2

Remote Security Risk Assessment Jobs in California

Sr. Security Engineer

San Francisco, CA ยท On-site +1

$180K - $230K/yr

Our partners will continue to manage structured assessments including Penetration Testing and ... Ownership in our approach to AI-related security risk, including: * Securing our own AI/ML systems ...

Sr. Cyber Assurance Analyst, Starlink

Hawthorne, CA ยท On-site +1

$130K - $195K/yr

Perform technical security and risk assessments of systems and networks within our environment and ... This role requires you to be onsite, remote/hybrid work will not be considered. COMPENSATION AND ...

This is a remote first role. You will partner closely with teams across the company and focus on ... Perform technical security assessments, code audits, and design reviews for new AI infrastructure ...

AVP, AI Risk and Governance

San Diego, CA ยท On-site +1

$117K - $195K/yr

Conduct risk assessments and gap analyses on AI solutions to identify and evaluate risks and ensure ... Relevant certifications such as Certified Information Systems Security Professional (CISSP ...

Remote Role Responsibilities * Review simulated vendor SOC 2 reports , security questionnaires, and ... Assess data-handling and sub-processor risk for vendors touching sensitive data. * Work ...

Remote Role Responsibilities * Review simulated vendor SOC 2 reports , security questionnaires, and ... Assess data-handling and sub-processor risk for vendors touching sensitive data. * Work ...

Senior GRC Lead

San Francisco, CA ยท On-site +1

$134K - $185K/yr

You'll support Trust Assurance, Third Party Risk Management, and other Security Risk Management ... As a perk, we also have up to four weeks per year of fully remote work! Responsibilities * Manage ...

Showing results 41-60

Remote Security Risk Assessment information

What is a remote security risk assessment?

A Remote Security Risk Assessment is a process where security professionals evaluate an organization's security risks, vulnerabilities, and threats without being physically present on-site. This assessment is typically conducted through virtual meetings, digital questionnaires, and remote access to systems and documentation. The goal is to identify potential security gaps and recommend improvements to protect sensitive data and systems from cyber threats. Remote assessments have become increasingly popular due to their flexibility, cost-effectiveness, and ability to serve organizations regardless of location.

What are the key skills and qualifications needed to thrive as a remote security risk assessor?

To thrive as a Remote Security Risk Assessor, you need expertise in cybersecurity principles, risk analysis, and a relevant degree or certifications such as CISSP, CISM, or CRISC. Familiarity with tools like vulnerability scanners, security information and event management (SIEM) systems, and risk assessment frameworks (e.g., NIST, ISO 27001) is essential. Strong analytical thinking, communication skills, and attention to detail help in accurately identifying and communicating risks to stakeholders. These skills and qualities are vital to ensure organizations can proactively mitigate threats and maintain robust security postures in remote or distributed environments.

What are some common challenges faced by professionals in remote security risk assessment roles?

Professionals in remote security risk assessment often encounter challenges such as limited on-site visibility, reliance on digital communication, and the need to assess complex IT environments from afar. Effective collaboration with on-site staff and stakeholders is essential to gather accurate information and implement recommendations. Additionally, staying up-to-date with evolving cybersecurity threats and maintaining clear documentation are vital for success in this role.

What is the difference between Remote Security Risk Assessment vs Cybersecurity Analyst?

AspectRemote Security Risk AssessmentCybersecurity Analyst
CredentialsCertifications like CISSP, CISA, CISMCertifications like CompTIA Security+, CISSP, CEH
Work EnvironmentRemote or on-site, focusing on risk evaluationRemote or on-site, focusing on security monitoring and incident response
Industry UsageUsed in risk management, compliance, and audit contextsUsed in security operations, threat analysis, and incident handling

Remote Security Risk Assessments and Cybersecurity Analysts both require security certifications and often work in similar environments. However, risk assessors focus on evaluating vulnerabilities and compliance, while analysts handle ongoing security monitoring and incident response. Understanding these differences helps organizations assign the right roles for their security needs.

What are the most commonly searched types of Security Risk Assessment jobs in California?

The most popular types of Security Risk Assessment jobs in California are:

What are popular job titles related to Remote Security Risk Assessment jobs in California?

For Remote Security Risk Assessment jobs in California, the most frequently searched job titles are:

What job categories do people searching Remote Security Risk Assessment jobs in California look for?

The top searched job categories for Remote Security Risk Assessment jobs in California are:

What cities in California are hiring for Remote Security Risk Assessment jobs?

Cities in California with the most Remote Security Risk Assessment job openings:

Infographic showing various Remote Security Risk Assessment job openings in California as of August 2026, with employment types broken down into 80% Full Time, 14% Part Time, 2% Temporary, and 4% Contract. Highlights an 100% Remote job distribution.

Sr. Security Engineer

OpenSpace

San Francisco, CA โ€ข On-site, Remote

$180K - $230K/yr

Full-time

Posted 27 days ago


Job description

At OpenSpace, we're redefining how the world's most complex projects are built. Our AI-powered Visual Intelligence Platform uses computer vision and spatial AI to give construction teams a real-time view of what's happening on-site, helping them build faster, safer, and with greater confidence.

But what truly sets us apart is our people. We hire curious, driven teammates who love solving hard problems, taking ownership, and making a real-world impact. Great people build great culture—and apparently it shows. Forbes has named OpenSpace one of America's Best Startup Employers five years in a row. Come see what all the fuss is about ✨

Brief summary of role:

Security is in OpenSpace's DNA. A significant portion of our core engineering team — including several of our most senior engineers — came together at a security SaaS company before OpenSpace, and that shows up in how we design systems, review code, and think about customer data. We run a mature program today: an external security partner handles pen testing and structured assessments, our DevOps and IT team owns infrastructure security, IAM, and endpoint, and product engineers carry real ownership of the code they ship.

This role is about pushing our team from strong to elite: building the proactive security review muscle that lives day-to-day inside the engineering org, rather than at the cadence of an external engagement.

You'll maintain partnership with our existing security consultants. Our partners will continue to manage structured assessments including Penetration Testing and security assessments. You will support our team and maintain our in-house practice that catches issues long before they reach one.

This role reports to the Director of DevOps and IT.

What you will be doing:

  • Run proactive security reviews of new features, architectures, and third-party integrations before they ship
  • Assist in optimizing our application and product security practice: threat modeling, design review, secure SDLC integration
  • Ownership in our approach to AI-related security risk, including:
    • Securing our own AI/ML systems and the data flowing through them
    • Governing internal use of AI dev tools (Claude Code and similar) so we move fast without leaking sensitive data
    • Reviewing AI-assisted code contributions and helping us evolve our policies as the tooling matures
  • Partner with engineering teams to triage and remediate vulnerabilities from pen tests, customer findings, and internal discovery
  • Support our SOC 2 and ISO 27001 programs as a key technical contributor (compliance ownership lives elsewhere, but you'll be the engineering voice in the room)
  • Help mature our incident response practice and run security tabletop exercises
  • Build internal tooling and automation that scales security review without bottlenecking shipping
  • Work with our consultant on scoping pen tests, vendor assessments, and customer security reviews

What we are looking for:

  • 5+ years in security engineering, application security, or product security
  • Hands-on experience doing proactive security review (threat modeling, design review, secure code review) on production systems
  • Strong fundamentals in web application security, cloud security (we run primarily on AWS and GCP), and modern auth patterns
  • Comfortable reading and reviewing code across at least one of our stacks (Python, Java/Kotlin, TypeScript)
  • A real point of view on how AI changes the security landscape, both as a new risk surface and as new tooling for defenders
  • Track record of working effectively in a startup or fast-moving environment where you have to prioritize ruthlessly and make tradeoffs
  • Ability to influence engineers without owning their roadmap

Nice to have:

  • Experience as the first or early security hire at a growth-stage company
  • Hands-on contributor experience with SOC 2 and/or ISO 27001
  • Background in security automation, internal tooling, or open source security work
  • Familiarity with construction tech, geospatial systems, or computer vision

Our US Benefits include:

  • ???? 100% employer-paid medical, dental, and vision coverage
  • ???? Flexible paid time off
  • ???? 401(k) with company match
  • ???? Paid parental leave
  • ???? Home office stipend
  • ???? Employee referral program
  • ✈️ Annual company retreats and team gatherings

Base Salary: $180,000-$230,000

The "Base Salary: range represents the low and high end of the anticipated salary range for this position across all US locations including but not limited to CA, CO, NY, WA, NV, MD, CT and RI. The determination of this anticipated Base Salary involves the consideration of many factors in making compensation decisions including but not limited to: location of candidate, unique skill sets, experience, training, performance, licensure and certifications, as well as other business and organizational needs.

Please note: We are unable to provide visa sponsorship or employment-based immigration support for this position. Applicants must be authorized to work in the country of employment without current or future sponsorship

#LI-Remote

OpenSpace welcomes employees from varied backgrounds and walks of life, and it's reflected in our diverse community. OpenSpace is proud to be an equal opportunity employer and is committed to providing equal employment opportunities to all employees and applicants for employment, without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.