1

Quantitative Cyber Risk Jobs in Chicago, IL (NOW HIRING)

next page

Showing results 1-20

Quantitative Cyber Risk information

See Chicago, IL salary details

$101K

$174.8K

$267.3K

How much do quantitative cyber risk jobs pay per year?

As of Aug 27, 2026, the average yearly pay for quantitative cyber risk in Chicago, IL is $174,845.00, according to ZipRecruiter salary data. Most workers in this role earn between $138,600.00 and $205,000.00 per year, depending on experience, location, and employer.

What is quantitative cyber risk?

Quantitative cyber risk involves using mathematical models and statistical techniques to measure and predict the financial impact of cyber threats on an organization. Unlike qualitative approaches that rely on subjective judgments, quantitative methods assign numerical values to risks, helping companies understand potential losses in dollar terms. This allows organizations to make more informed decisions about cybersecurity investments, insurance, and risk mitigation strategies.

What are some common challenges faced by professionals in quantitative cyber risk roles and how can they be addressed?

Professionals in Quantitative Cyber Risk roles often encounter challenges such as translating complex cyber threats into measurable financial terms and obtaining reliable data for risk modeling. Collaborating closely with IT security teams and business stakeholders is essential to bridge gaps in understanding and ensure risk assessments are both technically accurate and aligned with organizational goals. Staying current with evolving threat landscapes and regulatory requirements also demands continuous learning and adaptation. Leveraging industry-standard frameworks and advanced analytics tools can help address these challenges effectively.

What are the key skills and qualifications needed to thrive as a quantitative cyber risk professional, and why are they important?

To thrive as a Quantitative Cyber Risk professional, you need strong analytical skills, expertise in statistics or mathematics, and a background in cybersecurity or risk management, often supported by relevant degrees or certifications. Familiarity with risk modeling tools, programming languages like Python or R, and frameworks such as FAIR (Factor Analysis of Information Risk) is highly valued. Exceptional problem-solving, communication, and stakeholder management skills help translate complex risk data into actionable business insights. These competencies are critical for accurately assessing cyber risks, informing decision-making, and enhancing an organization's overall security posture.

What is the difference between Quantitative Cyber Risk vs Cyber Risk Analyst?

AspectQuantitative Cyber RiskCyber Risk Analyst
Required CredentialsCertifications like CRCM, CISSP, or CISA; strong quantitative backgroundCertifications such as CISA, CRISC; focus on risk assessment skills
Work EnvironmentFinancial institutions, cybersecurity firms, large corporationsFinancial services, consulting firms, government agencies
Industry UsageFocuses on modeling and quantifying cyber risks using data analysisEvaluates and reports on cyber risks, develops mitigation strategies

While both roles involve cybersecurity, Quantitative Cyber Risk specialists focus on modeling and quantifying risks using data and mathematical methods. Cyber Risk Analysts assess, analyze, and communicate cyber threats and vulnerabilities. The former is more data-driven and modeling-oriented, whereas the latter emphasizes risk evaluation and strategic recommendations.

What are popular job titles related to Quantitative Cyber Risk jobs in Chicago, IL?

For Quantitative Cyber Risk jobs in Chicago, IL, the most frequently searched job titles are:

What job categories do people searching Quantitative Cyber Risk jobs in Chicago, IL look for?

The top searched job categories for Quantitative Cyber Risk jobs in Chicago, IL are:

Infographic showing various Quantitative Cyber Risk job openings in Chicago, IL as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $174,845 per year, or $84.1 per hour.

Cyber Risk Assessor / Vulnerability Management Specialist

1 point system

Chicago, IL โ€ข On-site

Contractor

Posted 8 days ago


Job description

In-Office Requirement: We would require this candidate to be in the office 2-3 days a week, preferably on days when the rest of the team is also in the office for collaborative purposes. (Mon-Thurs)
 
Job Description Summary - We are seeking a skilled and motivated Senior Cyber Risk and Vulnerability Analyst to strengthen our cybersecurity risk management and vulnerability management capabilities. This role will conduct security risk assessments, support risk quantification and reporting, coordinate vulnerability remediation, and provide security consultation to business and technology stakeholders. The analyst will also contribute to security awareness and day-to-day operational security activities that help maintain a secure and resilient environment.
Requirements: 
Bachelor’s degree in cybersecurity, information technology, or a related field, or an equivalent combination of education and relevant experience. Relevant security or cloud certifications, such as Security+, Microsoft Azure, or AWS certifications, are preferred.
Five or more years of relevant experience in cybersecurity, technology risk, vulnerability management, security governance, or a related field, including demonstrated experience conducting security risk assessments and coordinating remediation activities.
Security risk assessment experience:Working knowledge of NIST CSF, NIST SP 800-53, ISO 27001, CIS Controls, or comparable security and control frameworks.
Experience evaluating technical and administrative controls.
Experience applying qualitative or quantitative methods to assess, prioritize, and communicate security risk.
Strong documentation and report-writing skills.
Ability to communicate risk to non-technical audiences.
Experience with vulnerability scanning tools such as Nexpose, Qualys or Nessus or similar vulnerability management platforms
Vulnerability management or remediation-governance experience
Experience developing and tracking remediation plans in partnership with technical teams
Excellent analytical and problem-solving skills.   
Be a clear and confident public speaker, able to tailor messaging around technical concepts to diverse audiences. 
Ability to quickly learn new processes and tools
Ability to think critically, ask thoughtful questions, and challenge assumptions in a constructive manner.
Naturally curious and driven to understand how technologies, applications, and business processes operate.
 
Preferred: 
Familiarity of Infrastructure, Container, SAST, DAST vulnerability remediation concepts from a vulnerability management remediation perspective is a plus. This role will work with existing application security resources to enhance the existing vulnerability management program.
Experience with ServiceNow Vulnerability Response Module is a plus
Self-starter who can work independently as well as in a team setting 
Experience analyzing security data in Tableau, Power BI, or comparable tools to identify trends, and develop metrics that support operational and strategic decision-making.
 
Key Responsibilities: 
Strengthen and expand the organization's Cyber Risk Management capabilities through risk assessments, advisory services, governance activities, and reporting.
Support risk analysis, quantification, and reporting efforts to improve organizational understanding and prioritization of cybersecurity risk.
Support the development, operationalization, and ongoing maintenance of the Security Risk Register, including risk documentation, scoring, stakeholder consultation, remediation tracking, governance, and reporting.
Demonstrates intellectual curiosity and a desire to continuously learn, investigate security concerns, challenge assumptions, and identify emerging risks, threats, and opportunities for security improvement.
Work with existing staff to identify and create process improvements to the existing vulnerability management and security awareness programs
Work with remediation teams to create and track plans to address discovered vulnerabilities.  
Identify and evaluate vulnerability metrics to determine areas of concern and improvement.  
Develop, maintain, and adhere to documented procedures, standards, and operational processes.
Conduct security risk assessments of applications, technologies, vendors, projects, and business initiatives to evaluate security control effectiveness and identify areas of risk.
Contribute to Security Awareness efforts on an as needed basis.
Support misc. operational tasks via ticket system
We are looking for additional support in the below operational support areas: 
Manage and resolve incoming service requests and incidents through a ticketing system. 
Evaluate new technologies and solutions to ensure alignment with organizational security policies, standards, and risk tolerance before adoption. 
Review and assess third-party SOC2 reports as part of vendor security evaluations. 
Review and respond to phishing emails reported by users, and escalate if necessary.