1

Quantitative Cyber Risk Jobs in Ashburn, VA (NOW HIRING)

Our team in the Cyber Risk and Resilience Directorate researches and develops software tools ... related highly quantitative discipline with eight (8) years of applicable experience; or a MS ...

Our team in the Cyber Risk and Resilience Directorate researches and develops software tools ... related highly quantitative discipline with eight (8) years of applicable experience; or a MS ...

Our team in the Cyber Risk and Resilience Directorate researches and develops software tools ... highly quantitative discipline with ten (10) years of applicable experience, or equivalent ...

... cyber capabilities, systems engineering, and technology transition. The SETA will serve as an ... Emphasis is placed on requirements definition, risk analysis, conceptual design, technology ...

Senior Data Scientist

Washington, DC ยท On-site

$148K - $263K/yr

... risk-scoring engines that prioritize security alerts * Create data models to determine the impact of cyber incidents. Minimum Qualifications: * Master's or PhD in a quantitative field (e.g ...

Management Analyst

Arlington, VA ยท On-site

$118K - $155K/yr

The Management Analyst shall assist and provide research, risk management, and cyber-physical ... The analyst provides quantitative, technical, and analytical expertise to support the program ...

Management Analyst

Arlington, VA ยท On-site

$118K - $155K/yr

The Management Analyst shall assist and provide research, risk management, and cyber-physical ... The analyst provides quantitative, technical, and analytical expertise to support the program ...

Showing results 21-40

Quantitative Cyber Risk information

See Ashburn, VA salary details

$100.2K

$173.6K

$265.4K

How much do quantitative cyber risk jobs pay per year?

As of Aug 11, 2026, the average yearly pay for quantitative cyber risk in Ashburn, VA is $173,565.00, according to ZipRecruiter salary data. Most workers in this role earn between $137,500.00 and $203,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in quantitative cyber risk roles and how can they be addressed?

Professionals in Quantitative Cyber Risk roles often encounter challenges such as translating complex cyber threats into measurable financial terms and obtaining reliable data for risk modeling. Collaborating closely with IT security teams and business stakeholders is essential to bridge gaps in understanding and ensure risk assessments are both technically accurate and aligned with organizational goals. Staying current with evolving threat landscapes and regulatory requirements also demands continuous learning and adaptation. Leveraging industry-standard frameworks and advanced analytics tools can help address these challenges effectively.

What is quantitative cyber risk?

Quantitative cyber risk involves using mathematical models and statistical techniques to measure and predict the financial impact of cyber threats on an organization. Unlike qualitative approaches that rely on subjective judgments, quantitative methods assign numerical values to risks, helping companies understand potential losses in dollar terms. This allows organizations to make more informed decisions about cybersecurity investments, insurance, and risk mitigation strategies.

What is the difference between Quantitative Cyber Risk vs Cyber Risk Analyst?

AspectQuantitative Cyber RiskCyber Risk Analyst
Required CredentialsCertifications like CRCM, CISSP, or CISA; strong quantitative backgroundCertifications such as CISA, CRISC; focus on risk assessment skills
Work EnvironmentFinancial institutions, cybersecurity firms, large corporationsFinancial services, consulting firms, government agencies
Industry UsageFocuses on modeling and quantifying cyber risks using data analysisEvaluates and reports on cyber risks, develops mitigation strategies

While both roles involve cybersecurity, Quantitative Cyber Risk specialists focus on modeling and quantifying risks using data and mathematical methods. Cyber Risk Analysts assess, analyze, and communicate cyber threats and vulnerabilities. The former is more data-driven and modeling-oriented, whereas the latter emphasizes risk evaluation and strategic recommendations.

What are the key skills and qualifications needed to thrive as a quantitative cyber risk professional, and why are they important?

To thrive as a Quantitative Cyber Risk professional, you need strong analytical skills, expertise in statistics or mathematics, and a background in cybersecurity or risk management, often supported by relevant degrees or certifications. Familiarity with risk modeling tools, programming languages like Python or R, and frameworks such as FAIR (Factor Analysis of Information Risk) is highly valued. Exceptional problem-solving, communication, and stakeholder management skills help translate complex risk data into actionable business insights. These competencies are critical for accurately assessing cyber risks, informing decision-making, and enhancing an organization's overall security posture.
What are popular job titles related to Quantitative Cyber Risk jobs in Ashburn, VA? For Quantitative Cyber Risk jobs in Ashburn, VA, the most frequently searched job titles are:
What job categories do people searching Quantitative Cyber Risk jobs in Ashburn, VA look for? The top searched job categories for Quantitative Cyber Risk jobs in Ashburn, VA are:
What cities near Ashburn, VA are hiring for Quantitative Cyber Risk jobs? Cities near Ashburn, VA with the most Quantitative Cyber Risk job openings:
Infographic showing various Quantitative Cyber Risk job openings in Ashburn, VA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $173,565 per year, or $83.4 per hour.

C Programmer

Cmu

Arlington, VA โ€ข On-site

Full-time

Re-posted 15 days ago


Job description

What We Do:

Our team in the Cyber Risk and Resilience Directorate researches and develops software tools capable of collecting, storing, and analyzing organizational network data to provide security analysts insights into what is traversing their network. We provide both the core network tools to facilitate this capability, and prototypes of new ways to present the data effectively. We deal with a scale of network data generally unseen by most organizations, handling record counts in the tens of billions per day.

Developing security insights at this scale requires creativity, efficiency, and staying up to date with modern computing platforms. In some cases, the computing has outpaced the methods, and it is incumbent upon us to generate novel views of both the entire data collection, and of focused datasets tailored to specific analyst needs.

Our network situational awareness security tools are published here: https://tools.netsa.cert.org/

Position Summary:

You'll be responsible for developing software within our network data collection suite and pushing the bounds of the uses of those tools. Much of the software is written in C, and some in Python. We are responsible for the entire life-cycle of the tools: requirements gathering/generation, development, testing, documentation, and user support.

There is room for independence for new tools or projects to make our software suite more complete. Making the tools easy to integrate and deploy, along with writing documentation are additional tasks for the position. You will work on existing projects with more senior developers until you have a grasp of the tool suite and gain domain expertise to take command of new or current tools.

You bring the design and software skills, and we'll bring the domain knowledge to solve the hard network security data problems.

Knowledge, Skills and Abilities:

  • Polished to expert programming skills in C.
  • Proficient scripting skills with bash.
  • Strong problem-solving skills.
  • Ability to learn a new programming language or development environment given appropriate time and resources.
  • Ability to work both independently and with teams, manage multiple projects, and elicit technical requirements from management and staff.

Requirements:

  • Education and Experience:BS degree in Computer Science, Statistics, Engineering, Mathematics, Economics, Data Science, or a related highly quantitative discipline with eight (8) years of applicable experience; or a MS degree in a relevant discipline with five (5) years of applicable experience; or a PhD in a relevant discipline with two (2) years of applicable experience.
  • Travel:Periodic travel to customer sites, conferences, workshops, and stakeholder meetings is required to support the SEI's mission and research activities.
  • Security Clearance:You will be subject to a background investigation and must have the ability to obtain and maintain a Department of War security clearance.
  • Applicants for this position must be currently legally authorized to work for CMU in the United States. CMU will not sponsor or take over sponsorship of an employment visa for this opportunity.

Duties:

  • Software Development (70%): Design, develop, and maintain high-performance software tools for collecting, processing, and analyzing large-scale network data using C, Python, and Bash. Participate in the full software development lifecycle, including requirements analysis, implementation, testing, deployment, and ongoing enhancement of cybersecurity research tools.
  • Customer Support (10%): Provide technical support by troubleshooting software issues, responding to user inquiries, and resolving reported defects. Collaborate with customers and stakeholders to gather feedback and recommend improvements to existing tools.
  • Documentation/Publication (10%):Prepare and maintain technical documentation, including user guides, installation instructions, and developer documentation. Contribute to technical reports, presentations, and publications that communicate software capabilities and research outcomes.
  • Testing (10%):Develop and execute unit, integration, and regression tests to ensure software quality, reliability, and performance. Identify, troubleshoot, and resolve software defects while supporting continuous improvement of testing processes.

Desired Experience:

  • Primary developer / project lead for a completed software project. Exposure to all phases of software development from requirements gathering to delivery. The feeling of ownership of the project.
  • An understanding of software / systems development lifecycle, QA testing, revision control, and change management practices
  • Experience developing software on Linux is preferred but not a requirement.
  • Experience working with containerization tools such as Docker is preferred.
  • Experience with network data collection or flow data, or awareness of network cyber threats is a plus, but not a requirement. It is our responsibility to transfer domain knowledge.

Location

Arlington, VA, Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff - Regular

Full time/Part time

Full time

Pay Basis

SalaryMore Information:
  • Please visit "Why Carnegie Mellon" to learn more about becoming part of an institution inspiring innovations that change the world.

  • Click here to view a listing of employee benefits

  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.

  • Statement of Assurance


CMU logo

About CMU

Sourced by ZipRecruiter

Industry

Offices of mental health practitioners

Company size

201 - 500 Employees

Headquarters location

Harrisburg, PA, US