At least 2 years of experience in cybersecurity risk management, cybersecurity operations, security monitoring, incident response, security engineering, technology risk, or a related discipline.
At least 2 years of experience in cybersecurity risk management, cybersecurity operations, security monitoring, incident response, security engineering, technology risk, or a related discipline.
Cyber Security Controls Assessor
San Francisco, CA · Hybrid
$104K - $145K/yr
The ideal candidate brings strong experience in security assessments, risk management, compliance ... Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control ...
Quick apply
Cyber Security Controls Assessor
San Francisco, CA · Hybrid
$104K - $145K/yr
The ideal candidate brings strong experience in security assessments, risk management, compliance ... Conduct cybersecurity control assessments for enterprise IT, cloud, and OT/industrial control ...
IT Cybersecurity & Compliance Manager
Baker, CA · On-site
$116K - $157K/yr
At least 3 to 5 years of experience in cybersecurity, information security, compliance, IT risk management, security operations, or a closely related IT discipline. * Practical experience supporting ...
IT Cybersecurity & Compliance Manager
Baker, CA · On-site
$116K - $157K/yr
At least 3 to 5 years of experience in cybersecurity, information security, compliance, IT risk management, security operations, or a closely related IT discipline. * Practical experience supporting ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance -Manager
San Francisco, CA · On-site
$99K - $232K/yr
Industry/Sector Not Applicable Specialism Cybersecurity & Privacy Management Level Manager & Summary The Opportunity As a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Manager, you ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance -Manager
San Francisco, CA · On-site
$99K - $232K/yr
Industry/Sector Not Applicable Specialism Cybersecurity & Privacy Management Level Manager & Summary The Opportunity As a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Manager, you ...
Cybersecurity Engineer
El Segundo, CA · On-site
$115K - $145K/yr
Cybersecurity Engineer Job Locations US-CA-El Segundo ID 2026-2030 Category Systems Engineer ... Provide technical input to Risk Management Framework activities and associated documentation.
New
Cybersecurity Engineer
El Segundo, CA · On-site
$115K - $145K/yr
Cybersecurity Engineer Job Locations US-CA-El Segundo ID 2026-2030 Category Systems Engineer ... Provide technical input to Risk Management Framework activities and associated documentation.
New
Cybersecurity Engineer
El Segundo, CA · Hybrid
$115K - $145K/yr
Provide technical input to Risk Management Framework activities and associated documentation ... Analyze cybersecurity architectures and network diagrams to identify vulnerabilities, risks, and ...
New
Cybersecurity Engineer
El Segundo, CA · Hybrid
$115K - $145K/yr
Provide technical input to Risk Management Framework activities and associated documentation ... Analyze cybersecurity architectures and network diagrams to identify vulnerabilities, risks, and ...
New
Cybersecurity Director
San Francisco, CA · On-site
About the Role The Cybersecurity Director is responsible for providing strategic leadership across ... Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits ...
Cybersecurity Director
San Francisco, CA · On-site
About the Role The Cybersecurity Director is responsible for providing strategic leadership across ... Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits ...
Cybersecurity Director
San Francisco, CA · On-site
$230 - $245/hr
About the Role The Cybersecurity Director is responsible for providing strategic leadership across ... Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits ...
Cybersecurity Director
San Francisco, CA · On-site
$230 - $245/hr
About the Role The Cybersecurity Director is responsible for providing strategic leadership across ... Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits ...
Financial Services Cybersecurity Senior Consultant
San Francisco, CA · On-site
$137K/yr
This role is focused on second-line cybersecurity and technology risk management and advisory, not internal audit. You will work with banks, insurers, asset and wealth managers, fintechs, and other ...
Financial Services Cybersecurity Senior Consultant
San Francisco, CA · On-site
$137K/yr
This role is focused on second-line cybersecurity and technology risk management and advisory, not internal audit. You will work with banks, insurers, asset and wealth managers, fintechs, and other ...
Cybersecurity Consultant
Roseville, CA · On-site
$118K - $133K/yr
This role brings cybersecurity, risk management, and regulatory expertise to consulting engagements and contributes practical, business-aligned recommendations that support risk reduction, compliance ...
Cybersecurity Consultant
Roseville, CA · On-site
$118K - $133K/yr
This role brings cybersecurity, risk management, and regulatory expertise to consulting engagements and contributes practical, business-aligned recommendations that support risk reduction, compliance ...
Financial Services Cybersecurity Senior Consultant
Sacramento, CA · On-site
$124K/yr
This role is focused on second-line cybersecurity and technology risk management and advisory, not internal audit. You will work with banks, insurers, asset and wealth managers, fintechs, and other ...
Financial Services Cybersecurity Senior Consultant
Sacramento, CA · On-site
$124K/yr
This role is focused on second-line cybersecurity and technology risk management and advisory, not internal audit. You will work with banks, insurers, asset and wealth managers, fintechs, and other ...
Financial Services Cybersecurity Senior Consultant
San Jose, CA · On-site
$136K/yr
This role is focused on second-line cybersecurity and technology risk management and advisory, not internal audit. You will work with banks, insurers, asset and wealth managers, fintechs, and other ...
Financial Services Cybersecurity Senior Consultant
San Jose, CA · On-site
$136K/yr
This role is focused on second-line cybersecurity and technology risk management and advisory, not internal audit. You will work with banks, insurers, asset and wealth managers, fintechs, and other ...
Financial Services Cybersecurity Senior Consultant
Los Angeles, CA · On-site
$125K/yr
This role is focused on second-line cybersecurity and technology risk management and advisory, not internal audit. You will work with banks, insurers, asset and wealth managers, fintechs, and other ...
Financial Services Cybersecurity Senior Consultant
Los Angeles, CA · On-site
$125K/yr
This role is focused on second-line cybersecurity and technology risk management and advisory, not internal audit. You will work with banks, insurers, asset and wealth managers, fintechs, and other ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager
San Francisco, CA · On-site
$124K - $280K/yr
Industry/Sector Not Applicable Specialism Cybersecurity & Privacy Management Level Senior Manager & Summary The Opportunity As a Security Risk & Engineering - Tech and Cyber Risk & Compliance ...
Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager
San Francisco, CA · On-site
$124K - $280K/yr
Industry/Sector Not Applicable Specialism Cybersecurity & Privacy Management Level Senior Manager & Summary The Opportunity As a Security Risk & Engineering - Tech and Cyber Risk & Compliance ...
Sr Cyber Engineer (ISSE)
San Diego, CA · On-site
$110 - $136.98/hr
We are seeking an Information Systems Security Engineer (ISSE)/Cybersecurity Engineer to support Risk Management Framework (RMF), cybersecurity engineering, Assessment & Authorization (A&A ...
Sr Cyber Engineer (ISSE)
San Diego, CA · On-site
$110 - $136.98/hr
We are seeking an Information Systems Security Engineer (ISSE)/Cybersecurity Engineer to support Risk Management Framework (RMF), cybersecurity engineering, Assessment & Authorization (A&A ...
Cybersecurity Consultant
$118K - $133K/yr
This role brings cybersecurity, risk management, and regulatory expertise to consulting engagements and contributes practical, business-aligned recommendations that support risk reduction, compliance ...
Cybersecurity Consultant
$118K - $133K/yr
This role brings cybersecurity, risk management, and regulatory expertise to consulting engagements and contributes practical, business-aligned recommendations that support risk reduction, compliance ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90 - $110/hr
The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90 - $110/hr
The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...
The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...
The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
The Cybersecurity Analyst I/II/III supports the Third-Party Cyber Risk Management (TPCRM) program by identifying, assessing, monitoring, and helping reduce cybersecurity risk across NAF's third-party ...
Cyber Security Risk Management information
See California salary details
$56.3K - $67.8K
1% of jobs
$67.8K - $79.4K
4% of jobs
$79.4K - $91K
5% of jobs
$91K - $102.5K
9% of jobs
$108.9K is the 25th percentile. Wages below this are outliers.
$102.5K - $114.1K
11% of jobs
$114.1K - $125.7K
10% of jobs
The median wage is $130.1K / yr.
$125.7K - $137.3K
28% of jobs
$143.9K is the 75th percentile. Wages above this are outliers.
$137.3K - $148.8K
14% of jobs
$148.8K - $160.4K
11% of jobs
$160.4K - $172K
4% of jobs
$172K - $183.6K
4% of jobs
$56.3K
$131.2K
$183.6K
How much do cyber security risk management jobs pay per year?
What is cyber security risk management?
What are the key skills and qualifications needed to thrive in cyber security risk management?
What are some typical challenges faced in cyber security risk management, and how can they be addressed?
What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?
| Aspect | Cyber Security Risk Management | Cyber Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CISSP, CISM | CompTIA Security+, CEH, CISSP (preferred) |
| Work Environment | Policy development, risk assessment, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Organizations focusing on risk mitigation and compliance | Organizations implementing and maintaining security measures |
Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.
What does a cyber security risk management do?
What are popular job titles related to Cyber Security Risk Management jobs in California?
For Cyber Security Risk Management jobs in California, the most frequently searched job titles are:
What job categories do people searching Cyber Security Risk Management jobs in California look for?
The top searched job categories for Cyber Security Risk Management jobs in California are:
What cities in California are hiring for Cyber Security Risk Management jobs?
Cities in California with the most Cyber Security Risk Management job openings:

Full-time
Medical, Retirement, PTO
Posted 5 days ago
MUFG rating
8.1
Based on 7 frontline employees who took The Breakroom Quiz
Job description
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.The Cybersecurity Operations Execution Specialist supports the Security Operations Center (SOC) and Regional Execution Office (REO) by designing, standardizing, and supporting the implementation of security monitoring controls for applications across the enterprise. This role partners closely with application owners, technology teams, business stakeholders, and SOC teams to understand application architectures and risk profiles, define appropriate monitoring requirements, and ensure controls are implemented effectively. The role also helps centralize security monitoring practices across regions and business lines, advances global standards and reusable patterns, and improves the maturity and transparency of the organization's cybersecurity monitoring posture.
Key Responsibilities:Security Monitoring Control Design & Execution
- Support the design and implementation of security monitoring controls for applications and technology environments, aligned with the organization's cybersecurity strategy and risk management framework.
- Translate relevant risks, threat scenarios, and application characteristics into clear monitoring requirements and detection use cases.
- Help ensure monitoring controls are practical, supportable, and aligned with SOC operating processes.
Stakeholder Partnership & Risk Profiling
- Partner with application owners, technology teams, business stakeholders, and cybersecurity teams to understand application architectures, data flows, logging capabilities, and risk profiles.
- Determine appropriate security monitoring requirements based on the application's risk, technology, and operating context.
- Guide stakeholders throughout the monitoring onboarding lifecycle to ensure controls are implemented effectively.
Control Implementation, Testing & Operationalization
- Coordinate with SOC, engineering, and application teams to implement defined monitoring controls and supporting log sources.
- Ensure completed controls are documented, transitioned into operations, and supported by appropriate procedures and ownership.
Centralization & Standardization
- Help centralize and standardize security monitoring controls across regions, entities, and business lines.
- Contribute to global standards, reusable monitoring patterns, onboarding procedures, and governance documentation.
- Identify opportunities to reduce duplication and improve consistency across SOC monitoring services.
Operations Maturity, Metrics & Reporting
- Support initiatives that improve the maturity, efficiency, and transparency of security monitoring operations.
- Identify and maintain meaningful metrics and data sources that help stakeholders understand onboarding progress, control coverage, risk posture, and operational effectiveness.
- Prepare status updates and reporting for governance forums, leadership, risk partners, and other stakeholders.
- Develop automations to increase team efficiency and sustainability.
Gap Identification & Remediation
- Collaborate with cybersecurity, risk, control, audit, and technology teams to identify gaps in monitoring coverage or control implementation.
- Document gaps, coordinate remediation plans, track actions to completion, and escalate barriers when needed.
- Support evidence collection and clear documentation for risk, control, and audit activities.
Service Enablement & Entity Engagement
- Build and maintain relationships with regional entities and teams that receive SOC monitoring services.
- Gather stakeholder feedback, translate needs into actionable plans, and coordinate those plans through completion.
- Promote clear expectations, shared accountability, and effective communication between service providers and service recipients.
- At least 2 years of experience in cybersecurity risk management, cybersecurity operations, security monitoring, incident response, security engineering, technology risk, or a related discipline.
- Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field, or equivalent professional experience.
- Experience evaluating applications or technologies to determine applicable cybersecurity controls.
- Relevant cybersecurity certification preferred, such as CISSP, CISM, GIAC, or equivalent.
- Working knowledge of SOC processes, including log onboarding, detection use cases, alert triage, escalation, and operational handoff.
- Familiarity with SIEM and security monitoring technologies, as well as common cloud, infrastructure, application, and identity log sources.
- Understanding of cybersecurity and risk frameworks, such as NIST CSF, CRI, MITRE ATT&CK/D3FEND, and the ability to apply them to monitoring requirements and control design.
- Experience coordinating work across application, technology, cybersecurity, risk, control, audit, and business stakeholders.
- Ability to document requirements, procedures, decisions, risks, action plans, metrics, and implementation evidence clearly and consistently.
- Strong analytical, problem-solving, project coordination, communication, and stakeholder engagement skills.
- Ability to manage multiple priorities, follow work through to completion, and operate effectively in a regional and global environment.
Education
- Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience
- Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position.
- The typical base pay range for this role is as follows:
- New York / New Jersey: $102k-153k
- Non-New York / New Jersey: $102k-141k
- depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
- Our hybrid work schedule is four days on-site and work remotely one day per week.
- MUFG Benefits Summary
About MUFG
Sourced by ZipRecruiter
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), the 6th largest financial group in the world. Across the globe, we're 160,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world. With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Industry
Banking and credit intermediation
Company size
10,000+ Employees
Headquarters location
New York, NY, US