1

Security Risk Compliance Jobs in California (NOW HIRING)

What you'll do Docusign is looking for a Lead Security Risk Manager to join our Security Governance, Risk & Compliance (GRC) team. In this hands-on role, you will lead modern, data-driven security ...

What you'll do Docusign is looking for a Lead Security Risk Manager to join our Security Governance, Risk & Compliance (GRC) team. In this hands-on role, you will lead modern, data-driven security ...

Senior Security Risk Manager

San Francisco, CA ยท Hybrid

$146K - $235K/yr

What you'll do Docusign is looking for a Senior Security Risk Manager to join our Security Governance, Risk & Compliance (GRC) team. In this hands-on role, you will lead and manage modern, data ...

The Compliance Assessor of IT Risk & Compliance Management performs Security Risk Assessments on DIRECTV's 3rd party vendors. An assesment would typically involve the following tasks: Communicating ...

IT Risk & Compliance Analyst

San Francisco, CA ยท On-site

$110K - $111K/yr

Ability to map key Information Security and Technology controls identified in policies, standards ... progress on risk and compliance initiatives. * Willingness to learn/use ITRC tools (e.g ...

Information Security Risk Manager

San Jose, CA ยท On-site

$172K - $229K/yr

We seek a candidate with strong security, technology, compliance, risk, and leadership skills. They must have experience with Information Security and risk oversight practices and principles. The ...

next page

Showing results 1-20

Security Risk Compliance information

See California salary details

$32.1K

$80.1K

$121.9K

How much do security risk compliance jobs pay per year?

As of Jun 16, 2026, the average yearly pay for security risk compliance in California is $80,081.00, according to ZipRecruiter salary data. Most workers in this role earn between $59,700.00 and $98,700.00 per year, depending on experience, location, and employer.

What is the difference between Security Risk Compliance vs Security Analyst?

AspectSecurity Risk ComplianceSecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISACISSP, CompTIA Security+, GIAC Security Certifications
Work EnvironmentPolicy development, compliance audits, risk assessmentsMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government sectors focusing on regulatory adherenceIT departments across various industries focusing on security operations

Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.

What are some common challenges faced by Security Risk Compliance professionals when balancing regulatory requirements with business objectives?

Security Risk Compliance professionals often need to navigate the delicate balance between adhering to complex regulatory standards and supporting the organization's operational goals. A major challenge is ensuring compliance without hindering business innovation or efficiency. This involves working closely with various departments to interpret regulations, communicate risks, and implement pragmatic controls that satisfy both legal requirements and business needs. Effective collaboration and ongoing education are key to overcoming these challenges and maintaining a strong security posture.

What are the key skills and qualifications needed to thrive as a Security Risk Compliance professional, and why are they important?

To thrive as a Security Risk Compliance professional, you need a solid understanding of information security frameworks, risk assessment methodologies, and relevant regulations, often supported by a degree in cybersecurity or a related field. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, vulnerability scanners, and certifications like CISSP, CISA, or CRISC is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and collaborate with stakeholders. These skills are vital to ensure organizations meet compliance requirements, mitigate risks, and maintain trust with clients and regulators.

What is Security Risk Compliance?

Security Risk Compliance refers to the process of identifying, assessing, and managing risks to an organization's information systems while ensuring adherence to relevant laws, regulations, and industry standards. Professionals in this field develop policies, conduct risk assessments, and implement controls to protect sensitive data from threats. Their work helps organizations minimize security vulnerabilities and avoid legal or financial consequences related to non-compliance.
What job categories do people searching Security Risk Compliance jobs in California look for? The top searched job categories for Security Risk Compliance jobs in California are:
What cities in California are hiring for Security Risk Compliance jobs? Cities in California with the most Security Risk Compliance job openings:
Information Security Risk & Compliance

Information Security Risk & Compliance

Trinus

Alhambra, CA โ€ข On-site

Contractor

Posted 24 days ago


Job description

Description:

Trinus Corporation is seeking a skilled Information Security Risk & Compliance professional for a 12-month contract with strong potential for extension after the initial period. This position is ONSITE in Alhambra, CA 91803. Candidates must be authorized to work in the U.S. on a W2 basis.

Skills:

  • Demonstrated expertise in governance, risk management, and cybersecurity compliance, including the development and implementation of policies, standards, and control frameworks.
  • Strong working knowledge of information security regulations and industry frameworks such as NIST (800-53, CSF), ISO/IEC 27001, and PCI DSS, with the ability to map controls and assess compliance.
  • Experience conducting risk assessments, control evaluations, and compliance audits to support enterprise-wide GRC initiatives.
  • Familiarity with vulnerability management, threat intelligence analysis, and security architecture design in support of risk and compliance objectives.
  • Understanding of encryption technologies and data protection principles as they relate to governance and regulatory obligations.
  • Foundational knowledge of technical environments including IT security, networking, and systems administration, with awareness of tools such as SIEM (e.g., Microsoft Sentinel), firewalls, and other endpoint/network security platforms.ย 

Experience Required:

  • 5 years of experience applying security policies, standards, testing, modification and implementation. At least 3 years of that experience must be in information security analysis.ย ย ย ย ย 
  • 3+ years of experience within each of the following:
    • Applying risk management principles, including conducting audits, security assessments, and interpreting industry-standard security frameworks (e.g., NIST, ISO 27001, CIS).
    • Conducting and supporting security operations, control assessments, audit remediation, and enterprise risk governance initiatives.
    • Performing information security risk assessments, evaluating control effectiveness, and analyzing risk impact for technology initiatives and third-party integrations.
    • Participating in incident response processes, including detection, containment, and post-incident analysis.
    • Managing the security of complex, multi-platform IT environments, including various operating systems, software suites, and network protocols, within a large organization.ย ย 

Education Required:ย ย 

  • This classification requires possession of a bachelorโ€™s degree in an IT-related or Engineering field. Additional qualifying experience may be substituted for the required education on a year-for-year basis.ย 

Certification (must have 1 of the following listed):

  • CISSP - Certified Information Systems Security Professional.
  • CRISC -ย Certified in Risk and Information Systems Control.
  • CISA -ย Certified Information Systems Auditor.
  • CISM - Certified Information Security Manager.

Interview Process:

  • Interviews will be conducted in person in Alhambra, CA 91803.

Work Schedule:

  • Work schedule is Mon - Thu 7:15 am โ€“ 6:00 pm (10 hours/day).