The Cybersecurity Engineer will work closely with software developers, cloud engineers, mission ... RMF & Compliance Support Risk Management Framework (RMF) activities across development, test ...
The Cybersecurity Engineer will work closely with software developers, cloud engineers, mission ... RMF & Compliance Support Risk Management Framework (RMF) activities across development, test ...
Senior DevSecOps Cybersecurity Engineer
El Segundo, CA · On-site
$149 - $186/hr
The Cybersecurity Engineer will work closely with software developers, cloud engineers, mission ... Support Risk Management Framework (RMF) activities across development, test, staging, and ...
Senior DevSecOps Cybersecurity Engineer
El Segundo, CA · On-site
$149 - $186/hr
The Cybersecurity Engineer will work closely with software developers, cloud engineers, mission ... Support Risk Management Framework (RMF) activities across development, test, staging, and ...
Project Manager III
Poway, CA · On-site
$100K - $183K/yr
Third Party and Supplier Cybersecurity Risk * Administer and support the third party risk management program by collecting, reviewing, and assessing supplier cybersecurity compliance information ...
Project Manager III
Poway, CA · On-site
$100K - $183K/yr
Third Party and Supplier Cybersecurity Risk * Administer and support the third party risk management program by collecting, reviewing, and assessing supplier cybersecurity compliance information ...
Sr. Manager, Information Security
Los Angeles, CA · On-site
$130 - $170/hr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Sr. Manager, Information Security
Los Angeles, CA · On-site
$130 - $170/hr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Sr. Manager, Information Security
Hollywood, CA · On-site
$130K - $170K/yr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Sr. Manager, Information Security
Hollywood, CA · On-site
$130K - $170K/yr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Cyber Risk Lead
San Francisco, CA · On-site
$180 - $210/hr
Medical
Dental
Vision
Retirement
PTO
... cyber security risk across Nscale's global AI infrastructure and build the risk function from the ground up. This senior individual contributor role sits at the intersection of risk management ...
Cyber Risk Lead
San Francisco, CA · On-site
$180 - $210/hr
Medical
Dental
Vision
Retirement
PTO
... cyber security risk across Nscale's global AI infrastructure and build the risk function from the ground up. This senior individual contributor role sits at the intersection of risk management ...
Sr. Manager, Information Security
Los Angeles, CA · On-site
$130 - $170/hr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Sr. Manager, Information Security
Los Angeles, CA · On-site
$130 - $170/hr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Sr. Manager, Information Security
Los Angeles, CA · Hybrid
$130K - $170K/yr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Sr. Manager, Information Security
Los Angeles, CA · Hybrid
$130K - $170K/yr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Sr. Manager, Information Security
Los Angeles, CA · Hybrid
$130K - $170K/yr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Quick apply
Sr. Manager, Information Security
Los Angeles, CA · Hybrid
$130K - $170K/yr
Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...
Senior Manager MedTech Cybersecurity
Irvine, CA · On-site +1
$119K - $161K/yr
Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred. * Excellent communication and collaboration skills, with the ability to network ...
Senior Manager MedTech Cybersecurity
Irvine, CA · On-site +1
$119K - $161K/yr
Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred. * Excellent communication and collaboration skills, with the ability to network ...
Vice President, Cybersecurity
Los Angeles, CA · On-site
$169K - $211K/yr
... party risk management program that ensures security requirements extend to managed service ... Required : • 15+ years of progressive cybersecurity leadership experience, with 10+ years leading ...
Vice President, Cybersecurity
Los Angeles, CA · On-site
$169K - $211K/yr
... party risk management program that ensures security requirements extend to managed service ... Required : • 15+ years of progressive cybersecurity leadership experience, with 10+ years leading ...
Senior Manager MedTech Cybersecurity
Irvine, CA · On-site
$119K - $161K/yr
Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred. * Excellent communication and collaboration skills, with the ability to network ...
Senior Manager MedTech Cybersecurity
Irvine, CA · On-site
$119K - $161K/yr
Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred. * Excellent communication and collaboration skills, with the ability to network ...
Senior Manager MedTech Cybersecurity
Irvine, CA · On-site +1
$119K - $161K/yr
Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred. * Excellent communication and collaboration skills, with the ability to network ...
Senior Manager MedTech Cybersecurity
Irvine, CA · On-site +1
$119K - $161K/yr
Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred. * Excellent communication and collaboration skills, with the ability to network ...
Third Party Risk Management Analyst
Newport Beach, CA · Hybrid
Medical
Dental
Vision
Life
Retirement
PTO
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
Third Party Risk Management Analyst
Newport Beach, CA · Hybrid
Medical
Dental
Vision
Life
Retirement
PTO
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
Third Party Risk Management Analyst
Newport Beach, CA · Hybrid
Medical
Dental
Vision
Life
Retirement
PTO
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
Third Party Risk Management Analyst
Newport Beach, CA · Hybrid
Medical
Dental
Vision
Life
Retirement
PTO
The Third Party Risk Management (TPRM) Analyst is a senior individual contributor responsible for ... This role ensures robust cybersecurity, resilience, and third party due diligence practices are ...
Cybersecurity Engineer, Product Security
San Francisco, CA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and ... RMF (Risk Management Framework) * ATO (Authority to Operate) * Export control and regulated data ...
Cybersecurity Engineer, Product Security
San Francisco, CA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and ... RMF (Risk Management Framework) * ATO (Authority to Operate) * Export control and regulated data ...
System Engineer- Cyber Security Engineering Focus
$57.50 - $70.75/hr
This position is focused on applying risk management frameworks, engineering security controls, and ... Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and ...
System Engineer- Cyber Security Engineering Focus
$57.50 - $70.75/hr
This position is focused on applying risk management frameworks, engineering security controls, and ... Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and ...
Cybersecurity Engineer, Product Security
Medical
Dental
Vision
Life
Retirement
PTO
We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and ... RMF (Risk Management Framework) * ATO (Authority to Operate) * Export control and regulated data ...
Cybersecurity Engineer, Product Security
Medical
Dental
Vision
Life
Retirement
PTO
We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and ... RMF (Risk Management Framework) * ATO (Authority to Operate) * Export control and regulated data ...
Cybersecurity Engineer and Risk Analyst
Medical
Life
Retirement
PTO
Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an opportunity to ... Using yourknowledgeandexperiencein Risk Management Framework (RMF), you'll assess security threats ...
Cybersecurity Engineer and Risk Analyst
Medical
Life
Retirement
PTO
Cybersecurity Engineer and Risk Analyst The Opportunity: Are you looking for an opportunity to ... Using yourknowledgeandexperiencein Risk Management Framework (RMF), you'll assess security threats ...
Cybersecurity Engineer, Product Security
El Segundo, CA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and ... RMF (Risk Management Framework) * ATO (Authority to Operate) * Export control and regulated data ...
Cybersecurity Engineer, Product Security
El Segundo, CA · On-site
Medical
Dental
Vision
Life
Retirement
PTO
We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and ... RMF (Risk Management Framework) * ATO (Authority to Operate) * Export control and regulated data ...
Cyber Security Risk Management information
See California salary details
$56.3K - $67.8K
1% of jobs
$67.8K - $79.4K
4% of jobs
$79.4K - $91K
5% of jobs
$91K - $102.5K
9% of jobs
$108.9K is the 25th percentile. Wages below this are outliers.
$102.5K - $114.1K
11% of jobs
$114.1K - $125.7K
10% of jobs
The median wage is $130.1K / yr.
$125.7K - $137.3K
28% of jobs
$143.9K is the 75th percentile. Wages above this are outliers.
$137.3K - $148.8K
14% of jobs
$148.8K - $160.4K
11% of jobs
$160.4K - $172K
4% of jobs
$172K - $183.6K
4% of jobs
$56.3K
$131.2K
$183.6K
How much do cyber security risk management jobs pay per year?
What are the key skills and qualifications needed to thrive in cyber security risk management?
What is cyber security risk management?
What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?
| Aspect | Cyber Security Risk Management | Cyber Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CISSP, CISM | CompTIA Security+, CEH, CISSP (preferred) |
| Work Environment | Policy development, risk assessment, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Organizations focusing on risk mitigation and compliance | Organizations implementing and maintaining security measures |
Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.
What are some typical challenges faced in cyber security risk management, and how can they be addressed?
