1

Security Analyst Jobs in California (NOW HIRING)

Security Analyst II

Mcfarland, CA · On-site

$100 - $125/hr

The Security Analyst II is expected to be familiar with a wide variety of IT security concepts, practices, and technologies. The position serves as an expert resource and relies on extensive ...

MANTECH seeks a motivated, career and customer-oriented Acquisition Security Analyst - II to join our team in El Segundo, CA . In this role, you will assist the Government Program Manager with the ...

MANTECH seeks a motivated, career and customer-oriented Acquisition Security Analyst - II to join our team in El Segundo, CA . In this role, you will assist the Government Program Manager with the ...

As a Network Security Analyst, you'll your career forward by performing monitoring, investigating and protecting the network's security infrastructure, ensuring its performance, reliability, and ...

SECURITY ANALYST (BLUE TEAM) As a Security Analyst at SpaceX, you are on the frontline of our information security operations. You will be responsible for analyzing and responding to threats directed ...

SECURITY ANALYST (THREAT DETECTION) As a Security Analyst at SpaceX, you are on the frontline of our information security operations. You will be responsible for analyzing and responding to threats ...

Senior Security Analyst

Santa Barbara, CA · On-site

$106K - $139K/yr

The Senior Security Analyst will monitor security events, lead incident response efforts, and mentor junior analysts to enhance the organization's security posture. Responsibilities : • Monitor and ...

MANTECH seeks a motivated, career and customer-oriented Acquisition Security Analyst - II to join our team in El Segundo, CA . In this role, you will assist the Government Program Manager with the ...

Showing results 41-60

Security Analyst information

See California salary details

$39K

$105.9K

$139.2K

How much do security analyst jobs pay per year?

As of Sep 8, 2026, the average yearly pay for security analyst in California is $105,928.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,300.00 and $128,300.00 per year, depending on experience, location, and employer.

What is a security analyst?

Security Analysts are professionals responsible for protecting an organization’s computer systems and networks from cyber threats. They monitor networks for security breaches, investigate suspicious activities, and implement security measures to prevent future attacks. Security Analysts also conduct vulnerability assessments, respond to incidents, and ensure compliance with security policies and regulations. Their work helps safeguard sensitive data and maintain the integrity of information systems.

What do security analysts do?

Security analysts evaluate information systems and recommend security measures and protocols to protect a company’s sensitive data from security threats. Security administrators implement their recommendations and put suggested protocols into action. As a security analyst, your job duties include monitoring security access, performing audits of internal and external network security programs, analyzing breaches to inform future security system measures, and training colleagues in security awareness and proper procedures. You also collaborate with outside vendors on security plans, which may include website applications, container, or cloud-based solutions.

What are the key skills and qualifications needed to thrive as a security analyst, and why are they important?

To thrive as a Security Analyst, you need a solid understanding of cybersecurity principles, risk assessment, and network security, often backed by a degree in computer science or a related field. Familiarity with tools like SIEM platforms, intrusion detection systems, and certifications such as CompTIA Security+ or CISSP are commonly required. Analytical thinking, attention to detail, and strong problem-solving abilities help Security Analysts excel in identifying vulnerabilities and responding to threats. These skills are crucial for protecting organizational assets, ensuring compliance, and maintaining a robust security posture.

What are some common challenges security analysts face when responding to security incidents, and how can they effectively manage these situations?

Security Analysts often encounter challenges such as rapidly evolving threats, the need to analyze large volumes of data, and coordinating responses across different teams. Responding quickly while accurately diagnosing incidents requires excellent technical skills and clear communication. To manage these situations effectively, successful analysts prioritize continuous learning, use automation tools to streamline repetitive tasks, and establish well-defined incident response procedures. Collaborating with IT, legal, and management teams is also crucial for a coordinated and effective response.

What is the difference between Security Analyst vs Network Security Analyst?

AspectSecurity AnalystNetwork Security Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, Cisco CCNA Security
Work EnvironmentIT security teams, cybersecurity firms, corporate securityNetwork operations centers, IT departments, cybersecurity teams
ResponsibilitiesMonitor security systems, analyze threats, implement security measuresSecure network infrastructure, monitor network traffic, prevent intrusions

Security Analysts focus on overall cybersecurity, including threat detection and incident response, while Network Security Analysts specialize in protecting network infrastructure and traffic. Both roles require similar certifications and often work in overlapping environments, but their core responsibilities differ in scope and focus.

What does a security analyst actually do?

A security analyst monitors and protects an organization’s computer systems and networks from cyber threats. They analyze security data, respond to incidents, implement security measures, and often use tools like intrusion detection systems and firewalls. Certifications such as CISSP or CompTIA Security+ can enhance their effectiveness in this role.

What qualifications do I need to be a security analyst?

A security analyst typically needs a bachelor's degree in cybersecurity, computer science, or a related field. Relevant skills include knowledge of network security, threat detection, and experience with security tools and protocols; certifications like CompTIA Security+ or CISSP can enhance job prospects.

What are the most commonly searched types of Security Analyst jobs in California?

The most popular types of Security Analyst jobs in California are:

What cities in California are hiring for Security Analyst jobs?

Cities in California with the most Security Analyst job openings:

Infographic showing various Security Analyst job openings in California as of August 2026, with employment types broken down into 93% Full Time, and 7% Contract. Highlights an 100% In-person job distribution, with an average salary of $105,928 per year, or $50.9 per hour.

Information Security Analyst

Bank of the Orient

Millbrae, CA • On-site

$90K - $110K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 28 days ago


Key responsibilities

  • Support the operation, monitoring, maintenance, and continuous improvement of the Bank's information security, cybersecurity risk, privacy, technology risk, and third-party risk programs.

  • Monitor and analyze security events, alerts, logs, and telemetry from various systems, triage and investigate suspicious activity, and escalate as needed.

  • Support cybersecurity incident response activities, including evidence collection, root-cause analysis, and post-incident improvement actions.


Job description

  Information Security Analyst

Bank of the Orient is an independent Asian Community Bank that has proudly served the financial needs of multiple Bay Area communities for over 55 years and the Texas area. We are well known for our commitment to providing the highest level of personal service to our customers; we take a personal interest in our communities' unique banking needs, we are dedicated to providing integrity in banking and financial services, we provide high quality dependable service by being accessible and reliable. We are committed to excellence in everything we do.

We have an opening for the Information Security Analyst supports the operation, monitoring, maintenance, and continuous improvement of the Bank's information security, cybersecurity risk, privacy, technology risk, and third-party risk programs. The role works across security operations, identity and access management, vulnerability management, incident response, cloud and SaaS security, data protection, business continuity/cyber resilience, security awareness, and governance, risk and compliance (GRC). The Analyst also supports the secure adoption and oversight of artificial intelligence (AI), including generative AI and large language model (LLM) technologies, and may serve as backup administrator for selected security and banking applications as needed.

ESSENTIAL DUTIES:

1.          Support the maintenance and continuous improvement of the Bank's Information Security, Cybersecurity, Technology Risk, Privacy, GRC, Third-Party Risk Management, and Business Continuity/Cyber Resilience programs in alignment with the Bank's risk appetite, policies, and applicable regulatory requirements.

2.          Monitor and analyze security events, alerts, logs, and telemetry from endpoints, servers, networks, identity platforms, cloud/SaaS services, email, and other critical systems. Triage, investigate, document, and escalate suspicious activity in accordance with established procedures and service-level expectations.

3.          Support security operations technologies such as SIEM/SOAR, EDR/XDR, network security, email security, cloud security, and threat intelligence platforms; assist with alert tuning, use-case development, log-source onboarding, and operational health monitoring.

4.          Perform and coordinate vulnerability and exposure management activities, including vulnerability scanning, risk-based prioritization, configuration reviews, patch/remediation tracking, penetration-test findings, security exceptions, and validation of corrective actions.

5.          Participate in and coordinate cybersecurity incident response activities, including phishing/business email compromise, credential compromise, malware/ransomware, data exposure, cloud/SaaS incidents, and AI-related security events. Support evidence collection, root-cause analysis, lessons learned, tabletop exercises, and post-incident improvement actions.

6.          Support identity and access management (IAM) controls, including multi-factor authentication (MFA), role-based access control (RBAC), privileged access, joiner/mover/leaver processes, periodic access certifications, service accounts, and segregation of duties for critical banking and technology systems.

7.          Assist with data security and privacy controls, including information classification, encryption, data loss prevention (DLP), secure file transfer, retention, sensitive-data handling, and monitoring of non-public customer and Bank information.

8.          Support security reviews for technology projects, system changes, cloud/SaaS implementations, APIs, integrations, digital banking capabilities, and new vendors. Document security requirements, identify risks/control gaps, and track remediation through implementation.

9.          Support secure cloud and modern infrastructure practices, including security configuration and monitoring for Microsoft 365, Azure and/or AWS environments, SaaS applications, remote access, Zero Trust principles, endpoint/device security, and secure network connectivity.

10.       Support the Bank's AI security and governance program. Perform security and risk assessments for AI/GenAI use cases and vendors; evaluate risks such as sensitive-information disclosure, prompt injection, insecure output handling, excessive agency, model/supply-chain risk, unauthorized data use, and inadequate logging or access control; and help implement appropriate guardrails, monitoring, human oversight, and acceptable-use requirements.

11.       Monitor the use of approved AI-enabled tools and services, where applicable, and support controls for enterprise AI platforms such as Microsoft 365 Copilot, Azure OpenAI, ChatGPT Enterprise, AWS Bedrock, Google Gemini, or equivalent technologies. Assist with evaluation of AI-enabled cybersecurity tools for accuracy, access, data handling, and operational risk.

12.       Support third-party/vendor risk management across onboarding, due diligence, contracting, ongoing monitoring, risk assessment, issue remediation, renewal, and termination. Review security documentation such as SOC reports, penetration-test summaries, business continuity information, cyber insurance, privacy practices, subcontractors/fourth parties, and AI/model-provider dependencies where relevant.

13.       Collaborate with business owners, Technology, Compliance, Risk, Audit, Operations, and other stakeholders to ensure technology and vendor risks are identified, documented, accepted or remediated, and supported by appropriate controls.

14.       Support cybersecurity threat intelligence and threat-informed defense activities using authoritative sources and industry information-sharing channels. Map relevant threats and incidents to recognized frameworks such as MITRE ATT&CK when useful for investigation, control improvement, or reporting.

15.       Conduct and coordinate security awareness activities, including phishing simulations, role-based training, emerging-threat communications, secure use of AI/GenAI, social-engineering awareness, and targeted education for employees, contractors, and third parties.

16.       Maintain security policies, standards, procedures, risk registers, control evidence, issue trackers, inventories, diagrams, and other documentation. Support regulatory examinations, internal/external audits, risk assessments, and management responses.

17.       Develop and analyze cybersecurity metrics, dashboards, key risk indicators (KRIs), control-performance reports, and executive-level materials to identify trends, highlight material risks, and support management decision-making.

18.       Maintain current knowledge of cybersecurity threats, AI security risks, privacy and security laws, regulatory guidance, and industry practices relevant to financial institutions. Support alignment, as appropriate, with frameworks such as FFIEC guidance, GLBA, NIST Cybersecurity Framework (CSF) 2.0, NIST AI Risk Management Framework, CIS Controls, and OWASP guidance.

19.       Serve as backup security/application administrator for selected Bank systems as assigned, including Fiserv Premier and related applications, with responsibilities focused on secure configuration, access administration, periodic access reviews, logging, and least-privilege controls. Support other operational systems (such as EZ Teller, Business Analytics, or Enterprise Output Manager) when security, access, resilience, or controlled file-transfer support is required.

20.       Demonstrate quality customer service with internal and external stakeholders, actively participate in required Bank and compliance training, maintain strict confidentiality of non-public information, and comply with all applicable Bank policies, security requirements, and banking laws and regulations. Perform other duties and special projects as assigned.

REQUIREMENTS:

1.          Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, Management Information Systems, or a related discipline; or four (4) or more years of equivalent relevant work experience.

2.          Two (2) or more years of experience in information security, cybersecurity operations, technology risk, systems/network administration, IT audit, GRC, or a related technology role is preferred. Experience in banking, financial services, or another regulated environment is strongly preferred.

3.          Working knowledge of Windows and Linux operating systems, TCP/IP, DNS, firewalls, VPN/remote access, Active Directory/identity services, Microsoft 365, endpoint management, cloud/SaaS concepts, and common enterprise security architectures.

4.          Practical experience with security monitoring, vulnerability management, incident response, IAM/access reviews, third-party risk, security awareness, or GRC activities. Experience across multiple areas is preferred; deep specialization in every area is not required.

5.          Knowledge of financial-services cybersecurity and privacy expectations, including GLBA and FFIEC guidance, and working familiarity with recognized security frameworks such as NIST CSF 2.0, CIS Controls, MITRE ATT&CK, and incident-response practices.

6.          Working knowledge of AI/GenAI security concepts and risks, with familiarity with resources such as the NIST AI Risk Management Framework and OWASP guidance for LLM/GenAI applications. Direct enterprise AI security experience is preferred but not required.

7.          Experience with reporting, data analysis, or query tools such as SQL, Power BI, Excel, or equivalent is preferred. Basic scripting/automation experience with PowerShell, Python, APIs, or workflow/SOAR tools is a plus.

8.          Familiarity with Fiserv Premier or other core banking/application security administration is a plus.

 

PREFERRED CERTIFICATIONS:

CompTIA Security+, CySA+, SSCP, GSEC, CISA, CISSP, GIAC certifications, Microsoft/Azure or AWS security certifications, or comparable credentials are preferred depending on experience level.

Bilingual a plus

The candidate will be subject to investigation through credit checks, reference checks, background checks and fingerprinting checks performed at the time permissible under relevant law.

Visit our website at: www.bankorient.com for additional information.

Bank of the Orient is proud to be an Affirmative Action, Equal Opportunity Employer.