1

Information Risk Management Jobs in California (NOW HIRING)

next page

Showing results 1-20

Information Risk Management information

See California salary details

$50.8K

$110.1K

$167.8K

How much do information risk management jobs pay per year?

As of Jun 10, 2026, the average yearly pay for information risk management in California is $110,095.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,800.00 and $127,300.00 per year, depending on experience, location, and employer.

What is Information Risk Management?

Information Risk Management is the process of identifying, assessing, and controlling risks to an organization's information assets. This includes protecting sensitive data from threats like cyberattacks, data breaches, and unauthorized access. Information risk managers develop policies and procedures to minimize risks, ensure compliance with regulations, and support business objectives. Their work helps organizations maintain data integrity, confidentiality, and availability.

What are some common challenges faced by professionals in Information Risk Management, and how can they be addressed?

Professionals in Information Risk Management often encounter challenges such as keeping up with rapidly evolving cyber threats, ensuring compliance with complex regulatory requirements, and effectively communicating risks to non-technical stakeholders. Staying current with industry trends and participating in ongoing training can help address knowledge gaps. Building strong relationships with IT, compliance, and business units fosters better collaboration and ensures risk mitigation efforts are aligned with organizational goals.

What are the key skills and qualifications needed to thrive in Information Risk Management, and why are they important?

To excel in Information Risk Management, you need a solid background in cybersecurity principles, risk assessment methodologies, and regulatory compliance, often supported by a degree in information security or a related field. Familiarity with risk management frameworks like ISO 27001, NIST, and certifications such as CISSP or CISM, as well as proficiency in using risk assessment tools, is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for translating technical risks into business terms and collaborating with stakeholders. These skills enable professionals to identify, assess, and mitigate information risks, safeguarding organizational assets and ensuring regulatory compliance.
What are popular job titles related to Information Risk Management jobs in California? For Information Risk Management jobs in California, the most frequently searched job titles are:
Infographic showing various Information Risk Management job openings in California as of June 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, 1% Temporary, and 2% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $110,095 per year, or $52.9 per hour.
Privacy & Information Security Risk Management Analyst II

Privacy & Information Security Risk Management Analyst II

Sutter Health

Sacramento, CA • On-site

Full-time

Posted 6 days ago


Sutter Health rating

8.3

Company rating: 8.3 out of 10

Based on 313 frontline employees who took The Breakroom Quiz

44th of 870 rated healthcare providers


Job description

We are so glad you are interested in joining Sutter Health!
Organization:
SHSO-Sutter Health System Office-Valley
Position Overview:
Uses the Sutter Health governance, risk management, and compliance (GRC) platform to conduct and validate technical security reviews and security assessments in alignment with the Sutter Health information security controls framework, state and federal regulations, and industry security best practices, culminating in the production of security risk assessment reports. Functions as a technical advisor to security leadership, Information Services (IS) departments, and Sutter Health business units on security-related issues and risks and provides support by leading resolution on complex security issues and initiatives. Provides security training to IS staff members through new hire orientation, just-in-time training, and regular department training. Develops and/or reviews technical information security policies, procedures, standards, and guidelines to support Sutter Health business initiatives in alignment with regulatory requirements, security best practices, and evolving technologies. Conducts technical security-related research and analysis and translates the results into meaningful input to the Information Security program.
Job Description:
****Please Note: While this position is listed as hybrid, regular in-office attendance is required. Candidates should be prepared to commute to the office on a consistent basis to support team collaboration and business needs.****
EDUCATION:
Equivalent experience will be accepted in lieu of the required degree or diploma.
  • Bachelor's in Business, Computer Science, Engineering, Information Security, Management, Mathematics, Science, Technology or related field

CERTIFICATION & LICENSURE:
  • CISSP or CRISC certification preferred, or one of the certifications will be required within one year of hire

TYPICAL EXPERIENCE:
  • 2 years recent relevant experience.

PREFERRED EXPERIENCE:
  • Third-party/vendor security risk assessments
  • Conducting formal risk assessments
  • GRC or third-party risk management platforms (e.g., ServiceNow VRM or equivalent)
  • Continuous security monitoring tools (e.g., BitSight or similar).
  • Experience assessing security risks affecting protected health information (PHI)

SKILLS AND KNOWLEDGE:
  • Proficient technical skills in planning, administration, and management of information systems, operational and technical security controls, and security risk analysis and management with thorough knowledge of information systems security concepts, current information security trends, practices including security processes, methods, and procedures.
  • Working knowledge of software, hardware, databases, networks, firewalls, encryption, and other systems security devices, including a good understanding of Transmission Control Protocol/Internet Protocol (TCP/IP), Domain Name System (DNS), Dynamic Host Configuration Protocol (DHCP), Active Directory, network topologies, and intrusion detection systems.
  • General knowledge regarding National Institute of Standards and Technology (NIST), Health Insurance Portability and Accountability Act/Health Information Technology for Economic and Clinical Health Act (HIPAA/HITECH), Federal Information Procession Standards (FIPS), and other related industry security standards, regulations, and best practices.
  • Advanced understanding of federal and state security and privacy-related regulatory requirements.
  • Good business acumen and advanced analytic skills, including the ability to analyze data and information, reach practical conclusions, recommend corrective actions, resolve conflicts, and institute effective changes.
  • Effective organizational and project management skills required, including the demonstrated ability to prioritize tasks, manage multiple projects simultaneously, and complete deliverables.
  • Attention to detail with time management and organization skills, including attention to detail, clear documentation, diagnostic capabilities and problem-solving skills.
  • Communication (written/verbal), interpersonal, and presentation skills to explain complex technical or sensitive information clearly and professionally to diverse audiences and all levels of internal and external constituencies.
  • Robust computer skills, including an advanced knowledge of Microsoft Office Suite (Word, Excel, Outlook, Access, Access Control List (ACL)), Microsoft Visio or other flowcharting tool, various database architectures and related security and assessment tools and applications.
  • Ability to identify key concepts, factors, and risks based on conversations and document them in clear and concise narrative.
  • Ability to work independently, as well as part of a multidisciplinary team, while demonstrating organization skills to efficiently and effectively conduct reviews and assessments within established timeframes and government regulations.

These Principal Accountabilities, Requirements and Qualifications are not exhaustive, but are merely the most descriptive of the current job. Management reserves the right to revise the job description or require that other tasks be performed when the circumstances of the job change (for example, emergencies, staff changes, workload, or technical development).
Job Shift:
Days
Schedule:
Full Time
Days of the Week:
Monday - Friday
Weekend Requirements:
As Needed
Benefits:
Yes
Unions:
No
Position Status:
Exempt
Weekly Hours:
40
Employee Status:
Regular
Sutter Health is an equal opportunity employer EOE/M/F/Disability/Veterans.
Pay Range is $86,216.00 to $129,334.40 / annual salary
The compensation range may vary based on the geographic location where the position is filled. Total compensation considers multiple factors, including, but not limited to a candidate's experience, education, skills, licensure, certifications, departmental equity, training, and organizational needs. Base pay is only one component of Sutter Health's comprehensive total rewards program. Eligible positions also include a comprehensive benefits package.

What Sutter Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom