1

It Risk Manager Jobs in California (NOW HIRING)

Oversee IT risk assessment and scoping process to ensure alignment with financial reporting risks ... Adhere to the Company's Quality Management System (QMS) as well as domestic and global quality ...

IT SOX Compliance Senior Manager

Alameda, CA · On-site

$165K - $230K/yr

Specific Duties and Responsibilities • Responsible for strategic leadership, oversight, and day-to-day management of the IT SOX compliance program. * • Oversee IT risk assessment and scoping ...

This Technology Risk Audit Manager role owns the technical side of that mission - IT SOX/ITGC, system controls, and domains centered around consumer trust - that protect hundreds of millions of our ...

Analyze business, risk, compliance, audit, security, and technology processes to identify ... Evaluate technology processes such as change management, logical access, IT operations, system ...

IT Auditor Sr

Irvine, CA · On-site

$102 - $138/hr

Understanding of IT Governance and IT Risk Management concepts. * Thorough knowledge of auditing standards, technology/security focused regulations, IT general controls and application controls.

Spectra Tech has an immediate need for an experienced Senior Project Risk Manager to lead ... risk information to ALS-U Project leadership and shall work closely with the Project Director ...

Spectra Tech has an immediate need for an experienced Senior Project Risk Manager to lead ... Maintain complete and current risk information in Safran Risk Manager or another approved system.

Showing results 41-60

It Risk Manager information

See California salary details

$50.8K

$110.1K

$167.8K

How much do it risk manager jobs pay per year?

As of Aug 22, 2026, the average yearly pay for it risk manager in California is $110,095.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,800.00 and $127,300.00 per year, depending on experience, location, and employer.

What does an IT Risk Manager do?

An IT Risk Manager is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They develop and implement risk management strategies, policies, and procedures to protect against cybersecurity threats, data breaches, and compliance violations. IT Risk Managers also work closely with other departments to ensure security best practices are followed and often lead risk assessments, audits, and incident response planning.

What are some common challenges faced by IT Risk Managers when implementing risk mitigation strategies across different departments?

IT Risk Managers often encounter challenges such as varying levels of risk awareness among departments, resistance to new controls or procedures, and balancing business objectives with security requirements. Successful risk mitigation requires clear communication, stakeholder buy-in, and tailored training to ensure all teams understand the importance of compliance. Building strong relationships and fostering a culture of shared responsibility are key to overcoming these hurdles and ensuring effective risk management across the organization.

What are the key skills and qualifications needed to thrive as an IT Risk Manager, and why are they important?

To thrive as an IT Risk Manager, you need a solid understanding of risk assessment, information security, and compliance frameworks, often backed by a bachelor's degree in information technology or related fields. Familiarity with tools such as risk management software, GRC platforms, and certifications like CISSP, CISM, or CRISC is typically required. Strong analytical thinking, communication skills, and the ability to influence stakeholders are crucial soft skills in this role. These skills ensure effective identification, mitigation, and communication of IT risks, supporting organizational resilience and compliance.

What is the difference between It Risk Manager vs Cybersecurity Analyst?

AspectIt Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISMCISSP, Security+, CEH
Work EnvironmentOversees risk management strategies across IT systemsMonitors and responds to security threats and incidents
Industry UsageUsed in organizations with complex IT infrastructuresCommon in security-focused roles across industries

The It Risk Manager focuses on identifying and managing IT risks at an organizational level, ensuring compliance and risk mitigation strategies. In contrast, a Cybersecurity Analyst primarily monitors security threats and responds to incidents. While both roles require similar certifications and work within the IT security domain, the It Risk Manager has a broader scope related to risk management policies, whereas the Cybersecurity Analyst concentrates on threat detection and response.

What are popular job titles related to It Risk Manager jobs in California?

For It Risk Manager jobs in California, the most frequently searched job titles are:

What job categories do people searching It Risk Manager jobs in California look for?

The top searched job categories for It Risk Manager jobs in California are:

What cities in California are hiring for It Risk Manager jobs?

Cities in California with the most It Risk Manager job openings:

Infographic showing various It Risk Manager job openings in California as of August 2026, with employment types broken down into 90% Full Time, 9% Part Time, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $110,095 per year, or $52.9 per hour.

IT SOX Compliance Senior Manager

Penumbra

Alameda, CA

$165K - $230K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 29 days ago


Job description

General Summary
The IT SOX Compliance Senior Manager plays a critical role in ensuring that the Company's IT environment maintains strong internal controls. This role is responsible for strategic leadership and oversight of the IT SOX compliance program as well as partnering with cross functional teams to mitigate risks. 

This position requires working onsite in Alameda, California 80% of the time.


Specific Duties and Responsibilities
   Responsible for strategic leadership, oversight, and day-to-day management of the IT SOX compliance program. *
   Oversee IT risk assessment and scoping process to ensure alignment with financial reporting risks. *
   Review control documentation and collaborate with control owners to ensure execution of processes and documentation are adequate.
   Partner with internal audit, external audit, and control owners to coordinate ITGC and ITAC control testing and timely resolution of control related matters. *
   Support new systems implementations and technology changes to ensure SOX requirements are incorporated. *
   Provide training and guidance to IT control owners on SOX expectations, documentation standards, and audit readiness. *
   Identify opportunities to improve the sox program through automation, metrics, tools, and process improvements. *
   Adhere to the Company's Quality Management System (QMS) as well as domestic and global quality system regulations, standards, and procedures. *
   Understand relevant security, privacy, and compliance principles and adhere to the regulations, standards, and procedures that are applicable to the Company. *
   Ensure other members of the department follow the QMS, regulations, standards, and procedures. *
   Perform other work-related duties as assigned.
*Indicates an essential function of the role
Position Qualifications
Minimum education and experience:
   Bachelor's degree in accounting or information systems, with 8+ years' experience in IT SOX compliance, Information Security or IT Risk Management, or an equivalent combination of education and experience.

Preferred Qualifications:
   CISA, CIA, or CPA certification is strongly preferred
   Deep knowledge of SOX 404, ITGCs, ITACs, and COSO-based internal control frameworks
   Expertise in SAP environments, including knowledge of SAP Security and Basis
   Experience evaluating technology risk within a Big 4 public accounting firm preferred
   Experience implementing or managing GRC platforms
   Technical understanding of IT operations including cloud security architectures, DevOps practices, and complex logical access management
   Strong oral, written and interpersonal communication skills
   High degree of accuracy, attention to detail and strong problem-solving skills


Working Conditions
   General office environment
   Willingness and ability to work on site in Alameda, CA.
   May have business travel from 0-5%
   Requires some lifting and moving of up to 25 pounds
   Must be able to move between buildings and floors
   Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day
   Must be able to read, prepare emails, and produce documents and spreadsheets
   Must be able to move within the office and access file cabinets or supplies, as needed
   Must be able to communicate and exchange accurate information with employees at all levels on a daily basis

Annual Base Salary Range: $165,000 - $230,000 
We offer a competitive compensation package plus a benefits and equity program, when    
applicable. Individual total compensation will vary based on factors such as qualifications, skill  level, competencies, and work location.

What We Offer
A collaborative teamwork environment where learning is constant, and performance is rewarded.
The opportunity to be part of the team that is revolutionizing the treatment of some of the world's most devastating diseases.
A generous benefits package for eligible employees that includes medical, dental, vision, life, AD&D, short and long-term disability insurance, 401(k) with employer match, paid parental leave, eleven paid company holidays per year, a minimum of fifteen days of accrued vacation per year, which increases with tenure, and paid sick time in compliance with applicable law(s).
 
Penumbra, Inc., headquartered in Alameda, California, is a global healthcare company focused on innovative therapies. Penumbra designs, develops, manufactures, and markets novel products and has a broad portfolio that addresses challenging medical conditions in markets with significant unmet need. Penumbra sells its products to hospitals and healthcare providers primarily through its direct sales organization in the United States, most of Europe, Canada, and Australia, and through distributors in select international markets. The Penumbra logo is a trademark of Penumbra, Inc.
 
Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, age, disability, military or veteran status, or any other characteristic protected by federal, state, or local laws.
 
If you reside in the State of California, please also refer to Penumbra's Privacy Notice for California Residents.
 
For additional information on Penumbra's commitment to being an equal opportunity employer, please see Penumbra's AAP Policy Statement.
apply for this job