1

Security Risk Analyst Jobs in California (NOW HIRING)

Position Summary SHEIN Global Security & Risk Management is a global security organization that ... The GRC Risk Analyst, a thought leader residing within our security organization, is responsible ...

Position Summary SHEIN Global Security & Risk Management is a global security organization that ... The GRC Risk Analyst, a thought leader residing within our security organization, is responsible ...

Security Risk Manager

San Francisco, CA · Hybrid

$194K - $220K/yr

Our security team protects Asana's employees, users, and customers by proactively addressing ... analysis. You back up risk ratings with numbers, not just color codes. * Hands-on experience ...

Security Risk Manager

San Francisco, CA · On-site

$194K - $220K/yr

Our security team protects Asana's employees, users, and customers by proactively addressing ... analysis. You back up risk ratings with numbers, not just color codes. * Hands-on experience ...

They are seeking an Insider Risk Analyst to protect their advanced technologies by conducting ... OR 4+ years professional experience in internal investigations, information security ...

IT Risk Analyst

San Diego, CA · On-site

$79K - $102K/yr

Position Summary The position of IT Risk Analyst is responsible for participating in IT compliance ... Information security and/or risk certification(s) desirable. * Track record of producing quality ...

The Compliance Assessor of IT Risk & Compliance Management performs Security Risk Assessments on DIRECTV's 3rd party vendors. An assesment would typically involve the following tasks: Communicating ...

Agentic Risk Analyst

San Francisco, CA · On-site

$288K - $425K/yr

About the Role As an Agentic Risk Analyst, you will shape OpenAI's operating picture for current ... By synthesizing signals from investigations, evaluations, red teaming, security reviews, product ...

Sr. Risk Analyst

Vacaville, CA · On-site

$98K - $121K/yr

... financial security. Profile: * Reviews and analyzes financial transactions for unusual or ... Senior Risk Analyst - Grade15/Exempt/$82,680.00 - $102,128.00 annually * * Reports directly to ...

next page

Showing results 1-20

Security Risk Analyst information

See California salary details

$10

$49

$69

How much do security risk analyst jobs pay per hour?

As of Jul 21, 2026, the average hourly pay for security risk analyst in California is $49.75, according to ZipRecruiter salary data. Most workers in this role earn between $40.34 and $59.33 per hour, depending on experience, location, and employer.

Can I make $200,000 a year in cyber security?

Security Risk Analysts and other cybersecurity professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP, and expertise in areas such as threat analysis or security architecture. High salaries are often found in senior roles, management, or specialized fields within cybersecurity.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

Can you make $500,000 a year in cyber security?

Security Risk Analysts typically earn salaries below $200,000 annually, but senior roles such as Chief Information Security Officers or cybersecurity executives can reach or exceed $500,000 with extensive experience, certifications, and leadership responsibilities. Achieving this level often requires advanced skills, industry certifications like CISSP, and years of experience in high-level security management. Salary potential varies based on the organization, location, and individual expertise.

Is SOC an entry-level job?

A Security Operations Center (SOC) analyst role is often considered an entry-level position in cybersecurity, suitable for individuals with foundational knowledge of security principles, network protocols, and security tools. However, some SOC roles may require prior experience or certifications such as CompTIA Security+ or Certified SOC Analyst (CSA).

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.
What job categories do people searching Security Risk Analyst jobs in California look for? The top searched job categories for Security Risk Analyst jobs in California are:
Infographic showing various Security Risk Analyst job openings in California as of July 2026, with employment types broken down into 75% Full Time, 12% Temporary, and 13% Contract. Highlights an 85% In-person, and 15% Remote job distribution, with an average salary of $103,475 per year, or $49.7 per hour.
VP, Lead Security Risk Analyst

