1

Cyber Risk Analyst Jobs in California (NOW HIRING)

Cyber Sys Secur Engr Sr

Palmdale, CA · On-site

$85.25 - $104.75/hr

... risk analyses and security assessments, and evaluate applicability of Security Technical ... cyber tools for enterprise security, vulnerability scanning and network monitoring - Strong ...

Senior Actuarial Analyst DRIVE PROFITABLE GROWTH FOR THE BUSINESS About At-Bay At-Bay is the world ... cyber risk head on. By combining industry-leading insurance with world-class cybersecurity ...

... analysis, decision-making, and follow-through. The role must be able to deliver work products ... What you will do**- Own cyber risk intake, triage, and prioritization, ensuring clear ...

... analysis, decision-making, and follow-through. The role must be able to deliver work products ... What you will do - Own cyber risk intake, triage, and prioritization, ensuring clear accountability ...

... analysis, decision-making, and follow-through. The role must be able to deliver work products ... What you will do**- Own cyber risk intake, triage, and prioritization, ensuring clear ...

next page

Showing results 1-20

Cyber Risk Analyst information

See California salary details

$43.9K

$106.1K

$149K

How much do cyber risk analyst jobs pay per year?

As of Jun 22, 2026, the average yearly pay for cyber risk analyst in California is $106,114.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,300.00 and $124,800.00 per year, depending on experience, location, and employer.

What does a Cyber Risk Analyst do?

A Cyber Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization's information systems and digital assets. They analyze potential threats, evaluate the effectiveness of security measures, and recommend strategies to protect against cyberattacks. Their work often includes conducting risk assessments, monitoring security controls, and ensuring compliance with industry regulations to help safeguard sensitive data and maintain business continuity.

What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?

AspectCyber Risk AnalystCyber Security Analyst
CertificationsCertified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC)CompTIA Security+, Certified Ethical Hacker (CEH)
Work EnvironmentRisk assessment, policy development, complianceNetwork monitoring, threat detection, incident response
Employer & IndustryFinancial, healthcare, government sectors focusing on risk managementIT departments, cybersecurity firms, tech companies

While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.

Can you make $500,000 a year in cyber security?

Cyber Risk Analysts typically earn salaries ranging from $70,000 to $150,000 annually, depending on experience, certifications, and location. Reaching a $500,000 annual salary generally requires senior roles such as Chief Information Security Officer (CISO) or executive-level positions, which involve broader responsibilities and leadership skills. High earnings in cybersecurity often depend on advanced expertise, industry demand, and strategic management roles.

Which country is no. 1 in cybersecurity?

As a Cyber Risk Analyst, understanding global cybersecurity leadership is important. The United States is often regarded as the leading country in cybersecurity due to its advanced infrastructure, government initiatives, and cybersecurity industry. However, other countries like Israel, the United Kingdom, and China also have strong cybersecurity capabilities and investments.

Is 40 too old for cyber security?

Cyber Risk Analysts and other cybersecurity professionals can successfully start or advance their careers at age 40 or older. Many employers value diverse experience and skills, and certifications like CISSP or CompTIA Security+ can enhance employability regardless of age.

What are the key skills and qualifications needed to thrive as a Cyber Risk Analyst, and why are they important?

To thrive as a Cyber Risk Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and often a degree in cybersecurity, computer science, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and security information and event management (SIEM) systems is typically required, along with certifications like CISSP or CISM. Analytical thinking, attention to detail, and strong communication skills are essential soft skills for this role. These competencies ensure accurate identification, evaluation, and mitigation of cyber risks to protect organizational assets and maintain regulatory compliance.

How does a Cyber Risk Analyst typically collaborate with other departments to improve an organization's security posture?

Cyber Risk Analysts work closely with various departments, such as IT, compliance, and business units, to identify and assess potential security threats. They often facilitate risk assessments, conduct training sessions to raise awareness, and help develop incident response plans. Regular communication and collaboration are essential, as analysts must ensure that security recommendations align with business goals and regulatory requirements. This cross-functional teamwork creates a more resilient security environment and helps integrate cybersecurity best practices throughout the organization.

What does a cybersecurity risk analyst do?

A cybersecurity risk analyst evaluates an organization’s information systems to identify vulnerabilities and assess potential threats. They analyze security data, develop risk mitigation strategies, and often use tools like risk assessment frameworks and security software to protect digital assets and ensure compliance.
What job categories do people searching Cyber Risk Analyst jobs in California look for? The top searched job categories for Cyber Risk Analyst jobs in California are:
Infographic showing various Cyber Risk Analyst job openings in California as of June 2026, with employment types broken down into 93% Full Time, 2% Part Time, and 5% Contract. Highlights an 86% In-person, 5% Hybrid, and 9% Remote job distribution, with an average salary of $106,114 per year, or $51 per hour.
Cyber Strategy, Risk & Compliance - AI Engineering for Cybersecurity - Manager

Cyber Strategy, Risk & Compliance - AI Engineering for Cybersecurity - Manager

Pwc

San Francisco, CA

$99K - $232K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 28 days ago


PwC rating

8.4

Company rating: 8.4 out of 10

Based on 74 frontline employees who took The Breakroom Quiz

19th of 57 rated business consultants


Job description

Industry/Sector

Not Applicable

Specialism

Cybersecurity & Privacy

Management Level

Manager

Job Description & Summary

At PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients, providing advice, and solutions. They help organisations navigate complex regulatory landscapes and enhance their internal controls to mitigate risks effectively.
In regulatory risk compliance at PwC, you will focus on confirming adherence to regulatory requirements and mitigating risks for clients. You will provide guidance on compliance strategies and help clients navigate complex regulatory landscapes.

Enhancing your leadership style, you motivate, develop and inspire others to deliver quality. You are responsible for coaching, leveraging team member's unique strengths, and managing performance to deliver on client expectations. With your growing knowledge of how business works, you play an important role in identifying opportunities that contribute to the success of our Firm. You are expected to lead with integrity and authenticity, articulating our purpose and values in a meaningful way. You embrace technology and innovation to enhance your delivery and encourage others to do the same.

Examples of the skills, knowledge, and experiences you need to lead and deliver value at this level include but are not limited to:

  • Analyse and identify the linkages and interactions between the component parts of an entire system.
  • Take ownership of projects, ensuring their successful planning, budgeting, execution, and completion.
  • Partner with team leadership to ensure collective ownership of quality, timelines, and deliverables.
  • Develop skills outside your comfort zone, and encourage others to do the same.
  • Effectively mentor others.
  • Use the review of work as an opportunity to deepen the expertise of team members.
  • Address conflicts or issues, engaging in difficult conversations with clients, team members and other stakeholders, escalating where appropriate.
  • Uphold and reinforce professional and technical standards (e.g. refer to specific PwC tax and audit guidance), the Firm's code of conduct, and independence requirements.

The Opportunity

As part of the Cyber Strategy, Risk & Compliance team, you will be at the forefront of transforming cybersecurity for our clients through innovative, AI-driven solutions. As a Manager, you will lead large projects, innovate processes, andmaintainoperational excellence while interacting with clients at a senior level to drive project success. You will design and architect AI-enabled solutions and transformations for cybersecurity organizations, helping them stay ahead of emerging threats.

Responsibilities

- Lead and manage strategy, transformation and engineering projects and teams

- Design and architect AI-enabled solutions and transformations for cybersecurity organizations and functions

- Innovate and enhance processes by integrating AI and machine learning capabilities

- Engage with clients at senior levels to drive success and provide strategic guidance

- Design and implement enterprise-wide cyber risk governance frameworks

- Develop thorough business risk scenarios and create AI-powered cyber threat models

- Provide industry-leading practices in AI-driven cyber risk management

- Architect agentic automations to scale cybersecurity capabilities

What You Must Have

- Bachelor's Degree

- At least 5 years of experience in cybersecurity and/or AI/ML engineering

What Sets You Apart

- Master's Degree in software development, AI/ML engineering, or another relevant technical field preferred

- A minimum of 2 years of Team Management experience

- A minimum of 1 year of experience in designing and implementing agentic and/or generative AI systems

- Demonstrated knowledge of AI services in AWS or GCP, especially Google Vertex AI SDK and Amazon Bedrock/AWS Boto3

- Knowledge of Python and leading AI frameworks (e.g., LangChain)

- Professional certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CRISC (Certified in Risk and Information Systems Control), Google AI Professional Certificate, AWS Certified AI Practitioner, Solution Architect-type certificates from AWS and/or Google, AWS Certified Security - Specialty, AWS Certified Generative AI Developer - Professional, AWS Security Engineer

- Experience in designing and implementing enterprise-wide cyber risk management controls

- Technology sales enablement experience, especially cybersecurity solutions

Travel Requirements

Up to 60%

Job Posting End Date

The salary range for this position is: $99,000 - $232,000. Actual compensation within the range will be dependent upon the individual's skills, experience, qualifications and location, and applicable employment laws. All hired individuals are eligible for an annual discretionary bonus. PwC offers a wide range of benefits, including medical, dental, vision, 401k, holiday pay, vacation, personal and family sick leave, and more. To view our benefits at a glance, please visit the following link: https://pwc.to/benefits-at-a-glanceAs PwC is anequal opportunity employer, all qualified applicants will receive consideration for employment at PwC without regard to race; color; religion; national origin; sex (including pregnancy, sexual orientation, and gender identity); age; disability; genetic information (including family medical history); veteran, marital, or citizenship status; or, any other status protected by law.PwC does not intend to hire experienced or entry level job seekers who will need, now or in the future, PwC sponsorship through the H-1B lottery, except as set forth within the following policy: https://pwc.to/H-1B-Lottery-Policy.Learn more about how we work: https://pwc.to/how-we-workFor only those qualified applicants that are impacted by the Los Angeles County Fair Chance Ordinance for Employers, the Los Angeles' Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, San Diego County Fair Chance Ordinance, and the California Fair Chance Act, where applicable, arrest or conviction records will be considered for Employment in accordance with these laws. At PwC, we recognize that conviction records may have a direct, adverse, and negative relationship to responsibilities such as accessing sensitive company or customer information, handling proprietary assets, or collaborating closely with team members. We evaluate these factors thoughtfully to establish a secure and trusted workplace for all.

What PwC employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom