1

Cyber Risk Assessment Jobs in California (NOW HIRING)

Championing adaptive insurance, Cowbell follows policyholders' cyber risk exposures as they evolve through continuous risk assessment and continuous underwriting. In its unique AI-based approach to ...

Championing adaptive insurance, Cowbell follows policyholders' cyber risk exposures as they evolve through continuous risk assessment and continuous underwriting. In its unique AI-based approach to ...

Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic ... Developing comprehensive strategies for insider risk programs, including program assessments and ...

Cyber - Cloud Architect - Consultant

Los Angeles, CA · On-site

$70.50 - $93.75/hr

Supporting cloud cyber risk engagements across assessment, design, implementation, and post-implementation activities for client environments. * Assisting clients with cloud security architecture ...

Cyber - Cloud Architect - Consultant

San Diego, CA · On-site

$69.50 - $92.25/hr

Supporting cloud cyber risk engagements across assessment, design, implementation, and post-implementation activities for client environments. * Assisting clients with cloud security architecture ...

next page

Showing results 1-20

Cyber Risk Assessment information

What is the difference between Cyber Risk Assessment vs Cyber Security Analyst?

AspectCyber Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating cybersecurity risks and vulnerabilitiesMonitoring, detecting, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams
ResponsibilitiesRisk analysis, vulnerability assessments, complianceThreat detection, incident response, security monitoring

While both roles involve cybersecurity, Cyber Risk Assessments focus on evaluating potential risks and vulnerabilities to inform security strategies, whereas Cyber Security Analysts actively monitor and respond to ongoing security threats. Understanding these differences helps organizations assign the right roles for comprehensive cybersecurity management.

How much does a cyber risk analyst make?

A cyber risk analyst typically earns between $70,000 and $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in industries with high cybersecurity demands.

What is a cyber risk assessment?

A cyber risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities in an organization's information systems. It helps organizations understand the potential impact of cyber threats and determine the likelihood of such events occurring. By conducting a cyber risk assessment, businesses can implement appropriate security controls and strategies to mitigate risks, comply with regulatory requirements, and protect sensitive data from cyberattacks. Regular assessments are essential to adapt to evolving threats and maintain a strong cybersecurity posture.

What are some common challenges faced by professionals in Cyber Risk Assessment, and how can they be addressed?

Professionals in Cyber Risk Assessment often encounter challenges such as rapidly evolving threat landscapes, keeping up with regulatory changes, and ensuring clear communication of technical risks to non-technical stakeholders. To address these, staying current with industry trends through continuous learning, leveraging robust risk assessment frameworks, and developing strong communication skills are essential. Additionally, collaborating closely with IT, compliance, and business units helps ensure comprehensive and effective risk management.

What are the key skills and qualifications needed to thrive as a Cyber Risk Assessor, and why are they important?

To thrive as a Cyber Risk Assessor, you need a strong understanding of cybersecurity principles, risk management frameworks, and relevant regulations, often backed by a degree in information security or related certifications like CISSP or CISA. Familiarity with security assessment tools, vulnerability scanners, and risk analysis platforms is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills for accurately identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets and ensuring compliance in an evolving threat landscape.

Can you make $200,000 in cyber security?

Cyber Risk Assessment professionals can potentially earn $200,000 or more annually, especially with advanced certifications like CISSP or CISA, extensive experience, and roles in high-demand industries or senior positions. Salaries vary based on location, company size, and individual expertise, with senior analysts and managers often reaching or exceeding this level.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is typically not entry-level and often requires some experience in cybersecurity, network monitoring, or related fields. Entry-level positions in cybersecurity may include roles like SOC analyst trainees or junior analysts, but more advanced SOC positions usually demand certifications such as CompTIA Security+ or Certified SOC Analyst (CSA) and familiarity with security tools and incident response processes.

Can you make $500,000 a year in cyber security?

Cyber Risk Assessment professionals typically earn between $80,000 and $150,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary generally requires senior roles such as Chief Information Security Officer (CISO) or executive-level positions, which involve strategic leadership, extensive experience, and often additional responsibilities. High salaries in cybersecurity are usually associated with leadership, specialized skills, or working in large organizations or high-demand industries.
What are popular job titles related to Cyber Risk Assessment jobs in California? For Cyber Risk Assessment jobs in California, the most frequently searched job titles are:
What cities in California are hiring for Cyber Risk Assessment jobs? Cities in California with the most Cyber Risk Assessment job openings:
Infographic showing various Cyber Risk Assessment job openings in California as of July 2026, with employment types broken down into 2% As Needed, 79% Full Time, 16% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution.

Other

Posted 15 days ago


University Of California rating

8.5

Company rating: 8.5 out of 10

Based on 34 frontline employees who took The Breakroom Quiz

80th of 614 rated colleges and universities


Job description

Apply for Job
Job ID
86945
Location
Oakland
Full/Part Time
Full Time
Add to Favorite Jobs
Email this Job
Job Posting

For UCOP internal applicants, please login to the internal candidate gateway at: Jobs at UCOP

UC OFFICE OF THE PRESIDENT

At the University of California (UC), your contributions make a difference. A world leader producing Nobel and Pulitzer Prize recipients with over 150 years of groundbreaking research transforming the world. Choose a career where you can leverage your knowledge, skills and aspirations to inspire and support some of the greatest minds in the world, and those who will follow in their footsteps. Working at the University of California is being part of a unique institution, and a vibrant and diverse community. At the University of California, Office of the President, we propel our mission through impactful work locally, in government centers and systemwide. We are passionate people, serving the greater good.

The University of California, one of the largest and most acclaimed institutions of higher learning in the world, is dedicated to excellence in teaching, research and public service. The University of California Office of the President is the headquarters to the 10 campuses, six academic medical centers and three national laboratories and enrolls premier students from California, the nation and the world. Learn more about the UC Office of the President

Department Overview
UC Digital Risk & Security (DRS) provides systemwide coordination, planning, and operational support primarily to technology and security teams, but indirectly to all students, faculty, patients and staff within the UC system. The team's cyber security services address timely and pervasive issues such as identity theft, data security breaches, data leakage, and system outages across organizations of various sizes, with the goal of enabling ongoing, secure, and reliable operations across the enterprise.
Position Summary
The University of California, Office of the President (UCOP) is seeking a collaborative Senior Risk Assessment Analyst to coordinate and maintain a systemwide cybersecurity risk methodology supporting the University of California's 10 higher education campuses and 6 medical centers. The methodology offers a consistent, scalable, cybersecurity risk assessment process across UC IT departments aligned to the UC information security policy and industry best practices. This role will maintain common standards, templates, and reporting practices; administer associated software platforms and tools; and provide guidance and support to local risk assessment teams to help align their efforts with systemwide standards. This individual contributor role reports to the systemwide Cyber Risk Unit Manager and works with cybersecurity leadership, IT risk and compliance teams, and auditors to provide subject matter expertise and support risk-informed decision making. They will also periodically gather assessment results, compile systemwide risk data and present executive level reports to UC leadership. The successful candidate will draw on previous experience managing enterprise cyber risk assessments. They will possess a deep understanding of common cybersecurity frameworks, including but not limited to NIST 800-53, NIST 800-171, NIST Cyber Security Framework (CSF), ISO/IEC 27001, PCI-DSS, and HIPAA. Strong communication, analytical, and presentation skills and comfort with explaining technical compliance concepts to non-technical audiences is preferred. This is an exciting opportunity to help improve the UC's cyber risk capabilities and make an immediate impact across the entire system.
Key Responsibilities

35% Communication & collaboration: Acts as primary contact from UCOP to locations regarding the risk assessment methodology. Presents written and verbal presentations regarding systemwide processes and program details. Provides guidance to locations regarding the application of the cyber risk methodology. Partners with location stakeholders to gather feedback and ensure that assessments meet the needs of UC with a high level of quality. Collects and shares best practices across locations. Coordinates with location cyber risk specialists to ensure assessments are consistent with systemwide standards and leadership expectations. Delivers aggregated assessment results and risk analysis to leadership.

30% Program planning & development: Develops and maintains relevant documentation including templates, framework mappings, risk management guidelines, control evaluation standards and training guides. Maintains internal resource center and distributes information to stakeholders. As applicable, provides support for administering governance, risk and compliance (GRC) assessment software platforms.

25% Risk management & analysis: Compiles and analyzes aggregated cyber risk assessment data. Develops executive dashboards, metrics and reports for a variety of audiences, including cybersecurity leadership, audit stakeholders and information security governance committees.

10% Change management: Monitors industry updates and developments for changes to compliance frameworks that may impact UC risk management processes, recommending updates as needed.


Experience
Required Qualifications

  • Min 8 years of relevant past work experience.


Skills and Abilities
Required Qualifications

  • Knowledge of regulatory compliance frameworks including NIST 800-53, NIST 800-171, NIST CSF, ISO27001, SOC 1 / 2, HIPAA, PCI-DSS.

  • Demonstrated experience with overseeing enterprise-level cyber security risk assessments, maturity assessments, and audits.

  • Familiarity with one or more GRC platforms and tools (ServiceNow, Archer, etc.)

  • Strong understanding of cyber risk management, including risk identification, analysis, prioritization and remediation.

  • Experience with developing aggregated cyber risk metrics and reports.

  • Highly developed interpersonal communication skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.

  • Strong written communication skills and experience with developing process documentation.

  • Experience with presenting to senior leadership.

  • Strong project management and organizational skills.

  • Demonstrated ability to operate with a high degree of autonomy.


Education
Required Qualifications

  • Bachelor's degree in related area and / or equivalent experience / training


Licenses and Certifications
Preferred Qualifications

  • Security Certifications (CISSP, CISA, CISM, CRISC, CGRC, Security+)


Job Code
006365
Salary Grade
STEPS
Payscale:
$160,000 - $184,000
The University of California, Office of the President, is required to provide a reasonable estimate of the compensation range for this role. This range takes into account the wide range of factors that are considered in making compensation decisions including but not limited to experience, skills, knowledge, abilities, education, licensure and certifications, and other business and organizational needs. It is not typical for an individual to be offered a salary at or near the top of the range for a position. Salary offers are determined based on final candidate qualifications and experience. The full salary range shows the growth potential for this position and the pay scale is the budgeted salary or hourly range that the University reasonably expects to pay for this position.

Benefits: For information on the comprehensive benefits package offered by the University visit: Benefits of Belonging

ADDITIONAL INFORMATION

This position is represented by the University Professional and Technical Employees (UPTE)

Not eligible for Visa sponsorship or transfer.

This position is eligible for a remote work arrangement within the state of California. The selected candidate must reside within the state of California or be willing to relocate to CA within a reasonable timeframe.

HOW TO APPLY

Please be prepared to attach a cover letter and resume with your application.

APPLICATION REVIEW DATE

The first review date for this job is (8/7/2026). The position will be open until filled.

CONDITIONS OF EMPLOYMENT

Background Check Process: Successful completion of a background check is required for this critical position. Background check process at UCOP

Smoke Free Work Environment: The University of California, Office of the President, is smoke & tobacco-free as of January 1, 2014. UC Smoke & Tobacco Free Policy

As a condition of employment, you will be required to comply with the University of California Policy on Vaccination Programs, as may be amended or revised from time to time. Federal, state, or local public health directives may impose additional requirements.

As a condition of employment, the finalist will be required to disclose if they are subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct, are currently being investigated for misconduct, left a position during an investigation for alleged misconduct, or have filed an appeal with a previous employer.

  • "Misconduct" means any violation of the policies or laws governing conduct at the applicant's previous place of employment, including, but not limited to, violations of policies or laws prohibiting sexual harassment, sexual assault, or other forms of harassment, discrimination, dishonesty, or unethical conduct, as defined by the employer.
    • UC Sexual Violence and Sexual Harassment Policy
    • UC Anti-Discrimination Policy for Employees, Students and Third Parties
    • APM - 035: Affirmative Action and Nondiscrimination in Employment

EEO STATEMENT

The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.

The University of California, Office of the President, strives to make this job board accessible to any and all users. If you have comments regarding the accessibility of our website or need assistance completing the application process, please contact us at: Accessibility or email the Human Resource Department at: epost@ucop.edu.


What University Of California employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom