1

Quantitative Cyber Risk Jobs in Foster City, CA (NOW HIRING)

ServiceNow Platform Architect - Manager

San Jose, CA ยท On-site

$83.50 - $105.25/hr

By coupling our business and cyber risk process functional experts on platform automation and ... quantitative return on investment, program and target operating model, data strategy & governance ...

Perform Quantitative Risk Assessment by quantifying security related safety risks, collaborating ... Experience with the security analysis of complex cyber-physical systems and automotive Systems on ...

next page

Showing results 1-20

Quantitative Cyber Risk information

See Foster City, CA salary details

$114.2K

$197.8K

$302.4K

How much do quantitative cyber risk jobs pay per year?

As of Aug 27, 2026, the average yearly pay for quantitative cyber risk in Foster City, CA is $197,821.00, according to ZipRecruiter salary data. Most workers in this role earn between $156,800.00 and $231,900.00 per year, depending on experience, location, and employer.

What is quantitative cyber risk?

Quantitative cyber risk involves using mathematical models and statistical techniques to measure and predict the financial impact of cyber threats on an organization. Unlike qualitative approaches that rely on subjective judgments, quantitative methods assign numerical values to risks, helping companies understand potential losses in dollar terms. This allows organizations to make more informed decisions about cybersecurity investments, insurance, and risk mitigation strategies.

What are some common challenges faced by professionals in quantitative cyber risk roles and how can they be addressed?

Professionals in Quantitative Cyber Risk roles often encounter challenges such as translating complex cyber threats into measurable financial terms and obtaining reliable data for risk modeling. Collaborating closely with IT security teams and business stakeholders is essential to bridge gaps in understanding and ensure risk assessments are both technically accurate and aligned with organizational goals. Staying current with evolving threat landscapes and regulatory requirements also demands continuous learning and adaptation. Leveraging industry-standard frameworks and advanced analytics tools can help address these challenges effectively.

What are the key skills and qualifications needed to thrive as a quantitative cyber risk professional, and why are they important?

To thrive as a Quantitative Cyber Risk professional, you need strong analytical skills, expertise in statistics or mathematics, and a background in cybersecurity or risk management, often supported by relevant degrees or certifications. Familiarity with risk modeling tools, programming languages like Python or R, and frameworks such as FAIR (Factor Analysis of Information Risk) is highly valued. Exceptional problem-solving, communication, and stakeholder management skills help translate complex risk data into actionable business insights. These competencies are critical for accurately assessing cyber risks, informing decision-making, and enhancing an organization's overall security posture.

What is the difference between Quantitative Cyber Risk vs Cyber Risk Analyst?

AspectQuantitative Cyber RiskCyber Risk Analyst
Required CredentialsCertifications like CRCM, CISSP, or CISA; strong quantitative backgroundCertifications such as CISA, CRISC; focus on risk assessment skills
Work EnvironmentFinancial institutions, cybersecurity firms, large corporationsFinancial services, consulting firms, government agencies
Industry UsageFocuses on modeling and quantifying cyber risks using data analysisEvaluates and reports on cyber risks, develops mitigation strategies

While both roles involve cybersecurity, Quantitative Cyber Risk specialists focus on modeling and quantifying risks using data and mathematical methods. Cyber Risk Analysts assess, analyze, and communicate cyber threats and vulnerabilities. The former is more data-driven and modeling-oriented, whereas the latter emphasizes risk evaluation and strategic recommendations.

What job categories do people searching Quantitative Cyber Risk jobs in Foster City, CA look for?

The top searched job categories for Quantitative Cyber Risk jobs in Foster City, CA are:

What cities near Foster City, CA are hiring for Quantitative Cyber Risk jobs?

Cities near Foster City, CA with the most Quantitative Cyber Risk job openings:

Senior Manager, Cybersecurity Strategy & Risk

Strava, Inc.

San Francisco, CA โ€ข On-site

$180 - $240/hr

Other

Re-posted 4 days ago


Job description

About Strava

Strava is the app for active people. With over 200 million athletes in more than 185 countries, itโ€™s more than tracking workoutsโ€”itโ€™s where people make progress together, from new habits to new personal bests. No matter your sport or how you track it, Stravaโ€™s got you covered. Find your crew, crush your goals, and make every effort count. Start your journey with Strava today.

Our mission is simple: to motivate people to live their best active lives. We believe in the power of movement to connect and drive people forward.

About This Role

Strava's Cybersecurity team protects the trust of a global community of athletes who rely on our platform every day. As the team scales its security program, we're rethinking how we assess and act on security risk: moving away from static, point-in-time risk registers and toward a living, data-driven view of where our real exposure lies.

This is a role with a 70/30 split between hands-on execution and people management, reporting directly to the CISO. You'll build this function largely from scratch, standing up a repeatable process that turns various risk signals into a single, prioritized view that executive stakeholders can act on. You'll partner closely with cross-functional stakeholders across the business.

We follow a flexible hybrid model that translates to more than half of your time on-site in our San Francisco office, three days per week.

What You'll Do
  • Own and advance Strava's security governance, strategy and risk management programs, leading a small team to help execute them

  • Build a repeatable process that turns risk signals (threat models, bugs, vulnerabilities, incidents, vendor assessments) into one prioritized risk view with defined risk acceptance thresholds and escalation paths

  • Own the AI and third-party risk management process โ€” delivering risk insights that matter, not rubber-stamping compliance

  • Establish a security steering committee with relevant stakeholders to ensure alignment on risk tolerance and prioritization

  • Establish a multi-year, actionable security strategy, roadmap and investment priorities

  • Deliver regular, executive- and board-ready risk reporting

  • Partner across Engineering, Trust & Safety, Legal, AI Enablement, and other business functions, representing security in cross-functional planning and risk reviews

  • Identify and implement opportunities to use AI and automation to improve efficiency of risk workflows

  • Continuously evolve the risk methodology as new data sources, attack patterns, and business priorities emerge

What You'll Bring to the Team
  • Bachelor's degree in Engineering, Cybersecurity or related field

  • 8-12 years of experience in security, cyber risk, technical security assurance or related technical risk roles

  • Security certifications e.g. CISSP, CISM, or other relevant certifications

  • Demonstrated success of standing up and managing security risk programs, treatment decisions and cross-functional execution end to end

  • Strong understanding of security controls and how to work with engineering on implementation details

  • Demonstrated track record translating technical security or threat findings into clear risk narratives

  • Handsโ€‘on technical fluency: you've personally read and interpreted threat models, vulnerability findings, or incident data, not just relayed summaries of them

  • Demonstrated experience using AI or automation tools to directly improve technical security or risk workflows (e.g., automating vulnerability triage, control testing, or risk scoring)

  • Experience handling ambiguity, driving accountability and working across multiple stakeholders

  • Excellent written and verbal communication skills, including ability to prepare and present risk reports to technical teams, senior leadership and board level executives

  • Experience managing and developing teams

  • Experience scaling GRC processes in a highโ€‘growth or consumer tech company is a plus

  • Thirdโ€‘party or vendor risk management experience is a plus

  • Quantitative risk methodology experience (e.g., FAIR) is a plus

Why Join Us?

Movement brings us together. At Strava, weโ€™re building the worldโ€™s largest community of active people, helping them stay motivated and achieve their goals.

Our global team is passionate about making movement fun, meaningful, and accessible to everyone. Whether youโ€™re shaping the technology, growing our community, or driving innovation, your work at Strava makes an impact.

When you join Strava, youโ€™re not just joining a companyโ€”youโ€™re joining a movement. If youโ€™re ready to bring your energy, ideas, and drive, letโ€™s build something incredible together.

Strava builds software that makes the best part of our athletesโ€™ days even better. Just as weโ€™re deeply committed to unlocking their potential, weโ€™re dedicated to providing a worldโ€‘class, inclusive workplace where our employees can grow and thrive, too. Weโ€™re backed by Sequoia Capital, TCV, Madrone Partners and Jackson Square Ventures, and weโ€™re expanding in order to exceed the needs of our growing community of global athletes. Our culture reflects our community. We are continuously striving to hire and engage teammates from all backgrounds, experiences and perspectives because we know we are a stronger team together.

Strava is an equal opportunity employer. In keeping with the values of Strava, we make all employment decisions including hiring, evaluation, termination, promotional and training opportunities, without regard to race, religion, color, sex, age, national origin, ancestry, sexual orientation, physical handicap, mental disability, medical condition, disability, gender or identity or expression, pregnancy or pregnancyโ€‘related condition, marital status, height and/or weight.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

California Consumer Protection Act Applicant Notice

#J-18808-Ljbffr