1

Security Risk Compliance Jobs in Hayward, CA (NOW HIRING)

Security Risk Manager

San Francisco, CA · Hybrid

$194K - $220K/yr

... compliance, and fostering a culture of security throughout our product and operations. As the ... You'll build the systems and processes that make risk scalable, not just the policies that describe ...

Security Risk Manager

San Francisco, CA · On-site

$194K - $220K/yr

... compliance, and fostering a culture of security throughout our product and operations. As the ... Own Asana's security risk management program: Design and continuously mature a quantitative risk ...

Risk and Compliance Lead

Foster City, CA · On-site

$210K - $270K/yr

Replit is building the security GRC function that will scale with an AI-native product. As the Risk & Compliance lead, you'll own our certification and audit program end to end: SOC 2, ISO 27001, and ...

next page

Showing results 1-20

Security Risk Compliance information

See Hayward, CA salary details

$37.3K

$93K

$141.6K

How much do security risk compliance jobs pay per year?

As of Sep 2, 2026, the average yearly pay for security risk compliance in Hayward, CA is $93,030.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,400.00 and $114,600.00 per year, depending on experience, location, and employer.

What is security risk compliance?

Security Risk Compliance refers to the process of identifying, assessing, and managing risks to an organization's information systems while ensuring adherence to relevant laws, regulations, and industry standards. Professionals in this field develop policies, conduct risk assessments, and implement controls to protect sensitive data from threats. Their work helps organizations minimize security vulnerabilities and avoid legal or financial consequences related to non-compliance.

What are the key skills and qualifications needed to thrive as a security risk compliance professional?

To thrive as a Security Risk Compliance professional, you need a solid understanding of information security frameworks, risk assessment methodologies, and relevant regulations, often supported by a degree in cybersecurity or a related field. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, vulnerability scanners, and certifications like CISSP, CISA, or CRISC is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and collaborate with stakeholders. These skills are vital to ensure organizations meet compliance requirements, mitigate risks, and maintain trust with clients and regulators.

What are some common challenges faced by security risk compliance professionals when balancing regulatory requirements with business objectives?

Security Risk Compliance professionals often need to navigate the delicate balance between adhering to complex regulatory standards and supporting the organization's operational goals. A major challenge is ensuring compliance without hindering business innovation or efficiency. This involves working closely with various departments to interpret regulations, communicate risks, and implement pragmatic controls that satisfy both legal requirements and business needs. Effective collaboration and ongoing education are key to overcoming these challenges and maintaining a strong security posture.

What is the difference between Security Risk Compliance vs Security Analyst?

AspectSecurity Risk ComplianceSecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISACISSP, CompTIA Security+, GIAC Security Certifications
Work EnvironmentPolicy development, compliance audits, risk assessmentsMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government sectors focusing on regulatory adherenceIT departments across various industries focusing on security operations

Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.

What cities near Hayward, CA are hiring for Security Risk Compliance jobs?

Cities near Hayward, CA with the most Security Risk Compliance job openings:

Security Governance, Risk, Compliance Analyst

CYNET SYSTEMS

San Jose, CA • On-site

Contractor

Re-posted 3 days ago


Job description

Job Overview:

Requirement/Must Have:

  • 4+ years working in governance, risk and compliance and/or information security and risk management.
  • Functional knowledge of some CISSP security domains and information security industry standard and best practices.
  • Functional knowledge of applicable security regulatory requirements (SOX, GDPR, AI Act).
  • Functional knowledge of ISMS governance models (i.e. ISO 27001, NIST, CAIQ), information security roles, security controls.
  • Functional knowledge of common security certifications (i.e. ISO 27001, ISO 42001, SOC1, SOC2) and ability to glean significance from findings identified in these reports.
  • Ability to communicate risk methodologies and concepts to business units and IT teams.
  • Demonstrated experience with controls definition, development, implementation and assessment.
  • Hands-on experience building or customizing AI/automation solutions, including LLM-based workflows, agents, or copilots, API integrations, scripting (e.g., Python), or low-code platforms.
  • Ability to translate GRC use cases into scalable automation solutions.
  • Understanding of AI risks, controls, and governance frameworks (ISO 42001, AI Act).
  • Strong interpersonal skills and ability to work effectively with diverse and distributed teams.
  • Strong attention to detail, project management and organizational skills.
  • Self-starter with the ability to effectively manage independent workloads asynchronously with stakeholders across multiple time zones.

Responsibilities:

  • Support the GRC operating model and the service-oriented customer engagement model.
  • Support GRC capabilities, such as enterprise security risk management, compliance and audit management, policy management, security awareness training, third party risk management, and metrics and reporting.
  • Assist to manage security compliance programs and activities that support various compliance regulations.
  • Perform risk assessments that address security threats, changes to systems and/or applications, process improvement initiatives, supplier assessments (including downstream outsourcers) and other requests from the business.
  • Collaborate with various operational and business teams to complete assessments and drive remediation items to closure. Maintain accurate reporting of remediation activities to bring appropriate visibility to stakeholders and leadership.
  • Monitor the security risk profiles and events of suppliers to objectively determine high risk suppliers that require additional review and treatment plans.
  • Design, build, and deploy AI-powered solutions (including agents) to scale GRC processes including but not limited to Security questionnaires, Risk assessments, Evidence collection and control testing.
  • Develop automated workflows and pipelines using APIs, scripting, or low-code platforms.
  • Apply LLMs/NLP to analyze policies, audit findings, and regulatory requirements.
  • Extract insights from large GRC datasets to build and maintain AI-driven risk scoring and prioritization models.
  • Partner with security, engineering, and data teams to productionize AI use cases.
  • Ensure secure, compliant, and governed use of AI aligned with ISO 42001 and EU AI Act.
  • Establish and maintain security metrics and reporting including automating KRI/KPI generation and reporting pipelines, deliver real-time visibility into security risk posture that aligns with operational/business risk areas and corporate risk.
  • Measure and report efficiency gains from automation (time saved, coverage increased, etc.).
  • Respond to customer security/compliance questionnaires.
  • Act as security risk management ambassador to internal customers.

Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading staffing and recruiting powerhouse. Proudly recognized as a nationally and locally certified diversity firm, Cynet delivers agile, scalable talent solutions across industries. With an active footprint in all 50 U.S. states and Canada, we support thousands of consultants through our expansive, high-performing recruitment engine operating across North America and Asia—ensuring speed, quality, and consistency in every hire.

Cynet Systems logo

About Cynet Systems

Sourced by ZipRecruiter

Cynet Systems Inc is a staffing and recruiting corporation nestled in Ashburn, VA, USA. Established in 2010, the company operates within the Information Technology and Services sector, specializing in providing effective workforce solutions to different business needs, including IT consulting, direct hire, and contract staffing services. Through the years, Cynet Systems has built an impressive portfolio, going beyond borders and expanding its operations internationally in Canada and India. Rooted in its core values of teamwork, leadership, and commitment, Cynet Systems helps businesses unlock their full potential by providing versatile and competent professionals that perfectly align with their needs. Fueled by their unwavering mission to deliver top-tier talent to businesses worldwide, Cynet Systems garnered various recognitions including SIA's fastest-growing staffing firms and Best Place to Work in Virginia for 2019.

Industry

It services

Company size

501 - 1,000 Employees

Headquarters location

Sterling, VA, US

Year founded

2010

Social media