1

Information Security Risk Intern Jobs in California

Security Risk Manager

San Francisco, CA ยท Hybrid

$194K - $220K/yr

About you * 7+ years of experience in information security with a strong focus on security risk management and GRC. * Demonstrated experience building or leading a security risk management program ...

Security Risk Manager

San Francisco, CA ยท On-site

$194K - $220K/yr

About you * 7+ years of experience in information security with a strong focus on security risk management and GRC. * Demonstrated experience building or leading a security risk management program ...

About the Role The Information Security Officer will have end-to-end ownership of MEDvidi ... You will inherit a completed Security Risk Analysis and be responsible for turning identified risks ...

This person will oversee security risk management, compliance, incident response, and cybersecurity ... Oversee information security operations, including threat intelligence, vulnerability management ...

About you * 7+ years of experience in information security with a strong focus on security risk management and GRC. * Demonstrated experience building or leading a security risk management program ...

next page

Showing results 1-20

Information Security Risk Intern information

What does an information security risk intern do?

An Information Security Risk Intern assists organizations in identifying, assessing, and mitigating risks related to information security. Their tasks typically include supporting risk assessments, helping to develop security policies, monitoring compliance, and analyzing security incidents. Interns often work closely with IT and security teams to learn about cybersecurity best practices and regulatory requirements. This role is ideal for students or recent graduates interested in gaining hands-on experience in information security and risk management.

What are the key skills and qualifications needed to thrive as an information security risk intern, and why are they important?

To thrive as an Information Security Risk Intern, you need foundational knowledge of cybersecurity principles, risk management concepts, and current security threats, often supported by coursework in information security or a related field. Familiarity with tools such as risk assessment software, vulnerability scanners, and security information and event management (SIEM) systems, as well as certifications like CompTIA Security+ or ISO 27001 awareness, is desirable. Strong analytical thinking, attention to detail, and effective communication skills help interns excel in identifying risks and collaborating with cross-functional teams. These competencies are crucial for accurately assessing threats and supporting the organization's efforts to mitigate security risks.

What are some common challenges an information security risk intern may face during their internship?

As an Information Security Risk Intern, you may encounter challenges such as understanding complex regulatory requirements, adapting to rapidly evolving security threats, and learning to use specialized risk assessment tools. Interns often need to quickly become familiar with internal policies, frameworks like NIST and ISO 27001, and effective communication with cross-functional teams to identify and report vulnerabilities. Balancing learning opportunities with real-world project deadlines can also be demanding, but these experiences provide valuable exposure to the dynamic nature of cybersecurity risk management.

What is the difference between Information Security Risk Intern vs Cybersecurity Risk Analyst?

AspectInformation Security Risk InternCybersecurity Risk Analyst
Required CredentialsTypically pursuing or recent graduate with relevant courseworkOften requires certifications like CISSP, CISA, or Security+
Work EnvironmentInternship setting, learning-focused, entry-levelFull-time professional role, more responsibility
Employer & Industry UsageInternships in tech, finance, government sectorsEstablished companies, cybersecurity firms, financial institutions
Comparison Search IntentUnderstanding entry-level roles in security riskSeeking professional risk analysis positions

The main difference is that an Information Security Risk Intern is an entry-level, learning-focused position often held by students or recent graduates, while a Cybersecurity Risk Analyst is a full-time professional role requiring more experience and certifications. Interns gain foundational knowledge, whereas analysts perform detailed risk assessments and develop security strategies.

What cities in California are hiring for Information Security Risk Intern jobs?

Cities in California with the most Information Security Risk Intern job openings:

Information Security Risk & Compliance

Alhambra, CA โ€ข On-site

Trinus
IT Servicesย โ€ขย 11 - 50 employees

Contractor

Re-posted 19 days ago


Job description

Description:

Trinus Corporation is seeking a skilled Information Security Risk & Compliance professional for a 12-month contract with strong potential for extension after the initial period. This position is ONSITE in Alhambra, CA 91803. Candidates must be authorized to work in the U.S. on a W2 basis.

Skills:

  • Demonstrated expertise in governance, risk management, and cybersecurity compliance, including the development and implementation of policies, standards, and control frameworks.
  • Strong working knowledge of information security regulations and industry frameworks such as NIST (800-53, CSF), ISO/IEC 27001, and PCI DSS, with the ability to map controls and assess compliance.
  • Experience conducting risk assessments, control evaluations, and compliance audits to support enterprise-wide GRC initiatives.
  • Familiarity with vulnerability management, threat intelligence analysis, and security architecture design in support of risk and compliance objectives.
  • Understanding of encryption technologies and data protection principles as they relate to governance and regulatory obligations.
  • Foundational knowledge of technical environments including IT security, networking, and systems administration, with awareness of tools such as SIEM (e.g., Microsoft Sentinel), firewalls, and other endpoint/network security platforms. 

Experience Required:

  • 5 years of experience applying security policies, standards, testing, modification and implementation. At least 3 years of that experience must be in information security analysis.     
  • 3+ years of experience within each of the following:
    • Applying risk management principles, including conducting audits, security assessments, and interpreting industry-standard security frameworks (e.g., NIST, ISO 27001, CIS).
    • Conducting and supporting security operations, control assessments, audit remediation, and enterprise risk governance initiatives.
    • Performing information security risk assessments, evaluating control effectiveness, and analyzing risk impact for technology initiatives and third-party integrations.
    • Participating in incident response processes, including detection, containment, and post-incident analysis.
    • Managing the security of complex, multi-platform IT environments, including various operating systems, software suites, and network protocols, within a large organization.  

Education Required:  

  • This classification requires possession of a bachelor’s degree in an IT-related or Engineering field. Additional qualifying experience may be substituted for the required education on a year-for-year basis. 

Certification (must have 1 of the following listed):

  • CISSP - Certified Information Systems Security Professional.
  • CRISC - Certified in Risk and Information Systems Control.
  • CISA - Certified Information Systems Auditor.
  • CISM - Certified Information Security Manager.

Interview Process:

  • Interviews will be conducted in person in Alhambra, CA 91803.

Work Schedule:

  • Work schedule is Mon - Thu 7:15 am – 6:00 pm (10 hours/day).