1

Cybersecurity Risk Management Jobs in California

Cybersecurity Counsel

Mountain View, CA

$130K - $177K/yr

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

In this hybrid role, you will report to a Managing Counsel. You will: * Develop risk-based approaches to cybersecurity compliance that balance legal risk mitigation and regulatory requirements with ...

Oversee cybersecurity controls and risk management practices across cloud platforms, including Microsoft 365, Azure, SaaS applications, identity systems, and hybrid environments, to protect critical ...

Support the Risk Management Framework (RMF) Assessment and Authorization processes (Steps 0 through 4 and Step 6) throughout the various systems' cybersecurity lifecycles, including documentation of ...

Apply manager-approved risk management concepts to mitigate vulnerabilities in system security ... The Cybersecurity Analyst I will be required to evaluate and implement security controls and ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See California salary details

$56.3K

$131.2K

$183.6K

How much do cybersecurity risk management jobs pay per year?

As of Jul 21, 2026, the average yearly pay for cybersecurity risk management in California is $131,221.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,500.00 and $148,000.00 per year, depending on experience, location, and employer.

Can I make $200,000 a year in cyber security?

Cybersecurity risk management professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and roles in senior management or specialized fields. Salary levels vary based on industry, location, and the complexity of the organization's security needs.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst typically earns between $70,000 and $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in high-demand industries.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What does a cyber risk manager do?

A cyber risk manager assesses and prioritizes cybersecurity threats to an organization, develops strategies to mitigate risks, and implements security policies. They often use tools like risk assessment frameworks and require certifications such as CISSP or CISM to effectively manage security risks and ensure compliance.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working for large organizations with complex security needs.
What are popular job titles related to Cybersecurity Risk Management jobs in California? For Cybersecurity Risk Management jobs in California, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in California look for? The top searched job categories for Cybersecurity Risk Management jobs in California are:
What cities in California are hiring for Cybersecurity Risk Management jobs? Cities in California with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in California as of July 2026, with employment types broken down into 3% Locum Tenens, 87% Full Time, 7% Part Time, and 3% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $131,221 per year, or $63.1 per hour.

Junior Cybersecurity Risk Management Consultant

Del Oro Consulting

San Francisco, CA • On-site, Remote

$55 - $60/hr

Contractor

Medical, Dental, Vision, Retirement

This job post has expired today. Applications are no longer accepted.


Job description

Junior Cybersecurity Risk Management Consultant
$55-$60/hr | 3-Month Consultant Contract | W2 |Remote
Del Oro Consultingis seeking a Junior Cybersecurity Risk Management Consultant tosupport the day-to-day operations of an enterprise Third-Party Risk Management(TPRM) program. This consultant is responsible for coordinating vendor securityassessments, tracking remediation activities, maintaining accuratedocumentation, and ensuring vendor risk activities are completed efficientlyand in accordance with established security and compliance standards.
The idealcandidate is highly organized, detail-oriented, and experienced working withincybersecurity governance, risk, and compliance (GRC) environments. This is aremote engagement supporting a large enterprise cybersecurity team.
Responsibilities:
  • Support the onboarding of new third-party vendors into the organization's Third-Party Risk Management (TPRM) program.
  • Review vendor intake requests to ensure required information is complete and accurate.
  • Coordinate the distribution, collection, and tracking of vendor security questionnaires and assessment documentation.
  • Monitor vendor assessment progress and proactively follow up on outstanding questionnaires, evidence requests, and documentation.
  • Maintain accurate assessment records and workflow updates within the ServiceNow platform.
  • Collect, organize, and maintain vendor security documentation, including policies, certifications, and supporting evidence.
  • Coordinate remediation efforts by tracking identified security gaps and following up on corrective actions.
  • Validate vendor security controls and supporting documentation against established security requirements.
  • Support vendor risk tracking, reporting, and status updates for internal stakeholders.
  • Assist with daily operational activities within the Third-Party Risk Management program as assigned by the TPRM Manager.
  • Ensure all assigned work is completed according to established priorities and timelines.

Deliverables:
  • Vendor risk assessment documentation
  • Assessment status report updates
  • Updated vendor inventory records
  • Organize vendor security documentation repositories
  • Vendor communication logs
  • Engagement summary

Qualifications:
  • 3+ years of experience supporting Third-Party Risk Management (TPRM), Vendor Risk Management (VRM), Cybersecurity Risk Management, and/or Governance, Risk & Compliance (GRC) programs.
  • Experience coordinating vendor security assessments and managing assessment documentation.
  • Familiarity with industry security questionnaires (SIG, CAIQ, custom questionnaires, etc.).
  • Experience working with ServiceNow
  • Understanding of cybersecurity controls and vendor risk assessment processes.
  • Strong organizational skills with the ability to manage multiple vendor assessments simultaneously.
  • Excellent written and verbal communication skills with experience interacting directly with vendors and internal stakeholders.
  • Strong attention to detail and ability to maintain accurate records and documentation.

Details of Position:
  • Work Arrangement: Remote
  • $55-$60/hr Consultant, 3-Month Contract Opportunity on W2
  • Benefits include Medical, Dental, Vision & 401(k) (with a match)
  • Applicants must be authorized to work for any employer in the United States. We are currently unable to sponsor or take over sponsorship of employment Visa.

Del Oro Consulting is an equalopportunity employer, and all qualified applicants will receive considerationfor employment without regard to race, color, religion, sex, national origin,disability status, protected veteran status, or any other characteristicprotected by law.