1

Cybersecurity Risk Management Jobs in California

Cybersecurity Counsel

Mountain View, CA ยท On-site

$130K - $177K/yr

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

Cybersecurity Program Manager

Watsonville, CA ยท On-site

$116K - $158K/yr

Oversee cybersecurity controls and risk management practices across cloud platforms, including Microsoft 365, Azure, SaaS applications, identity systems, and hybrid environments, to protect critical ...

At least 3 to 5 years of experience in cybersecurity, information security, compliance, IT risk management, security operations, or a closely related IT discipline. * Practical experience supporting ...

Support the Risk Management Framework (RMF) Assessment and Authorization processes (Steps 0 through 4 and Step 6) throughout the various systems' cybersecurity lifecycles, including documentation of ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See California salary details

$56.3K

$131.2K

$183.6K

How much do cybersecurity risk management jobs pay per year?

As of Aug 11, 2026, the average yearly pay for cybersecurity risk management in California is $131,221.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,500.00 and $148,000.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.
What are popular job titles related to Cybersecurity Risk Management jobs in California? For Cybersecurity Risk Management jobs in California, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in California look for? The top searched job categories for Cybersecurity Risk Management jobs in California are:
What cities in California are hiring for Cybersecurity Risk Management jobs? Cities in California with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in California as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 14% Part Time, 2% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $131,221 per year, or $63.1 per hour.

Cybersecurity Counsel

Waymo

Mountain View, CA โ€ข On-site

$130K - $177K/yr

Full-time

Posted 27 days ago


Job description

As part of Waymo's Legal team, you will work on the exciting legal issues surrounding our transformational autonomous driving technology and help drive our business lines forward from technology ideation through scaled commercial deployment. We partner with our public policy, safety, security and privacy experts to define transportation policy for the autonomous driving world to come, advising on regulatory changes that support and protect our users around the world. We collaborate with our engineering, product, strategy and operations teams to develop and protect our intellectual property portfolio and drive our corporate and commercial transactions. We ensure compliance with an increasingly complex and dynamic range of global regulations. And we anticipate, mitigate, and litigate high-profile and precedent-setting legal matters.

In this hybrid role, you will report to a Managing Counsel.

You will:

  • Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with business objectives.

  • Partner effectively with Security, Engineering, Safety, and Product teams on vulnerability management, threat analyses, and cybersecurity risk assessments.

  • Spearhead the evolution of Waymo's cybersecurity incident response and reporting program in connection with the domestic and international expansion of its autonomous vehicle operations.

  • Drive efforts to manage cybersecurity risk effectively within the company's supplier and partner ecosystem and promote supply chain security.
  • Support internal and external audits, assessments, and regulatory inquiries related to cybersecurity compliance.
  • Monitor emerging cybersecurity laws, regulations, executive orders, and agency guidance, and lead business-focused compliance efforts.

You have:

  • Law degree (LLB, LLM, or JD), plus at least 5 years of experience counseling on cybersecurity matters with a law firm, government agency, or in-house legal department.

  • Excellent written and oral communication skills with ability to explain complex legal and cybersecurity issues cogently to technical and non-technical audiences, including executives.

  • Experience advising clients on cybersecurity compliance and incident response programs (e.g., ransomware events, supply chain compromises, and insider threats), including incident containment, forensic investigations, and reporting programs for complying with federal, state, and international laws and regulations.

  • Experience with supply chain cybersecurity risk management, including advising on third-party security risk assessments, preparation of SBOMs and HBOMs, and supply chain cybersecurity.
  • Strong organizational skills and attention to detail; ability to manage a significant workload with competing deadlines in a fast-paced environment.
  • Proficiency and comfort navigating ambiguity and developing effective, business-oriented solutions to managing legal and cybersecurity risk; enthusiasm for winning together as a team and working collaboratively with legal and non-legal stakeholders.

We prefer:

  • Extensive knowledge of applicable standards for cybersecurity, including NIST CSF, ISO 27001, and/or ISO 28000.

  • Experience engaging with regulators, such as CISA, FBI, or state attorneys general, on cybersecurity matters.

  • Experience advising on security risk management in connection with AI/ML systems, operational technology, cyber physical systems, critical infrastructure, or autonomous systems.

  • Cybersecurity or information security certifications (e.g., CISSP, CISM).
  • Experience advising and participating in incident response teams in connection with cybersecurity attacks.
  • Technical background in cybersecurity or demonstrated experience working closely with security engineers and professionals.