Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Engineer III - Cybersecurity Risk Analyst
Rancho Cucamonga, CA · Hybrid
$135K/yr
The purpose of this position is to provide highly skilled technical and cyber expertise for ... Analyze risk associated with technology stack and supply chain and work with business leaders to ...
Engineer III - Cybersecurity Risk Analyst
Rancho Cucamonga, CA · Hybrid
$135K/yr
The purpose of this position is to provide highly skilled technical and cyber expertise for ... Analyze risk associated with technology stack and supply chain and work with business leaders to ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk * Preparing client-facing analyses, dashboards, and status updates to track remediation progress ...
Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an opportunity to ... In this role, you'll closely impact Navy missions by championing cybersecurity, discovering cyber ...
Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an opportunity to ... In this role, you'll closely impact Navy missions by championing cybersecurity, discovering cyber ...
Engineer III - Cybersecurity Risk Analyst
Rancho Cucamonga, CA · On-site
$110 - $150/hr
The Cybersecurity Risk Analyst is a cybersecurity program and control assessor and advisor in ... The purpose of this position is to provide highly skilled technical and cyber expertise for ...
Engineer III - Cybersecurity Risk Analyst
Rancho Cucamonga, CA · On-site
$110 - $150/hr
The Cybersecurity Risk Analyst is a cybersecurity program and control assessor and advisor in ... The purpose of this position is to provide highly skilled technical and cyber expertise for ...
Claims Counsel
Pleasanton, CA · On-site
$165K/yr
Championing adaptive insurance, Cowbell follows policyholders' cyber risk exposures as they evolve ... Perform tasks such as coverage analysis and letter writing; investigation; incident response ...
Claims Counsel
Pleasanton, CA · On-site
$165K/yr
Championing adaptive insurance, Cowbell follows policyholders' cyber risk exposures as they evolve ... Perform tasks such as coverage analysis and letter writing; investigation; incident response ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an opportunity to ... In this role, you'll closely impact Navy missions by championing cybersecurity, discovering cyber ...
Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an opportunity to ... In this role, you'll closely impact Navy missions by championing cybersecurity, discovering cyber ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an opportunity to ... In this role, you'll closely impact Navy missions by championing cybersecurity, discovering cyber ...
Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an opportunity to ... In this role, you'll closely impact Navy missions by championing cybersecurity, discovering cyber ...
Experience: 7+ years of experience in Technology Risk, Cyber Risk, GRC, or IT Risk Management ... Strong analytical, documentation, and process design skills * Language Skills : Excellent ...
Quick apply
Experience: 7+ years of experience in Technology Risk, Cyber Risk, GRC, or IT Risk Management ... Strong analytical, documentation, and process design skills * Language Skills : Excellent ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
... risk, and technology programs. Recruiting for this role ends on 12/31/2026. Work you'll do As a ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
Cyber Risk Analyst information
See California salary details
$43.9K - $53.5K
9% of jobs
$53.5K - $63K
2% of jobs
$63K - $72.6K
6% of jobs
$72.6K - $82.1K
1% of jobs
$86K is the 25th percentile. Wages below this are outliers.
$82.1K - $91.7K
17% of jobs
$91.7K - $101.2K
11% of jobs
The median wage is $105.1K / yr.
$101.2K - $110.8K
11% of jobs
$110.8K - $120.4K
17% of jobs
$122K is the 75th percentile. Wages above this are outliers.
$120.4K - $129.9K
10% of jobs
$129.9K - $139.5K
13% of jobs
$139.5K - $149K
4% of jobs
$43.9K
$106.1K
$149K
How much do cyber risk analyst jobs pay per year?
How does a cyber risk analyst typically collaborate with other departments to improve an organization's security posture?
What are the key skills and qualifications needed to thrive as a cyber risk analyst, and why are they important?
What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?
| Aspect | Cyber Risk Analyst | Cyber Security Analyst |
|---|---|---|
| Certifications | Certified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC) | CompTIA Security+, Certified Ethical Hacker (CEH) |
| Work Environment | Risk assessment, policy development, compliance | Network monitoring, threat detection, incident response |
| Employer & Industry | Financial, healthcare, government sectors focusing on risk management | IT departments, cybersecurity firms, tech companies |
While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.
How much does a cyber risk analyst make?
What does a cyber risk analyst do?
What are popular job titles related to Cyber Risk Analyst jobs in California?
For Cyber Risk Analyst jobs in California, the most frequently searched job titles are:
What job categories do people searching Cyber Risk Analyst jobs in California look for?
The top searched job categories for Cyber Risk Analyst jobs in California are:

Full-time
Re-posted 6 hours ago
Deloitte rating
8.2
Based on 93 frontline employees who took The Breakroom Quiz
46th of 151 rated financial services
Job description
Help organizations reduce cyber risk and improve resilience as part of Deloitte's Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team. In this role, you'll support clients in identifying, prioritizing, and remediating security exposures across complex technology environments. You'll work with cross-functional stakeholders to strengthen vulnerability management and patching processes, improve visibility into risk, and support cyber transformation initiatives.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Security Engineer II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...
- Supporting vulnerability remediation and patching activities aligned to CTEM priorities
- Executing vulnerability and patch management tasks across infrastructure, middleware, and applications
- Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize remediation activities
- Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk
- Preparing client-facing analyses, dashboards, and status updates to track remediation progress and exposure reduction
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, the CTEM team helps clients identify exposures, prioritize remediation, and reduce risk across complex technology environments.
Qualifications
Required:
- 3+ years of experience in information technology, information security, vulnerability management, patch management, or a combination of these
- Experience supporting vulnerability remediation, patch management, or continuous threat exposure management activities
- Experience remediating vulnerabilities across Linux, Windows, middleware, and applications
- Experience using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
- Experience using PowerShell, Bash, Python, Ansible, Terraform, or JavaScript Object Notation for automation, scripting, or configuration activities
- Experience using ServiceNow or another Information Technology Service Management platform to coordinate remediation activities and track status
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, or a related field
- Experience in a consulting environment
- Experience preparing remediation metrics, dashboards, or status reporting
- Experience with security or risk frameworks such as the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix
- Experience supporting automation or orchestration of remediation workflows
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberCDR27
Qualifications:Help organizations reduce cyber risk and improve resilience as part of Deloitte's Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team. In this role, you'll support clients in identifying, prioritizing, and remediating security exposures across complex technology environments. You'll work with cross-functional stakeholders to strengthen vulnerability management and patching processes, improve visibility into risk, and support cyber transformation initiatives.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Security Engineer II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for...
- Supporting vulnerability remediation and patching activities aligned to CTEM priorities
- Executing vulnerability and patch management tasks across infrastructure, middleware, and applications
- Analyzing exposure data, asset criticality, exploitability, and attack paths to help prioritize remediation activities
- Assisting with exception management, reporting, and process improvement efforts that reduce cyber risk
- Preparing client-facing analyses, dashboards, and status updates to track remediation progress and exposure reduction
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Deloitte's Cyber Specialists help organizations manage cyber risk through stronger security, greater visibility, and embedded privacy practices. The Cyber Defense & Resilience team works with clients to design, implement, and operate programs that help protect critical assets, support digital transformation, and respond to evolving threats. Within this practice, the CTEM team helps clients identify exposures, prioritize remediation, and reduce risk across complex technology environments.
Qualifications
Required:
- 3+ years of experience in information technology, information security, vulnerability management, patch management, or a combination of these
- Experience supporting vulnerability remediation, patch management, or continuous threat exposure management activities
- Experience remediating vulnerabilities across Linux, Windows, middleware, and applications
- Experience using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite, Windows Server Update Services, Tenable, Rapid7, or Qualys
- Experience using PowerShell, Bash, Python, Ansible, Terraform, or JavaScript Object Notation for automation, scripting, or configuration activities
- Experience using ServiceNow or another Information Technology Service Management platform to coordinate remediation activities and track status
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Information Technology, or a related field
- Experience in a consulting environment
- Experience preparing remediation metrics, dashboards, or status reporting
- Experience with security or risk frameworks such as the National Institute of Standards and Technology Cybersecurity Framework, Center for Internet Security, International Organization for Standardization 27001, or Cloud Security Alliance Cloud Controls Matrix
- Experience supporting automation or orchestration of remediation workflows
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberCDR27
Education:Bachelor's DegreeEmployment Type:About Deloitte
Sourced by ZipRecruiter
Industry
Finance and insurance and business management consulting
Company size
10,000+ Employees
Headquarters location
Orlando, FL, US