1

Information Security Jobs in Santa Rosa, CA (NOW HIRING)

The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provide support and guidance at the corporate ...

Senior Security Engineer

Sonoma, CA · On-site

$200K - $315K/yr

Partner closely with product and infrastructure engineering to embed security into shipping cycles What you'll need: * 3 to 8 years hands-on information security experience, with core work in ...

Senior Security Engineer

Santa Rosa, CA · On-site

$200K - $315K/yr

Partner closely with product and infrastructure engineering to embed security into shipping cycles What you'll need: * 3 to 8 years hands-on information security experience, with core work in ...

next page

Showing results 1-20

Information Security information

See Santa Rosa, CA salary details

$68.3K

$148.8K

$218.7K

How much do information security jobs pay per year?

As of Sep 7, 2026, the average yearly pay for information security in Santa Rosa, CA is $148,807.00, according to ZipRecruiter salary data. Most workers in this role earn between $120,800.00 and $175,500.00 per year, depending on experience, location, and employer.

What is information security?

Information security, often abbreviated as InfoSec, refers to the processes and tools designed to protect sensitive business and personal information from unauthorized access, use, disclosure, disruption, modification, or destruction. It encompasses various practices such as risk management, access control, encryption, and incident response to ensure data confidentiality, integrity, and availability. Professionals in this field work to safeguard digital and physical information against threats like cyberattacks, data breaches, and insider threats.

What is an information security job?

Information security jobs are jobs in which your primary responsibilities are to ensure an organization or business has the proper IT and cybersecurity protocols in place. Some specific job titles for working in information security include information security analyst, information security specialist, and security manager. Your specific duties differ by position. Specialists and analysts often research and review information security practices and analyze weak spots in an organization’s infosec. Managers and implementation specialists identify methods for improving system security and implement these protocols, ensuring proper documentation of changes. Some analysts monitor security systems and prevent unauthorized access to data.

What are the key skills and qualifications needed to thrive as an information security professional, and why are they important?

To thrive as an Information Security professional, you need a solid understanding of network security, risk assessment, and cybersecurity principles, often backed by a degree in computer science or related field. Familiarity with security tools like firewalls, intrusion detection/prevention systems, and certifications such as CISSP or CompTIA Security+ are commonly required. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart. These competencies are crucial for identifying threats, protecting sensitive data, and ensuring organizational resilience against cyberattacks.

How does an information security professional typically collaborate with other departments within an organization?

Information Security professionals frequently work cross-functionally, partnering with IT, legal, HR, and compliance teams to ensure organizational data and systems are protected. They may provide training sessions, develop security policies, and assist other departments in recognizing and mitigating risks. Effective communication and relationship-building skills are key, as they must translate technical security requirements into practical guidelines for non-technical staff. This collaborative approach helps foster a security-minded culture across the organization.

What is the difference between Information Security vs Network Security?

AspectInformation SecurityNetwork Security
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, Cisco CCNA Security
Work EnvironmentProtects data across entire organization, including policies and proceduresFocuses on securing network infrastructure and devices
Employer & Industry UsageUsed across all industries to safeguard information assetsPrimarily in IT and networking sectors
Common Search & ComparisonOften compared for broad security rolesMore technical, network-focused roles

Information Security encompasses protecting all organizational data, policies, and systems, while Network Security specifically targets securing network infrastructure and communications. Both roles often overlap but differ in scope and focus, with Information Security providing a broader security strategy and Network Security concentrating on network-specific defenses.

What are the most commonly searched types of Information Security jobs in Santa Rosa, CA?

The most popular types of Information Security jobs in Santa Rosa, CA are:

What are popular job titles related to Information Security jobs in Santa Rosa, CA?

For Information Security jobs in Santa Rosa, CA, the most frequently searched job titles are:

What job categories do people searching Information Security jobs in Santa Rosa, CA look for?

The top searched job categories for Information Security jobs in Santa Rosa, CA are:

What cities near Santa Rosa, CA are hiring for Information Security jobs?

Cities near Santa Rosa, CA with the most Information Security job openings:

Infographic showing various Information Security job openings in Santa Rosa, CA as of August 2026, with employment types broken down into 1% As Needed, 69% Full Time, 27% Part Time, and 3% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $148,807 per year, or $71.5 per hour.

Senior Information Security Analyst

Goldbelt, Inc.

Petaluma, CA • On-site

$100 - $125/hr

Other

Medical, Dental, Vision, Retirement, PTO

Re-posted 2 days ago


Job description

Overview

Please note that this position is contingent upon the successful award of a contract currently under bid.

Peregrine is a pioneer within the cybersecurity industrial control systems and the Internet of Things, supporting many federal and commercial customers. Peregrine's experienced staff knows the cybersecurity and operational technology environment and provides these capabilities for our customers daily.

Summary:

The Senior Information Security Analyst is responsible for the overall cybersecurity of assigned networks and devices. They must have intimate knowledge of federal government, Department of Defense, and U.S. Coast Guard cybersecurity requirements.

Responsibilities

Essential Job Functions:

  • Aggressively manage Cyber security accreditation requirements by working closely with the Program Manager, system administrators, database administrators and other key personnel to ensure all system accreditations remain current.
  • Ensure that all initial and recurring certification and accreditation activities are completed in accordance with DoDI 8500.01, Cyber Security, and DoDI 8510.01, Risk Management Framework (RMF) for assigned information systems, as well as maintaining compliance with the Federal Information Security Management Act (FISMA) of 2002 and other applicable directives for the assigned information systems.
  • Working directly with leadership, developers, engineers, system and database administrators to track changes to the system configurations and software, conducting regular reviews, updates and maintenance of certification and accreditation plans, topology drawings, and associated documents, and uploading completed documents to eMASS.
  • Schedule, oversee and document information system compliance testing, to include weekly Assured Compliance Assessment Solution (ACAS) scans and annual execution and testing of the Contingency Plans.
  • Manage accreditation and annual compliance actions using eMASS and the U.S. Coast Guard tracking tools to ensure annual reviews, control tests and contingency plan tests are completed on schedule to comply with FSMA requirements and keep the Program Manager informed of compliance and status of ATO efforts via updates to the PM’s Drumbeat and Metrics products.
  • Conduct a continuous review of all applications and database tools that make up the family of systems to ensure all software versions are registered and approved for use by the U.S. Coast Guard.
  • Conduct an annual review and update of all parent and child system profiles in the DHS approved repository system to ensure system’s registrations are complete and accurate, and that essential waivers for Data-At-Rest (DAR) and unsupported Commercial-Off-The-Shelf (COTS) software are documented and approved by U.S. Coast Guard CIO so that accreditations are not adversely affected.
  • Serve as Information Assurance Officer (IAO)/Information Systems Security Officer (ISSO), directly advising and assisting the Program Manager, developers, engineers, system and database administrators and staff on all cyber security policy, configuration and compliance matters.
    • This includes all aspects of cyber security that may affect the system security posture, to include emerging threats published in Cyber Alerts, Communication Tasking Orders, and vulnerability alerts and bulletins issued under the Information Assurance Vulnerability Management program.
  • As IAO/ISSO, advise the team on ports, protocols and services (PPS) approved for use by the U.S. Coast Guard, and register new PPS in the U.S. Coast Guard PPS Management Registry.
  • Prior to testing, identify Security Technical Implementation Guides (STIGs) to be applied to systems under development and test, and identify appropriate vulnerability scanning tools to be used during testing, to include the ACAS and Security Content Automation Protocol (SCAP) Compliance Checker automated scanning tools.
  • The IAO/ISSO will assist during scanning and advise the team on the remediation of findings identified during testing.
  • Following testing, the IAO will collect, collate, review and validate all test results and prepare supporting documentation, reports and artifacts to support the certification and accreditation of the system. Following accreditation, the IAO/ISSO will track and manage open findings in the Risk Assessment Report until mitigated or closed.
  • Provide expert advice in support of special projects, to include the development of an automated Cross Domain Solution (CDS) for use by the program and closely coordinate actions with the U.S. Coast Guard Cross Domain Solutions Office (USCGCDSO) and the Department of Homeland Security Unified Cross Domain Management Office (UCDMO).
    • This support includes authoring and submitting detailed system documentation and architectural drawings and working closely with both USCGCDSO and UCDMO personnel to navigate through a complex and highly technical approval process.
  • On a daily and weekly basis, provide authoritative cyber security advice during Internal Review Boards and make recommendations on open Configuration Change Requests (CCRs); Application Change Requests (ACRs), Database Change Requests (DBCRs), QA Trouble Reports (QTRs), Problem Reports (PRs), and Program Trouble Reports (PTRs).
Qualifications

Necessary Skills and Knowledge:

  • Proven record of honesty and integrity in all relationships.
  • Demonstrated leadership and organizational skills.
  • Excellent interpersonal skills and a collaborative management style.
  • Excellent communication skills, both verbal and written.
  • Excellent computer skills and proficient in Excel, Word, PowerPoint, Outlook, Visio, and Access.

Minimum Qualifications:

  • Minimum of five (5) years relevant experience.
  • Detailed knowledge of DoD Risk Management Framework.
  • Experience in an IAO/ISSO or Information Assurance Manager (IAM)/Information Systems Security Manager (ISSM) position.
  • Appropriate professional certifications per DoD 8570.01 (CISSP, GSLC or equivalent).
  • Must be eligible for a federal Public Trust clearance.

Preferred Qualifications:

  • Bachelors degree in cybersecurity or related degree.
  • CISSP Certification.
Pay and Benefits

The annual salary range for this position is $100,000 to $140,000.

At Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.

#J-18808-Ljbffr