1

It Risk Consultant Jobs in California (NOW HIRING)

Manager, IT Risk Operations

Palo Alto, CA · On-site

$147K - $198K/yr

Strengthen IT Governance & Controls * Lead the development of executive-level reporting on IT risk, ... consulting)preferred * Proven ability to lead reporting, analytics, and governance initiatives

Prior knowledge leading and executing IT risk consulting, IT process re-engineering, IT audit, and IT internal controls engagements, leveraging IT governance and control frameworks such as Control ...

The Risk Consultant must be positive and approachable, and work effectively with diverse ... Demonstrated ability to retrieve and enter information using various proprietary software ...

At Crowe, consultants are expected to build both technical and transferable skills, think ... Evaluate technology processes such as change management, logical access, IT operations, system ...

At Crowe, consultants are expected to build both technical and transferable skills, think ... Evaluate technology processes such as change management, logical access, IT operations, system ...

At Crowe, consultants are expected to build both technical and transferable skills, think ... Evaluate technology processes such as change management, logical access, IT operations, system ...

At Crowe, consultants are expected to build both technical and transferable skills, think ... Evaluate technology processes such as change management, logical access, IT operations, system ...

At Crowe, consultants are expected to build both technical and transferable skills, think ... Evaluate technology processes such as change management, logical access, IT operations, system ...

next page

Showing results 1-20

It Risk Consultant information

See California salary details

$24

$52

$85

How much do it risk consultant jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for it risk consultant in California is $52.27, according to ZipRecruiter salary data. Most workers in this role earn between $43.17 and $57.40 per hour, depending on experience, location, and employer.

How does an IT Risk Consultant typically collaborate with other departments to manage organizational risks?

IT Risk Consultants often work closely with departments such as IT, legal, compliance, and business operations to identify, assess, and mitigate risks. This collaboration involves facilitating risk assessments, developing risk mitigation strategies, and ensuring that all teams understand their roles in maintaining security and compliance. Regular cross-functional meetings and clear communication are key to aligning risk management efforts with business objectives. Successful consultants build strong relationships across the organization to create a culture of proactive risk awareness.

What are the key skills and qualifications needed to thrive as an IT Risk Consultant, and why are they important?

To thrive as an IT Risk Consultant, you need a solid understanding of information security, risk assessment methodologies, and regulatory compliance, typically supported by a degree in information technology or a related field. Familiarity with frameworks such as ISO 27001, NIST, and tools like risk management software and vulnerability scanners—as well as certifications like CISSP or CISA—is highly valuable. Strong analytical thinking, problem-solving, and communication skills help convey risks and collaborate with stakeholders effectively. These competencies are crucial for identifying vulnerabilities, recommending mitigation strategies, and ensuring organizations meet security and compliance requirements.

What is the difference between It Risk Consultant vs Cybersecurity Analyst?

AspectIt Risk ConsultantCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentConsulting firms, corporate risk teamsSecurity operations centers, IT departments
Industry UsageFinancial, healthcare, governmentTech, finance, retail

While both roles focus on protecting information, an It Risk Consultant assesses overall IT risks and compliance, providing strategic advice, whereas a Cybersecurity Analyst monitors and responds to security threats in real-time. The roles often overlap but differ in scope and daily responsibilities.

Does risk consulting pay well?

Risk consulting, including roles like IT Risk Consultants, generally offers competitive salaries that vary based on experience, certifications, and location. Entry-level positions may start lower, but experienced consultants with specialized skills can earn high compensation, often supplemented by bonuses and benefits. The profession values analytical skills, industry knowledge, and certifications such as CISSP or CISA.

What does an IT risk consultant do?

An IT risk consultant assesses an organization's technology systems to identify vulnerabilities and develop strategies to mitigate cybersecurity threats and data breaches. They analyze security controls, recommend improvements, and often use tools like risk management frameworks and compliance standards such as ISO 27001 or NIST. Their work helps organizations protect sensitive information and ensure regulatory compliance.
Infographic showing various It Risk Consultant job openings in California as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 13% Part Time, and 4% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $108,713 per year, or $52.3 per hour.

Manager, IT Risk Operations

Palo Alto, CA • On-site

Wilson Sonsini Goodrich & Rosati, Professional Corporation
Law Firms • 1 - 5K employees

$150 - $200/hr

Other

Posted 7 days ago


Key responsibilities

  • Lead the firm's IT risk, security, and operational governance activities.

  • Develop executive-level reporting and dashboards on IT risk, compliance, and operational performance.

  • Partner with teams to investigate incidents, analyze data, and optimize workflows within ServiceNow.


Job description

Wilson Sonsini is the premier legal advisor to technology, life sciences, and growth enterprises worldwide. We represent companies at every stage of development, from entrepreneurial start-ups to multibillion‑dollar global corporations.

Job Summary

The Governance, Risk & Compliance Manager will lead the firm’s IT risk, security, and operational governance. The role is highly collaborative, working closely with senior IT, Security Engineering, General Counsel, and firm leadership. It can be 100% remote or hybrid near a physical office.

Key Responsibilities
  • Strengthen IT Governance & Controls: develop executive‑level reporting on IT risk, compliance posture, and operational performance.
  • Build and evolve KPI/KRI dashboards that provide real‑time visibility into risk trends and control effectiveness.
  • Translate complex IT and security data into meaningful insights for decision‑making.
  • Ensure adherence to IT policies, standards, and leading frameworks (e.g., NIST, ISO 27001).
  • Own and evolve the firm’s IT risk register and Risk & Control Self‑Assessment (RCSA) program.
  • Identify emerging and systemic risks across IT, security, privacy, and operational processes.
  • Incident Governance & Investigations: partner with General Counsel, Security, and IT to lead internal investigations.
  • Own ITSM Governance & ServiceNow Analytics: oversee governance and reporting across the IT Service Management ecosystem.
  • Analyze incident, change, and problem management data to identify trends and improvement opportunities.
  • Drive workflow optimization and automation within ServiceNow.
  • Vendor Risk Management: review and advise on vendor agreements; enhance vendor risk processes including risk tiering, assessments, and monitoring.
  • Introduce data‑driven approaches to risk management and operational oversight.
  • Perform related duties as assigned or directed by supervisor and maintain compliance with all firm policies and procedures.
Qualifications
  • Bachelor’s degree preferred.
  • Seven years of experience in IT risk, security compliance, technology audit, or IT governance preferred.
  • Experience operating in complex, regulated environments (e.g., law firms, financial services, consulting) preferred.
  • Proven ability to lead reporting, analytics, and governance initiatives.
  • Familiarity with ServiceNow and ITSM reporting, including understanding of incident, change, and problem management lifecycles.
  • Experience with security and collaboration platforms such as Microsoft 365, Purview, and email security tools.
  • Working knowledge of frameworks such as the NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2.
  • Strong understanding of control design, risk registers, RCSA programs, and audit response.
  • Basic understanding of privacy regulations.
  • Preferred certifications: CISA, CISSP, CRISC, CTPRM, and/or ITIL.
Compensation and Benefits

Compensation includes a base salary that varies by location, with discretionary year‑end merit bonus potential. Base pay ranges from $147,050 to $220,800 per year depending on geographic region. Benefits information is provided separately upon request.

Other Information

Primary location: Palo Alto, CA (other locations may be considered). The role may be performed remotely or in a hybrid model if the candidate resides near an office.

Equal Opportunity Employer (EOE).

#J-18808-Ljbffr