1

Information Security Risk Management Jobs in California

Security Risk Engineer

San Francisco, CA · On-site

$202K - $230K/yr

About you * 7+ years of experience in information security with a strong focus on security risk management and GRC. * Demonstrated experience building or leading a security risk management program ...

Be Seen First

... IT risk management and third-party risk management programs. This role will conduct cybersecurity and supplier risk assessments, manage the enterprise security risk register, oversee the vendor risk ...

New

A minimum of 7 years of experience in information security risk management, including business impact analysis, risk assessment and treatment, risk metrics and trend analysis. * Possess a bachelor ...

A minimum of 7 years of experience in information security risk management, including business impact analysis, risk assessment and treatment, risk metrics and trend analysis. * Possess a bachelor ...

What You'll Bring Experience * 4-6 years of experience in information security, cybersecurity, risk management, compliance, or IT audit. * Demonstrated experience conducting information security risk ...

Lead Security Analysis

Dublin, CA · On-site

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Lead Security Analysis

Dublin, CA · Hybrid

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Lead Security Analysis

Dublin, CA · On-site

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Lead Security Analysis

Dublin, CA · On-site

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Lead Security Analysis

Dublin, CA · On-site

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Showing results 21-40

Information Security Risk Management information

See California salary details

$31

$57

$74

How much do information security risk management jobs pay per hour?

As of Sep 13, 2026, the average hourly pay for information security risk management in California is $57.69, according to ZipRecruiter salary data. Most workers in this role earn between $44.86 and $64.76 per hour, depending on experience, location, and employer.

What is information security risk management?

Information Security Risk Management is the process of identifying, assessing, and prioritizing risks to an organization's information assets and implementing measures to mitigate those risks. This field involves analyzing potential threats, vulnerabilities, and the impact of security breaches to ensure data protection and regulatory compliance. Professionals in this area develop policies, select security controls, and monitor systems to reduce the likelihood and consequences of cybersecurity incidents. Effective risk management helps organizations safeguard sensitive information and maintain trust with customers and stakeholders.

What are the key skills and qualifications needed to thrive in information security risk management?

To thrive in Information Security Risk Management, you need a deep understanding of cybersecurity principles, risk assessment methodologies, and relevant legal or regulatory requirements, often supported by a bachelor’s degree in IT or cybersecurity and certifications like CISSP or CISM. Familiarity with risk management frameworks (e.g., ISO 27001, NIST), vulnerability assessment tools, and governance, risk, and compliance (GRC) systems is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills set top professionals apart in this field. These competencies are crucial for identifying, evaluating, and mitigating security risks, ensuring organizational resilience and regulatory compliance.

What are some common challenges faced by professionals in information security risk management, and how are they typically addressed?

Professionals in Information Security Risk Management often face challenges such as keeping up with constantly evolving cyber threats, balancing security needs with business objectives, and ensuring compliance with various regulations. These challenges are typically addressed through continuous learning, close collaboration with IT and business teams, and implementing robust risk assessment frameworks. Proactive communication and regular updates to security policies also help manage risks effectively while supporting organizational goals.

What is the difference between Information Security Risk Management vs Cybersecurity Analyst?

AspectInformation Security Risk ManagementCybersecurity Analyst
CertificationsISO 27001, CISSP, CISMCompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk assessments, complianceMonitoring security systems, incident response
Industry UsageRisk management, governance, compliance teamsSecurity operations centers, IT departments

While both roles focus on protecting information assets, Information Security Risk Management emphasizes identifying and mitigating risks through policies and assessments, whereas Cybersecurity Analysts focus on monitoring security systems and responding to threats. Both roles often collaborate but serve different functions within an organization's security framework.

Infographic showing various Information Security Risk Management job openings in California as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $119,985 per year, or $57.7 per hour.

Sr. Director, Information Security

Los Angeles, CA • On-site

ICANN
Software Development • 201 - 500 employees

Full-time

Re-posted 10 days ago


Key responsibilities

  • Develop and implement an enterprise-wide information security strategy aligned with business objectives.

  • Oversee security risk management, compliance, incident response, and cybersecurity initiatives.

  • Guide the selection, deployment, and management of security technologies and collaborate with stakeholders to align security objectives with business needs.


Job description

Job Summary:
The Sr. Director of Information Security is responsible for establishing and maintaining the ICANN's enterprise information security vision, strategy, and programs to ensure information assets and technologies are protected. This person will oversee security risk management, compliance, incident response, and cybersecurity initiatives while fostering a security-first culture across the organization.
Key Responsibilities & Duties:
Security Strategy & Leadership: Develop and implement an enterprise-wide information security strategy aligned with business objectives.
Risk Management: Identify, assess, and mitigate security risks while ensuring compliance with regulatory and industry standards.
Cybersecurity Operations: Oversee information security operations, including threat intelligence, vulnerability management, and incident response.
Compliance & Governance: Ensure adherence to security frameworks, policies, and industry regulations such as NIST CSF, ISO 27001, NIST SP 800 series, GDPR, CCPA, and SOC 2.
Incident Response & Crisis Management: Lead efforts to detect, investigate, and remediate security incidents, ensuring minimal disruption to business operations.
Security Awareness & Training: Foster a culture of security awareness by conducting employee training and implementing best practices.
Technology & Architecture Oversight: Guide the selection, deployment, and management of security technologies, including firewalls, SIEM, endpoint protection, and IAM solutions.
Collaboration & Stakeholder Engagement: Work closely with executive leadership, Engineering and Information Technology (E&IT), legal, and compliance teams to align security objectives with business needs.
Third-Party Risk Management: Evaluate and monitor vendors, partners, and supply chains to manage information security risk.
Budget & Resource Management: Develop and manage the cybersecurity budget, ensuring the efficient allocation of monetary, time and people resources.
Incident Response: Provide expertise to Crisis Management Team; oversight and accountability for resolution of information security incidents.
Mentorship: Encourage and facilitate the development of a significant knowledge base in others; may define role of staff members
• Other duties as assigned or requested
Required Knowledge, Skills, and Abilities (KSAs): (Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions)
• Strong interpersonal communication skills and the ability to maintain effective working relationships with co-workers, vendors, business owners and the public are required
• Hands-on experience with security technologies, including SIEM, IDS/IPS, encryption, and cloud security solutions.
• Strong knowledge of IT infrastructure, networking, and cloud environments.
• Proven track record in managing security incidents and crisis response.
• Exceptional leadership, communication, and stakeholder management skills.
• Experience in highly regulated industries such as finance, healthcare, or government.
• Familiarity with AI-driven security solutions and emerging threat landscapes.
• Background in ethical hacking, penetration testing, or red teaming
• General understanding of all areas of ICANN's business and functional groups, including relevant industry issues
• Demonstrated expertise in a diverse variety of IT process improvement concepts, practices, and procedures
• Ability to effectively facilitate meetings at senior management level
Education and Experience Requirements:
• Bachelor's or master's degree in computer science, IT, Engineering, or a related field.
• Minimum fifteen (15) years of experience in related field.
• Minimum eight (8) years of supervisory experience
• Industry certifications such as CISSP, CISM, CISA, or CCISO.
• Fluency, both written and spoken, in English is required
• ICANN is a global organization that values diversity; preference will be given to candidates with demonstrated skills in additional languages besides English
Working Conditions & Physical Requirements:
• Work is performed in a normal office environment with limited privacy and some exposure to background noise
• While performing the duties of this job, the employee is frequently required to stand and walk. The employee regularly is required to sit. The employee is frequently required to talk or hear; use hands and arms to reach, handle or feel. Specific vision abilities required by this job include close vision, color vision, and ability to adjust focus.
• The employee may occasionally lift and/or move up to 25 pounds
Targeted Base Salary Low:
180,000.00 + 20% Bonus + Benefits
Targeted Base Salary High:
245,000.00 + 20% Bonus + Benefits
Note: The salary range provided here is a general estimation for the position at the time of posting based on the primary location. Salary ranges vary based upon geographic regions and countries. Final compensation packages take into consideration of a variety of factors including but not limited to a candidate's location, work experience, knowledge, skills and other compensable factors.