1

Cyber Risk Jobs in California (NOW HIRING)

Cyber Risk Lead

San Francisco, CA ยท On-site

$180 - $210/hr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

You'll own the cyber risk register, risk treatment, and remediation governance, partnering with control and system owners who execute fixes, the compliance engineering function that provides ...

Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte ...

Cyber Defense & Resilience - Insider Risk Manager Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte ...

Design and maintain model policies for cybersecurity and frontier-risk domains, especially dual-use and high-risk cyber capabilities. * Translate cybersecurity threat models into clear behavioral ...

Cyber Broker - NA FINEX

San Francisco, CA ยท On-site

$90K - $125K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

You will be responsible for designing, marketing, and placing complex cyber insurance programs while delivering strategic advice on cyber risk transfer solutions. The successful candidate will ...

Cyber Broker - NA FINEX

Los Angeles, CA ยท On-site

$90 - $125/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

You will be responsible for designing, marketing, and placing complex cyber insurance programs while delivering strategic advice on cyber risk transfer solutions. The successful candidate will ...

The Cyber Analysis Lead will direct the team responsible for identifying cyber threats, analyzing ... Approximately 100 Risk Management Framework (RMF) authorization boundaries. * Hybrid cloud ...

Cyber Analytics Team Lead

Seaside, CA ยท On-site

$131K - $237K/yr

  • Medical

  • Retirement

  • PTO

The Cyber Analysis Lead will direct the team responsible for identifying cyber threats, analyzing ... Approximately 100 Risk Management Framework (RMF) authorization boundaries. * Hybrid cloud ...

next page

Showing results 1-20

Cyber Risk information

What is cyber risk?

Cyber risk refers to the potential for financial loss, disruption, or damage to an organization due to the failure of its information technology systems. This includes threats such as data breaches, hacking, malware, ransomware, and unauthorized access to sensitive information. Managing cyber risk involves identifying vulnerabilities, implementing security measures, and creating response plans to minimize the impact of cyber incidents. Organizations often employ specialists to assess and mitigate these risks, ensuring the safety of their digital assets.

What are the key skills and qualifications needed to thrive as a Cyber Risk professional?

To thrive as a Cyber Risk professional, you need a solid understanding of information security principles, risk assessment methodologies, and regulatory compliance frameworks, often supported by a degree in cybersecurity, IT, or related fields. Familiarity with tools such as SIEM platforms, vulnerability scanners, and relevant certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey complex security issues to diverse stakeholders. These competencies are crucial for protecting organizational assets, ensuring compliance, and proactively managing evolving cyber threats.

What are some typical challenges faced by professionals in a Cyber Risk role, and how can they be addressed?

Professionals in Cyber Risk roles often encounter challenges such as rapidly evolving cyber threats, balancing business needs with security requirements, and managing cross-departmental communication. Staying current with emerging risks and regulatory changes requires continuous learning and adaptability. Effective collaboration with IT, legal, and business units is crucial to implement practical risk mitigation strategies. Building strong relationships and clear communication channels within the organization can help address these challenges and ensure cyber risk is managed proactively.

What is the difference between Cyber Risk vs Cyber Security Analyst?

AspectCyber RiskCyber Security Analyst
Primary FocusIdentifying, assessing, and managing cybersecurity risks and vulnerabilitiesMonitoring, analyzing, and responding to security threats and incidents
Required CredentialsCertifications like CISSP, CISM, CRISC; risk management experienceCertifications like CompTIA Security+, CISSP; technical security skills
Work EnvironmentRisk management teams, compliance departments, strategic planningSecurity operations centers, IT teams, incident response teams
Industry UsageUsed across finance, healthcare, government for risk mitigationUsed in IT and cybersecurity departments for threat defense

While both roles focus on cybersecurity, Cyber Risk professionals primarily assess and manage potential threats at a strategic level, whereas Cyber Security Analysts focus on technical threat detection and response. Understanding these differences helps organizations allocate resources effectively and align roles with their security objectives.

What are the most commonly searched types of Cyber Risk jobs in California?

The most popular types of Cyber Risk jobs in California are:

What cities in California are hiring for Cyber Risk jobs?

Cities in California with the most Cyber Risk job openings:

Infographic showing various Cyber Risk job openings in California as of August 2026, with employment types broken down into 1% As Needed, 91% Full Time, 6% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Cyber Risk Lead

Nscale

San Francisco, CA โ€ข On-site

$180 - $210/hr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 26 days ago


Job description

Houston; New York; San Francisco; Seattle

About Nscale

Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.

We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, youโ€™ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, youโ€™ll be contributing to building the technology that powers the future.

About the Role

Weโ€™re hiring a Cyber Risk Lead to own enterprise-wide cyber security risk across Nscaleโ€™s global AI infrastructure and build the risk function from the ground up.

This senior individual contributor role sits at the intersection of risk management, statistical analysis, engineering, and governance. Youโ€™ll own the cyber risk register, risk treatment, and remediation governance, partnering with control and system owners who execute fixes, the compliance engineering function that provides continuous monitoring, and the enterprise risk team that represents cyber exposure within Nscaleโ€™s broader enterprise risk register.

We approach risk as an engineering problem. Youโ€™ll create a dynamic, threat-informed cyber risk program that turns technical telemetry into measured insights and scalable treatment plans, defining how cyber risk is quantified, prioritized, and reduced as Nscale grows.

What you'll be doing
  • Build and operate Nscaleโ€™s continuously measured cyber risk program, transforming technical telemetry into actionable risk insights.
  • Develop and maintain a dynamic cyber risk model that reflects asset exposure across technology, data centers, and software supply chains.
  • Model realistic attack scenarios using threat intelligence, adversary TTPs, historical incidents, and attack path analysis to prioritize risks by likelihood and loss magnitude.
  • Quantify cyber risk using recognized methodologies such as FAIR, NIST SP 800-30, or ISO 27005, adapting them to support engineering decisions rather than compliance reporting.
  • Own the cyber risk treatment lifecycle, translating prioritized risks into actionable engineering work with clear ownership, measurable objectives, and expected risk reduction.
  • Establish measurable risk treatment objectives and engineering service levels.
  • Validate that remediation activities produce demonstrable reductions in cyber risk.
  • Align cyber risk with enterprise risk management through shared taxonomies, scoring models, and reporting that accurately represent enterprise exposure.
Issue Management & Remediation Governance
  • Establish engineering service levels, escalation paths, and governance that drive timely remediation while balancing operational and business priorities.
  • Hold remediation owners accountable for closing risks within agreed service levels.
  • Validate completed remediation through technical evidence rather than administrative closure.
  • Maintain the cyber risk register and closure discipline while control owners resolve identified gaps.
Risk Automation & Continuous Posture
  • Integrate risk into the compliance-as-code platform so posture is continuous and evidence-backed.
  • Apply risk-as-code where it materially improves risk and issue management.
  • Improve the fidelity of cyber risk measurements through engineering automation, analytics, and new data sources.
  • Connect risk, vulnerability, asset, GRC, and engineering workflow data to reduce manual effort and improve visibility.
Program Development & Reporting
  • Report material enterprise risk scenarios using defensible logic and clear, articulate presentations.
  • Provide leadership with measured insights into Nscaleโ€™s cyber risk posture and treatment progress.
  • Help shape the broader GRC program architecture as it grows.
KPIs
  • Risk register completeness, evidence freshness, and continuous coverage
  • Remediation service-level attainment and reduction in overdue issues
  • High-risk remediation completed within engineering service levels
  • Risks continuously assessed through technical telemetry
About You
  • 8+ years of experience in enterprise security risk management, including building or running a risk register and treatment program.
  • Risk quantification and treatment expertise grounded in a recognized method such as the NIST Cybersecurity Framework, ISO 27005, or FAIR.
  • A track record of driving remediation across engineering teams, not simply logging issues.
  • Comfort working directly with risk data using SQL, scripting, or equivalent tooling to pull and trend risk, vulnerability, and asset data.
  • Experience building risk tooling or automation, including integrations between scanners, asset inventories, GRC platforms, and engineering issue trackers.
  • Ability to use automation and AI-assisted workflows to reduce manual GRC work.
  • Strong understanding of cloud infrastructure and security controls, including the ability to read infrastructure-as-code such as Terraform well enough to assess whether a control is effective.
  • Experience with automation-first risk management, continuous control monitoring, or actuarial approaches to risk modeling.
  • Experience with AI infrastructure, hyperscale, regulated environments, critical infrastructure, data center operations, or sovereign cloud requirements.
  • Relevant certifications such as CISSP or CRISC, and a strong statistics or mathematics background, are advantageous.
What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.

  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
  • Join one of the fastest-growing AI infrastructure companies โ€” your chance to directly shape how global AI capacity is planned and deployed.
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy โ€” always with our full support.
  • Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.

If thereโ€™s anything we can do to accommodate your specific situation, please let us know.

The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

Salary Range

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

Salary Range

$180,000 - $210,000 USD

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice:Here.

#J-18808-Ljbffr