Based on 80 frontline employees who took The Breakroom Quiz

324th of 544 rated manufacturers

Good employer

Paid breaks

Recommended by parents


Full-time

Posted 29 days ago


Job description

Job ID: 16335 

Alternate Locations:  

Newell Brands is a leading consumer products company with a portfolio of iconic brands like Graco, Coleman, Oster, Rubbermaid, Sharpie and Yankee Candle - and 24,000 talented teammates around the world. Our culture is built on values in action: Integrity, Teamwork, Passion for Winning, Ownership, and Leadership. We work together to win, grow, and make a real impact-supported by a high-performing, inclusive, and collaborative environment where you can be your best, every day.

Job Overview

The Information Security Risk Management Senior Analyst is an intermediate-level professional within the Global Information Security Risk & Resilience team at Newell Brands. Reporting to the Information Security (IS) Risk Management Manager, this role is responsible for identifying, assessing, quantifying, and communicating cyber risk across a diverse global technology landscape. The IS Risk Management Manager retains program accountability; the Senior Associate operates with routine oversight and exercises independent judgment and discretion on moderately complex assignments.

This role partners with business and technology leaders to evaluate cybersecurity risks across enterprise applications, cloud platforms, infrastructure, manufacturing environments, digital transformation initiatives, and emerging technologies, including Artificial Intelligence (AI). The Senior Associate conducts qualitative and quantitative cyber risk assessments, develops executive-ready risk recommendations, and supports strategic initiatives including the enterprise Crown Jewels program. Success requires strong analytical capability, excellent stakeholder engagement skills, and the ability to translate complex technical risks into meaningful business impact. The Senior Associate also serves as a mentor to junior team members.

The role focuses primarily on assessments and Cyber Risk Quantification (45%), strategic risk initiatives (20%), business partnership and executive risk advisory (20%), and program maturity and process improvement (15%). The actual task percentages can change based on business needs.

Assessments and Cyber Risk Quantification (45%)

  • Conduct qualitative and Factor Analysis of Information Risk (FAIR)-based Cyber Risk Quantification (CRQ) assessments across enterprise applications, cloud environments, infrastructure, manufacturing technologies, and strategic initiatives.
  • Facilitate structured risk workshops with business and technical stakeholders to identify, analyze, and quantify cyber risk scenarios.
  • Develop defensible estimates of financial exposure using FAIR methodology and supporting data.
  • Document risk treatment recommendations aligned to business objectives.
  • Monitor remediation activities and evaluate residual risk.

Strategic risk initiatives (20%)

  • Conduct risk assessments supporting the enterprise Crown Jewels initiative.
  • Perform security risk assessments for strategic business initiatives, mergers and acquisitions, AI implementations, and major technology programs.
  • Assess emerging technology risks, including AI adoption, from an Information Security perspective.
  • Identify cyber risk trends and recommend improvements.

Business partnership and executive risk advisory (20%)

  • Serve as a risk advisor for assigned business and technology initiatives.
  • Present assessment findings and recommendations to managers, directors, and senior leaders.
  • Build collaborative relationships across Information Security, IT enterprise architecture, and business teams.
  • Translate technical cybersecurity risks into business-focused language that supports informed decision-making.

Program maturity and process improvement (15%)

  • Mentor junior analysts and provide guidance on assessment execution and stakeholder engagement.
  • Support the development of security risk assessment standards and, from an Information Security perspective, AI risk assessment practices.
  • Identify opportunities to use automation and AI-enabled capabilities to improve program efficiency and effectiveness.
  • Promote continuous improvement through documentation, knowledge sharing, and process improvement.

Qualifications:

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business, or a related discipline.
  • 2 to 4 years of experience in cybersecurity, risk management, Governance, Risk, and Compliance (GRC), or consulting.
  • Professional certification such as Certified in Risk and Information Systems Control (CRISC), CompTIA Security+, or equivalent is a plus.
  • Demonstrated experience using AI tools, including major large language models (LLMs) such as ChatGPT, Microsoft Copilot, and Claude, to produce high-quality work outputs, increase efficiency, and drive process improvements.
  • Solid understanding of primary control frameworks, including the Center for Internet Security (CIS) Critical Security Controls (CSC) Top 18 and the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0, with awareness of the NIST AI Risk Management Framework (AI RMF).
  • Strong analytical and critical-thinking skills.
  • Excellent written, verbal, and presentation skills, with the ability to communicate technical concepts to non-technical audiences.
  • Experience managing multiple priorities in a fast-paced global environment.
  • Experience performing FAIR-based CRQ is a strong plus.
  • Experience with Optro (formerly AuditBoard), Archer, or ServiceNow GRC is a plus.
  • Exposure to AI security risk assessments is a plus.

*Please note this role will not be able to sponsor H1B visa or support OPT status.

Newell Brands (NASDAQ: NWL) is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid, Sharpie, Graco, Coleman, Rubbermaid Commercial Products, Yankee Candle, Paper Mate, FoodSaver, Dymo, EXPO, Elmer's, Oster, NUK, Spontex and Campingaz. We are focused on delighting consumers by lighting up everyday moments. Newell Brands and its subsidiaries are Equal Opportunity Employers and comply with applicable employment laws. EOE/M/F/Vet/Disabled are encouraged to apply. 


Newell Brands logo

About Newell Brands

Sourced by ZipRecruiter

Newell Brands (NASDAQ: NWL) is a leading global consumer goods company with a strong portfolio of well-known brands, including Rubbermaid, Sharpie, Graco, Coleman, Rubbermaid Commercial Products, Yankee Candle, Paper Mate, FoodSaver, Dymo, EXPO, Elmer's, Oster, NUK, Spontex and Campingaz.

Industry

Manufacturing

Company size

10,000+ Employees

Headquarters location

Atlanta, GA, US

Year founded

1903

Social media


What Newell Brands employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom