1

It Risk Manager Jobs in California (NOW HIRING)

Sr. Technology Auditor

San Francisco, CA · On-site

$110.60K - $145.30K/yr

Who You Are * 3-4 years of experience in IT auditing, risk management, or information security. * Experience with SOX IT controls (ITGCs & ITACs) and a solid understanding of ICFR concepts and ...

... risk-based decision-making, and executive-level stakeholder management capabilities, enabling ... Oversee the annual IT risk assessment and scoping process to ensure alignment with financial ...

next page

Showing results 1-20

It Risk Manager information

See California salary details

$50.8K

$110.1K

$167.8K

How much do it risk manager jobs pay per year?

As of May 29, 2026, the average yearly pay for it risk manager in California is $110,095.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,800.00 and $127,300.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

What cities in California are hiring for It Risk Manager jobs? Cities in California with the most It Risk Manager job openings:
Infographic showing various It Risk Manager job openings in California as of May 2026, with employment types broken down into 1% As Needed, 81% Full Time, 17% Part Time, and 1% Contract. Highlights an 96% Physical, 2% Hybrid, and 2% Remote job distribution, with an average salary of $110,095 per year, or $52.9 per hour.
Senior Analyst, Information Security Governance, Risk, & Compliance

Senior Analyst, Information Security Governance, Risk, & Compliance

AltaMed Health Services Corporation

Commerce, CA • On-site

$121.78K - $152.23K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 28 days ago


AltaMed rating

8.2

Company rating: 8.2 out of 10

Based on 34 frontline employees who took The Breakroom Quiz

56th of 864 rated healthcare providers


Job description

Grow Healthy
If you are as passionate about helping those in need as you are about growing your career, consider AltaMed. At AltaMed, your passion for helping others isn't just welcomed - it's nurtured, celebrated, and promoted, allowing you to grow while making a meaningful difference. We don't just serve our communities; we are an integral part of them. By raising the expectations of what a community clinic can deliver, we demonstrate our belief that quality care is for everyone. Our commitment to providing exceptional care, despite any challenges, goes beyond just a job; it's a calling that drives us forward every day.
Job Overview
The Senior Analyst, Information Security Governance, Risk, & Compliance will be responsible for the corporate-wide Information Security GRC program. This person will work closely with Information Services, Office of Compliance and Risk Management (OCRM), Legal, HR, and Procurement to ensure reasonable and appropriate IT controls are in place to minimize risk and ensure compliance with AltaMed's Information Security Policy and Standards, the HIPAA Security Rule, Data Privacy regulations and the Payment Card Industry - Data Security Standards (PCI-DSS). This person will assist with the development, implementation, and maintenance of AltaMed's Information Security Policies, standards, and guidelines, and be an SME for HIPAA, PCI, and Privacy. Additionally, this person will also be responsible for leading vulnerability management efforts, and vendor and risk management programs, including leading the risk-based change management program, liaising with internal/external auditors to ensure audits lead to a successful outcome, and being responsible for the Security Exception/Risk Acceptance process. The position will also manage, maintain, and administer the company's IT Risk Register and Information Security Awareness Training program.
Minimum Requirements
  • A bachelor's degree in business, information systems management, or a related field is required.
  • A minimum of 5 years of experience in IT audit or IT risk management is required.
  • Experience in leading security assessments, IT vendor risk assessments, and InfoSec control management.
  • Working knowledge of HIPAA, Privacy, and PCI data requirements, and other state / federal regulatory requirements of sensitive information.
  • Experience with application security, SaaS, and/or cloud security is a plus.
  • Must hold an active Certified Information Systems Security Professional (CISSP) certification.

Compensation
$121,780.05 - $152,225.07 annually
Compensation Disclaimer
Actual salary offers are considered by various factors, including budget, experience, skills, education, licensure and certifications, and other business considerations. The range is subject to change. AltaMed is committed to ensuring a fair and competitive compensation package that reflects the candidate's value and the role's strategic importance within the organization. This role may also qualify for discretionary bonuses or incentives.
Benefits & Career Development
  • Medical, Dental and Vision insurance
  • 403(b) Retirement savings plans with employer matching contributions
  • Flexible Spending Accounts
  • Commuter Flexible Spending
  • Career Advancement & Development opportunities
  • Paid Time Off & Holidays
  • Paid CME Days
  • Malpractice insurance and tail coverage
  • Tuition Reimbursement Program
  • Corporate Employee Discounts
  • Employee Referral Bonus Program
  • Pet Care Insurance

Job Advertisement & Application Compliance Statement
AltaMed Health Services Corp. will consider qualified applicants with criminal history pursuant to the California Fair Chance Act and City of Los Angeles Fair Chance Ordinance for Employers. You do not need to disclose your criminal history or participate in a background check until a conditional job offer is made to you. After making a conditional offer and running a background check, if AltaMed Health Service Corp. is concerned about a conviction directly related to the job, you will be given a chance to explain the circumstances surrounding the conviction, provide mitigating evidence, or challenge the accuracy of the background report.

What AltaMed employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


AltaMed Health Services logo

About AltaMed Health Services

Sourced by ZipRecruiter

AltaMed Health Services, based in Los Angeles, CA, US, is a leading provider in the healthcare industry. Founded in 1969 as the East LA Barrio Free Clinic, the organization provides high-quality health and human services to the underserved and uninsured communities in Southern California. AltaMed offers a broad range of services including medical care, senior care, dental services, HIV care, pharmacy services, and health education. The company's mission is to eliminate disparities in healthcare access and outcomes by providing superior quality health and human services through an integrated world-class delivery system. AltaMed has also made notable achievements, including becoming the nation's largest federally qualified community health center (FQHC) and being named a leader in healthcare equality by the Human Rights Campaign for several consecutive years.

Industry

Fitness and sports centers

Company size

1,001 - 5,000 Employees

Headquarters location

Los Angeles, CA, US

Year founded

1969

Social media