Coordinates with location cyber risk specialists to ensure assessments are consistent with ... systemwide standards and leadership expectations. Delivers aggregated assessment results and risk ...
Coordinates with location cyber risk specialists to ensure assessments are consistent with ... systemwide standards and leadership expectations. Delivers aggregated assessment results and risk ...
Seeking a Senior Cyber Risk Management Capability Assessor to evaluate the effectiveness of cyber risk management capabilities, including policies, processes, and technical controls. This role will ...
Seeking a Senior Cyber Risk Management Capability Assessor to evaluate the effectiveness of cyber risk management capabilities, including policies, processes, and technical controls. This role will ...
Expert Cyber Risk Management Engineer Location: Oakland, CA (Onsite only) Duration: Contract to ... Assess the effectiveness of cybersecurity capabilities, provide guidance on managing risks ...
Quick apply
Expert Cyber Risk Management Engineer Location: Oakland, CA (Onsite only) Duration: Contract to ... Assess the effectiveness of cybersecurity capabilities, provide guidance on managing risks ...
An established industry player is seeking a Senior Cyber Risk Management Capability Assessor to enhance cyber risk management frameworks. This role involves conducting thorough risk assessments ...
An established industry player is seeking a Senior Cyber Risk Management Capability Assessor to enhance cyber risk management frameworks. This role involves conducting thorough risk assessments ...
Claims Specialist
Pleasanton, CA · On-site +1
Championing adaptive insurance, Cowbell follows policyholders' cyber risk exposures as they evolve through continuous risk assessment and continuous underwriting. In its unique AI-based approach to ...
Claims Specialist
Pleasanton, CA · On-site +1
Championing adaptive insurance, Cowbell follows policyholders' cyber risk exposures as they evolve through continuous risk assessment and continuous underwriting. In its unique AI-based approach to ...
Claims Specialist
Pleasanton, CA · On-site +1
Championing adaptive insurance, Cowbell follows policyholders' cyber risk exposures as they evolve through continuous risk assessment and continuous underwriting. In its unique AI-based approach to ...
Claims Specialist
Pleasanton, CA · On-site +1
Championing adaptive insurance, Cowbell follows policyholders' cyber risk exposures as they evolve through continuous risk assessment and continuous underwriting. In its unique AI-based approach to ...
Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic ... Developing comprehensive strategies for insider risk programs, including program assessments and ...
Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic ... Developing comprehensive strategies for insider risk programs, including program assessments and ...
Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic ... Developing comprehensive strategies for insider risk programs, including program assessments and ...
Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic ... Developing comprehensive strategies for insider risk programs, including program assessments and ...
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Quick apply
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Quick apply
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Managing Director, Digital Investigations & Cyber Risk
Los Angeles, CA · On-site
$250K - $300K/yr
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Managing Director, Digital Investigations & Cyber Risk
Los Angeles, CA · On-site
$250K - $300K/yr
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Quick apply
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Cyber - Cloud Architect - Consultant
$77.25 - $102.50/hr
Supporting cloud cyber risk engagements across assessment, design, implementation, and post-implementation activities for client environments. * Assisting clients with cloud security architecture ...
Cyber - Cloud Architect - Consultant
$77.25 - $102.50/hr
Supporting cloud cyber risk engagements across assessment, design, implementation, and post-implementation activities for client environments. * Assisting clients with cloud security architecture ...
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Quick apply
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Managing Director, Digital Investigations & Cyber Risk
San Francisco, CA · On-site
$250K - $300K/yr
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Managing Director, Digital Investigations & Cyber Risk
San Francisco, CA · On-site
$250K - $300K/yr
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Other skills of interest include business valuation, internal controls assessment and advisory, and ... risk and strategic intelligence, digital investigations and cyber defense, monitorships and ...
Cyber - Cloud Architect - Consultant
Los Angeles, CA · On-site
$70.50 - $93.75/hr
Supporting cloud cyber risk engagements across assessment, design, implementation, and post-implementation activities for client environments. * Assisting clients with cloud security architecture ...
Cyber - Cloud Architect - Consultant
Los Angeles, CA · On-site
$70.50 - $93.75/hr
Supporting cloud cyber risk engagements across assessment, design, implementation, and post-implementation activities for client environments. * Assisting clients with cloud security architecture ...
Cyber - Cloud Architect - Consultant
San Diego, CA · On-site
$69.50 - $92.25/hr
Supporting cloud cyber risk engagements across assessment, design, implementation, and post-implementation activities for client environments. * Assisting clients with cloud security architecture ...
Cyber - Cloud Architect - Consultant
San Diego, CA · On-site
$69.50 - $92.25/hr
Supporting cloud cyber risk engagements across assessment, design, implementation, and post-implementation activities for client environments. * Assisting clients with cloud security architecture ...
Manage the internal sales process, including proposal development, competitive assessments, multi-discipline client presentations, and unified positioning of RSM's cyber and risk advisory ...
Manage the internal sales process, including proposal development, competitive assessments, multi-discipline client presentations, and unified positioning of RSM's cyber and risk advisory ...
Cyber Risk Assessment information
What is the difference between Cyber Risk Assessment vs Cyber Security Analyst?
| Aspect | Cyber Risk Assessment | Cyber Security Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating cybersecurity risks and vulnerabilities | Monitoring, detecting, and responding to security threats |
| Certifications | CompTIA Security+, CISSP, CISA | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk management teams, consulting firms, security departments | Security operations centers, IT departments, incident response teams |
| Responsibilities | Risk analysis, vulnerability assessments, compliance | Threat detection, incident response, security monitoring |
While both roles involve cybersecurity, Cyber Risk Assessments focus on evaluating potential risks and vulnerabilities to inform security strategies, whereas Cyber Security Analysts actively monitor and respond to ongoing security threats. Understanding these differences helps organizations assign the right roles for comprehensive cybersecurity management.
How much does a cyber risk analyst make?
What is a cyber risk assessment?
What are some common challenges faced by professionals in Cyber Risk Assessment, and how can they be addressed?
What are the key skills and qualifications needed to thrive as a Cyber Risk Assessor, and why are they important?
Can you make $200,000 in cyber security?
Is SOC an entry level job?
Can you make $500,000 a year in cyber security?

Other
Posted 15 days ago
University Of California rating
8.5
Based on 34 frontline employees who took The Breakroom Quiz
80th of 614 rated colleges and universities
Job description
For UCOP internal applicants, please login to the internal candidate gateway at: Jobs at UCOP
UC OFFICE OF THE PRESIDENT
At the University of California (UC), your contributions make a difference. A world leader producing Nobel and Pulitzer Prize recipients with over 150 years of groundbreaking research transforming the world. Choose a career where you can leverage your knowledge, skills and aspirations to inspire and support some of the greatest minds in the world, and those who will follow in their footsteps. Working at the University of California is being part of a unique institution, and a vibrant and diverse community. At the University of California, Office of the President, we propel our mission through impactful work locally, in government centers and systemwide. We are passionate people, serving the greater good.
The University of California, one of the largest and most acclaimed institutions of higher learning in the world, is dedicated to excellence in teaching, research and public service. The University of California Office of the President is the headquarters to the 10 campuses, six academic medical centers and three national laboratories and enrolls premier students from California, the nation and the world. Learn more about the UC Office of the President
Department Overview
UC Digital Risk & Security (DRS) provides systemwide coordination, planning, and operational support primarily to technology and security teams, but indirectly to all students, faculty, patients and staff within the UC system. The team's cyber security services address timely and pervasive issues such as identity theft, data security breaches, data leakage, and system outages across organizations of various sizes, with the goal of enabling ongoing, secure, and reliable operations across the enterprise.
Position Summary
The University of California, Office of the President (UCOP) is seeking a collaborative Senior Risk Assessment Analyst to coordinate and maintain a systemwide cybersecurity risk methodology supporting the University of California's 10 higher education campuses and 6 medical centers. The methodology offers a consistent, scalable, cybersecurity risk assessment process across UC IT departments aligned to the UC information security policy and industry best practices. This role will maintain common standards, templates, and reporting practices; administer associated software platforms and tools; and provide guidance and support to local risk assessment teams to help align their efforts with systemwide standards. This individual contributor role reports to the systemwide Cyber Risk Unit Manager and works with cybersecurity leadership, IT risk and compliance teams, and auditors to provide subject matter expertise and support risk-informed decision making. They will also periodically gather assessment results, compile systemwide risk data and present executive level reports to UC leadership. The successful candidate will draw on previous experience managing enterprise cyber risk assessments. They will possess a deep understanding of common cybersecurity frameworks, including but not limited to NIST 800-53, NIST 800-171, NIST Cyber Security Framework (CSF), ISO/IEC 27001, PCI-DSS, and HIPAA. Strong communication, analytical, and presentation skills and comfort with explaining technical compliance concepts to non-technical audiences is preferred. This is an exciting opportunity to help improve the UC's cyber risk capabilities and make an immediate impact across the entire system.
Key Responsibilities
35% Communication & collaboration: Acts as primary contact from UCOP to locations regarding the risk assessment methodology. Presents written and verbal presentations regarding systemwide processes and program details. Provides guidance to locations regarding the application of the cyber risk methodology. Partners with location stakeholders to gather feedback and ensure that assessments meet the needs of UC with a high level of quality. Collects and shares best practices across locations. Coordinates with location cyber risk specialists to ensure assessments are consistent with systemwide standards and leadership expectations. Delivers aggregated assessment results and risk analysis to leadership.
30% Program planning & development: Develops and maintains relevant documentation including templates, framework mappings, risk management guidelines, control evaluation standards and training guides. Maintains internal resource center and distributes information to stakeholders. As applicable, provides support for administering governance, risk and compliance (GRC) assessment software platforms.
25% Risk management & analysis: Compiles and analyzes aggregated cyber risk assessment data. Develops executive dashboards, metrics and reports for a variety of audiences, including cybersecurity leadership, audit stakeholders and information security governance committees.
10% Change management: Monitors industry updates and developments for changes to compliance frameworks that may impact UC risk management processes, recommending updates as needed.
Experience
Required Qualifications
-
Min 8 years of relevant past work experience.
Skills and Abilities
Required Qualifications
-
Knowledge of regulatory compliance frameworks including NIST 800-53, NIST 800-171, NIST CSF, ISO27001, SOC 1 / 2, HIPAA, PCI-DSS.
-
Demonstrated experience with overseeing enterprise-level cyber security risk assessments, maturity assessments, and audits.
-
Familiarity with one or more GRC platforms and tools (ServiceNow, Archer, etc.)
-
Strong understanding of cyber risk management, including risk identification, analysis, prioritization and remediation.
-
Experience with developing aggregated cyber risk metrics and reports.
-
Highly developed interpersonal communication skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.
-
Strong written communication skills and experience with developing process documentation.
-
Experience with presenting to senior leadership.
-
Strong project management and organizational skills.
-
Demonstrated ability to operate with a high degree of autonomy.
Education
Required Qualifications
-
Bachelor's degree in related area and / or equivalent experience / training
Licenses and Certifications
Preferred Qualifications
-
Security Certifications (CISSP, CISA, CISM, CRISC, CGRC, Security+)
Job Code
006365
Salary Grade
STEPS
Payscale:
$160,000 - $184,000
The University of California, Office of the President, is required to provide a reasonable estimate of the compensation range for this role. This range takes into account the wide range of factors that are considered in making compensation decisions including but not limited to experience, skills, knowledge, abilities, education, licensure and certifications, and other business and organizational needs. It is not typical for an individual to be offered a salary at or near the top of the range for a position. Salary offers are determined based on final candidate qualifications and experience. The full salary range shows the growth potential for this position and the pay scale is the budgeted salary or hourly range that the University reasonably expects to pay for this position.
Benefits: For information on the comprehensive benefits package offered by the University visit: Benefits of Belonging
ADDITIONAL INFORMATION
This position is represented by the University Professional and Technical Employees (UPTE)
Not eligible for Visa sponsorship or transfer.
This position is eligible for a remote work arrangement within the state of California. The selected candidate must reside within the state of California or be willing to relocate to CA within a reasonable timeframe.
HOW TO APPLY
Please be prepared to attach a cover letter and resume with your application.
APPLICATION REVIEW DATE
The first review date for this job is (8/7/2026). The position will be open until filled.
CONDITIONS OF EMPLOYMENT
Background Check Process: Successful completion of a background check is required for this critical position. Background check process at UCOP
Smoke Free Work Environment: The University of California, Office of the President, is smoke & tobacco-free as of January 1, 2014. UC Smoke & Tobacco Free Policy
As a condition of employment, you will be required to comply with the University of California Policy on Vaccination Programs, as may be amended or revised from time to time. Federal, state, or local public health directives may impose additional requirements.
As a condition of employment, the finalist will be required to disclose if they are subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct, are currently being investigated for misconduct, left a position during an investigation for alleged misconduct, or have filed an appeal with a previous employer.
- "Misconduct" means any violation of the policies or laws governing conduct at the applicant's previous place of employment, including, but not limited to, violations of policies or laws prohibiting sexual harassment, sexual assault, or other forms of harassment, discrimination, dishonesty, or unethical conduct, as defined by the employer.
- UC Sexual Violence and Sexual Harassment Policy
- UC Anti-Discrimination Policy for Employees, Students and Third Parties
- APM - 035: Affirmative Action and Nondiscrimination in Employment
EEO STATEMENT
The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.
The University of California, Office of the President, strives to make this job board accessible to any and all users. If you have comments regarding the accessibility of our website or need assistance completing the application process, please contact us at: Accessibility or email the Human Resource Department at: epost@ucop.edu.
What University Of California employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom