1

Quantitative Cyber Risk Jobs (NOW HIRING)

Experience performing cyber risk analysis, risk quantification, or security measurement. * Expertise in one or more quantitative disciplines such as statistics, mathematics, econometrics, operations ...

The Insider Risk team, in partnership with the Information Security Data Operations team, is ... The role partners closely with Cyber, HR, Legal, Compliance, Anti‐Fraud, and Enterprise ...

Cyber Data Scientist

$130K - $140K/yr

... risk management solutions. Hunter Strategy was founded on the premise that IT is 21st century ... quantitative summaries for technical and non-technical audiences. • Explore and adopt new ...

Cyber Security Strategy Lead

Charlotte, NC

$108K - $146K/yr

Our Cyber Risk and Data Protection team serves the cybersecurity and data protection related needs ... Demonstrated ability to perform quantitative and qualitative analysis of security data * Basic ...

Cyber Security Strategy Lead

Charlotte, NC · On-site

$108K - $146K/yr

Our Cyber Risk and Data Protection team serves the cybersecurity and data protection related needs ... Demonstrated ability to perform quantitative and qualitative analysis of security data * Basic ...

The ideal candidate will possess strong analytical and quantitative skills with experience ... Develop cost-benefit analysis, risk analysis, simulation model execution, operational effectiveness ...

The selected candidate will provide quantitative analysis, modeling, and decision-support ... Conduct cost-benefit, risk, and economic analysis to support mission effectiveness * Develop and ...

ITSO Sr. Program Manager

Durham, NC · On-site

$112K - $112K/yr

This role focuses on quantifying, contextualizing, and managing cyber risk across Duke University ... quantitative and qualitative analysis supporting data-driven decisions. Other Requirements • ...

ITSO Sr. Program Manager

Durham, NC

$112K - $112K/yr

This role focuses on quantifying, contextualizing, and managing cyber risk across Duke University ... Proficiency with quantitative and qualitative analysis supporting datadriven decisions. Other ...

next page

Showing results 1-20

Quantitative Cyber Risk information

See salary details

$98K

$169.7K

$259.5K

How much do quantitative cyber risk jobs pay per year?

As of Jun 26, 2026, the average yearly pay for quantitative cyber risk in the United States is $169,729.00, according to ZipRecruiter salary data. Most workers in this role earn between $134,500.00 and $199,000.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in Quantitative Cyber Risk roles and how can they be addressed?

Professionals in Quantitative Cyber Risk roles often encounter challenges such as translating complex cyber threats into measurable financial terms and obtaining reliable data for risk modeling. Collaborating closely with IT security teams and business stakeholders is essential to bridge gaps in understanding and ensure risk assessments are both technically accurate and aligned with organizational goals. Staying current with evolving threat landscapes and regulatory requirements also demands continuous learning and adaptation. Leveraging industry-standard frameworks and advanced analytics tools can help address these challenges effectively.

What is quantitative cyber risk?

Quantitative cyber risk involves using mathematical models and statistical techniques to measure and predict the financial impact of cyber threats on an organization. Unlike qualitative approaches that rely on subjective judgments, quantitative methods assign numerical values to risks, helping companies understand potential losses in dollar terms. This allows organizations to make more informed decisions about cybersecurity investments, insurance, and risk mitigation strategies.

What is quantitative risk in cyber security?

Quantitative cyber risk involves measuring and analyzing cybersecurity threats using numerical data, such as probabilities and potential financial impacts. Cybersecurity professionals use models and tools like risk assessment frameworks to quantify vulnerabilities and prioritize mitigation efforts based on measurable risk levels.

Is quantitative risk management in demand?

Quantitative cyber risk management is in high demand due to increasing cyber threats and the need for data-driven security strategies. Professionals in this field often utilize statistical models, risk assessment tools, and certifications like CRCM to address complex cybersecurity challenges across various industries.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role can be entry level, especially for positions labeled as SOC analyst I or junior SOC analyst. However, many SOC roles require some prior knowledge of cybersecurity concepts, security tools, and incident response, often necessitating relevant certifications like CompTIA Security+ or SANS certifications. Experience and technical skills can influence whether a SOC position is suitable for entry-level candidates.

What career in cybersecurity pays $500,000?