What are popular job titles related to Cyber Security Risk Management jobs in California?
For Cyber Security Risk Management jobs in California, the most frequently searched job titles are:
What job categories do people searching Cyber Security Risk Management jobs in California look for?
The top searched job categories for Cyber Security Risk Management jobs in California are:
What cities in California are hiring for Cyber Security Risk Management jobs?
Cities in California with the most Cyber Security Risk Management job openings:

Full-time
Posted 9 days ago
Job description
ENSCO, Inc is a diverse engineering and technology company that provides engineering, science and advanced technology solutions that guarantee mission success, safety, and security to governments and private industries worldwide.
ENSCO is seeking a Senior DevSecOps Cybersecurity Engineer to join our team in Colorado Springs, CO or El Segundo, CA. This role serves as a senior cybersecurity and RMF expert embedded within Agile and DevSecOps development teams responsible for delivering capabilities into government-owned production environments operating at IL5 and IL6. The emphasis is on CVE analysis and remediation, RMF execution, cybersecurity documentation, deployment approval activities, security compliance, and effective communication of cyber risk to government stakeholders while enabling rapid and secure mission capability delivery.
The Cybersecurity Engineer will work closely with software developers, cloud engineers, mission owners, systems engineers, Information System Security Managers (ISSMs), Authorizing Officials (AOs), and government cybersecurity personnel to ensure software releases meet security, compliance, and operational requirements.
The position requires deep expertise in RMF implementation, vulnerability management, CVE assessment and remediation, secure deployment methodologies, and cybersecurity activities necessary to support Authority to Operate (ATO) accredited environments.
The candidate must be capable of explaining cybersecurity risk to both technical and non-technical stakeholders, developing mitigation strategies for identified vulnerabilities, and ensuring mission capabilities can be rapidly and securely deployed into operational environments.
The MILSATCOM Systems Engineering, Integration, and Test (MSEIT) effort provides leading edge Systems Engineering & Integration (SE&I) for the Air Force's Space and Missiles System Center. We support the Air Force's acquisition of state of the art Military Satellite Communications systems, providing global secure, survivable, and protected communications for our nation's warfighters. We seek technical individuals who will thrive in a highly collaborative work environment of small teams, using the most modern tools and methodologies to tackle the challenges of integrating complex space and ground communications systems. This position is on-site in Colorado Springs, CO or El Segundo, CA. Some of the job responsibilities include but are not limited to:
Cybersecurity Engineering
Serve as the primary cybersecurity engineering lead supporting DevSecOps software delivery efforts.
Provide cybersecurity guidance throughout the software development lifecycle from design through production deployment.
Evaluate system architectures, software components, and deployment pipelines for compliance with DoD and Department of the Air Force cybersecurity requirements.
Partner with development, platform, cloud, and infrastructure teams to ensure security is integrated into all phases of delivery.
CVE Analysis & Remediation
Assess Common Vulnerabilities and Exposures (CVEs) identified through automated scanning, security testing, and cybersecurity reviews.
Analyze operational impact, exploitability, mission risk, and remediation options for vulnerabilities affecting mission systems.
Develop mitigation strategies and Plans of Action and Milestones (POA&M) recommendations when immediate remediation is not feasible.
Provide technical justification and risk-based explanations to government stakeholders regarding vulnerability disposition decisions.
Support vulnerability review boards and release decisions for software entering production environments.
RMF & Compliance
Support Risk Management Framework (RMF) activities across development, test, staging, and production environments.
Assist with implementation and maintenance of NIST 800-53 security controls.
Develop and maintain cybersecurity artifacts required to support system authorization and continuous monitoring activities.
Prepare material supporting cybersecurity assessments, authorization reviews, and package updates.
Assist with security control assessments and remediation activities associated with authorization findings.
Secure Deployment & Operations
Support secure software release processes into IL5 and IL6 production environments.
Collaborate with DevSecOps teams to establish compliant deployment methodologies and release procedures.
Validate cybersecurity readiness prior to production deployments and major software releases.
Review security impacts of infrastructure, software, and configuration changes.
Ensure application, container, platform, and infrastructure security requirements are met prior to deployment.
Security Documentation & Readiness Activities
Support development and maintenance of cybersecurity documentation including Cybersecurity Strategies (CSS), System Security Plans (SSPs), authorization package artifacts, and supporting cybersecurity documentation.
Participate in Cyber Vulnerability Identification (CVI) events, cybersecurity assessments, security audits, and remediation activities.
Support Continuity of Operations (COOP) planning, tabletop exercises, incident response activities, and operational readiness events.
Assist mission teams in preparing for cybersecurity inspections, compliance reviews, and authorization activities.
Coordinate with government cybersecurity organizations to ensure documentation remains current and audit-ready.
Stakeholder Collaboration
Interface directly with government cybersecurity personnel, ISSMs, ISSOs, Authorizing Officials, mission owners, and engineering teams.
Communicate cybersecurity risks, mitigation options, and deployment recommendations to leadership and operational stakeholders.
Support Agile ceremonies, release planning events, architecture reviews, and technical working groups.
Provide cybersecurity guidance to software teams on secure coding, vulnerability remediation, and release readiness.
Qualifications Required
Bachelor's degree in engineering, computer science, information systems, cybersecurity or related technical field
7+ years of cybersecurity, information assurance, DevSecOps, system security engineering, or related defense experience
Extensive experience implementing and supporting the Risk Management Framework (RMF)
Strong understanding of NIST 800-53 security controls and DoD cybersecurity policies
Demonstrated experience evaluating, explaining, mitigating, and remediating Common Vulnerabilities and Exposures (CVEs)
Experience supporting software deployments within accredited government production environments
Strong understanding of IL5 and IL6 cloud environments and associated cybersecurity requirements
Experience supporting ATO and continuous monitoring activities
Experience working directly with government cybersecurity organizations and mission stakeholders
Ability to communicate technical cybersecurity issues to both technical and executive audiences
Strong written communication skills supporting cybersecurity documentation, risk acceptance packages, and authorization artifacts
ABILITY TO OBTAIN AND MAINTAIN A DOD SECRET SECURITY CLEARANCE FOR WHICH, YOU MUST BE A U.S. CITIZEN
Qualifications Desired
Master's degree in engineering, computer science, information systems, cybersecurity or related technical field
Experience supporting Space Systems Command (SSC), Space Operations Command (SpOC), U.S. Space Force, or other DoD space organizations
Experience supporting operational systems accredited under RMF within classified environments
Familiarity with Platform One, Cloud One, Kubernetes, Iron Bank, Big Bang, and related DoD DevSecOps ecosystems
Experience supporting Authority to Operate (ATO) and Continuous Authorization to Operate (cATO) initiatives
Knowledge of Secure Software Development Framework (SSDF) and modern DevSecOps pipelines
Experience supporting Cybersecurity Strategies (CSS), Cyber Vulnerability Identification (CVI) events, cybersecurity inspections, and COOP tabletop exercises
Experience with STIG implementation, SCAP compliance, ACAS, Nessus, Fortify, SonarQube, Snyk, Prisma Cloud, Twistlock, or similar security tooling
Security certifications such as CISSP, CASP+, Security+, CISM, CCSP, or GIAC certifications
Experience supporting mission-critical systems deployed in classified cloud environments
Experience supporting software modernization efforts within U.S. Space Force programs
Familiarity with SATCOM, space operations, command and control systems, mission planning systems, or enterprise management platforms
Experience implementing Zero Trust architectures within DoD environments
Experience balancing mission delivery timelines with cybersecurity compliance requirements in operational production systems
Experience supporting large-scale software factories or government-managed production environments
Certifications such as CISSP, CompTIA Security+
Certifications such as INCOSE CSEP or ESEP
Active DoD Secret security clearance or higher
Required Certifications: None
U.S. Citizenship Required: Yes
Security Clearance Required: Ability to Obtain
Employment Type: Regular Full-time
Background Check Type: 7 Year Pre-Employment
Drug Screen Required: None
Position Contingent Upon Contract Award: No
About ENSCO
Sourced by ZipRecruiter
Industry
Guided missile and space vehicle manufacturing
Company size
501 - 1,000 Employees
Headquarters location
Springfield, VA, US
Year founded
1969