1

Contract Vulnerability Scanning Jobs in Riverside, CA

VP, Information Security and Compliance

Irvine, CA · On-site

$135K - $181K/yr

Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence ... Risk & Contract Negotiation: Demonstrated success negotiating security exhibits, data processing ...

Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence ... Risk & Contract Negotiation: Demonstrated success negotiating security exhibits, data processing ...

VP, Information Security and Compliance

Santa Ana, CA · On-site

$131K - $175K/yr

Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence ... Risk & Contract Negotiation: Demonstrated success negotiating security exhibits, data processing ...

New

VP, Information Security and Compliance

Anaheim, CA · On-site

$131K - $176K/yr

Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence ... Risk & Contract Negotiation: Demonstrated success negotiating security exhibits, data processing ...

New

VP, Information Security and Compliance

Santa Ana, CA · On-site

$131K - $175K/yr

Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence ... Risk & Contract Negotiation: Demonstrated success negotiating security exhibits, data processing ...

New

VP, Information Security and Compliance

Anaheim, CA · On-site

$131K - $176K/yr

Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence ... Risk & Contract Negotiation: Demonstrated success negotiating security exhibits, data processing ...

New

Contract Vulnerability Scanning information

See Riverside, CA salary details

$13

$17

$23

How much do contract vulnerability scanning jobs pay per hour?

As of Aug 27, 2026, the average hourly pay for contract vulnerability scanning in Riverside, CA is $18.00, according to ZipRecruiter salary data. Most workers in this role earn between $16.06 and $19.33 per hour, depending on experience, location, and employer.

What is contract vulnerability scanning?

Contract vulnerability scanning refers to the process of hiring third-party professionals or firms to assess and identify security weaknesses in an organization's systems, networks, or applications. The scanning is typically performed on a contractual basis, often as part of compliance requirements or routine security practices. These experts use automated tools and manual techniques to detect vulnerabilities that could be exploited by attackers, providing detailed reports and recommendations for remediation. This approach allows organizations to benefit from specialized expertise without maintaining a full-time, in-house vulnerability scanning team.

What are some common challenges faced by professionals in contract vulnerability scanning roles?

Professionals in Contract Vulnerability Scanning often encounter challenges such as managing tight deadlines, adapting to varied client environments, and ensuring clear communication of technical findings to non-technical stakeholders. They must stay updated with the latest vulnerabilities and scanning tools, as threats and technologies evolve rapidly. Additionally, balancing thoroughness with efficiency is crucial, as clients expect comprehensive reports without significant delays. Collaboration with IT, security, and management teams is also key to ensure that identified vulnerabilities are properly addressed.

What are the key skills and qualifications needed to thrive as a contract vulnerability scanning specialist, and why are they important?

To thrive as a Contract Vulnerability Scanning Specialist, you need expertise in network security, vulnerability assessment methodologies, and a solid understanding of operating systems and protocols, often supported by certifications like CompTIA Security+ or CEH. Proficiency with vulnerability scanning tools such as Nessus, OpenVAS, or Qualys, and familiarity with ticketing and reporting systems are typically required. Attention to detail, analytical thinking, and clear communication are essential soft skills for identifying risks and conveying findings to non-technical stakeholders. These capabilities ensure the accurate detection of security weaknesses and effective risk mitigation for clients or organizations.

What is the difference between Contract Vulnerability Scanning vs Penetration Tester?

AspectContract Vulnerability ScanningPenetration Tester
Primary FocusAutomated identification of security vulnerabilities in systemsManual and automated testing to exploit vulnerabilities and assess security
Tools & TechniquesVulnerability scanners, automated toolsCustom scripts, penetration tools, manual testing
Work EnvironmentTypically performed remotely or on client sites, within security teamsOften on-site, conducting simulated attacks
CertificationsCompTIA Security+, CISSP, CEHOSCP, CEH, GPEN

Contract Vulnerability Scanning involves automated tools to identify security weaknesses, while Penetration Testers perform manual and automated testing to exploit vulnerabilities. Both roles require security certifications but differ in approach and scope, with vulnerability scanning being more automated and penetration testing more hands-on.

What are the most commonly searched types of Vulnerability Scanning jobs in Riverside, CA?

The most popular types of Vulnerability Scanning jobs in Riverside, CA are:

What are popular job titles related to Contract Vulnerability Scanning jobs in Riverside, CA?

For Contract Vulnerability Scanning jobs in Riverside, CA, the most frequently searched job titles are:

What cities near Riverside, CA are hiring for Contract Vulnerability Scanning jobs?

Cities near Riverside, CA with the most Contract Vulnerability Scanning job openings:

Infographic showing various Contract Vulnerability Scanning job openings in Riverside, CA as of June 2026, with employment types broken down into 71% Full Time, 27% Part Time, 1% Temporary, and 1% Contract. Highlights an 82% Physical, 3% Hybrid, and 15% Remote job distribution, with an average salary of $37,432 per year, or $18 per hour.

VP, Information Security and Compliance

Irvine, CA • On-site

Veritone
Software Development • 501 - 1,000 employees

$135K - $181K/yr

Full-time

Medical, Life, Retirement, PTO

Posted 23 days ago


Job description

POSITION SUMMARY
The VP, Information Security & Compliance, will serve as the Company's Chief Information Security Officer and executive champion for our global enterprise security and compliance programs. Reporting directly to the Chief Legal Officer, this role will design, execute and mature an overarching security strategy that protects customer data, intellectual property and infrastructure across all of Veritone's business units, including, but not limited to commercial SaaS and high stringency public sector (federal, state and defense) environments.
The role requires a rare blend of strategic vision, commercial SaaS agility, public sector governance (e.g., FedRAMP, NIST, DoD), and public company risk management capabilities (e.g., SOX, SEC disclosure requirements).
WHAT YOU'LL DO
Strategic Leadership & Governance
  • Security Vision & Roadmap: Architect and execute a multi-year, enterprise wide information security and compliance strategy aligned with commercial growth targets and public sector expansion goals.
  • Executive Presence: Serve as the primary security advisor to the Board of Directors, Executive Leadership Team and entire organization. Clearly translate complex security risks into actionable business terms.
  • Team Leadership: Build, mentor and lead a high performing global security team and compliance organization across security operations, engineering, risk management and regulatory compliance
  • Security Culture: Foster a company-wide security first culture through continuous training, awareness programs and cross-functional advocacy

Compliance
  • FedRAMP & Defense Authorizations: Lead the strategy, deployment and continuous monitoring required to achieve and maintain FedRAMP (moderate/high), StateRAMP, DoD/CMMC, and CJIS authorizations in cloud environments (AWS GovCloud/Azure Government)
  • Commercial Frameworks: Oversee compliance and auditing for SOC 2 Type II, ISO 27001, PCI-DSS and global privacy standards (GDPR, CCPA/CPRA)
  • Public Company Compliance: Partner with legal, finance and internal audit teams to maintain robust IT general controls (ITGCs) for SOX compliance and support SEC cybersecurity disclosure requirements

Security Operations, Architecture & Incident Response
  • Cloud & Product Architecture: Partner with Enterprise Architecture, Infrastructure, and Engineering teams to embed security controls into multi-tenant SaaS platforms, CI/CD pipelines, and cloud environments.
  • Threat & Vulnerability Management: Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence operations to proactively address emerging vector threats.
  • Incident Management: Oversee breach investigations, threat response protocols, and tabletop exercises, ensuring rapid containment, notification, and mitigation when incidents arise.

Enterprise Risk Management & Operations
  • Third-Party & Vendor Risk: Establish and enforce third-party risk management (TPRM) programs to audit and secure vendor ecosystems, software supply chains, and external partners.
  • M&A Due Diligence: Lead security and compliance due diligence for mergers and acquisitions, driving post-acquisition security integration strategies.
  • Business Continuity & Resilience: Construct policies and operational frameworks for Business Continuity Planning (BCP), Disaster Recovery (DR), loss prevention, and fraud prevention.

WHAT YOU'LL NEED
  • Education: Bachelor of Science degree in Computer Science, Cybersecurity, Computer Engineering, Information Technology, or equivalent technical discipline.
  • Executive Experience: 10+ years of progressive leadership experience in information security, cloud architecture, and compliance within a global, publicly traded cloud/SaaS technology company.
  • Proven FedRAMP Track Record: Hands-on experience leading a cloud solution through the FedRAMP authorization lifecycle (PMO/JAB or Agency route) and continuous monitoring in AWS and/or Azure cloud environments.
  • Dual-Domain Capability: Equal fluency in scaling commercial enterprise SaaS security and navigating rigid public sector regulatory landscapes (NIST 800-53, NIST 800-171, CMMC, CJIS, FISMA).
  • Executive Presence & Communication: Exceptional ability to communicate security concepts to technical engineers, enterprise buyers, regulatory auditors, and Board members alike.
  • Risk & Contract Negotiation: Demonstrated success negotiating security exhibits, data processing agreements (DPAs), and risk terms with enterprise clients and vendors.

BONUS POINTS IF YOU HAVE...
  • Advanced Degree: Master's degree (M.S. in Cybersecurity/Computer Science or MBA).
  • Industry Certifications: Active professional certifications such as CISSP, CISM, CRISC, CISA, or CCSP.
  • Security Clearance: Active or clearable U.S. Government Security Clearance (DoD Secret or Top Secret preferred).
  • AI/ML Security: Knowledge of security, privacy, and governance frameworks surrounding Artificial Intelligence and Machine Learning workloads.

DISCLOSURE
Our company provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics.
(Colorado & California Only*): The Annual salary listed for the position is a range of $200,000-$250,000. This base pay is for illustrative purposes only and will be determined based on skills and experience comparable to the job requirements. This position may be eligible for additional compensation and benefits including but not limited to: incentive compensation; health benefits; retirement benefits; life insurance; paid time off; parental leave and benefits; and other employee perks and benefits.
*Note: Disclosure as required by sb19-085 (8-5-20) of the minimum salary compensation for this role when being hired in Colorado & California.