VP, Lead Security Risk Analyst

Banc of California

Los Angeles, CA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 17 days ago


Banc Of California rating

7.9

Company rating: 7.9 out of 10

Based on 5 frontline employees who took The Breakroom Quiz

68th of 149 rated banks


Job description

BANC OF CALIFORNIA AND YOUR CAREER
Banc of California, Inc. (NYSE: BANC) is a bank holding company with over $34 billion in assets and the parent company of Banc of California. Banc of California is one of the nation's premier relationship-based business banks, providing banking and treasury management services to small, middle market, and venture backed businesses. As the largest independent bank headquartered in California, the bank offers a broad range of loan and deposit products and services through a network of full-service branches and regional offices, as well as through digital and nationwide capabilities. The bank also provides full-service payment processing solutions to its clients and serves the Community Association Management industry nationwide through its technology forward platform, SmartStreet™. Banc of California is committed to supporting its local communities through the Banc of California Charitable Foundation and by partnering with organizations that promote financial literacy, job training, small business support, affordable housing, and more.
At Banc of California, our success is powered by our people and a shared commitment to delivering meaningful results. We foster an environment where entrepreneurial thinking is encouraged, and accountability and operational excellence are expected. Our team members are empowered to take ownership, make informed decisions, and make a meaningful impact as the bank continues to grow and evolve. We are dedicated to supporting your growth and wellbeing through comprehensive benefits, robust development opportunities, and inclusive programs that enable you to perform at your best. Together we win!
THE OPPORTUNITY
The VP, Lead Security Risk Analyst leads enterprise-wide Information Security risk engagement across corporate initiatives, embedding security-by-design principles into business and technology decisions. This role drives the development and execution of the Information Security risk and GRC programs, conducting complex, high-impact risk assessments across enterprise architecture, cloud, AI/ML, and third-party environments. Serving as a senior advisor, the position partners with leadership, architects, and engineering teams to translate regulatory and security requirements into actionable architectural controls and secure design standards. The VP, Lead Security Risk Analyst also drives cross-functional remediation efforts to ensure risks are effectively managed in alignment with the organization's risk appetite. Performs all duties in accordance with the Company's policies and procedures, all U.S. state and federal laws and regulations, wherein the Company operates.
HOW YOU'LL MAKE A DIFFERENCE
  • Lead enterprise Information Security engagement across all enterprise-wide corporate projects, championing security by design principles, influencing security decisions without direct authority and driving alignment across multiple business and technology domains.
  • Contribute to the development, management, and ongoing improvement of the Information Security risk program, compliance initiatives, and overall security risk posture.
  • Partner with senior management to design and implement maturity strategies and operations into the Information Security GRC team.
  • Maintain Information Security risk register, report monthly to appropriately address key risk areas.
  • Support policies and procedures maintenance aligned with in-scope security frameworks, regulations, and internal standards to manage identified risk effectively.
  • Conduct regular risk assessments to identify potential threats and vulnerabilities across the organization analyzing their impact and likelihood of occurrence.
  • Generate reports on risk assessments, compliance status, and control effectiveness to communicate findings to stakeholders at various levels within the organization.
  • Lead and deliver enterprise and domain risk assessments (at least annually, or event driven) using consistent methodology that complies with regulatory requirements
  • Conduct and lead the bank's most complex and high-impact risk assessments, including those involving enterprise architecture, modernization initiatives, AI/ML platforms, cloud deployments, or third-party integrations.
  • Drive cross-functional remediation initiatives, ensuring timely resolution of identified issues and alignment with enterprise risk appetite.
  • Act as the primary GRC representative and senior advisor in enterprise security architecture projects, ensuring that security, compliance, and risk considerations are embedded in design decisions for cloud, infrastructure, and applications.
  • Lead architecture-focused risk assessments for new technologies, major system integrations, cloud migrations, and high-impact projects to identify systemic risks and required compensating controls.
  • Translate security policies, standards, regulatory requirements and control frameworks into detailed architectural requirements, control patterns, and secure design standards consumable by engineering and application teams.
  • Advise solution architects, engineers, and product teams on secure design patterns, identity and access architecture, encryption frameworks, data protection requirements, and logging/monitoring standards.
  • Evaluate the security implications of modernization initiatives, and system migrations ensuring risks are documented and mitigated through appropriate design.
  • Define architecture-aligned security requirements and control baselines that engineering and architecture teams use to build secure-by-design systems.
  • Partner with detection engineering and cloud teams to ensure logging, auditability, and monitoring capabilities are embedded in the technology stack.
  • Lead complex and technical vendor security reviews, including onboarding assessments, and high-risk assessments involving cloud platforms, data integrations, and critical infrastructure providers.
  • Follow all established policies and procedures.
  • Perform other duties and projects as assigned.

