1

Cybersecurity Risk Management Analyst Jobs in California

About the Role The Vendor Risk Management Analyst is an integral part of Latham's Global Finance team. This role will be responsible for assessing, monitoring, and mitigating risks associated with ...

GRC Risk Management Analyst

San Jose, CA · On-site

$68.97 - $72.80/hr

Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations. Strong analytical, organizational, stakeholder-management, and written and verbal ...

Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations. * Strong analytical, organizational, stakeholder-management, and written and verbal ...

Partner effectively with Security, Engineering, Safety, and Product teams on vulnerability management, threat analyses, and cybersecurity risk assessments. * Spearhead the evolution of Waymo ...

Commercial insurance operations experience within a corporate risk management department, commercial insurance brokerage, or underwriting organization. * Analytical and quantitative aptitude ...

Showing results 21-40

Cybersecurity Risk Management Analyst information

What does a Cybersecurity Risk Management Analyst do?

A Cybersecurity Risk Management Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security policies, conduct risk assessments, and recommend controls to minimize potential threats. Their work involves monitoring security measures, ensuring compliance with regulations, and helping develop strategies to protect the organization from cyberattacks. Ultimately, they play a crucial role in safeguarding sensitive information and supporting overall cybersecurity posture.

What are some typical challenges a Cybersecurity Risk Management Analyst faces when working with cross-functional teams?

Cybersecurity Risk Management Analysts often collaborate with IT, legal, compliance, and business units to identify and mitigate risks. A common challenge is bridging the communication gap between technical and non-technical stakeholders, ensuring that risk recommendations are understood and actionable. Additionally, balancing business objectives with security requirements can be complex, requiring strong negotiation and diplomacy skills. Analysts must also stay updated on evolving threats while tailoring solutions to each department’s unique needs.

What are the key skills and qualifications needed to thrive as a Cybersecurity Risk Management Analyst, and why are they important?

To thrive as a Cybersecurity Risk Management Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and regulatory frameworks, typically backed by a degree in cybersecurity or a related field. Familiarity with tools such as risk management software, vulnerability scanners, and certifications like CISSP, CISM, or CRISC is highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in translating technical risks into actionable insights for stakeholders. These skills ensure organizations can proactively identify, assess, and mitigate cyber risks to protect sensitive information and maintain regulatory compliance.

What is the difference between Cybersecurity Risk Management Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk Management AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentFocus on risk assessment, policy development, and complianceFocus on threat detection, incident response, and system monitoring
Employer & Industry UsageUsed in organizations prioritizing risk mitigation and complianceUsed across various sectors for security operations and monitoring

While both roles involve cybersecurity, the Cybersecurity Risk Management Analyst primarily assesses and manages risks, ensuring compliance and policy adherence. In contrast, the Cybersecurity Analyst concentrates on identifying threats, monitoring security systems, and responding to incidents. Both roles are essential but focus on different aspects of cybersecurity defense.

What are popular job titles related to Cybersecurity Risk Management Analyst jobs in California?

For Cybersecurity Risk Management Analyst jobs in California, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management Analyst jobs in California look for?

The top searched job categories for Cybersecurity Risk Management Analyst jobs in California are:

Infographic showing various Cybersecurity Risk Management Analyst job openings in California as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 15% Part Time, and 4% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution.

Vendor Risk Management Analyst

Latham & Watkins LLP

Los Angeles, CA • Hybrid

$80K - $110K/yr

Full-time

Medical, Life, Retirement, PTO

Re-posted 16 days ago


Latham & Watkins rating

8.5

Company rating: 8.5 out of 10

Based on 5 frontline employees who took The Breakroom Quiz

13th of 34 rated law firms


Job description

Latham & Watkins is one of the world’s leading global law firms advising the businesses and institutions that drive the global economy. We are the market leaders in major financial and business centers around the world. Our investment in people, commitment to innovation, and focus on the future empower you to build an incredible career and thrive as an exceptional professional in a supportive culture. If you aspire to be the best, and work with the best, this is where you belong.


The Vendor Risk Management Analyst is an integral part of Latham’s Global Finance team. This role will be responsible for assessing, monitoring, and mitigating risks associated with our vendor relationships, as well as analyzing vendor risk profiles through various due diligence activities of new and existing vendors to identify potential risks and vulnerabilities, in order to develop risk profiles and categorize vendors based on risk levels. This role will be located in our Global Services Office (GSO) in Downtown Los Angeles. Please note that this role may be eligible for a flexible working schedule that allows for a hybrid and in-office presence.


Other key responsibilities include:

  • Ensuring vendor performance and compliance with contractual obligations and regulatory requirements, and preparing detailed reports and dashboards to communicate risk findings to management
  • Developing and implementing risk mitigation strategies to address identified risks, and collaborating with vendors and internal teams to ensure effective risk management practices are in place
  • Analyzing vendor performance metrics and reports to assess service quality, cost-effectiveness, and compliance, and providing recommendations for improvement and cost-saving opportunities
  • Coordinating and conducting vendor audits to evaluate compliance with company policies and industry standards, as well as documenting findings and following up on corrective actions
  • Assisting in the development and maintenance of vendor risk management policies and procedures, and ensuring alignment with industry best practices and regulatory requirements
  • Protecting and maintaining any highly sensitive, confidential, privileged, financial, and/or proprietary information that Latham & Watkins retains 

We’d love to hear from you if you:

  • Demonstrate strong analytical skills with proficiency in data analysis tools and software
  • Exhibit the ability to work in a team environment with a strong customer service focus
  • Possess strong communication skills

And have:

  • A bachelor’s degree, preferably a master’s degree, professional certification, or extended education in a related field
  • A minimum of four (4) years of experience in vendor risk management, compliance, or a related role
  • Relevant experience at a professional services firm or Fortune 500 company, preferably

Successful candidates will not only be provided with an outstanding career opportunity and welcoming environment, but will also be provided with a generous total compensation package with bonuses awarded in recognition of both individual and firm performance. Eligible employees can participate in Latham’s comprehensive benefit program which includes:

  • Healthcare, life and disability insurance
  • A generous 401k plan
  • At least 11 paid holidays per year, and a PTO program that accrues 23 days during the first year of employment and grows with tenure
  • Well-being programs (e.g. mental health services, mindfulness and resiliency, medical resources, well-being events, and more)
  • Professional development programs
  • Employee discounts
  • Affinity groups, networks, and coalitions for lawyers and staff

Latham & Watkins is an equal opportunity employer. The Firm prohibits discrimination against any employee or applicant for employment on the basis of race (including, but not limited to, hair texture and protective hairstyles), color, religion, sex, age, national origin, sexual orientation, gender identity, veteran status (including veterans of the Vietnam era), gender expression, marital status, or any other characteristic or condition protected by applicable statute.

Latham & Watkins LLP will consider qualified applicants with criminal histories in a manner consistent with the City of Los Angeles Fair Chance Initiative for Hiring Ordinance (FCIHO).  Please click the link below to review the Ordinance.


Please click here to review your rights under U.S. employment laws. 

#Associate #LI-SR1


USD $80,000.00 - USD $110,000.00 /Yr.

What Latham & Watkins employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom