1

It Risk Compliance Jobs in California (NOW HIRING)

This high-impact position in the Governance, Risk & Compliance function sits at the center of the ... Strengthen IT Governance & Controls * Lead the development of executive-level reporting on IT risk, ...

What you'll do The IT Risk Senior Analyst is a strategic advisor responsible for integrating IT risk management and compliance into enterprise technology transformation initiatives. This role ensures ...

What you'll do The IT Risk Senior Analyst is a strategic advisor responsible for integrating IT risk management and compliance into enterprise technology transformation initiatives. This role ensures ...

The Compliance Assessor of IT Risk & Compliance Management performs Security Risk Assessments on DIRECTV's 3rd party vendors. An assesment would typically involve the following tasks: Communicating ...

... IT audit/risk advisory, financial services or healthcare). * Proven track record as a senior IC leading complex, cross-functional risk or compliance programs with high visibility to engineering and ...

next page

Showing results 1-20

It Risk Compliance information

See California salary details

$30.4K

$113.7K

$197.3K

How much do it risk compliance jobs pay per year?

As of Aug 3, 2026, the average yearly pay for it risk compliance in California is $113,678.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,172.00 and $140,519.00 per year, depending on experience, location, and employer.

What is the difference between It Risk Compliance vs It Security Analyst?

AspectIt Risk ComplianceIt Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, Security+
Work EnvironmentPolicy development, audits, compliance assessmentsMonitoring security systems, incident response
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

It Risk Compliance focuses on ensuring organizations adhere to regulatory standards and manage risks through policies and audits. In contrast, It Security Analysts primarily monitor and respond to security threats, implementing technical safeguards. Both roles are vital in protecting organizational assets but differ in their core responsibilities and focus areas.

What are the key skills and qualifications needed to thrive as an IT Risk Compliance professional, and why are they important?

To thrive as an IT Risk Compliance professional, you need a solid understanding of risk assessment, regulatory frameworks (like SOX, GDPR), and information security principles, often supported by a degree in IT, cybersecurity, or a related field. Familiarity with compliance management tools, risk analysis software, and certifications such as CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and articulate compliance needs to stakeholders. These competencies are crucial for safeguarding organizational data, ensuring regulatory adherence, and minimizing operational risks.

What is IT Risk Compliance?

IT Risk Compliance refers to the process of identifying, assessing, and managing risks related to information technology systems to ensure that an organization complies with internal policies, industry standards, and regulatory requirements. Professionals in this field help organizations protect sensitive data, prevent security breaches, and maintain the integrity of their IT operations. They often work closely with other departments to implement controls, conduct audits, and ensure that IT practices align with laws such as GDPR, HIPAA, or SOX. The role is critical for minimizing risks and avoiding costly penalties stemming from non-compliance.

What are some common challenges faced by professionals in IT Risk Compliance roles, and how can they be addressed?

Professionals in IT Risk Compliance often encounter challenges such as staying updated with rapidly changing regulations, managing competing priorities, and ensuring organization-wide adherence to compliance standards. Navigating these obstacles requires effective communication skills, continuous professional development, and strong collaboration with IT, legal, and business units. Proactively fostering a culture of compliance and leveraging automation tools can also help streamline processes and reduce manual workload.
What job categories do people searching It Risk Compliance jobs in California look for? The top searched job categories for It Risk Compliance jobs in California are:
What cities in California are hiring for It Risk Compliance jobs? Cities in California with the most It Risk Compliance job openings:
Infographic showing various It Risk Compliance job openings in California as of July 2026, with employment types broken down into 1% As Needed, 81% Full Time, 14% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $113,678 per year, or $54.7 per hour.

IT Risk & Compliance Analyst

Superbeo

San Francisco, CA • On-site

Contractor

Re-posted 21 days ago


Job description

Job Title: IT Risk & Compliance Analyst

Job Location: San Francisco, CA 94104

  • Please local candidates that are able to work hybrid work schedule, Tuesday and Wednesday, at the SF Offices.

Job Duration: 6 months (Possibility of extension)

Qualifications (Must Have):

  • Ability to map key Information Security and Technology controls identified in policies, standards, and process documents to industry frameworks such as NIST CSF, NIST 800-53, CSA CCM, CIS v8.1, and regulatory requirements in FHFA Advisory Bulletins.
  • Interpret compliance information to create a recurring cadence of reports of open findings, observations, self-identified issues, progress on risk and compliance initiatives.
  • Willingness to learn/use ITRC tools (e.g., ProcessUnity, Black Kite) and support ITRC team lead with supply chain cyber risk program management

Primary Responsibilities:

  • Conduct readiness assessments, including reviews of relevant documentation in advance of audits, 2LOD assessments, and external assessments.
  • Maintain the inventory of SOX IT General Controls (ITGC) and control tests in ServiceNow, updating as directed, and identifying opportunities for improvements in reporting and in using automation.
  • Liaison between control owner and internal auditors, and 2LOD assessors during audits and assessments, responsible for supporting control owners in the timely submission of artifacts.
  • Ability to map key Information Security and Technology controls identified in policies, standards, and process documents to industry frameworks such as NIST CSF, NIST 800-53, CSA CCM, CIS v8.1, and regulatory requirements in FHFA Advisory Bulletins.
  • Ability to identify and document technology processes.
  • Manage the LogicGate Governance Library ensuring Information Security and Technology documents align with approval and publication requirements, relying equally on automated reminders as well as active engagement with document owners.
  • Maintain ITRC document archives in the ITRC shared repository.
  • Responsible for reporting status at a recurring cadence of open findings, observations, recommendations, and self-identified issues, and for submitting formal audit observation closure documentation.
  • As directed by the ITRC MD, document and report the progress and value of in-flight ITRC initiatives, identified risks, and planned initiatives.
  • Provide compliance review of requests for deviations from Information Security and Technology policies and standards, confirming compliance with Technology Exception requirements for components such as compensating controls, risk assessment, and  documentation supporting exception request rationale.
  • Participate as a key stakeholder in the Architecture Assessment Review process, documenting meeting decisions,  tracking deliverable commitments, and ensuring next steps are completed for proposed new technologies or changes in existing technologies.
  • Support ITRC team members as needed in conducting third-party security risk assessments for changes to existing third parties or proposed third party technologies.

Skills/Knowledge:

  • Required Core Competencies:  Customer Focus, Decision Quality, Ensures Accountability, Drives Results, Drives Engagement, Collaborates, Values Differences, Communicates Effectively with all levels of staff and management, Instills Trust
  • 3 - 5 years of experience in technology risk or IT audit.
  • Knowledge and experience with technology frameworks is required, e.g., CIS v8.1, CSA CCM, CoBIT, NIST, ITIL, et al.
  • Knowledge of Operational Risk Management and Technology Risk Management.
  • Demonstrated ability to promote teamwork, act as a change agent, effectively remove obstacles, maintain high level of morale and motivation, and lead by example.
  • Familiarity with SOX ITGC
  • Must be proficient with Microsoft Office (Word, Excel, PowerPoint) and Microsoft SharePoint.
  • Must have strong communication skills and be able to effectively communicate with all functional levels of the organization.
  • Project management, planning, problem-solving and organizational skills required, preferably using Atlassian JIRA
  • Strong analytical, issue identification, prioritization, resolution, and report writing skills required.
  • Must be proactive and must be able to meet established deadlines.
  • Experience with a Governance, Risk and Compliance (GRC) tool is highly desirable, preferably ServiceNow and LogicGate.
  • Ability to learn use of the ProcessUnity/CyberGRX third party risk management platform