1

Cybersecurity Risk Management Jobs in Santa Rosa, CA

... and cybersecurity best practices. As one of the fastest growing firms in the nation, BT has the ... Provide leadership, management and strategic direction with a focus on providing an exceptional ...

next page

Showing results 1-20

Cybersecurity Risk Management information

See Santa Rosa, CA salary details

$62.3K

$145.4K

$203.4K

How much do cybersecurity risk management jobs pay per year?

As of Jul 21, 2026, the average yearly pay for cybersecurity risk management in Santa Rosa, CA is $145,372.00, according to ZipRecruiter salary data. Most workers in this role earn between $121,400.00 and $164,000.00 per year, depending on experience, location, and employer.

Can I make $200,000 a year in cyber security?

Cybersecurity risk management professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and roles in senior management or specialized fields. Salary levels vary based on industry, location, and the complexity of the organization's security needs.

What are some common challenges faced by professionals in Cybersecurity Risk Management, and how can they be addressed?

Professionals in Cybersecurity Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with industry regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and close collaboration with IT, legal, and business teams. Building strong partnerships across departments and investing in ongoing training can help mitigate these obstacles and support proactive risk management.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst typically earns between $70,000 and $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in high-demand industries.

What is the difference between Cybersecurity Risk Management vs Cybersecurity Analyst?

AspectCybersecurity Risk ManagementCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentRisk assessment, policy development, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government, large enterprisesIT departments, cybersecurity firms, corporate security teams

Cybersecurity Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy creation and strategic planning. In contrast, a Cybersecurity Analyst primarily monitors security systems, responds to incidents, and analyzes vulnerabilities. Both roles require similar certifications but serve different functions within cybersecurity teams.

What are the key skills and qualifications needed to thrive in Cybersecurity Risk Management, and why are they important?

To thrive in Cybersecurity Risk Management, you need a solid understanding of information security principles, risk assessment methodologies, compliance standards, and typically a degree in cybersecurity or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security tools, and professional certifications like CISSP or CRISC is highly valued. Strong analytical thinking, effective communication, and problem-solving skills help professionals translate technical risks for non-technical stakeholders and foster collaboration. These competencies are crucial to proactively identifying threats, managing vulnerabilities, and ensuring organizational resilience in a rapidly evolving digital landscape.

What does a cyber risk manager do?

A cyber risk manager assesses and prioritizes cybersecurity threats to an organization, develops strategies to mitigate risks, and implements security policies. They often use tools like risk assessment frameworks and require certifications such as CISSP or CISM to effectively manage security risks and ensure compliance.

What is cybersecurity risk management?

Cybersecurity risk management is the process of identifying, assessing, and prioritizing risks to an organization's digital assets and information systems. It involves implementing strategies and controls to minimize the impact of potential cyber threats, such as data breaches, malware, and unauthorized access. The goal is to balance security measures with business needs, ensuring sensitive information remains protected while maintaining operational efficiency. Effective risk management is ongoing, adapting to new threats and changes within the organization.

Can you make $500,000 a year in cyber security?

Cybersecurity risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working for large organizations with complex security needs.
What are popular job titles related to Cybersecurity Risk Management jobs in Santa Rosa, CA? For Cybersecurity Risk Management jobs in Santa Rosa, CA, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Risk Management jobs in Santa Rosa, CA look for? The top searched job categories for Cybersecurity Risk Management jobs in Santa Rosa, CA are:
What cities near Santa Rosa, CA are hiring for Cybersecurity Risk Management jobs? Cities near Santa Rosa, CA with the most Cybersecurity Risk Management job openings:
Network and Infrastructure Security Specialist

Network and Infrastructure Security Specialist

Solairus Aviation

Petaluma, CA • On-site

$85K - $93K/yr

Full-time

Re-posted 13 days ago


Job description

The IT Network and Infrastructure Security Specialist is responsible for the administration, security, and resilience of the organization’s network, server, and Microsoft cloud infrastructure. This role ensures secure configuration, monitoring, and maintenance of enterprise IT systems, including firewalls, switches, wireless networks, identity platforms, physical and virtual servers, and cloud environments.


The specialist works closely with IT, infrastructure, and security teams to safeguard systems against threats, maintain high availability, and support security initiatives across the organization. This position requires strong hands-on experience in IT infrastructure administration as well as practical security administration expertise.


Network and Infrastructure Administration
  • Manage, maintain, and troubleshoot network infrastructure, including switches, routers, firewalls, VPN appliances, and wireless systems.
  • Administer Windows and Linux servers, virtualization platforms (VMware / HyperV), and enterprise storage solutions.
  • Ensure network performance, availability, and uptime through proactive monitoring and maintenance.
  • Implement and maintain secure configurations, patching, hardening standards, and baseline system builds.
Security Administration
  • Manage and monitor security tools, including Identity Management (OKTA), Mobile Device Management (MDM), Remote Monitoring and Management (NinjaOne), firewalls, IDS/IPS, vulnerability scanners, and identity security platforms.
  • Assist Security Analysis with SIEM and EDR administration support.
  • Maintain endpoint security policies, access controls, MFA, privileged accounts, and identity governance settings.
  • Perform and validate vulnerability scans, system hardening, and remediation of infrastructure weaknesses.
  • Ensure network segmentation, zero-trust controls, and secure access principles are implemented across environments.
Incident Management and Response
  • Participate in incident response activities, supporting containment, remediation, and recovery actions.
  • Help investigate security alerts, perform triage, and support containment, eradication, and recovery activities.
  • Conduct root-cause analysis and contribute to strengthening security controls to reduce recurrence.
  • Maintain incident documentation, reporting, and continuous improvement of response processes.
  • Collaborate with thirdparty security partners (SOC/MDR) on detection and mitigation activities.
Risk Management and Compliance
  • Support risk assessments across network, server, cloud, and identity systems.
  • Document, track, and support remediation of risks and vulnerabilities across infrastructure assets. Assist with IT and security policy enforcement, compliance audits, and regulatory alignment (NIST, CIS, SOC 2, GDPR, CCPA).
  • Participate in building and maintaining security roadmaps and improvement plans.
Collaboration and Operational Support
  • Work with IT, cloud, infrastructure, and business units to ensure secure design and implementation of systems.
  • Provide reporting on infrastructure health, security posture, patch status, and risk findings.
  • Support security awareness initiatives and ensure proper security practices are followed throughout the organization.
Identity and Privileged Account Management
  • Administer identity and privileged account management using Okta, including lifecycle management, MFA enforcement, rolebased access, and privileged identity controls.
  • Maintain endpoint security policies, access controls, MFA, privileged accounts, and identity governance settings.
  • Perform and validate vulnerability scans, system hardening, and remediation of infrastructure weaknesses.
  • Ensure network segmentation, zerotrust controls, and secure access principles are implemented across environments.

Associate’s or bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field (or equivalent experience).

  • 3+ years of hands-on experience in IT infrastructure administration, network administration, or security operations.
  • Strong experience managing enterprise networks (LAN/WAN), switches, firewalls, VPN, and wireless systems.
  • Advanced working knowledge in Microsoft M365 administration.
  • Working knowledge of Windows Server, Active Directory, Group Policy, Linux systems, and virtualization platforms.
  • Experience with security tools (SIEM, EDR, firewalls, vulnerability scanners, identity security).
  • Solid understanding of cybersecurity principles, network security, identity and access management, and cloud security (AWS/Azure).
  • Ability to analyze threats, evaluate risks, and provide practical remediation recommendations.
  • Effective communication, analytical thinking, and problem-solving skills.

Solairus Aviation embraces diversity and equal opportunity.  We are committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better our work will be.

To comply with the Americans with Disabilities Act (ADA) regulations, the principal duties in job descriptions must be essential to the job. To identify essential functions, focus on the purpose and the result of the duties rather than the manner in which they are performed. The following definition applies: a job function is essential if the removal of that function would fundamentally change the job

Salary Range: $85,000 - $93,000