1

Cybersecurity Risk Management Jobs in Brea, CA (NOW HIRING)

Sr. Cybersecurity GRC Manager

Irvine, CA ยท On-site

$119K - $161K/yr

Strong knowledge of Information Security risk management frameworks, Governance, Risk, and ... Cybersecurity Regulation, PCI-DSS, FFIEC, SOX, and other relevant laws and regulations Strong ...

Sr. Cybersecurity GRC Manager

Irvine, CA ยท On-site

$132K - $204K/yr

Qualifications What You Will Bring โ€ข Minimum 8 years progressive experience in cybersecurity governance, risk management, or compliance with a deep understanding of security risk management, system ...

Sr. Cybersecurity GRC Manager

Irvine, CA ยท On-site

$119K - $161K/yr

Qualifications What You Will Bring โ€ข Minimum 8 years progressive experience in cybersecurity governance, risk management, or compliance with a deep understanding of security risk management, system ...

Collaborate with Quality, Regulatory, and Risk Management teams to support cybersecurity compliance and product lifecycle security activities. * Serve as a trusted advisor to engineering leadership ...

Principal Cybersecurity Architect

Irvine, CA ยท On-site

$170K - $210K/yr

Collaborate with Quality, Regulatory, and Risk Management teams to support cybersecurity compliance and product lifecycle security activities. * Serve as a trusted advisor to engineering leadership ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Brea, CA salary details

$59K

$137.7K

$192.7K

How much do cybersecurity risk management jobs pay per year?

As of Jun 8, 2026, the average yearly pay for cybersecurity risk management in Brea, CA is $137,730.00, according to ZipRecruiter salary data. Most workers in this role earn between $115,000.00 and $155,400.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.
What job categories do people searching Cybersecurity Risk Management jobs in Brea, CA look for? The top searched job categories for Cybersecurity Risk Management jobs in Brea, CA are:
What cities near Brea, CA are hiring for Cybersecurity Risk Management jobs? Cities near Brea, CA with the most Cybersecurity Risk Management job openings:

Sr. Cybersecurity GRC Manager

Hyundai Capital

Irvine, CA โ€ข On-site

$119K - $161K/yr

Full-time

Medical, Dental, Vision, Retirement

Posted 18 days ago


Job description

Who We Are

Through our service brands Hyundai Motor Finance, Genesis Finance, and Kia Finance, Hyundai Capital America offers a wide range of financial products tailored to meet the needs of Hyundai, Genesis, and Kia customers and dealerships.ย  We provide vehicle financing, leasing, subscription, and insurance solutions to over 3 million consumers and businesses. Embodying our commitment to grow, innovate, and diversify, we strive to reimagine the customer and dealer experience and launch innovative new products that broaden our market reach. We believe that success comes from within and are proud to support our team members through skill development and career advancement. Hyundai Capital America is an Equal Opportunity Employer committed to creating a diverse and inclusive culture for our workforce. We are a values-driven company dedicated to supporting both internal and external communities through volunteering, philanthropy, and the empowerment of our Employee Resource Groups. Together, we strive to be the leader in financing freedom of movement.

We Take Care of Our People

Along with competitive pay, as an employee of HCA, you are eligible for:

ย ย ย ย ย ย ย ย  Medical, dental, and vision plans with no-cost and low-cost options

ย ย ย ย ย ย ย ย  Annual employer HSA contribution

ย ย ย ย ย ย ย ย  401(k) matching and immediate vesting

ย ย ย ย ย ย ย ย  Vehicle purchase and lease discounts, plus monthly vehicle allowances by job level:

oย ย ย  Associate / Sr. Associate: $350

oย ย ย  Manager / Sr. Manager: $600

oย ย ย  Director: $800

oย ย ย  Executive Director: $900

oย ย ย  VP or Above: $1,000

ย ย ย ย ย ย ย ย  100% employer-paid life and disability insurance

ย ย ย ย ย ย ย ย  No-cost health and wellbeing programs, including a gym benefit

ย ย ย ย ย ย ย ย  Six weeks of paid parental leave

ย ย ย ย ย ย ย ย  Paid Volunteer Time Off, plus a company donation to a charity of your choice

What to Expect

The Sr. Cybersecurity Risk Manager requires a deep understanding of security risk management and the evolving threat landscape, ensuring the internal security risk strategy is resilient and forward-thinking to oversee the security risk posture internally, proactively identifying, assessing, and mitigating risks that could impact business operations, financial stability, and regulatory compliance. In addition, this role may assist the development of vendors/partners security risk evaluation to ensure alignment with our cybersecurity policies, regulatory requirements, and risk mitigation strategies.

What You Will Do

1.ย ย ย ย ย  Develop and executive internal security risk assessments, threat modeling, and impact analyses to identify vulnerabilities across internal leveraged solutions, systems, applications, and processes including guiding and supporting team to ensure effective collaboration for assigned projects and work efforts.

2.ย ย ย ย ย  Develop, execute and enhance a cybersecurity risk management framework aligned with business objectives and regulatory requirements.

3.ย ย ย ย ย  Establish and maintain security risk metrics by tracking Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), along with reporting mechanisms to communicate cybersecurity effectiveness and provide actionable insights to executives and stakeholders.

4.ย ย ย ย ย  Manage governance around internal cybersecurity risks, ensuring compliance with internal security policies and regulatory requirements.

What You Will Bring

ย ย ย  ย Minimum 8 years progressive experience in cybersecurity governance, risk management, or compliance with a deep understanding of security risk management, system development life cycle (SDLC), and the evolving threat landscape ensuring the internal security risk strategy is resilient and forward-thinking.

ย ย ย ย ย ย ย  Financial services industry preferred.

ย ย ย ย ย ย ย  Bachelor's degree in finance, business or related discipline.

ย ย ย ย ย ย ย  Certifications such as CISSP, CISM, CRISC, CGEIT, and ITIL are highly desirable.

ย ย ย ย ย ย ย  Strong knowledge of Information Security risk management frameworks, Governance, Risk, and Compliance process, IT general controls (e.g. asset classification, risk assessments, vulnerability and threat analysis, risk treatment, audit controls and remediation, vendor risk management, and IT risk management & reporting)

ย ย ย ย ย ย ย  Strong knowledge of Information Security & Risk Frameworks including ISO 27001/2, ISO 310002018, ISO 270052022; NIST Special Publications and Methodologies (e.g. SP800-12, 30, 37, 39, 53, 150, 161)

ย ย ย ย ย ย ย  Working knowledge of California Consumer Privacy Act (CCPA), Gramm-Leach-Bliley Act (GLBA), NYDFS Cybersecurity Regulation, PCI-DSS, FFIEC, SOX, and other relevant laws and regulations

ย ย ย ย ย ย ย  Strong understanding of financial regulatory frameworks and cybersecurity best practices.

ย ย ย ย ย ย ย  Intermediate skills with Microsoft Office Suite, including Word, Excel and PowerPoint.

ย ย ย ย ย ย ย  Ability to communicate complex security concepts to business leaders and technical teams.

ย ย ย ย ย ย ย  Proven ability to assess risk, interpret security findings, and provide strategic guidance.

ย ย ย ย ย ย ย  Exceptional attention to detail and quality.

ย ย ย ย ย ย ย  Ability to work autonomously and in a team environment.

ย ย ย ย ย ย ย  Excellent verbal and written communication, including presentation skills.

ย ย ย ย ย ย ย  Excellent interpersonal skills to successfully collaborate with cross functional departments.

ย ย ย ย ย ย ย  Strong orientation toward results coupled with reputation for integrity, creativity and good judgment

ย ย ย ย ย ย ย  Must have the ability to challenge, when appropriate, existing practices.

Work Environment

Employees in this class are subject to extended periods of sitting, standing, and walking, vision to monitor and moderate noise levels. Work is performed in an at home and office environment.

The posted salary range for this job takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; geographic location, and other business and organizational needs. Successful candidates may be hired anywhere in the salary range based on these factors. It is uncommon to hire candidates at or near the top of the range.

California Privacy Notice

This notice only applies to our applicants who reside in the State of California.

The latest version of our Privacy Policy can be found here. This Privacy Policy provides you with notice, at or before the point of collection, about the categories of personal information to be collected from you, the purposes for which your personal information is collected or used, and whether that information is sold or shared, so that you can exercise meaningful control over our use of your personal information. We are providing this notice to comply with the California Consumer Privacy Act of 2018, as amended as amended by the California Privacy Rights Act of 2020 ("CCPA").ย 

If you have any questions about CCPA regarding California residents or HCA team members, please contact the Privacy Team at Privacy2@hcs.com.

#LI-DNI