... of cybersecurity experience in risk management, security architecture, product security, or cloud security. * Expertise with NIST, FAIR, ISO, and quantitative risk assessment methodologies.
... of cybersecurity experience in risk management, security architecture, product security, or cloud security. * Expertise with NIST, FAIR, ISO, and quantitative risk assessment methodologies.
... of cybersecurity experience in risk management, security architecture, product security, or cloud security. * Expertise with NIST, FAIR, ISO, and quantitative risk assessment methodologies.
... of cybersecurity experience in risk management, security architecture, product security, or cloud security. * Expertise with NIST, FAIR, ISO, and quantitative risk assessment methodologies.
... of cybersecurity experience in risk management, security architecture, product security, or cloud security. * Expertise with NIST, FAIR, ISO, and quantitative risk assessment methodologies.
... of cybersecurity experience in risk management, security architecture, product security, or cloud security. * Expertise with NIST, FAIR, ISO, and quantitative risk assessment methodologies.
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... and cybersecurity best practices. As one of the fastest growing firms in the nation, BT has the ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... and cybersecurity best practices. As one of the fastest growing firms in the nation, BT has the ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... and cybersecurity best practices. As one of the fastest growing firms in the nation, BT has the ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... and cybersecurity best practices. As one of the fastest growing firms in the nation, BT has the ...
Conduct cyber risk assessment activities including threat modeling, vulnerability analysis and ... Conduct cybersecurity test and evaluation of hardware and/or software designs to verify and ...
Conduct cyber risk assessment activities including threat modeling, vulnerability analysis and ... Conduct cybersecurity test and evaluation of hardware and/or software designs to verify and ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... and cybersecurity best practices. As one of the fastest growing firms in the nation, BT has the ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... and cybersecurity best practices. As one of the fastest growing firms in the nation, BT has the ...
Conduct cyber risk assessment activities including threat modeling, vulnerability analysis and ... Conduct cybersecurity test and evaluation of hardware and/or software designs to verify and ...
Conduct cyber risk assessment activities including threat modeling, vulnerability analysis and ... Conduct cybersecurity test and evaluation of hardware and/or software designs to verify and ...
Senior Software Quality Engineer - Cybersecurity
Irvine, CA · On-site
$108K - $153K/yr
Experience with cybersecurity risk assessments * Experience integrating cybersecurity into the SDLC / design controls * Familiarity with vulnerability management and post market cybersecurity ...
Senior Software Quality Engineer - Cybersecurity
Irvine, CA · On-site
$108K - $153K/yr
Experience with cybersecurity risk assessments * Experience integrating cybersecurity into the SDLC / design controls * Familiarity with vulnerability management and post market cybersecurity ...
CyberSecurity Consultant
Sacramento, CA · On-site
Position: CyberSecurity Consultant Location: Sacramento, CA Duration: 12 Months Qualifications ... Knowledge of risk assessment methodologies, IT policies and standards development * Working ...
CyberSecurity Consultant
Sacramento, CA · On-site
Position: CyberSecurity Consultant Location: Sacramento, CA Duration: 12 Months Qualifications ... Knowledge of risk assessment methodologies, IT policies and standards development * Working ...
System Engineer- Cyber Security Engineering Focus
Redlands, CA · On-site
$57.50 - $70.75/hr
... risk mitigation activities • Assess security impacts of system changes and supporting ... Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and ...
System Engineer- Cyber Security Engineering Focus
Redlands, CA · On-site
$57.50 - $70.75/hr
... risk mitigation activities • Assess security impacts of system changes and supporting ... Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and ...
Principal Cybersecurity Architect
$170K - $210K/yr
The Principal Cybersecurity Architect, Engineering serves as a senior technical authority ... Strong experience with threat modeling, vulnerability assessment, and risk-based security decision ...
Principal Cybersecurity Architect
$170K - $210K/yr
The Principal Cybersecurity Architect, Engineering serves as a senior technical authority ... Strong experience with threat modeling, vulnerability assessment, and risk-based security decision ...
Principal Cybersecurity Architect
Irvine, CA · On-site
$170K - $210K/yr
The Principal Cybersecurity Architect, Engineering serves as a senior technical authority ... Strong experience with threat modeling, vulnerability assessment, and risk-based security decision ...
Principal Cybersecurity Architect
Irvine, CA · On-site
$170K - $210K/yr
The Principal Cybersecurity Architect, Engineering serves as a senior technical authority ... Strong experience with threat modeling, vulnerability assessment, and risk-based security decision ...
Develop techniques and procedures for conducting cybersecurity risk assessments and compliance audits, the evaluation and testing of hardware, firmware and software for possible impact on system ...
Develop techniques and procedures for conducting cybersecurity risk assessments and compliance audits, the evaluation and testing of hardware, firmware and software for possible impact on system ...
System Engineer- Cyber Security Engineering Focus
$57.50 - $70.75/hr
... and risk mitigation activities * Assess security impacts of system changes and supporting ... Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and ...
System Engineer- Cyber Security Engineering Focus
$57.50 - $70.75/hr
... and risk mitigation activities * Assess security impacts of system changes and supporting ... Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
Our Risk Advisory practice provides a full spectrum of services to help our clients assess their ... Cybersecurity * Third party risk * ITGC and application controls * SOC reporting * Regulatory and ...
Cybersecurity Governance, Risk and Compliance (GRC) Program Manager Location: San Jose, CA (Onsite ... Strong understanding IT security concepts emphasis Security Risk Assessment. * Relevant ...
Cybersecurity Governance, Risk and Compliance (GRC) Program Manager Location: San Jose, CA (Onsite ... Strong understanding IT security concepts emphasis Security Risk Assessment. * Relevant ...
Senior Manager - Risk Advisory (Cybersecurity)
Burbank, CA · Hybrid
$155K - $190K/yr
Manage, lead, and perform cybersecurity assessments, cyber threat and risk assessments, network and security reviews, compliance, assessments, and system configuration review * Lead cybersecurity ...
Senior Manager - Risk Advisory (Cybersecurity)
Burbank, CA · Hybrid
$155K - $190K/yr
Manage, lead, and perform cybersecurity assessments, cyber threat and risk assessments, network and security reviews, compliance, assessments, and system configuration review * Lead cybersecurity ...
Cyber Security Risk Assessment information
See California salary details
$56.3K - $67.8K
1% of jobs
$67.8K - $79.4K
4% of jobs
$79.4K - $91K
5% of jobs
$91K - $102.5K
9% of jobs
$108.9K is the 25th percentile. Wages below this are outliers.
$102.5K - $114.1K
11% of jobs
$114.1K - $125.7K
10% of jobs
The median wage is $130.1K / yr.
$125.7K - $137.3K
28% of jobs
$143.9K is the 75th percentile. Wages above this are outliers.
$137.3K - $148.8K
14% of jobs
$148.8K - $160.4K
11% of jobs
$160.4K - $172K
4% of jobs
$172K - $183.6K
4% of jobs
$56.3K
$131.2K
$183.6K
How much do cyber security risk assessment jobs pay per year?
Can you make $500,000 a year in cyber security?
What are the key skills and qualifications needed to thrive in Cyber Security Risk Assessment, and why are they important?
What is the role of risk assessment in cyber security?
What is the difference between Cyber Security Risk Assessment vs Cyber Security Analyst?
| Aspect | Cyber Security Risk Assessment | Cyber Security Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating security risks and vulnerabilities | Monitoring, analyzing, and responding to security threats |
| Certifications | CompTIA Security+, CISSP, CISA | CompTIA Security+, CISSP, CEH |
| Work Environment | Risk assessment teams, consulting firms, security departments | Security operations centers, IT departments, incident response teams |
While both roles require similar certifications and work within cybersecurity, a Cyber Security Risk Assessment focuses on evaluating potential vulnerabilities and risks to an organization’s assets. In contrast, a Cyber Security Analyst actively monitors and responds to security threats, ensuring ongoing protection. Understanding these differences helps organizations assign the right responsibilities to each role.
Is SOC analyst a high paying job?
What are some common challenges faced by professionals conducting cyber security risk assessments?
What is a cyber security risk assessment?
What is the 80 20 rule in cyber security?
- Night Shift Cyber Security Analyst Intern
- Cyber Security Engineering
- Cyber Security Analytics
- Cyber Security Contractors
- Overnight Cyber Security Purple Team
- Cyber Security Analyst Contract
- Federal Government Cyber Security
- Visa Sponsorship Available Cyber Security Manager
- Cyber Power
- Volunteer Cyber Security Analyst
Full-time
Posted 4 days ago
Job description
About Us:
Proofpoint is a global leader in human- and agent-centric cybersecurity. We protect how people, data, and AI agents connect across email, cloud, and collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world and empower people to work securely and confidently. Join us in our pursuit to defend data and protect people.
How We Work:
At Proofpoint you'll be part of a global team that breaks barriers to redefine cybersecurity guided by our BRAVE core values:
Bold in how we dream and innovate
Responsive to feedback, challenges and opportunities
Accountable for results and best in class outcomes
Visionary in future focused problem-solving
Exceptional in execution and impact
Location: Sunnyvale, CA
Department: Information Security
Reports To: Chief Information Security Officer (CISO)
Role Overview
Proofpoint is seeking a Principal Engineer - Risk Management & Threat Modeling to serve as one of the company's most senior technical leaders for cybersecurity risk and security architecture analysis. This role combines deep technical expertise, strategic business influence, and cross-functional leadership to shape and mature Proofpoint's enterprise cyber risk posture across corporate systems, cloud infrastructure, SaaS products, and AI-powered services.
As a Principal Engineer, you will establish technical direction for cyber risk assessment, threat modeling, and AI risk management capabilities. You will partner closely with Product Security, Engineering, Enterprise Architecture, and executive leadership to identify emerging threats, quantify business risk, and drive secure-by-design outcomes at scale.
This role is highly visible across the organization and requires the ability to translate complex technical and architectural risks into actionable guidance for executives, engineering teams, customers, and board stakeholders. A key focus area will be advancing Proofpoint's security posture for AI-enabled products, agentic systems, and large language model (LLM) integrations while enabling innovation and business growth.
Key Responsibilities
Enterprise Cyber Risk Leadership
Provide technical leadership for enterprise cyber risk management across corporate, cloud, and product environments.
Define and evolve data-driven risk assessment methodologies using FAIR, NIST, and ISO frameworks.
Establish measurable risk metrics, KRIs, and reporting that support executive decision-making.
Partner with engineering, product, and business stakeholders to drive risk treatment and remediation.
Serve as a senior technical authority for risk analysis and risk acceptance decisions.
Threat Modeling & Security Architecture
Lead threat modeling for enterprise platforms, cloud-native architectures, SaaS applications, and customer-facing services.
Define and scale threat modeling practices using STRIDE, PASTA, MITRE ATT&CK, and related methodologies.
Identify attack surfaces, trust boundaries, and architectural weaknesses through analysis of distributed systems.
Partner with Product Security and Engineering to integrate threat modeling into architecture reviews and the SDLC.
Develop reusable threat models, reference architectures, and security design guidance.
AI & Agentic Security Risk
Lead security assessments and threat modeling for AI-enabled products, LLM integrations, and agentic workflows.
Identify attack surfaces, trust boundaries, and threats involving prompt injection, excessive agency, model compromise, training data poisoning, and data exposure.
Partner with Product Security, Engineering, and Architecture to embed security throughout the AI development lifecycle.
Evaluate risks associated with AI models, tool integrations, retrieval systems, and agent communications.
Define measurable security requirements aligned with NIST AI RMF, ISO 42001, OWASP LLM Top 10, and MITRE ATLAS.
Develop reusable AI security patterns and assessment methodologies that enable secure AI adoption.
Executive & Board-Level Risk Communication
Develop data-driven, executive-ready risk narratives that clearly communicate technical risk in business terms.
Support preparation of cyber risk briefings for the CISO, executive leadership team, Board of Directors, and Audit Committee.
Present threat modeling findings, emerging risks, AI security concerns, and architectural risk trends to senior stakeholders.
Provide strategic guidance regarding evolving threat landscapes and their potential business impact.
Technical Leadership & Influence
Drive cybersecurity strategy and technical direction through influence rather than organizational authority.
Mentor security architects, engineers, and technical leaders across the organization.
Build scalable programs, frameworks, and repeatable processes that improve measurable security maturity.
Foster a culture of secure-by-design engineering and data-driven, risk-informed decision making.
Qualifications
Required Qualifications
Bachelor's degree in Computer Science, Information Security, Engineering, or related field.
10+ years of cybersecurity experience in risk management, security architecture, product security, or cloud security.
Expertise with NIST, FAIR, ISO, and quantitative risk assessment methodologies.
Experience conducting threat modeling, risk analysis, and security assessments in enterprise and cloud environments.
Strong understanding of AWS, Azure, GCP, and associated security risks.
Experience securing AI/ML systems, LLM integrations, or agentic architectures.
Strong analytical skills with the ability to derive actionable risk insights from technical data.
Knowledge of MITRE ATT&CK and threat-informed defense methodologies.
Excellent communication and influence skills across executive and technical audiences.
Preferred Qualifications
Experience supporting FedRAMP authorization efforts and government compliance programs.
Experience with AI governance programs and emerging AI security standards.
Background in product security, application security, or secure software development.
Experience supporting M&A cybersecurity due diligence and integration activities.
Experience developing quantitative cyber risk programs using FAIR or similar methodologies.
Relevant certifications such as CISSP, CRISC, CISM, CCSP, CGEIT, SABSA, or AI-focused security certifications.
Key Success Attributes
Recognized technical authority in cyber risk management, threat modeling, and risk analytics.
Strategic thinker who translates technical risk into measurable business impact.
Strong executive presence with the ability to influence leaders across the organization.
Data-driven and analytical, using evidence to prioritize risk and drive outcomes.
Pragmatic and risk-focused, balancing security, innovation, and business agility.
Effective collaborator who builds alignment through clear communication and partnership.
Passion for solving complex security challenges in cloud, SaaS, AI, and agentic environments.
Why Proofpoint?
At Proofpoint, we believe that an exceptional career experience includes a comprehensive compensation and benefits package. Here are just a few reasons you'll love working with us:
Competitive compensation
Comprehensive benefits
Career success on your terms
Flexible work environment
Annual wellness and community outreach days
Always on recognition for your contributions
Global collaboration and networking opportunities
Our Culture:
Our culture is rooted in values that inspire belonging, empower purpose and drive success-every day, for everyone.
We encourage applications from individuals of all backgrounds, experiences, and perspectives. If you need accommodation during the application or interview process, please reach out to accessibility@proofpoint.com.
How to Apply
Interested? Submit your application along with any supporting information- we can't wait to hear from you!
Consistent with Proofpoint values and applicable law, we provide the following information to promote pay transparency and equity. Our compensation reflects the cost of labor across several U.S. geographic markets, and we pay differently based on those defined markets as set out below. Pay within these ranges varies and depends on job-related knowledge, skills, and experience. The actual offer will be based on the individual candidate. The range provided may represent a candidate range and may not reflect the full range for an individual tenured employee. This role may be eligible for variable compensation and/or equity. We offer a competitive benefits package, including flexible time off, a comprehensive well-being program with two paid Wellbeing Days and two paid Volunteer Days per year, plus a three-week Work from Anywhere option.
Base Pay Ranges:
SF Bay Area, New York City Metro Area:
Base Pay Range: 200,300.00 - 293,810.00 USDCalifornia (excludes SF Bay Area), Colorado, Connecticut, Illinois, Washington DC Metro, Maryland, Massachusetts, New Jersey, Texas, Washington, Virginia, and Alaska:
Base Pay Range: 167,300.00 - 245,355.00 USDAll other cities and states excluding those listed above:
Base Pay Range: 152,900.00 - 224,235.00 USD