1

Cybersecurity Risk Management Analyst Jobs in California

Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations. * Strong analytical, organizational, stakeholder-management, and written and verbal ...

Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations. * Strong analytical, organizational, stakeholder-management, and written and verbal ...

Commercial insurance operations experience within a corporate risk management department, commercial insurance brokerage, or underwriting organization. * Analytical and quantitative aptitude ...

Your Mission We are seeking a driven and detail-oriented Enterprise Risk Analyst to support two ... Qualifications * 5+ years of experience in enterprise risk management, GRC, cybersecurity risk ...

Showing results 21-40

Cybersecurity Risk Management Analyst information

What does a Cybersecurity Risk Management Analyst do?

A Cybersecurity Risk Management Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security policies, conduct risk assessments, and recommend controls to minimize potential threats. Their work involves monitoring security measures, ensuring compliance with regulations, and helping develop strategies to protect the organization from cyberattacks. Ultimately, they play a crucial role in safeguarding sensitive information and supporting overall cybersecurity posture.

What are some typical challenges a Cybersecurity Risk Management Analyst faces when working with cross-functional teams?

Cybersecurity Risk Management Analysts often collaborate with IT, legal, compliance, and business units to identify and mitigate risks. A common challenge is bridging the communication gap between technical and non-technical stakeholders, ensuring that risk recommendations are understood and actionable. Additionally, balancing business objectives with security requirements can be complex, requiring strong negotiation and diplomacy skills. Analysts must also stay updated on evolving threats while tailoring solutions to each department’s unique needs.

What are the key skills and qualifications needed to thrive as a Cybersecurity Risk Management Analyst, and why are they important?

To thrive as a Cybersecurity Risk Management Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and regulatory frameworks, typically backed by a degree in cybersecurity or a related field. Familiarity with tools such as risk management software, vulnerability scanners, and certifications like CISSP, CISM, or CRISC is highly valued. Strong analytical thinking, attention to detail, and effective communication skills help in translating technical risks into actionable insights for stakeholders. These skills ensure organizations can proactively identify, assess, and mitigate cyber risks to protect sensitive information and maintain regulatory compliance.

What is the difference between Cybersecurity Risk Management Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk Management AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentFocus on risk assessment, policy development, and complianceFocus on threat detection, incident response, and system monitoring
Employer & Industry UsageUsed in organizations prioritizing risk mitigation and complianceUsed across various sectors for security operations and monitoring

While both roles involve cybersecurity, the Cybersecurity Risk Management Analyst primarily assesses and manages risks, ensuring compliance and policy adherence. In contrast, the Cybersecurity Analyst concentrates on identifying threats, monitoring security systems, and responding to incidents. Both roles are essential but focus on different aspects of cybersecurity defense.

What are popular job titles related to Cybersecurity Risk Management Analyst jobs in California?

For Cybersecurity Risk Management Analyst jobs in California, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Risk Management Analyst jobs in California look for?

The top searched job categories for Cybersecurity Risk Management Analyst jobs in California are:

Infographic showing various Cybersecurity Risk Management Analyst job openings in California as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 15% Part Time, and 4% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution.

Department Manager, Cyber Security

Orange, CA • On-site

Orange County Transportation Authority
1 - 5K employees

$173K - $205K/yr

Full-time

Posted 6 days ago


Orange County Transportation Authority rating

9.7

Company rating: 9.7 out of 10

Based on 5 frontline employees who took The Breakroom Quiz


Job description

Job Description

Department Manager - Enterprise Cybersecurity

Under the direction of the Chief Information Officer, the Department Manager - Enterprise Cybersecurity establishes, directs, and advances OCTA's enterprise cybersecurity program, protecting information, technology, transportation operations, and critical infrastructure from evolving cyber risks.

As OCTA's senior cybersecurity leader, this position provides strategic direction for cybersecurity governance and risk management, security operations and incident response, data privacy and classification, and the secure adoption of cloud, artificial intelligence, operational, and emerging technologies. The role advises executive leadership on cybersecurity posture, material risks, resilience, regulatory obligations, significant incidents, and strategic investment priorities while building a mature, risk-based cybersecurity program that enables OCTA's business and public-service objectives.

This is an exempt position in Salary Grade 260: Min - $173,180.80 | Mid - $205,753.60 | Max - $238,305.60/year. The starting salary and level will be within this range based on qualifications.

This posting will remain open until a candidate is selected.

What You'll Do

  • Establish and lead OCTA's enterprise cybersecurity strategy, governance framework, policies, standards, performance objectives, and multi-year cybersecurity roadmap
  • Direct cybersecurity risk management across cloud and on-premises environments, enterprise networks, identity and access management, operational and transportation technologies, and critical infrastructure
  • Advise the CIO, executive leadership, and, as appropriate, the Board of Directors on cybersecurity posture, material risks, significant incidents, program maturity, remediation efforts, and investment priorities
  • Lead cybersecurity incident readiness and response, including incident command, executive communications, stakeholder coordination, evidence preservation, regulatory notifications, recovery priorities, exercises, and after-action reviews
  • Establish risk-based vulnerability management, privileged-access, least-privilege, network segmentation, exposure management, and security monitoring practices
  • Lead OCTA's Data Privacy and Data Classification Program, including sensitive-data discovery, information protection, data loss prevention, handling requirements, and data lifecycle considerations
  • Establish cybersecurity governance for artificial intelligence and emerging technologies, ensuring appropriate safeguards and human oversight
  • Direct third-party and supply-chain cybersecurity risk management, including vendor due diligence, contractual security requirements, monitoring, incident coordination, and remediation
  • Promote secure-by-design practices so cybersecurity considerations are incorporated early into technology projects, procurements, cloud modernization, system development, and operational changes
  • Partner closely with IS Operations and business leaders to develop practical, risk-informed security solutions that protect OCTA while supporting operational continuity and organizational objectives
  • Direct analysis of threat intelligence, security events, vulnerabilities, control performance, audit findings, third-party risks, and emerging technologies to identify trends and required actions
  • Lead targeted security awareness and role-based training programs and establish measures to evaluate effectiveness and compliance
  • Coordinate cybersecurity audits and assessments and ensure findings and corrective actions are appropriately tracked through closure
  • Develop and lead the cybersecurity workforce through mentoring, professional development, cross-training, effective use of consultants and contractors, and knowledge transfer
  • Build strategic relationships with transportation agencies, regulators, law enforcement, government partners, information-sharing organizations, vendors, and industry peers to strengthen cyber preparedness and awareness

What We're Looking For

  • Bachelor's degree in Computer Science, Mathematics, Business, or a related field, or an equivalent combination of education and experience
  • Minimum of eight years of related cybersecurity experience in business environments, including at least four years in a cybersecurity management position
  • Hands-on experience with network security services and technologies
  • Demonstrated experience leading enterprise cybersecurity governance, risk management, security operations, and incident response
  • Strong understanding of cybersecurity risks affecting cloud, enterprise infrastructure, identity, operational technology, transportation systems, and critical infrastructure
  • Experience developing cybersecurity strategies, policies, standards, performance measures, and multi-year roadmaps
  • Strong knowledge of vulnerability and exposure management, identity and privileged-access security, network segmentation, security monitoring, and remediation practices
  • Understanding of data privacy, data classification, information protection, and data loss prevention principles
  • Knowledge of cybersecurity considerations associated with artificial intelligence, cloud services, emerging technologies, and third-party/supply-chain risk
  • Demonstrated ability to lead significant cybersecurity incidents while balancing containment, service continuity, evidence preservation, operational safety, regulatory requirements, and recovery
  • Strong business and risk-management judgment with the ability to translate complex cybersecurity issues into clear recommendations for executive and nontechnical audiences
  • Proven ability to build strong partnerships with technology operations, business leaders, regulators, vendors, and external stakeholders
  • Experience leading and developing cybersecurity professionals, consultants, and contractors
  • One current or previously held security-related certification is preferred, such as CISM, CISSP, CISA, GSNA, GSAE, or comparable certification
  • An advanced degree is preferred

Why You'll Love It Here

  • Lead the enterprise cybersecurity program protecting technology and critical transportation infrastructure that supports mobility throughout Orange County
  • Serve as a trusted cybersecurity advisor to the CIO and executive leadership
  • Shape OCTA's long-term approach to cyber risk, resilience, data protection, artificial intelligence, cloud security, and emerging technologies
  • Lead cybersecurity strategy across both traditional enterprise IT and mission-critical operational and transportation technology environments
  • Build and develop a high-performing cybersecurity organization while strengthening partnerships across Information Systems and the agency
  • Collaborate with transportation agencies, government partners, regulators, law enforcement, and cybersecurity professionals on evolving threats and industry challenges
  • Make a meaningful public-service impact by strengthening the security and resilience of the systems that support OCTA's customers, employees, and transportation operations

Join a team where innovation, integrity, and strategic thinking are valued. Apply now to lead OCTA's Enterprise Cybersecurity program and help protect the technology, information, and critical infrastructure that keep Orange County moving.

OCTA is an equal employment opportunity employer that recruits, hires, and promotes qualified people without regard to race, color, religion, creed, ancestry, national origin, age, sex, pregnancy, gender, gender identity and/or expression, sexual orientation, marital status, medical condition, disability, genetic information, military and veteran status, or other legally protected status.


What Orange County Transportation Authority employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom