
Manager, Cybersecurity, Quantitative Risk
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in Michigan.
• Lead initiatives for quantifying enterprise cyber risks and create a consistent, measurable understanding of cybersecurity risk exposure.
• Convert quantitative risk insights into actionable recommendations for executive leadership and governance discussions.
• Collaborate across security, technology, finance, audit, compliance, enterprise risk, and business areas to facilitate risk-informed decision-making.
• Design and uphold quantitative cyber risk assessment methodologies, risk models, and scoring frameworks.
• Evaluate and analyze cyber risk exposure across various business units, products, technologies, and third-party environments.
• Execute scenario-based risk analyses, loss estimations, Monte Carlo simulations, and assessments of control effectiveness.
• Utilize FAIR or similar methodologies for cyber risk quantification projects.
• Create cyber risk dashboards, key risk indicators, quantitative reporting capabilities, and executive reporting tools.
• Assess cybersecurity investments and remediation initiatives through analyses focused on risk reduction.
• Carry out assessments of emerging risks and trend analyses related to cyber threats, vulnerabilities, and control environments.
• Provide quantitative risk insights to support regulatory, audit, governance, and cybersecurity strategy requirements.
• Implement cybersecurity frameworks, risk management principles, statistical modeling, and governance processes in enterprise risk analyses.
• Distill complex quantitative information into clear communications tailored for executive and senior leadership audiences.
• Manage multiple analyses, reporting demands, and deadlines while ensuring consistent risk measurement practices.
• Bachelor's degree in Cybersecurity, Risk Management, Statistics, Mathematics, Data Science, Information Systems, Finance, Engineering, or a related field.
• At least 8 years of professional experience in information technology or cybersecurity.
• A minimum of 5 years of experience in cybersecurity risk management, quantitative risk analysis, enterprise risk, data analytics, or a related discipline.
• Proven experience in conducting cyber risk assessments and evaluating control effectiveness.
• Experience in developing risk models, risk scoring methodologies, and quantitative reporting capabilities, along with proficiency in data analytics or visualization tools.
• Preferred training in quantitative risk analysis, statistical modeling, enterprise risk management, or cybersecurity risk management.
• Familiarity with FAIR, Monte Carlo analysis, risk modeling techniques, or similar methodologies is preferred.
• Preferred certifications include CRISC, CISSP, CISM, FAIR, Financial Risk Manager (FRM), or equivalent.
• Flexible remote work options.
• No travel necessary (Travel Percentage: None).
• Protections for equal employment opportunities.
• Transparency in pay and protections for discussions about pay.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.