1

Security Risk Analyst Jobs in California (NOW HIRING)

Insider Risk Analyst

Hawthorne, CA · On-site

$85K - $100K/yr

INSIDER RISK ANALYST SpaceX is seeking a dynamic and driven individual with a demonstrated ability ... Conduct internal investigations working with Information Security, HR, Legal, Government Security ...

INSIDER RISK ANALYST SpaceX is seeking a dynamic and driven individual with a demonstrated ability ... Conduct internal investigations working with Information Security, HR, Legal, Government Security ...

Respond to DLP alerts, monitor DLP consoles and analyze security events to identify potential data loss incidents. * Lead in-depth investigations of suspected insider threat incidents, including ...

Credit Risk Analyst

San Francisco, CA · On-site +1

$122K - $140K/yr

A Credit Risk Analyst at Prosper has the opportunity to utilize advanced analytical skills to ... financial security. * Holistic well-being: We provide the resources you need to thrive, from ...

Credit Risk Analyst

San Francisco, CA · On-site +1

$122K - $140K/yr

A Credit Risk Analyst at Prosper has the opportunity to utilize advanced analytical skills to ... financial security. * Holistic well-being: We provide the resources you need to thrive, from ...

Required : • Undergraduate degree in Intelligence Studies, Forensic Science, Security Studies ... risk analysis. • Demonstrates the ability to work effectively with a diverse range of ...

Credit Risk Analyst

San Francisco, CA · On-site

$122K - $140K/yr

A Credit Risk Analyst at Prosper has the opportunity to utilize advanced analytical skills to ... financial security. * Holistic well-being: We provide the resources you need to thrive, from ...

next page

Showing results 1-20

Security Risk Analyst information

See California salary details

$10

$49

$69

How much do security risk analyst jobs pay per hour?

As of Jul 22, 2026, the average hourly pay for security risk analyst in California is $49.75, according to ZipRecruiter salary data. Most workers in this role earn between $40.34 and $59.33 per hour, depending on experience, location, and employer.

Can I make $200,000 a year in cyber security?

Security Risk Analysts and other cybersecurity professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP, and expertise in areas such as threat analysis or security architecture. High salaries are often found in senior roles, management, or specialized fields within cybersecurity.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

Can you make $500,000 a year in cyber security?

Security Risk Analysts typically earn salaries below $200,000 annually, but senior roles such as Chief Information Security Officers or cybersecurity executives can reach or exceed $500,000 with extensive experience, certifications, and leadership responsibilities. Achieving this level often requires advanced skills, industry certifications like CISSP, and years of experience in high-level security management. Salary potential varies based on the organization, location, and individual expertise.

Is SOC an entry-level job?

A Security Operations Center (SOC) analyst role is often considered an entry-level position in cybersecurity, suitable for individuals with foundational knowledge of security principles, network protocols, and security tools. However, some SOC roles may require prior experience or certifications such as CompTIA Security+ or Certified SOC Analyst (CSA).

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.
What job categories do people searching Security Risk Analyst jobs in California look for? The top searched job categories for Security Risk Analyst jobs in California are:
Infographic showing various Security Risk Analyst job openings in California as of July 2026, with employment types broken down into 75% Full Time, 12% Temporary, and 13% Contract. Highlights an 85% In-person, and 15% Remote job distribution, with an average salary of $103,475 per year, or $49.7 per hour.
Principal Technology Risk Management - Data Security

Principal Technology Risk Management - Data Security

Early Warning Services

San Francisco, CA

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 13 days ago


Job description

At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle, Paze, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.

Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Job Description

OverallPurpose

Provides independent second-line oversight, assessment, and crediblechallengeof first-line technology risk management activities across the company. Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk indicators, governance reporting, and escalation. Helps ensure technology-related risks are managedconsistentwith enterprise risk appetite, regulatory expectations, and sound industry practice. May support one or more focus areas based on business need, including Enterprise Technology Risk, Data Security Risk, Access Management Risk, Offensive Security Risk, Vulnerability Management Risk, AI SecurityRisk, andAsset and Inventory Management Risk.


Essential Functions

  • Provide independent review, oversight, and crediblechallengeoffirst-line technology risk management activities, controls, and decisions.

  • Evaluate the design and execution of risk management practices to ensure alignment with enterprise frameworks, policies, regulatory expectations, and relevant industry standards.

  • Provide independentchallengeand oversight of risk identification and assessment activities.

  • Review and challenge risk and control self-assessments,issuesmanagement, remediation plans, control validation outcomes, and key risk indicators.

  • Assess the adequacy of severity ratings, root cause analyses, action plans, and closure evidence for technology-related issues and risk events.

  • Identifyrisk trends, concentrations, and emerging themes through analysis of risk data, governance materials, and business changes; develop an independent view of risk exposure and control effectiveness.

  • Prepare and support reporting, escalation, anddiscussionmaterials for senior leaders, governance forums, and risk committees.

  • Partner with first-line leaders, subject matter experts, and independent testing or validation teams to improve clarity of control expectations, testing scope, and evidence requirements.

  • Provide ongoing risk advisory support whilemaintainingsecond-line independence and accountability for effectivechallenge.

  • Recommendopportunities to strengthen risk awareness, governance routines, and training that improve technology risk management maturity.

  • Support the company's commitment to risk management and protecting the integrity and confidentiality of systems and data.


Focus: Enterprise Technologyand Information SecurityRisk

  • Provide independentchallengeand oversight of technology risk management practices across infrastructure, cloud, cybersecurity, product, and operational technology domains.

  • Provide independentchallengeand oversight ofinformation securityrisk management practices acrossthreat management, network, endpoint, cloud, architecture,data, access, AI,or applicationsecuritydomains.

  • Assess alignment of technology risk and control activities to enterprise policies, risk frameworks, and applicable industry standards.

  • Evaluate whether risk assessments, control inventories,issuesmanagement, and key risk indicators are executed consistently and effectively across the technology organization.

  • Challenge risk identification activities related to significant technology changes, new products or capabilities, and cross-functional initiatives.

  • Assess risk trends and systemic themes across the technology environment and provide independent reporting and escalation as needed.

Minimum Qualifications

  • Education and/or experience typically obtained through completion of aBachelor'sdegree or equivalent.

  • Typically has 12 years of experience ordemonstratedportfolio consistent with experience required of the role in technology risk, information security, operational risk, or related disciplines within a regulatedor otherwisecomplex operating environment.

  • Strong understanding of risk management practices, control frameworks, and second-line oversight withinathree lines of defense model.

  • Demonstrated experience providing independent review, challenge, or governance of first-line technology, security, data, or operational risk activities.

  • Strong ability to assess control design and effectiveness, synthesize risk data,identifythemes, and translate technical issues into business risk.

  • Excellent written, verbal, presentation, and stakeholder management skills, including experience interacting with senior leaders and cross-functional partners.

  • Strong critical thinking, judgment, and problem-solving skills, with the ability to provide practical, risk-based recommendations in a complex environment.

  • Ability tooperateindependently, manage competing priorities, andmaintaineffective working relationships while preserving second-line objectivity.

  • Background and drug screen.

Preferred Qualifications

  • Advanced degree oradditionalrelated education and/or experience preferred.

  • Experience in financial services, payments, fintech, oranotherhighly regulated industry.

  • Familiarity with relevant regulatory expectations and industry standardsand frameworksapplicable to technology and security risk managementsuchas;ISO 27002, PCI DSS, NIST, FFIEC,andSOC 2.

  • Experience supporting governance committees, audits, examinations, or regulatory interactions.

  • Relevant risk, security, audit, or control certifications preferredsuch as CISA, CISM, CISSP, CCSP, CRISC, GSNA, CGIH, or equivalent preferred.

  • Project or process management experience supporting cross-functional risk, control, or governance initiatives preferred.

The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.

Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling, and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.
Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.

The base pay scale for this position in:
Phoenix, AZ/ Chicago, IL / Washington, DC in USD per year is: $184,000 - $230,000.
New York, NY/ San Francisco, CA in USD per year is: $221,000 - $276,000.
Additionally, candidates are eligible for a discretionary incentive plan and benefits.

This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.

#Dice

#LI-AV

Some of the Ways We Prioritize Your Health and Happiness

  • Healthcare Coverage-Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.

  • 401(k) Retirement Plan-Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.

  • Paid Time Off -Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.

  • 12 weeks of Paid Parental Leave

  • Maven Family Planning - provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.

AndSOmuch more! We continue to enhance our program, so be sure tocheck our Benefits page herefor the latest. Ourteamcan share more during the interview process!

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.