1

Security Risk Analyst Jobs in California (NOW HIRING)

... Insider Risk Analyst to protect their advanced technologies. The role involves conducting ... OR 4+ years professional experience in internal investigations, information security ...

GENERAL SUMMARY Our Information Security Team is responsible for identifying potential threats ... The Insider Risk Analyst supports the Insider Risk Program by monitoring and triaging insider-risk ...

They are seeking an Insider Risk Analyst to protect their advanced technologies by conducting ... OR 4+ years professional experience in internal investigations, information security ...

GENERAL SUMMARY Our Information Security Team is responsible for identifying potential threats ... The Insider Risk Analyst supports the Insider Risk Program by monitoring and triaging insider-risk ...

IT Risk Analyst

San Diego, CA · On-site

$79K - $102K/yr

Position Summary The position of IT Risk Analyst is responsible for participating in IT compliance ... Information security and/or risk certification(s) desirable. * Track record of producing quality ...

The Compliance Assessor of IT Risk & Compliance Management performs Security Risk Assessments on DIRECTV's 3rd party vendors. An assesment would typically involve the following tasks: Communicating ...

Risk Analyst, Temp Work Schedule: Monday - Friday, 8:50 am to 5:00 pm Pay Rate: $37.84 per hourJob ... security Qualifications * High school diploma or equivalent required; Bachelor's degree in a ...

Risk Analyst, Temp Work Schedule: Monday - Friday, 8:50 am to 5:00 pm Pay Rate: $37.84 per hour Job ... security Qualifications * High school diploma or equivalent required; Bachelor's degree in a ...

Agentic Risk Analyst

San Francisco, CA · On-site

$288K - $425K/yr

About the Role As an Agentic Risk Analyst, you will shape OpenAI's operating picture for current ... By synthesizing signals from investigations, evaluations, red teaming, security reviews, product ...

next page

Showing results 1-20

Security Risk Analyst information

See California salary details

$10

$49

$69

How much do security risk analyst jobs pay per hour?

As of Jun 30, 2026, the average hourly pay for security risk analyst in California is $49.75, according to ZipRecruiter salary data. Most workers in this role earn between $40.34 and $59.33 per hour, depending on experience, location, and employer.

Can I make $200,000 a year in cyber security?

Security Risk Analysts and other cybersecurity professionals can potentially earn $200,000 or more annually, especially with advanced skills, certifications like CISSP, and experience in high-demand areas such as threat intelligence or security architecture. Achieving this level often requires several years of experience, specialized knowledge, and working in senior or managerial roles within organizations or consulting firms.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

Can you make $500,000 a year in cyber security?

Security Risk Analysts typically earn salaries below $200,000 annually, but senior roles such as Chief Information Security Officers or cybersecurity executives can reach or exceed $500,000 with extensive experience, certifications, and leadership responsibilities. Achieving this level often requires advanced skills, industry certifications like CISSP, and years of experience in high-level security management.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is typically not entry-level and usually requires some experience in cybersecurity, network monitoring, or related fields. Entry-level positions may be labeled as SOC analyst I or junior SOC analyst, but higher-level roles often demand certifications like CompTIA Security+ or CISSP and familiarity with security tools such as SIEM systems.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.
What job categories do people searching Security Risk Analyst jobs in California look for? The top searched job categories for Security Risk Analyst jobs in California are:
Information Security Risk Analyst

Information Security Risk Analyst

AllSTEM Connections

San Francisco, CA • On-site

$153K/yr

Temporary

Medical, Dental, Vision, Retirement

Posted 18 days ago


Job description

JOB SUMMARY
Are you passionate about strengthening security through risk insight and strategic partnership? We are seeking an experienced Information Security Risk Analyst to help identify, assess, and reduce cybersecurity risk across cloud and on-prem environments.
In this role, you will partner closely with application development teams, technical stakeholders, and leadership to evaluate security controls, advise on secure cloud and DevSecOps practices, and translate complex technical risks into actionable business guidance. This is an opportunity to play a highly visible role in improving enterprise security posture while influencing modern development practices, third-party risk management, and emerging AI/GenAI governance considerations.
If you thrive in collaborative environments and enjoy combining technical depth with risk strategy and communication, this role offers meaningful impact and professional growth.
KEY RESPONSIBILITIES
• Support enterprise risk strategies by identifying security risks in processes and technologies and leading initiatives to reduce exposure.
• Apply and interpret security policies and contribute insights to ongoing policy and control improvements.
• Partner with business and technical teams to help them understand and implement security controls, policies, and procedures.
• Establish trusted relationships across assigned business areas to understand operational and technical requirements and enable secure outcomes.
• Advise application development teams on Secure Cloud Development and DevSecOps best practices to mature security practices.
• Assess technical implementations in both cloud and on-prem environments to evaluate security risk and recommend control enhancements or compensating controls.
• Perform complex security analyses and provide clear, practical mitigation recommendations.
• Evaluate third-party service providers, identify associated risks, and clarify shared security responsibilities.
• Conduct formal security control assessments and prepare detailed assessment reports documenting scope, methodology, findings, risk impact, and remediation recommendations.
• Communicate security risks and business implications to stakeholders at all levels, including executive leadership.
• Collaborate cross-functionally, manage multiple initiatives simultaneously, and navigate ambiguity in a fast-paced, results-driven environment.
REQUIRED QUALIFICATIONS
• Experience performing security control assessments aligned to NIST 800-37 (SCA and CMCA).
• Hands-on experience conducting assessments using NIST 800-53 controls.
• Experience reviewing and evaluating FedRAMP authorization packages.
• Experience mapping OWASP Top Ten risks within DevSecOps environments to strengthen security operations.
• Strong understanding of cloud security principles and secure development practices.
• Ability to analyze complex technical security issues and translate them into clear, actionable risk narratives.
PREFERRED QUALIFICATIONS
• Experience in DevSecOps environments, including governance and security automation.
• Exposure to AI / GenAI-related cybersecurity governance and risk considerations.
• Experience working in regulated or compliance-driven environments.
KEY COMPETENCIES
• Strong verbal and written communication skills with the ability to convey risk to both technical and non-technical stakeholders.
• Excellent relationship-building and stakeholder partnership skills.
• Strategic thinking with practical, solutions-oriented execution.
• Ability to manage competing priorities while maintaining accountability and delivering results. Equal Opportunity Employer / Disabled / Protected Veterans
The Know Your Rights poster is available here:
https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12.pdf
The pay transparency policy is available here:
https://www.dol.gov/sites/dolgov/files/ofccp/pdf/pay-transp_%20English_formattedESQA508c.pdf
For temporary assignments lasting 13 weeks or longer, AllSTEM Connections is pleased to offer major medical, dental, vision, 401k and any statutory sick pay where required.
We are committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please contact your staffing representative who will reach out to our HR team.
AllSTEM Connections participates in the E-Verify program in certain locations as required by law. Learn more about the E-Verify program.
https://e-verify.uscis.gov/web/media/resourcesContents/E-Verify_Participation_Poster_ES.pdf
We also consider for employment qualified applicants regardless of criminal histories, consistent with legal requirements, including, if applicable, the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance. Pursuant to applicable state and municipal Fair Chance Laws and Ordinances, we will consider for employment-qualified applicants with arrest and conviction records, including, if applicable, the San Francisco Fair Chance Ordinance. For Los Angeles, CA applicants: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Additional Skills
(none specified)
AllSTEM Representative Contact Info
Account Executive:
IN HOUSE
Branch Phone:
(909) 244-1777
Location:
Ontario, CA