1

Cyber Security Risk Management Jobs in California

Cybersecurity Counsel

Mountain View, CA

$130K - $177K/yr

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

Oversee cybersecurity controls and risk management practices across cloud platforms, including Microsoft 365, Azure, SaaS applications, identity systems, and hybrid environments, to protect critical ...

Support the Risk Management Framework (RMF) Assessment and Authorization processes (Steps 0 through 4 and Step 6) throughout the various systems' cybersecurity lifecycles, including documentation of ...

Apply risk management concepts to mitigate vulnerabilities in system security architectures ... The Cybersecurity Analyst II will be required to analyze, propose, and implement security controls ...

Cybersecurity Consultant

Roseville, CA · On-site

$118K - $133K/yr

This role brings cybersecurity, risk management, and regulatory expertise to consulting engagements and contributes practical, business-aligned recommendations that support risk reduction, compliance ...

Senior CyberSecurity

San Jose, CA · On-site

$85 - $95/hr

Risk Management & Assessment: o Lead comprehensive cybersecurity risk assessments across the enterprise, identifying vulnerabilities and recommending prioritized mitigation strategies. o Develop and ...

next page

Showing results 1-20

Cyber Security Risk Management information

See California salary details

$56.3K

$131.2K

$183.6K

How much do cyber security risk management jobs pay per year?

As of Jul 26, 2026, the average yearly pay for cyber security risk management in California is $131,221.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,500.00 and $148,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cyber Security Risk Management professional, and why are they important?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What does a cyber risk manager do?

A cyber risk manager assesses and prioritizes cybersecurity threats to an organization, develops strategies to mitigate risks, and implements security policies. They often use tools like risk assessment frameworks and require certifications such as CISSP or CISM to effectively manage security risks in a dynamic environment.

What are some typical challenges faced by professionals in Cyber Security Risk Management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

Can you make $500,000 a year in cyber security?

Cyber security risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working for large organizations with complex security needs.

Can I make $200,000 a year in cyber security?

Cyber Security Risk Management professionals can potentially earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and roles in high-demand sectors or leadership positions. Salaries vary based on location, company size, and individual expertise, but high-level cybersecurity roles often reach or exceed this income level.

Is security risk management a good career?

Security risk management is a valuable career in cybersecurity, focusing on identifying and mitigating potential threats to an organization’s information systems. It often requires knowledge of security frameworks, risk assessment tools, and certifications like CISSP or CISM, and offers strong job growth and demand across various industries.
What are popular job titles related to Cyber Security Risk Management jobs in California? For Cyber Security Risk Management jobs in California, the most frequently searched job titles are:
What job categories do people searching Cyber Security Risk Management jobs in California look for? The top searched job categories for Cyber Security Risk Management jobs in California are:
What cities in California are hiring for Cyber Security Risk Management jobs? Cities in California with the most Cyber Security Risk Management job openings:
Infographic showing various Cyber Security Risk Management job openings in California as of July 2026, with employment types broken down into 3% Locum Tenens, 88% Full Time, 6% Part Time, and 3% Contract. Highlights an 90% Physical, 4% Hybrid, and 6% Remote job distribution, with an average salary of $131,221 per year, or $63.1 per hour.
Cybersecurity Counsel

Cybersecurity Counsel

Waymo

Mountain View, CA

$130K - $177K/yr

Other

Posted 11 days ago


Job description

As part of Waymo's Legal team, you will work on the exciting legal issues surrounding our transformational autonomous driving technology and help drive our business lines forward from technology ideation through scaled commercial deployment. We partner with our public policy, safety, security and privacy experts to define transportation policy for the autonomous driving world to come, advising on regulatory changes that support and protect our users around the world. We collaborate with our engineering, product, strategy and operations teams to develop and protect our intellectual property portfolio and drive our corporate and commercial transactions. We ensure compliance with an increasingly complex and dynamic range of global regulations. And we anticipate, mitigate, and litigate high-profile and precedent-setting legal matters.

In this hybrid role, you will report to a Managing Counsel.

You will:

  • Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with business objectives.

  • Partner effectively with Security, Engineering, Safety, and Product teams on vulnerability management, threat analyses, and cybersecurity risk assessments.

  • Spearhead the evolution of Waymo's cybersecurity incident response and reporting program in connection with the domestic and international expansion of its autonomous vehicle operations.

  • Drive efforts to manage cybersecurity risk effectively within the company's supplier and partner ecosystem and promote supply chain security.
  • Support internal and external audits, assessments, and regulatory inquiries related to cybersecurity compliance.
  • Monitor emerging cybersecurity laws, regulations, executive orders, and agency guidance, and lead business-focused compliance efforts.

You have:

  • Law degree (LLB, LLM, or JD), plus at least 5 years of experience counseling on cybersecurity matters with a law firm, government agency, or in-house legal department.

  • Excellent written and oral communication skills with ability to explain complex legal and cybersecurity issues cogently to technical and non-technical audiences, including executives.

  • Experience advising clients on cybersecurity compliance and incident response programs (e.g., ransomware events, supply chain compromises, and insider threats), including incident containment, forensic investigations, and reporting programs for complying with federal, state, and international laws and regulations.

  • Experience with supply chain cybersecurity risk management, including advising on third-party security risk assessments, preparation of SBOMs and HBOMs, and supply chain cybersecurity.
  • Strong organizational skills and attention to detail; ability to manage a significant workload with competing deadlines in a fast-paced environment.
  • Proficiency and comfort navigating ambiguity and developing effective, business-oriented solutions to managing legal and cybersecurity risk; enthusiasm for winning together as a team and working collaboratively with legal and non-legal stakeholders.

We prefer:

  • Extensive knowledge of applicable standards for cybersecurity, including NIST CSF, ISO 27001, and/or ISO 28000.

  • Experience engaging with regulators, such as CISA, FBI, or state attorneys general, on cybersecurity matters.

  • Experience advising on security risk management in connection with AI/ML systems, operational technology, cyber physical systems, critical infrastructure, or autonomous systems.

  • Cybersecurity or information security certifications (e.g., CISSP, CISM).
  • Experience advising and participating in incident response teams in connection with cybersecurity attacks.
  • Technical background in cybersecurity or demonstrated experience working closely with security engineers and professionals.