Manager, Cybersecurity, Quantitative Risk - Remote
Stryker Careers · Michigan, Kalamazoo 4100 East Milham Rd
Job description
Work Flexibility: Remote Preference will be given to candidates residing in the Eastern or Central time zones.As a Manager, Cybersecurity, Quantitative Risk, you will lead the development and application of quantitative methods that measure, model, and communicate cybersecurity risk across the enterprise. You will partner with Cyber GRC, Cyber Strategy, Security Operations, Enterprise Risk Management, Finance, and business leaders to inform investment priorities, control effectiveness, cybersecurity strategy, and executive risk reporting. What you will do: • Lead enterprise cyber risk quantification initiatives and establish a consistent, measurable view of cybersecurity risk exposure. • Translate quantitative risk insights into recommendations for executive leadership and governance forums. • Partner across security, technology, finance, audit, compliance, enterprise risk, and business functions to support risk-informed decisions. Technical Responsibilities: • Develop and maintain quantitative cyber risk assessment methodologies, risk models, and scoring approaches. • Measure and analyze cyber risk exposure across business units, products, technologies, and third-party environments. • Perform scenario-based risk analyses, loss estimation, Monte Carlo analysis, and control effectiveness evaluations. • Apply FAIR or similar methodologies to cyber risk quantification initiatives. • Develop cyber risk dashboards, key risk indicators, quantitative reporting capabilities, and executive reporting mechanisms. • Evaluate cybersecurity investments and remediation initiatives through risk reduction analyses. • Conduct emerging risk assessments and trend analyses involving cyber threats, vulnerabilities, and control environments. • Support regulatory, audit, governance, and cybersecurity strategy requirements through quantitative risk insights. Knowledge and Capabilities: • Apply cybersecurity frameworks, risk management principles, statistical modeling, and governance processes to enterprise risk analyses. • Synthesize complex quantitative information into concise communications for executive and senior leadership audiences. • Prioritize concurrent analyses, reporting needs, and deadlines while maintaining consistent risk measurement practices. What You Need: Required Qualifications • Bachelor's degree in Cybersecurity, Risk Management, Statistics, Mathematics, Data Science, Information Systems, Finance, Engineering, or a related discipline. • Minimum 8 years of professional experience in information technology or cybersecurity. • Minimum 5 years of experience in cybersecurity risk management, quantitative risk analysis, enterprise risk, data analytics, or a related discipline. • Experience conducting cyber risk assessments and control effectiveness evaluations. • Experience developing risk models, risk scoring methodologies, quantitative reporting capabilities, and using data analytics or visualization tools. Preferred Qualifications • Training in quantitative risk analysis, statistical modeling, enterprise risk management, or cybersecurity risk management. • Experience with FAIR, Monte Carlo analysis, risk modeling techniques, or similar methodologies. • CRISC, CISSP, CISM, FAIR, Financial Risk Manager (FRM), or equivalent certification. United States of America Pay Ranges:USN: $135,600 - $225,900 USD Annual US5: $142,400 - $237,200 USD Annual US10: $149,200 - $248,500 USD Annual US15: $155,900 - $259,800 USD Annual US20: $162,700 - $271,100 USD Annual US30: $176,300 - $293,700 USD Annual View the U.S. work location and transparency guide to find the pay range for your location. Travel Percentage: None Stryker Corporation is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected veteran status. Stryker is an EO employer – M/F/Veteran/Disability. Stryker Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information.
Verified and listed by ActiveJobs. Applications are made directly on Stryker Careers's own career page — we never sit in the middle.