1

Cyber Risk Analyst Jobs in California (NOW HIRING)

Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic ... the triage, analysis, investigation, and remediation of insider risk-related inquiries Leading ...

Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic ... the triage, analysis, investigation, and remediation of insider risk-related inquiries Leading ...

Agentic Risk Analyst

San Francisco, CA · On-site

$288K - $425K/yr

About the Role As an Agentic Risk Analyst, you will shape OpenAI's operating picture for current ... Have significant experience-typically 7+ years-in trust and safety, integrity, security, cyber ...

next page

Showing results 1-20

Cyber Risk Analyst information

See California salary details

$43.9K

$106.1K

$149K

How much do cyber risk analyst jobs pay per year?

As of Aug 3, 2026, the average yearly pay for cyber risk analyst in California is $106,114.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,300.00 and $124,800.00 per year, depending on experience, location, and employer.

What does a cyber risk analyst do?

A cyber risk analyst evaluates an organization's cybersecurity threats and vulnerabilities to identify potential risks. They analyze security data, develop risk mitigation strategies, and often use tools like risk assessment frameworks and security information and event management (SIEM) systems to protect digital assets.

What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?

AspectCyber Risk AnalystCyber Security Analyst
CertificationsCertified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC)CompTIA Security+, Certified Ethical Hacker (CEH)
Work EnvironmentRisk assessment, policy development, complianceNetwork monitoring, threat detection, incident response
Employer & IndustryFinancial, healthcare, government sectors focusing on risk managementIT departments, cybersecurity firms, tech companies

While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.

Can you make $500,000 a year in cyber security?

Cyber Risk Analysts typically earn between $70,000 and $150,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires senior roles such as Chief Information Security Officer or specialized consulting positions, often combined with extensive experience and advanced skills in areas like threat management and security architecture.

Is 30 too late for cyber security?

Cyber Risk Analysts and other cybersecurity professionals can enter the field at any age, including 30 or older. Success often depends on acquiring relevant skills, certifications, and experience, which can be achieved through training programs, self-study, or prior related work experience.

Can you make $200,000 in cyber security?

Cyber Risk Analysts and other cybersecurity professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP, and in senior or specialized roles. Salaries vary based on industry, location, and level of expertise, with high-demand areas offering higher compensation.

What are the key skills and qualifications needed to thrive as a Cyber Risk Analyst, and why are they important?

To thrive as a Cyber Risk Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and often a degree in cybersecurity, computer science, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and security information and event management (SIEM) systems is typically required, along with certifications like CISSP or CISM. Analytical thinking, attention to detail, and strong communication skills are essential soft skills for this role. These competencies ensure accurate identification, evaluation, and mitigation of cyber risks to protect organizational assets and maintain regulatory compliance.

How does a Cyber Risk Analyst typically collaborate with other departments to improve an organization's security posture?

Cyber Risk Analysts work closely with various departments, such as IT, compliance, and business units, to identify and assess potential security threats. They often facilitate risk assessments, conduct training sessions to raise awareness, and help develop incident response plans. Regular communication and collaboration are essential, as analysts must ensure that security recommendations align with business goals and regulatory requirements. This cross-functional teamwork creates a more resilient security environment and helps integrate cybersecurity best practices throughout the organization.
What are popular job titles related to Cyber Risk Analyst jobs in California? For Cyber Risk Analyst jobs in California, the most frequently searched job titles are:
What job categories do people searching Cyber Risk Analyst jobs in California look for? The top searched job categories for Cyber Risk Analyst jobs in California are:
Infographic showing various Cyber Risk Analyst job openings in California as of July 2026, with employment types broken down into 78% Full Time, and 22% Contract. Highlights an 74% In-person, 17% Hybrid, and 9% Remote job distribution, with an average salary of $106,114 per year, or $51 per hour.

Other

Posted 15 days ago


University Of California rating

8.5

Company rating: 8.5 out of 10

Based on 34 frontline employees who took The Breakroom Quiz

80th of 614 rated colleges and universities


Job description

Apply for Job
Job ID
86945
Location
Oakland
Full/Part Time
Full Time
Add to Favorite Jobs
Email this Job
Job Posting

For UCOP internal applicants, please login to the internal candidate gateway at: Jobs at UCOP

UC OFFICE OF THE PRESIDENT

At the University of California (UC), your contributions make a difference. A world leader producing Nobel and Pulitzer Prize recipients with over 150 years of groundbreaking research transforming the world. Choose a career where you can leverage your knowledge, skills and aspirations to inspire and support some of the greatest minds in the world, and those who will follow in their footsteps. Working at the University of California is being part of a unique institution, and a vibrant and diverse community. At the University of California, Office of the President, we propel our mission through impactful work locally, in government centers and systemwide. We are passionate people, serving the greater good.

The University of California, one of the largest and most acclaimed institutions of higher learning in the world, is dedicated to excellence in teaching, research and public service. The University of California Office of the President is the headquarters to the 10 campuses, six academic medical centers and three national laboratories and enrolls premier students from California, the nation and the world. Learn more about the UC Office of the President

Department Overview
UC Digital Risk & Security (DRS) provides systemwide coordination, planning, and operational support primarily to technology and security teams, but indirectly to all students, faculty, patients and staff within the UC system. The team's cyber security services address timely and pervasive issues such as identity theft, data security breaches, data leakage, and system outages across organizations of various sizes, with the goal of enabling ongoing, secure, and reliable operations across the enterprise.
Position Summary
The University of California, Office of the President (UCOP) is seeking a collaborative Senior Risk Assessment Analyst to coordinate and maintain a systemwide cybersecurity risk methodology supporting the University of California's 10 higher education campuses and 6 medical centers. The methodology offers a consistent, scalable, cybersecurity risk assessment process across UC IT departments aligned to the UC information security policy and industry best practices. This role will maintain common standards, templates, and reporting practices; administer associated software platforms and tools; and provide guidance and support to local risk assessment teams to help align their efforts with systemwide standards. This individual contributor role reports to the systemwide Cyber Risk Unit Manager and works with cybersecurity leadership, IT risk and compliance teams, and auditors to provide subject matter expertise and support risk-informed decision making. They will also periodically gather assessment results, compile systemwide risk data and present executive level reports to UC leadership. The successful candidate will draw on previous experience managing enterprise cyber risk assessments. They will possess a deep understanding of common cybersecurity frameworks, including but not limited to NIST 800-53, NIST 800-171, NIST Cyber Security Framework (CSF), ISO/IEC 27001, PCI-DSS, and HIPAA. Strong communication, analytical, and presentation skills and comfort with explaining technical compliance concepts to non-technical audiences is preferred. This is an exciting opportunity to help improve the UC's cyber risk capabilities and make an immediate impact across the entire system.
Key Responsibilities

35% Communication & collaboration: Acts as primary contact from UCOP to locations regarding the risk assessment methodology. Presents written and verbal presentations regarding systemwide processes and program details. Provides guidance to locations regarding the application of the cyber risk methodology. Partners with location stakeholders to gather feedback and ensure that assessments meet the needs of UC with a high level of quality. Collects and shares best practices across locations. Coordinates with location cyber risk specialists to ensure assessments are consistent with systemwide standards and leadership expectations. Delivers aggregated assessment results and risk analysis to leadership.

30% Program planning & development: Develops and maintains relevant documentation including templates, framework mappings, risk management guidelines, control evaluation standards and training guides. Maintains internal resource center and distributes information to stakeholders. As applicable, provides support for administering governance, risk and compliance (GRC) assessment software platforms.

25% Risk management & analysis: Compiles and analyzes aggregated cyber risk assessment data. Develops executive dashboards, metrics and reports for a variety of audiences, including cybersecurity leadership, audit stakeholders and information security governance committees.

10% Change management: Monitors industry updates and developments for changes to compliance frameworks that may impact UC risk management processes, recommending updates as needed.


Experience
Required Qualifications

  • Min 8 years of relevant past work experience.


Skills and Abilities
Required Qualifications

  • Knowledge of regulatory compliance frameworks including NIST 800-53, NIST 800-171, NIST CSF, ISO27001, SOC 1 / 2, HIPAA, PCI-DSS.

  • Demonstrated experience with overseeing enterprise-level cyber security risk assessments, maturity assessments, and audits.

  • Familiarity with one or more GRC platforms and tools (ServiceNow, Archer, etc.)

  • Strong understanding of cyber risk management, including risk identification, analysis, prioritization and remediation.

  • Experience with developing aggregated cyber risk metrics and reports.

  • Highly developed interpersonal communication skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.

  • Strong written communication skills and experience with developing process documentation.

  • Experience with presenting to senior leadership.

  • Strong project management and organizational skills.

  • Demonstrated ability to operate with a high degree of autonomy.


Education
Required Qualifications

  • Bachelor's degree in related area and / or equivalent experience / training


Licenses and Certifications
Preferred Qualifications

  • Security Certifications (CISSP, CISA, CISM, CRISC, CGRC, Security+)


Job Code
006365
Salary Grade
STEPS
Payscale:
$160,000 - $184,000
The University of California, Office of the President, is required to provide a reasonable estimate of the compensation range for this role. This range takes into account the wide range of factors that are considered in making compensation decisions including but not limited to experience, skills, knowledge, abilities, education, licensure and certifications, and other business and organizational needs. It is not typical for an individual to be offered a salary at or near the top of the range for a position. Salary offers are determined based on final candidate qualifications and experience. The full salary range shows the growth potential for this position and the pay scale is the budgeted salary or hourly range that the University reasonably expects to pay for this position.

Benefits: For information on the comprehensive benefits package offered by the University visit: Benefits of Belonging

ADDITIONAL INFORMATION

This position is represented by the University Professional and Technical Employees (UPTE)

Not eligible for Visa sponsorship or transfer.

This position is eligible for a remote work arrangement within the state of California. The selected candidate must reside within the state of California or be willing to relocate to CA within a reasonable timeframe.

HOW TO APPLY

Please be prepared to attach a cover letter and resume with your application.

APPLICATION REVIEW DATE

The first review date for this job is (8/7/2026). The position will be open until filled.

CONDITIONS OF EMPLOYMENT

Background Check Process: Successful completion of a background check is required for this critical position. Background check process at UCOP

Smoke Free Work Environment: The University of California, Office of the President, is smoke & tobacco-free as of January 1, 2014. UC Smoke & Tobacco Free Policy

As a condition of employment, you will be required to comply with the University of California Policy on Vaccination Programs, as may be amended or revised from time to time. Federal, state, or local public health directives may impose additional requirements.

As a condition of employment, the finalist will be required to disclose if they are subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct, are currently being investigated for misconduct, left a position during an investigation for alleged misconduct, or have filed an appeal with a previous employer.

  • "Misconduct" means any violation of the policies or laws governing conduct at the applicant's previous place of employment, including, but not limited to, violations of policies or laws prohibiting sexual harassment, sexual assault, or other forms of harassment, discrimination, dishonesty, or unethical conduct, as defined by the employer.
    • UC Sexual Violence and Sexual Harassment Policy
    • UC Anti-Discrimination Policy for Employees, Students and Third Parties
    • APM - 035: Affirmative Action and Nondiscrimination in Employment

EEO STATEMENT

The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.

The University of California, Office of the President, strives to make this job board accessible to any and all users. If you have comments regarding the accessibility of our website or need assistance completing the application process, please contact us at: Accessibility or email the Human Resource Department at: epost@ucop.edu.


What University Of California employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom