1

Security Risk Analyst Jobs in California (NOW HIRING)

Analyze risk data to uncover recurring issues, trends, and root causes, and recommend changes to strengthen controls * Partner with Engineering, Security, and business functions to embed risk ...

Risk Analyst

San Jose, CA ยท On-site +1

Bachelor's degree in a relevant field, such as intelligence studies, security studies ... Risk Analyst Contract Application." Applications are reviewed on a rolling basis.

Bachelor's degree in a relevant field, such as intelligence studies, security studies ... Risk Analyst Contract Application." Applications are reviewed on a rolling basis.

... Insider Risk Analyst to protect its advanced technologies. The role involves conducting ... OR 4+ years professional experience in internal investigations, information security ...

They are seeking an Insider Risk Analyst responsible for protecting the safety and security of personnel, brand, global assets, and operations by conducting investigations and analyzing insider ...

They are seeking an Insider Risk Analyst to protect their advanced technologies by conducting ... OR 4+ years professional experience in internal investigations, information security ...

IT Risk Analyst

San Diego, CA ยท On-site

$79K - $102K/yr

Position Summary The position of IT Risk Analyst is responsible for participating in IT compliance ... Information security and/or risk certification(s) desirable. * Track record of producing quality ...

next page

Showing results 1-20

Security Risk Analyst information

See California salary details

$10

$49

$69

How much do security risk analyst jobs pay per hour?

As of Jun 7, 2026, the average hourly pay for security risk analyst in California is $49.75, according to ZipRecruiter salary data. Most workers in this role earn between $40.34 and $59.33 per hour, depending on experience, location, and employer.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What job categories do people searching Security Risk Analyst jobs in California look for? The top searched job categories for Security Risk Analyst jobs in California are:
Information Security Risk Analyst

Information Security Risk Analyst

AllSTEM Connections

San Francisco, CA โ€ข On-site

$153K/yr

Temporary

Medical, Dental, Vision, Retirement

Posted 25 days ago


Job description

JOB SUMMARY
Are you passionate about strengthening security through risk insight and strategic partnership? We are seeking an experienced Information Security Risk Analyst to help identify, assess, and reduce cybersecurity risk across cloud and on-prem environments.
In this role, you will partner closely with application development teams, technical stakeholders, and leadership to evaluate security controls, advise on secure cloud and DevSecOps practices, and translate complex technical risks into actionable business guidance. This is an opportunity to play a highly visible role in improving enterprise security posture while influencing modern development practices, third-party risk management, and emerging AI/GenAI governance considerations.
If you thrive in collaborative environments and enjoy combining technical depth with risk strategy and communication, this role offers meaningful impact and professional growth.
KEY RESPONSIBILITIES
โ€ข Support enterprise risk strategies by identifying security risks in processes and technologies and leading initiatives to reduce exposure.
โ€ข Apply and interpret security policies and contribute insights to ongoing policy and control improvements.
โ€ข Partner with business and technical teams to help them understand and implement security controls, policies, and procedures.
โ€ข Establish trusted relationships across assigned business areas to understand operational and technical requirements and enable secure outcomes.
โ€ข Advise application development teams on Secure Cloud Development and DevSecOps best practices to mature security practices.
โ€ข Assess technical implementations in both cloud and on-prem environments to evaluate security risk and recommend control enhancements or compensating controls.
โ€ข Perform complex security analyses and provide clear, practical mitigation recommendations.
โ€ข Evaluate third-party service providers, identify associated risks, and clarify shared security responsibilities.
โ€ข Conduct formal security control assessments and prepare detailed assessment reports documenting scope, methodology, findings, risk impact, and remediation recommendations.
โ€ข Communicate security risks and business implications to stakeholders at all levels, including executive leadership.
โ€ข Collaborate cross-functionally, manage multiple initiatives simultaneously, and navigate ambiguity in a fast-paced, results-driven environment.
REQUIRED QUALIFICATIONS
โ€ข Experience performing security control assessments aligned to NIST 800-37 (SCA and CMCA).
โ€ข Hands-on experience conducting assessments using NIST 800-53 controls.
โ€ข Experience reviewing and evaluating FedRAMP authorization packages.
โ€ข Experience mapping OWASP Top Ten risks within DevSecOps environments to strengthen security operations.
โ€ข Strong understanding of cloud security principles and secure development practices.
โ€ข Ability to analyze complex technical security issues and translate them into clear, actionable risk narratives.
PREFERRED QUALIFICATIONS
โ€ข Experience in DevSecOps environments, including governance and security automation.
โ€ข Exposure to AI / GenAI-related cybersecurity governance and risk considerations.
โ€ข Experience working in regulated or compliance-driven environments.
KEY COMPETENCIES
โ€ข Strong verbal and written communication skills with the ability to convey risk to both technical and non-technical stakeholders.
โ€ข Excellent relationship-building and stakeholder partnership skills.
โ€ข Strategic thinking with practical, solutions-oriented execution.
โ€ข Ability to manage competing priorities while maintaining accountability and delivering results.
Equal Opportunity Employer / Disabled / Protected Veterans
The Know Your Rights poster is available here:
https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12.pdf
The pay transparency policy is available here:
https://www.dol.gov/sites/dolgov/files/ofccp/pdf/pay-transp_%20English_formattedESQA508c.pdf
For temporary assignments lasting 13 weeks or longer, AllSTEM Connections is pleased to offer major medical, dental, vision, 401k and any statutory sick pay where required.
We are committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please contact your staffing representative who will reach out to our HR team.
AllSTEM Connections participates in the E-Verify program in certain locations as required by law. Learn more about the E-Verify program.
https://e-verify.uscis.gov/web/media/resourcesContents/E-Verify_Participation_Poster_ES.pdf
We also consider for employment qualified applicants regardless of criminal histories, consistent with legal requirements, including, if applicable, the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance. Pursuant to applicable state and municipal Fair Chance Laws and Ordinances, we will consider for employment-qualified applicants with arrest and conviction records, including, if applicable, the San Francisco Fair Chance Ordinance. For Los Angeles, CA applicants: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Additional Skills
(none specified)
AllSTEM Representative Contact Info
Account Executive:
IN HOUSE
Branch Phone:
(909) 244-1777
Location:
Ontario, CA