1

Cyber Security Risk Management Jobs in California

Cybersecurity Counsel

Mountain View, CA · On-site

$130K - $177K/yr

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

IT Cybersecurity & Compliance Manager

Baker, CA · On-site

$116K - $157K/yr

At least 3 to 5 years of experience in cybersecurity, information security, compliance, IT risk management, security operations, or a closely related IT discipline. * Practical experience supporting ...

Senior Cybersecurity Risk Analyst - USA Remote

Orange, CA · Remote

$130K - $160K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...

Cybersecurity Director

San Francisco, CA · On-site

$230 - $245/hr

  • Medical

  • Retirement

  • PTO

About the Role The Cybersecurity Director is responsible for providing strategic leadership across ... Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits ...

next page

Showing results 1-20

Cyber Security Risk Management information

See California salary details

$56.3K

$131.2K

$183.6K

How much do cyber security risk management jobs pay per year?

As of Aug 16, 2026, the average yearly pay for cyber security risk management in California is $131,221.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,500.00 and $148,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in cyber security risk management?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What are some typical challenges faced in cyber security risk management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

What are popular job titles related to Cyber Security Risk Management jobs in California?

For Cyber Security Risk Management jobs in California, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Management jobs in California look for?

The top searched job categories for Cyber Security Risk Management jobs in California are:

What cities in California are hiring for Cyber Security Risk Management jobs?

Cities in California with the most Cyber Security Risk Management job openings:

Infographic showing various Cyber Security Risk Management job openings in California as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 14% Part Time, 2% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $131,221 per year, or $63.1 per hour.

Cybersecurity Technology Architect

Pivot Point Solutions

Oakland, CA

$121K - $178K/yr

Full-time

Posted 4 days ago


Job description

Pivot Point Solutions

Pivot Point Solutions is a California-based technology consulting firm that specializes in delivering IT solutions and support for the construction and utility industries. We partner with organizations across the state to provide reliable technology services that improve operational efficiency, enhance project delivery, and support critical business systems.

Our team understands the unique technology challenges facing construction and utility organizations, from field operations and infrastructure projects to enterprise applications and cybersecurity. By combining industry expertise with responsive service, we help clients modernize their technology environments, streamline workflows, and maintain secure, reliable IT systems that support long-term growth.

Job Overview

Title: Senior Cybersecurity Risk & Governance Consultant

Sector: Cybersecurity

Seniority: Senior Level

Location: Oakland, CA

Job Type: Contract

Contract Length: 18 months

Compensation: $121,181 – $178,422

As a Senior Cybersecurity Risk & Governance Consultant, you will help shape and oversee cybersecurity strategy, risk management, regulatory compliance, and security governance across a complex enterprise environment. This role works closely with cybersecurity leadership, business stakeholders, regulatory partners, and technical teams to evaluate risk and strengthen security practices across both information technology (IT) and operational technology (OT) environments.

The position also supports emerging areas of cybersecurity risk, including artificial intelligence governance and security. You'll provide senior-level guidance on cybersecurity frameworks, critical infrastructure protection, regulatory requirements, and enterprise risk while helping translate complex technical risks into actionable recommendations for leadership.

Your Day-to-Day Activities
  • Lead and support enterprise cybersecurity governance, risk management, and compliance initiatives

  • Develop cybersecurity strategies, roadmaps, operating plans, and risk reduction priorities

  • Maintain and evaluate cybersecurity risk portfolios across multiple business and technology environments

  • Serve as a cybersecurity liaison with regulatory organizations and key internal stakeholders

  • Lead or participate in security governance committees, steering groups, and executive discussions

  • Perform cybersecurity and compliance assessments using established industry frameworks

  • Evaluate cybersecurity risks associated with AI and machine learning technologies, including data exposure, model misuse, adversarial attacks, and emerging threats

  • Support development of AI security policies, governance practices, and responsible-use standards

  • Assess Industrial Control Systems (ICS), SCADA environments, PLCs, and other operational technology for cybersecurity risk

  • Develop and recommend OT security controls aligned with critical infrastructure security practices

  • Evaluate security architecture, applications, systems, networks, and business processes to identify vulnerabilities and control gaps

  • Partner with legal, compliance, technology, and business teams to address regulatory and cybersecurity requirements

  • Translate complex cybersecurity findings into clear risk recommendations for technical and executive stakeholders

  • Monitor evolving cybersecurity regulations, frameworks, threats, and technology trends

The Job Requirements
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related discipline, or equivalent professional experience

  • 8+ years of combined cybersecurity, information security, IT, critical infrastructure, intelligence, or related experience

  • Advanced experience with cybersecurity risk management, governance, and compliance

  • Experience conducting cybersecurity risk assessments and evaluating security controls

  • Knowledge of enterprise IT security across applications, systems, networks, and infrastructure

  • Experience working with cybersecurity standards and frameworks such as NIST and ISO

  • Understanding of regulatory and compliance requirements within complex or highly regulated organizations

  • Current cybersecurity certification such as Security+, GIAC, SANS, Cisco Security, Microsoft Security, or equivalent

  • Strong executive communication, analytical, and decision-making capabilities

  • Ability to influence stakeholders and lead cybersecurity initiatives across multiple teams

You'll Stand Out If You Have
  • CISSP, CISM, CRISC, CISA, or comparable advanced cybersecurity certification

  • Master's degree in Cybersecurity, Computer Science, Information Systems, or a related discipline

  • Cybersecurity experience within utilities, energy, critical infrastructure, or another regulated industry

  • Experience securing Operational Technology (OT), Industrial Control Systems (ICS), SCADA, or PLC environments

  • Knowledge of NIST 800-82 and industrial control system security practices

  • Experience with NERC CIP or other critical infrastructure regulatory requirements

  • Experience with AI/ML security, AI governance, model risk, or the NIST AI Risk Management Framework

  • Knowledge of SOX, CCPA/CPRA, HIPAA, or other security and privacy regulations

  • Experience presenting cybersecurity risk and strategy recommendations to senior or executive leadership