1

Security Risk Analyst Jobs in California (NOW HIRING)

The Compliance Assessor of IT Risk & Compliance Management performs Security Risk Assessments on DIRECTV's 3rd party vendors. An assesment would typically involve the following tasks: Communicating ...

Analyze risk data to uncover recurring issues, trends, and root causes, and recommend changes to strengthen controls * Partner with Engineering, Security, and business functions to embed risk ...

Analyze risk data to identify trends, root causes, and control gaps, and recommend changes to strengthen controls * Partner with Engineering, Security, and business teams to embed risk insights into ...

Analyze risk data to identify trends, root causes, and control gaps, and recommend changes to strengthen controls * Partner with Engineering, Security, and business teams to embed risk insights into ...

Sr. Risk Analyst

Vacaville, CA · On-site

$98K - $121K/yr

... financial security. Profile: * Reviews and analyzes financial transactions for unusual or ... Senior Risk Analyst - Grade15/Exempt/$82,680.00 - $102,128.00 annually * * Reports directly to ...

Sr. Risk Analyst

Vacaville, CA · Hybrid

$98K - $121K/yr

... financial security. Profile: * Reviews and analyzes financial transactions for unusual or ... Senior Risk Analyst - Grade15/Exempt/$82,680.00 - $102,128.00 annually * Reports directly to ...

Sr. Risk Analyst

Vacaville, CA · On-site

$98K - $121K/yr

... financial security. Profile: * Reviews and analyzes financial transactions for unusual or ... Senior Risk Analyst - Grade15/Exempt/$82,680.00 - $102,128.00 annually * Reports directly to ...

INSIDER RISK ANALYST SpaceX is seeking a dynamic and driven individual with a demonstrated ability ... Conduct internal investigations working with Information Security, HR, Legal, Government Security ...

Insider Risk Analyst

Hawthorne, CA · On-site

$85K - $100K/yr

INSIDER RISK ANALYST SpaceX is seeking a dynamic and driven individual with a demonstrated ability ... Conduct internal investigations working with Information Security, HR, Legal, Government Security ...

next page

Showing results 1-20

Security Risk Analyst information

See California salary details

$10

$49

$69

How much do security risk analyst jobs pay per hour?

As of Jun 7, 2026, the average hourly pay for security risk analyst in California is $49.75, according to ZipRecruiter salary data. Most workers in this role earn between $40.34 and $59.33 per hour, depending on experience, location, and employer.

What does a Security Risk Analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges Security Risk Analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What job categories do people searching Security Risk Analyst jobs in California look for? The top searched job categories for Security Risk Analyst jobs in California are:
IT Security Risk and Compliance Analyst - Hybrid - 139800

IT Security Risk and Compliance Analyst - Hybrid - 139800

University of California San Diego

San Diego, CA • On-site

$105K - $132K/yr

Full-time

Posted 8 days ago


University Of California San Diego rating

8.1

Company rating: 8.1 out of 10

Based on 40 frontline employees who took The Breakroom Quiz

131st of 534 rated colleges and universities


Job description

Payroll Title:
IT SCRTY ANL 3 TX Department:
INFORMATION SERVICES Hiring Pay Scale
$105,000 - $132,000 / Year Worksite:
Towne Centre Drive Appointment Type:
Career Appointment Percent:
100% Union:
TX Contract Total Openings:
1 Work Schedule:
Days, 8 hrs/day, Monday-Friday
#139800 IT Security Risk and Compliance Analyst - Hybrid
Filing Deadline: Thu 6/11/2026
Apply Now
UC San Diego values and welcomes people from all backgrounds. If you are interested in being part of our team, possess the needed licensure and certifications, and feel that you have most of the qualifications and/or transferable skills for a job opening, we strongly encourage you to apply.
UCSD Layoff from Career Appointment : Apply by 05/26/26 for consideration with preference for rehire. All layoff applicants should contact their Employment Advisor.
Reassignment Applicants : Eligible Reassignment clients should contact their Disability Counselor for assistance.
This position has recently been accreted by UPTE TX union and will be a part of that union moving forward.
This position will work a hybrid schedule which includes a combination of working both onsite at Towne Centre Drive (San Diego, CA) and remote.
DESCRIPTION
The IT Security Risk and Compliance Analyst executes processes across the organization to conduct the required IT security risk assessment and compliance program to reduce information security risk, address threats and vulnerabilities to information assets, monitor compliance to policy, and improve the overall security posture of the University.
The role performs security risk assessments and internal security audits/reviews, supports external audits and accreditation activities, and operates the governance components of the vulnerability management program. This includes vulnerability analysis, risk based prioritization, remediation tracking, validation of remediation effectiveness, and documentation of risk acceptance where remediation is deferred. The position provides recommendations for security controls and ensures follow through through established governance processes to meet campus policy and regulatory requirements such as HIPAA, PCI, FERPA, and related standards.
The incumbent maintains clear, audit ready decision records and evidence artifacts that support internal and external audits, regulatory oversight, and legally mandated information requests. This includes documentation of risk assessments, vulnerability decisions, compensating controls, governance approvals, secure handling of sensitive data, access constraints, and defensible evidence production for legal hold and eDiscovery matters. These activities are required elements of HIPAA compliance and are used to prioritize remediation based on risk, including patient safety and operational resiliency impacts where applicable. Thorough, documented risk assessments and compliance programs are foundational components of the Information Security Program and drive security improvement activities across the organization.
MINIMUM QUALIFICATIONS
  • Seven (7) years of related experience, education/training, OR a Bachelor's degree in related area plus three (3) years of related experience/training. Related experience: experience performing security risk assessments and/or internal security reviews to ensure that security controls meet policy and/or regulatory requirements, including evaluating control design and effectiveness. This may include experience in areas such as IT security risk and compliance (GRC), IT audit, vendor/third-party risk assessments, security consulting or assessment roles, or technical security roles with responsibility for evaluating control effectiveness and producing audit-ready documentation.
  • Ability to follow department processes and procedures.
  • Interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.
  • Experience using IT security systems and tools.
  • Knowledge of data encryption techniques.
  • Knowledge of other areas of IT, department processes and procedures.
  • Demonstrated skills applying security controls to computer software and hardware.
  • Experience in incident response and digital forensics including data collection, examination and analysis.
  • Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks.
  • Knowledge of computer hardware, software and network security issues and approaches.
  • Demonstrated experience selecting and applying appropriate data encryption technologies.
PREFERRED QUALIFICATIONS
  • Exposure to vulnerability management programs, including risk based prioritization, remediation tracking, validation of remediation effectiveness, and documentation of risk acceptance.
  • Ability to apply security risk assessment practices to third party/vendor reviews, including evaluation of evidence, identification of risks, and documentation of findings and conditions.
  • Familiarity with legal hold and eDiscovery workflows, including secure handling of sensitive exports and defensible evidence production.
  • Familiarity with external security audits/accreditations and internal security audit/review processes.
  • Comfort operating in regulated environments (healthcare and/or research) and with applicable compliance drivers (e.g., HIPAA, PCI, FERPA, campus policy requirements).
  • Skilled in documenting risk exceptions/acceptances, compensating controls, and governance routing/approvals.
  • Strong cross functional advisory skills with technical and non technical stakeholders.
SPECIAL CONDITIONS
  • Must be able to work various hours and locations based on business needs.
  • Employment is subject to a criminal background check and pre-employment physical.
Pay Transparency Act
Annual Full Pay Range: Unclassified - No data available (will be prorated if the appointment percentage is less than 100%)
Hourly Equivalent: Unclassified - No data available
Factors in determining the appropriate compensation for a role include experience, skills, knowledge, abilities, education, licensure and certifications, and other business and organizational needs. The Hiring Pay Scale referenced in the job posting is the budgeted salary or hourly range that the University reasonably expects to pay for this position. The Annual Full Pay Range may be broader than what the University anticipates to pay for this position, based on internal equity, budget, and collective bargaining agreements (when applicable).
Apply Now
If employed by the University of California, you will be required to comply with our Policy on Vaccination Programs, which may be amended or revised from time to time. Federal, state, or local public health directives may impose additional requirements.
If applicable, life-support certifications (BLS, NRP, ACLS, etc.) must include hands-on practice and in-person skills assessment; online-only certification is not acceptable.
UC San Diego Health is the only academic health system in the San Diego region, providing leading-edge care in patient care, biomedical research, education, and community service. Our facilities include two university hospitals, a National Cancer Institute-designated Comprehensive Cancer Center, Shiley Eye Institute, Sulpizio Cardiovascular Center, the only Burn Center in the county, and dozens of outpatient clinics. We invite you to join our team!
Applications/Resumes are accepted for current job openings only. For full consideration on any job, applications must be received prior to the initial closing date. If a job has an extended deadline, applications/resumes will be considered during the extension period; however, a job may be filled before the extended date is reached.
To foster the best possible working and learning environment, UC San Diego strives to cultivate a rich and diverse environment, inclusive and supportive of all students, faculty, staff and visitors. For more information, please visit UC San Diego Principles of Community .
The University of California is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, protected veteran status, or other protected status under state or federal law.
For the University of California's Anti-Discrimination Policy, please visit: https://policy.ucop.edu/doc/1001004/Anti-Discrimination
UC San Diego is a smoke and tobacco free environment. Please visit smokefree.ucsd.edu for more information.
UC San Diego Health maintains a marijuana and drug free environment. Employees may be subject to drug screening.
Misconduct Disclosure Requirement: As a condition of employment, the final candidate who accepts an offer of employment will be required to disclose if they have been subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct; or have filed an appeal of a finding of substantiated misconduct with a previous employer.
a. "Misconduct" means any violation of the policies governing employee conduct at the applicant's previous place of employment, including, but not limited to, violations of policies prohibiting sexual harassment, sexual assault, or other forms of harassment, or discrimination, as defined by the employer. For reference, below are UC's policies addressing some forms of misconduct:
  • UC Sexual Violence and Sexual Harassment Policy
  • UC Anti-Discrimination Policy
  • Abusive Conduct in the Workplace

What University Of California San Diego employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom