1

Information Security Analyst Jobs in Santa Rosa, CA

... Information Security, Platform Infrastructure Engineering, and more - provide support and guidance ... The Role The Staff Data Analyst will join the Block Compliance Analytics team chartered to put data ...

Senior GRC Engineer

Bodega Bay, CA · On-site

$135K - $186K/yr

The Role Block Information Security is an engineering-driven team focused on scaling security ... analysis, control monitoring, classification, and assessment * Build the evals, benchmarks, and ...

next page

Showing results 1-20

Information Security Analyst information

See Santa Rosa, CA salary details

$43.7K

$105.7K

$172.7K

How much do information security analyst jobs pay per year?

As of Sep 7, 2026, the average yearly pay for information security analyst in Santa Rosa, CA is $105,673.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,400.00 and $125,200.00 per year, depending on experience, location, and employer.

What does an information security analyst do?

An Information Security Analyst is responsible for protecting an organization's computer systems and networks from cyber threats. They monitor networks for security breaches, investigate violations, and implement measures such as firewalls and encryption programs to safeguard sensitive information. Analysts also conduct security assessments, develop security policies, and educate staff about security best practices. Their work helps ensure the confidentiality, integrity, and availability of critical data.

How to become an information security analyst?

Information security analysts create and implement an organization’s plan to defend against computer network security threats. The minimum requirement to become an information security analyst is a bachelor’s degree in computer science or management information systems. Focus your coursework in systems security, data management, cybersecurity, and software testing. You may find an internship as a way to gain experience and begin your career in cybersecurity.

What are the key skills and qualifications needed to thrive as an information security analyst, and why are they important?

To thrive as an Information Security Analyst, you need a solid understanding of cybersecurity principles, risk management, and network security, typically backed by a degree in computer science or a related field. Familiarity with security information and event management (SIEM) tools, firewalls, intrusion detection systems, and certifications like CISSP or CompTIA Security+ are commonly required. Strong analytical thinking, problem-solving abilities, and effective communication skills help you identify threats and convey risks to stakeholders. These competencies are crucial for protecting organizational assets, ensuring regulatory compliance, and minimizing potential cyber threats.

What are some common challenges information security analysts face when responding to security incidents?

Information Security Analysts often encounter challenges such as quickly identifying the scope of a breach, coordinating with various teams, and managing the pressure to restore normal operations while preserving evidence for forensic analysis. They must communicate clearly with both technical and non-technical stakeholders and stay up to date with evolving threats. Handling multiple incidents simultaneously and ensuring compliance with regulatory requirements can also add complexity to the role.

What is the difference between Information Security Analyst vs Network Security Analyst?

AspectInformation Security AnalystNetwork Security Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, Cisco CCNA Security, CISSP
Work EnvironmentCorporate IT departments, cybersecurity firmsNetwork operations centers, IT departments
Primary FocusOverall security policies, threat detection, incident responseNetwork infrastructure security, firewall management, intrusion detection

While both roles focus on cybersecurity, an Information Security Analyst has a broader scope, handling overall security strategies and incident response. A Network Security Analyst specializes in securing network infrastructure and managing network-specific threats. Both roles often require similar certifications and work environments, but their core responsibilities differ in scope and focus.

Is it hard to become an information security analyst?

Becoming an information security analyst typically requires a bachelor's degree in cybersecurity, computer science, or a related field, along with relevant skills in network security, risk assessment, and familiarity with security tools. Certifications like CompTIA Security+ or CISSP can enhance job prospects and demonstrate expertise. The role often involves continuous learning due to evolving threats and technologies.

What are the most commonly searched types of Information Security Analyst jobs in Santa Rosa, CA?

The most popular types of Information Security Analyst jobs in Santa Rosa, CA are:

What are popular job titles related to Information Security Analyst jobs in Santa Rosa, CA?

For Information Security Analyst jobs in Santa Rosa, CA, the most frequently searched job titles are:

What job categories do people searching Information Security Analyst jobs in Santa Rosa, CA look for?

The top searched job categories for Information Security Analyst jobs in Santa Rosa, CA are:

What cities near Santa Rosa, CA are hiring for Information Security Analyst jobs?

Cities near Santa Rosa, CA with the most Information Security Analyst job openings:

Infographic showing various Information Security Analyst job openings in Santa Rosa, CA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $105,673 per year, or $50.8 per hour.

Senior Information Security Analyst

Goldbelt, Inc.

Petaluma, CA • On-site

$100 - $140/hr

Other

Medical, Dental, Vision, Retirement, PTO

Re-posted yesterday


Job description

Overview

Please note that this position is contingent upon the successful award of a contract currently under bid.

Peregrine is a pioneer within the cybersecurity industrial control systems and the Internet of Things, supporting many federal and commercial customers. Peregrine's experienced staff knows the cybersecurity and operational technology environment and provides these capabilities for our customers daily.

Summary:

The Senior Information Security Analyst is responsible for the overall cybersecurity of assigned networks and devices. They must have intimate knowledge of federal government, Department of Defense, and U.S. Coast Guard cybersecurity requirements.

Responsibilities

Essential Job Functions:

  • Aggressively manage Cyber security accreditation requirements by working closely with the Program Manager, system administrators, database administrators and other key personnel to ensure all system accreditations remain current.
  • Ensure that all initial and recurring certification and accreditation activities are completed in accordance with DoDI 8500.01, Cyber Security, and DoDI 8510.01, Risk Management Framework (RMF) for assigned information systems, as well as maintaining compliance with the Federal Information Security Management Act (FISMA) of 2002 and other applicable directives for the assigned information systems.
  • Working directly with leadership, developers, engineers, system and database administrators to track changes to the system configurations and software, conducting regular reviews, updates and maintenance of certification and accreditation plans, topology drawings, and associated documents, and uploading completed documents to eMASS.
  • Schedule, oversee and document information system compliance testing, to include weekly Assured Compliance Assessment Solution (ACAS) scans and annual execution and testing of the Contingency Plans.
  • Manage accreditation and annual compliance actions using eMASS and the U.S. Coast Guard tracking tools to ensure annual reviews, control tests and contingency plan tests are completed on schedule to comply with FSMA requirements and keep the Program Manager informed of compliance and status of ATO efforts via updates to the PM’s Drumbeat and Metrics products.
  • Conduct a continuous review of all applications and database tools that make up the family of systems to ensure all software versions are registered and approved for use by the U.S. Coast Guard.
  • Conduct an annual review and update of all parent and child system profiles in the DHS approved repository system to ensure system’s registrations are complete and accurate, and that essential waivers for Data-At-Rest (DAR) and unsupported Commercial-Off-The-Shelf (COTS) software are documented and approved by U.S. Coast Guard CIO so that accreditations are not adversely affected.
  • Serve as Information Assurance Officer (IAO)/Information Systems Security Officer (ISSO), directly advising and assisting the Program Manager, developers, engineers, system and database administrators and staff on all cyber security policy, configuration and compliance matters.
    • This includes all aspects of cyber security that may affect the system security posture, to include emerging threats published in Cyber Alerts, Communication Tasking Orders, and vulnerability alerts and bulletins issued under the Information Assurance Vulnerability Management program.
  • As IAO/ISSO, advise the team on ports, protocols and services (PPS) approved for use by the U.S. Coast Guard, and register new PPS in the U.S. Coast Guard PPS Management Registry.
  • Prior to testing, identify Security Technical Implementation Guides (STIGs) to be applied to systems under development and test, and identify appropriate vulnerability scanning tools to be used during testing, to include the ACAS and Security Content Automation Protocol (SCAP) Compliance Checker automated scanning tools.
  • The IAO/ISSO will assist during scanning and advise the team on the remediation of findings identified during testing.
  • Following testing, the IAO will collect, collate, review and validate all test results and prepare supporting documentation, reports and artifacts to support the certification and accreditation of the system. Following accreditation, the IAO/ISSO will track and manage open findings in the Risk Assessment Report until mitigated or closed.
  • Provide expert advice in support of special projects, to include the development of an automated Cross Domain Solution (CDS) for use by the program and closely coordinate actions with the U.S. Coast Guard Cross Domain Solutions Office (USCGCDSO) and the Department of Homeland Security Unified Cross Domain Management Office (UCDMO).
    • This support includes authoring and submitting detailed system documentation and architectural drawings and working closely with both USCGCDSO and UCDMO personnel to navigate through a complex and highly technical approval process.
  • On a daily and weekly basis, provide authoritative cyber security advice during Internal Review Boards and make recommendations on open Configuration Change Requests (CCRs); Application Change Requests (ACRs), Database Change Requests (DBCRs), QA Trouble Reports (QTRs), Problem Reports (PRs), and Program Trouble Reports (PTRs).
Qualifications

Necessary Skills and Knowledge:

  • Proven record of honesty and integrity in all relationships.
  • Demonstrated leadership and organizational skills.
  • Excellent interpersonal skills and a collaborative management style.
  • Excellent communication skills, both verbal and written.
  • Excellent computer skills and proficient in Excel, Word, PowerPoint, Outlook, Visio, and Access.

Minimum Qualifications:

  • Minimum of five (5) years relevant experience.
  • Detailed knowledge of DoD Risk Management Framework.
  • Experience in an IAO/ISSO or Information Assurance Manager (IAM)/Information Systems Security Manager (ISSM) position.
  • Appropriate professional certifications per DoD 8570.01 (CISSP, GSLC or equivalent).
  • Must be eligible for a federal Public Trust clearance.

Preferred Qualifications:

  • Bachelors degree in cybersecurity or related degree.
  • CISSP Certification.
Pay and Benefits

The annual salary range for this position is $100,000 to $140,000.

At Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.

#J-18808-Ljbffr