WHAT YOU'LL BRING
  • Bachelor's degree in information systems, engineering, business, risk management, or related field; and related certifications (e.g., CISSP ISSAP, SABSA, CCSP, GCAD, CRISC, CISSP).
  • 7-9+ years of experience in GRC, cybersecurity, risk management or related fields, and most importantly cloud/security architecture, particularly in highly regulated industries such as financial, or professional services.
  • Demonstrated history of influencing architectural decisions and driving enterprise-level security program improvements.
  • High technical knowledge across Cybersecurity domains, including Security Operations, Incident
  • Response, Security Engineering, Cloud Security, Artificial Intelligence (AI), Data Security, Configuration
  • Management, Log Generation, Security Risk Assessments/testing methodologies, Secure Software Development Lifecycle, evaluating the adequacy and efficiency of internal controls.
  • Advanced knowledge of cloud architecture, application security, identity governance, encryption, secure design patterns, network architecture, and telemetry design.
  • Experience translating requirements into architectural controls and technical standards.
  • Expert knowledge of GRC frameworks and regulations (e.g., PCI-DSS, GDPR, CCPA, GLBA, NIST, ISO 27001).
  • Strong knowledge in OWASP, CIS and/or other security standards and secure configuration baselines.
  • Excellent analytical skills with the ability to assess complex risks and develop effective mitigation security strategies.
  • Comfortable solving ambiguous, enterprise-scale problems.
  • Proven ability to lead multi-team initiatives and drive results in a fast-paced environment.
  • Excellent communication and interpersonal skills, with the ability to influence senior engineers, architects, and business leaders
  • High School diploma or equivalent required

HOW WE'LL SUPPORT YOU
  • Financial Security: You will be eligible to participate in the company's 401k plan which includes a company match and immediate vesting.
  • Health & Well-Being: We offer comprehensive insurance options including medical, dental, vision, AD&D, supplemental life, long-term disability, pre-tax Health Savings Account with employer contributions, and pre-tax Flexible Spending Account (FSA).
  • Building & Supporting Your Family: Banc of California partners with providers that offer adoption, surrogacy, and fertility assistance as well as paid parental leave and family support solutions including care options for your family.
  • Paid Time Away: Eligible team members receive paid vacation days, holidays, and volunteer time off.
  • Career Growth Opportunities: To support career growth of our team members, we offer tuition reimbursement, an annual mentorship program, leadership development resources, access to LinkedIn Learning, and more.

SALARY RANGE
The base salary ultimately offered is determined through a review of education, industry experience, training, knowledge, skills, abilities of the applicant in alignment with market data and other factors.
Banc of California is an equal opportunity employer committed to creating a diverse workforce. All qualified applicants will receive consideration for employment without regard to their actual or perceived race (including traits associated with race, such as hair texture, hair type or protective hairstyles), religion or religious creed (including religious dress and grooming practices), color, sex (including pregnancy, childbirth, breastfeeding and related medical conditions), sexual orientation, gender, gender identity, gender expression, gender transitioning, citizenship status, national origin, ancestry, age, marital status, military or veteran status, medical condition, genetic information, or disability (mental or physical), requests for accommodation and any additional protected categories set forth in applicable federal, state or local laws. If you require reasonable accommodation as part of the application process, please contact Talent Acquisition.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.

What Banc Of California employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom