1

Cybersecurity Risk Management Jobs in California

Oversee third-party cybersecurity risk management, including vendor assessments, SOC report reviews, cloud security evaluations, ongoing risk monitoring, and remediation of control gaps. * Ensure ...

New

Cyber Risk Lead

San Francisco, CA · On-site

$180 - $210/hr

... cyber security risk across Nscale's global AI infrastructure and build the risk function from the ground up. This senior individual contributor role sits at the intersection of risk management ...

Project Manager III

Poway, CA · On-site

$100K - $183K/yr

Third Party and Supplier Cybersecurity Risk * Administer and support the third party risk management program by collecting, reviewing, and assessing supplier cybersecurity compliance information ...

Senior Manager MedTech Cybersecurity

Irvine, CA · On-site +1

$119K - $161K/yr

Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred. * Excellent communication and collaboration skills, with the ability to network ...

Senior Manager MedTech Cybersecurity

Irvine, CA · On-site +1

$119K - $161K/yr

Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred. * Excellent communication and collaboration skills, with the ability to network ...

Showing results 41-60

Cybersecurity Risk Management information

See California salary details

$56.3K

$131.2K

$183.6K

How much do cybersecurity risk management jobs pay per year?

As of Aug 12, 2026, the average yearly pay for cybersecurity risk management in California is $131,221.00, according to ZipRecruiter salary data. Most workers in this role earn between $109,500.00 and $148,000.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in cybersecurity risk management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in cybersecurity risk management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.
What are popular job titles related to Cybersecurity Risk Management jobs in California? For Cybersecurity Risk Management jobs in California, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in California look for? The top searched job categories for Cybersecurity Risk Management jobs in California are:
What cities in California are hiring for Cybersecurity Risk Management jobs? Cities in California with the most Cybersecurity Risk Management job openings:
Infographic showing various Cybersecurity Risk Management job openings in California as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 14% Part Time, 2% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $131,221 per year, or $63.1 per hour.

Cybersecurity Internship Fall 2026 - Enterprise Risk Management

Tevora

Irvine, CA • On-site

$27/hr

Other

Re-posted 8 days ago


Job description

Consultant Development Program (Fall)
at Tevora
Irvine, CA, and Fairfax, VA - DC Local
 

(Fall): Ouranticipatedstart date for this cohort willbe on October 5th-December 11th 

 
If you haven't heard of Tevora, it's because we've done our job!
 
Tevora is a tight-knit community of professionals with a shared passion for our craft. Every day, we combine in-depth knowledge of cybersecurity, technology, and compliance to help create more secure digital environments. To Tevorans, every problem is a puzzle in need of solving. We strongly believe that if we put smart, driven people in a room together, they will accomplish great things. We maintain a supportive culture that celebrates continuous learning, diverse perspectives, and sharing the wins. That's why we have our eyes on you.
 
What is the Cybersecurity Consultant Development Program?  
Our Cybersecurity Consultant Development Program is an immersive paid-training internship program designed to help participants strengthen the technical and professional skills needed to enter the workforce as a full-time Information Security Associate.
Security Practice Area: Enterprise Risk Management (ERM) 
  • Aid in the development and maintenance of Enterprise Risk Management programs for organizations across all industries 

  • Conduct Enterprise Risk Assessments and analyze potential exposure at a strategic level 

  • Perform Vendor Risk Assessments on behalf of client organizations 

  • Develop Governance frameworks and Strategies for managing information security 

  • Provide General Advisement Services to help organizations adequately address information security risks upon changes to strategic initiatives, projects, and infrastructure architecture 

What's the Role? 

The Developing Consultant (DC) is an up-and-coming part of the client-facing consulting team. DCs are responsible for helping in conducting project delivery activities based on their selected Tevora Information Security practice areas, including Enterprise Risk, Compliance, Solutions Implementation, and Threat Research. Interns are expected to continually develop their skills through personal development and Information Security industry participation. 

Key Responsibilities: 
  • Develop technical and business skills required to perform billable work on projects as quickly as possible 

  • Learn about industry-standard certifications and their benefits 

  • Learn about National and International standards and frameworks like PCI-DSS, HIPAA, and ISO 27001 

  • Observe implementations of Enterprise Security Solutions 

  • Observe and help with internal and external penetration testing and social engineering projects 

  • Plan technical execution plans to meet business requirements 

  • Gather requirements to complete execution plans 

  • Execute on previously designed plans 

  • Document execution procedures andprovideprofessional insights into the technologies involved 

  • Assist Consultants with client engagements 

Necessary skills and qualifications: 

Every DC at Tevora is a technologist at heart but understands the critical intersection between business and technology. Foundationally, the ideal candidate will have basic familiarity with: 

  • Networking concepts like firewalls, routers, switches, and DNS 

  • Computer troubleshooting and server systems administration 

  • Business planning and accounting 

  • Any knowledge of compliance frameworks is a plus 

Abilities: 

  • Multi-tasking and time management skills 

  • Dynamic, enthusiastic, and excellent interpersonal skills 

  • Excellent writing both expository and technical documentation 

  • Intermediate working knowledge of Excel and Word 

  • Self-starter who likes to tinker and learn on their own 

Education and Experience: 
  • Bachelor's Degree from an accredited 4-year university (or Military equivalent) or currently enrolled at an accredited 4-year university (or Military equivalent) 

  • IT, Cybersecurity, and Information Security certifications a plus 

Additional requirements: 
  • Eligibility to work in the United States. 

  • Required to work onsite at our Fairfax, VA, or Irvine, CA, location. 

We've got you covered! 
  • Paid Sick Time Off 

  • Vibrant work culture 

  • Career advancement opportunities 

$27 - $27 an hour
Thank you for your interest in our Consultant Development Program (CDP). If you are selected for this program, you will become a Developing Consultant with us. This opportunity will challenge and motivate both your aptitude and attitude in Cyber Security. Successful completion of our program as a Developing Consultant may lead to a full-time offer as an entry-level Information Security Associate.
 
EEOC Statement
 
Tevora is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, disability status, or other applicable legally protected characteristics.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job