1

Information Security Risk Management Jobs in California

About the Role The Information Security Officer will have end-to-end ownership of MEDvidi ... This includes remediation execution, ongoing risk management, technical and administrative ...

About you * 7+ years of experience in information security with a strong focus on security risk management and GRC. * Demonstrated experience building or leading a security risk management program ...

IT Security Analyst 2

Palo Alto, CA Β· On-site

$58 - $76/hr

Qualifications: β€’ Experience in information security, risk management, and compliance. β€’ Knowledge of industry standards and regulations, particularly NIST & HIPAA. β€’ Strong analytical and ...

New

Security Risk Engineer

San Francisco, CA Β· Hybrid

$202K - $230K/yr

About you * 7+ years of experience in information security with a strong focus on security risk management and GRC. * Demonstrated experience building or leading a security risk management program ...

next page

Showing results 1-20

Information Security Risk Management information

See California salary details

$31

$57

$74

How much do information security risk management jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for information security risk management in California is $57.69, according to ZipRecruiter salary data. Most workers in this role earn between $44.86 and $64.76 per hour, depending on experience, location, and employer.

What is information security risk management?

Information Security Risk Management is the process of identifying, assessing, and prioritizing risks to an organization's information assets and implementing measures to mitigate those risks. This field involves analyzing potential threats, vulnerabilities, and the impact of security breaches to ensure data protection and regulatory compliance. Professionals in this area develop policies, select security controls, and monitor systems to reduce the likelihood and consequences of cybersecurity incidents. Effective risk management helps organizations safeguard sensitive information and maintain trust with customers and stakeholders.

What are the key skills and qualifications needed to thrive in information security risk management?

To thrive in Information Security Risk Management, you need a deep understanding of cybersecurity principles, risk assessment methodologies, and relevant legal or regulatory requirements, often supported by a bachelor’s degree in IT or cybersecurity and certifications like CISSP or CISM. Familiarity with risk management frameworks (e.g., ISO 27001, NIST), vulnerability assessment tools, and governance, risk, and compliance (GRC) systems is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills set top professionals apart in this field. These competencies are crucial for identifying, evaluating, and mitigating security risks, ensuring organizational resilience and regulatory compliance.

What are some common challenges faced by professionals in information security risk management, and how are they typically addressed?

Professionals in Information Security Risk Management often face challenges such as keeping up with constantly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with various regulations. These challenges are typically addressed through continuous learning, close collaboration with IT and business teams, and implementing robust risk assessment frameworks. Proactive communication and regular updates to security policies also help manage risks effectively while supporting organizational goals.

What is the difference between Information Security Risk Management vs Cybersecurity Analyst?

AspectInformation Security Risk ManagementCybersecurity Analyst
CertificationsISO 27001, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk assessments, complianceMonitoring security systems, incident response
Industry UsageRisk management, governance, compliance teamsSecurity operations centers, IT departments

While both roles focus on protecting information assets, Information Security Risk Management emphasizes identifying and mitigating risks through policies and assessments, whereas Cybersecurity Analysts focus on monitoring security systems and responding to threats. Both roles often collaborate but serve different functions within an organization's security framework.

Infographic showing various Information Security Risk Management job openings in California as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $119,985 per year, or $57.7 per hour.

Information Security Risk & Compliance

Alhambra, CA β€’ On-site

Trinus
IT ServicesΒ β€’Β 11 - 50 employees

Contractor

Re-posted 22 days ago


Job description

Description:

Trinus Corporation is seeking a skilled Information Security Risk & Compliance professional for a 12-month contract with strong potential for extension after the initial period. This position is ONSITE in Alhambra, CA 91803. Candidates must be authorized to work in the U.S. on a W2 basis.

Skills:

  • Demonstrated expertise in governance, risk management, and cybersecurity compliance, including the development and implementation of policies, standards, and control frameworks.
  • Strong working knowledge of information security regulations and industry frameworks such as NIST (800-53, CSF), ISO/IEC 27001, and PCI DSS, with the ability to map controls and assess compliance.
  • Experience conducting risk assessments, control evaluations, and compliance audits to support enterprise-wide GRC initiatives.
  • Familiarity with vulnerability management, threat intelligence analysis, and security architecture design in support of risk and compliance objectives.
  • Understanding of encryption technologies and data protection principles as they relate to governance and regulatory obligations.
  • Foundational knowledge of technical environments including IT security, networking, and systems administration, with awareness of tools such as SIEM (e.g., Microsoft Sentinel), firewalls, and other endpoint/network security platforms. 

Experience Required:

  • 5 years of experience applying security policies, standards, testing, modification and implementation. At least 3 years of that experience must be in information security analysis.     
  • 3+ years of experience within each of the following:
    • Applying risk management principles, including conducting audits, security assessments, and interpreting industry-standard security frameworks (e.g., NIST, ISO 27001, CIS).
    • Conducting and supporting security operations, control assessments, audit remediation, and enterprise risk governance initiatives.
    • Performing information security risk assessments, evaluating control effectiveness, and analyzing risk impact for technology initiatives and third-party integrations.
    • Participating in incident response processes, including detection, containment, and post-incident analysis.
    • Managing the security of complex, multi-platform IT environments, including various operating systems, software suites, and network protocols, within a large organization.  

Education Required:  

  • This classification requires possession of a bachelor’s degree in an IT-related or Engineering field. Additional qualifying experience may be substituted for the required education on a year-for-year basis. 

Certification (must have 1 of the following listed):

  • CISSP - Certified Information Systems Security Professional.
  • CRISC - Certified in Risk and Information Systems Control.
  • CISA - Certified Information Systems Auditor.
  • CISM - Certified Information Security Manager.

Interview Process:

  • Interviews will be conducted in person in Alhambra, CA 91803.

Work Schedule:

  • Work schedule is Mon - Thu 7:15 am – 6:00 pm (10 hours/day).