A senior Quantitative Cyber Risk analyst or risk management executive in cybersecurity can earn $500,000 or more annually, especially with extensive experience, advanced certifications, and leadership roles. High-level positions in financial institutions or large corporations often offer such compensation, which may include bonuses and stock options.

What is the difference between Quantitative Cyber Risk vs Cyber Risk Analyst?

AspectQuantitative Cyber RiskCyber Risk Analyst
Required CredentialsCertifications like CRCM, CISSP, or CISA; strong quantitative backgroundCertifications such as CISA, CRISC; focus on risk assessment skills
Work EnvironmentFinancial institutions, cybersecurity firms, large corporationsFinancial services, consulting firms, government agencies
Industry UsageFocuses on modeling and quantifying cyber risks using data analysisEvaluates and reports on cyber risks, develops mitigation strategies

While both roles involve cybersecurity, Quantitative Cyber Risk specialists focus on modeling and quantifying risks using data and mathematical methods. Cyber Risk Analysts assess, analyze, and communicate cyber threats and vulnerabilities. The former is more data-driven and modeling-oriented, whereas the latter emphasizes risk evaluation and strategic recommendations.

What are the key skills and qualifications needed to thrive as a Quantitative Cyber Risk professional, and why are they important?

To thrive as a Quantitative Cyber Risk professional, you need strong analytical skills, expertise in statistics or mathematics, and a background in cybersecurity or risk management, often supported by relevant degrees or certifications. Familiarity with risk modeling tools, programming languages like Python or R, and frameworks such as FAIR (Factor Analysis of Information Risk) is highly valued. Exceptional problem-solving, communication, and stakeholder management skills help translate complex risk data into actionable business insights. These competencies are critical for accurately assessing cyber risks, informing decision-making, and enhancing an organization's overall security posture.
More about Quantitative Cyber Risk jobs
What cities are hiring for Quantitative Cyber Risk jobs? Cities with the most Quantitative Cyber Risk job openings:
What states have the most Quantitative Cyber Risk jobs? States with the most job openings for Quantitative Cyber Risk jobs include:
What job categories do people searching Quantitative Cyber Risk jobs look for? The top searched job categories for Quantitative Cyber Risk jobs are:
Infographic showing various Quantitative Cyber Risk job openings in the United States as of June 2026, with employment types broken down into 87% Full Time, and 13% Contract. Highlights an 100% In-person job distribution, with an average salary of $169,729 per year, or $81.6 per hour.

Senior Cybersecurity Engineer

Cmu

Pittsburgh, PA

Full-time

Posted 3 days ago


Job description

Cybersecurity Risk Engineersat the SEI use advanced skills in statistics, mathematics, risk analysis, systems engineering, economics and other technical fields in an interdisciplinary manner to help our government and industry mission partners to identify, research, and solve cyber security challenges. In this role, you will work with our mission partners to identify areas where advanced quantitative & technical skills can help tackle problems, plan and develop prototype solutions, and create final products designed to better manage risk. You'll work with cyber security professionals and university collaborators to build new technologies that will influence national cyber security strategies for decades to come. You will build and evaluate models, create products, conduct applied research, present findings to stakeholders, and develop transition plans for solutions to our partners.

Our team works on a wide range of projects. Our current research focus includes experimental designs for measuring cyber risk, researching methodologies for improvement of risk-based decision making, and building and evaluating models to identify security vulnerabilities. Additionally, we work on developing and conducting organizational security assessments, evaluating risk management programs, threat modeling, economics of cybersecurity and measurement. If you are an experienced researcher with an interest in risk management and cybersecurity, we want to hear from you!

As a Senior Cyber Risk Engineer, you will work directly with government, industry, and academic partners to identify, analyze, and solve complex cybersecurity risk management challenges. You will apply expertise in statistics, mathematics, risk analysis, systems engineering, and data science to develop innovative approaches for measuring, modeling, and managing cyber risk. Your work will help shape cybersecurity strategies, influence risk-based decision making, and improve the resilience of mission-critical systems and services.

Knowledge, Skills, and Abilities:

Candidates should have experience or knowledge in several of the following:

  • Understanding of risk management principles and their application to cybersecurity.
  • Experience performing cyber risk analysis, risk quantification, or security measurement.
  • Expertise in one or more quantitative disciplines such as statistics, mathematics, econometrics, operations research, systems engineering, data science, or machine learning.
  • Experience developing and applying statistical models, predictive analytics, or simulation techniques.
  • Experience with uncertainty quantification, probabilistic analysis, or decision science methodologies.
  • Experience conducting threat modeling, vulnerability analysis, or security assessments.
  • Knowledge of cybersecurity risk management frameworks and methodologies.
  • Experience evaluating organizational cybersecurity programs and risk management practices.
  • Ability to design and conduct applied research in cybersecurity, risk management, or related fields.
  • Experience developing analytical tools, models, or decision-support capabilities.
  • Ability to collaborate effectively within multidisciplinary teams of researchers, engineers, and cybersecurity professionals.
  • Strong analytical, problem-solving, and critical-thinking skills.
  • Ability to communicate complex technical concepts and analytical findings to both technical and non-technical audiences.
  • Ability to work collaboratively, diplomatically, and effectively with customers, colleagues, researchers, and senior stakeholders.

Requirements:

  • Education and Experience: BS degree in Computer Science, Statistics, Engineering, Mathematics, Economics, Data Science, or a related highly quantitative discipline with ten (10) years of applicable experience; or a MS degree in a relevant discipline with eight (8) years of applicable experience; or a PhD in a relevant discipline with five (5) years of applicable experience.
  • Technical Excellence: You have a track record of applying advanced analytical methods to solve complex cybersecurity challenges and delivering impactful technical outcomes. You possess expertise in one or more areas including cybersecurity risk management, risk quantification, statistics, econometrics, systems engineering, machine learning, modeling and simulation, or data science. You are focused on developing practical solutions that improve risk-based decision making for mission partners.
  • Leadership: You have the ability to lead multidisciplinary teams in analyzing and solving real-world cybersecurity and risk management problems. You can guide research efforts, develop analytical frameworks, and influence technical direction while collaborating with researchers, engineers, government stakeholders, and external partners. Your leadership extends beyond formal reporting relationships through technical influence and collaboration.
  • Working in a Creative, Dynamic Environment: You have experience contributing to multiple simultaneous projects and thrive in a fast-paced research environment. You are willing to experiment with innovative analytical techniques, explore emerging technologies, and develop new methodologies that advance cybersecurity risk management and measurement.
  • Mentorship: You enjoy mentoring and motivating team members. You contribute to the development of technical talent through knowledge sharing, collaboration, and professional guidance.
  • Communication: You have outstanding communication skills and can interact collaboratively and diplomatically with customers, mission partners, researchers, and colleagues at all levels. You understand both strategic objectives and technical details and can communicate complex analytical findings to audiences with varying levels of technical expertise.
  • Travel: Periodic travel to customer sites, conferences, workshops, and stakeholder meetings is required to support the SEI's mission and research activities.
  • Security Clearance: You will be subject to a background investigation and must have the ability to obtain and maintain a Department of War security clearance.
  • Applicants for this position must be currently legally authorized to work for CMU in the United States. CMU will not sponsor or take over sponsorship of an employment visa for this opportunity.

Desired Experience:

  • Experience in cyber risk quantification and measurement.
  • Experience in econometrics, applied statistics, or quantitative risk analysis.
  • Experience in uncertainty quantification and probabilistic modeling.
  • Experience in machine learning, data science, or advanced analytics.
  • Experience in modeling and simulation.
  • Experience conducting threat modeling and vulnerability analysis.
  • Experience evaluating organizational cybersecurity and risk management programs.
  • Experience supporting test and evaluation activities for large-scale government research programs.
  • Demonstrated ability to learn new concepts and grow into emerging technical areas.
  • Strong technical writing, editing, and presentation skills.
  • Experience working with government agencies, defense organizations, federally funded research centers, or academic institutions is a plus.

Location

Arlington, VA, Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff - Regular

Full time/Part time

Full time

Pay Basis

SalaryMore Information:
  • Please visit "Why Carnegie Mellon" to learn more about becoming part of an institution inspiring innovations that change the world.

  • Click here to view a listing of employee benefits

  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.

  • Statement of Assurance


About CMU

Sourced by ZipRecruiter

Industry

Offices of mental health practitioners

Company size

201 - 500 Employees

Headquarters location

Harrisburg, PA, US