Contribute to the development, management, and ongoing improvement of the Information Security risk program, compliance initiatives, and overall security risk posture. * Partner with senior ...
Contribute to the development, management, and ongoing improvement of the Information Security risk program, compliance initiatives, and overall security risk posture. * Partner with senior ...
We are rebuilding risk management to operate as an engineering function through automation and AI-native platforms to enable decision making. The systems we assess span Anthropic's full security ...
New
We are rebuilding risk management to operate as an engineering function through automation and AI-native platforms to enable decision making. The systems we assess span Anthropic's full security ...
New
We are rebuilding risk management to operate as an engineering function through automation and AI-native platforms to enable decision making. The systems we assess span Anthropic's full security ...
New
We are rebuilding risk management to operate as an engineering function through automation and AI-native platforms to enable decision making. The systems we assess span Anthropic's full security ...
New
Information Security Analyst 4
Irvine, CA · On-site
They are seeking a Senior Information Security Analyst to lead the enterprise Information Security Governance, Risk Management, and Strategy function, focusing on Responsible GenAI and ensuring ...
New
Information Security Analyst 4
Irvine, CA · On-site
They are seeking a Senior Information Security Analyst to lead the enterprise Information Security Governance, Risk Management, and Strategy function, focusing on Responsible GenAI and ensuring ...
New
Information Security Analyst 4
Irvine, CA · On-site
They are seeking a Senior Information Security Analyst to lead their enterprise Information Security Governance, Risk Management, and Strategy function, focusing on Responsible GenAI and ensuring ...
New
Information Security Analyst 4
Irvine, CA · On-site
They are seeking a Senior Information Security Analyst to lead their enterprise Information Security Governance, Risk Management, and Strategy function, focusing on Responsible GenAI and ensuring ...
New
Information Security Analyst 4
Irvine, CA · On-site
$124K - $206K/yr
Embed GenAI risk evaluation into procurement, vendor risk management, and IT risk workflows ... Information Security GRC * Implement and mature enterprise information security risk management ...
New
Information Security Analyst 4
Irvine, CA · On-site
$124K - $206K/yr
Embed GenAI risk evaluation into procurement, vendor risk management, and IT risk workflows ... Information Security GRC * Implement and mature enterprise information security risk management ...
New
Information Security Analyst 4
Irvine, CA · On-site
Embed GenAI risk evaluation into procurement, vendor risk management, and IT risk workflows ... Information Security GRC * Implement and mature enterprise information security risk management ...
New
Information Security Analyst 4
Irvine, CA · On-site
Embed GenAI risk evaluation into procurement, vendor risk management, and IT risk workflows ... Information Security GRC * Implement and mature enterprise information security risk management ...
New
As the R&D Security & Export Control Risk Manager, you play a critical role in ensuring that ... Export Control Risk Management * Identify and assess export control risks related to R&D activities ...
As the R&D Security & Export Control Risk Manager, you play a critical role in ensuring that ... Export Control Risk Management * Identify and assess export control risks related to R&D activities ...
Risk Management Analyst
Sacramento, CA · On-site
Risk Management Analyst Location: Sacramento, CA Duration: 12 Months Minimum Skills ... Must understand the current security threats model and demonstrate a strong willingness to stay at ...
Risk Management Analyst
Sacramento, CA · On-site
Risk Management Analyst Location: Sacramento, CA Duration: 12 Months Minimum Skills ... Must understand the current security threats model and demonstrate a strong willingness to stay at ...
Information Security Risk and Governance Specialist, Senior
El Dorado Hills, CA · On-site
$102K - $154K/yr
The Information Security Risk & Governance Specialist, Senior will report to the Senior Manager, Technology External Assurance. In this role, you will be a key individual contributor to the ...
Information Security Risk and Governance Specialist, Senior
El Dorado Hills, CA · On-site
$102K - $154K/yr
The Information Security Risk & Governance Specialist, Senior will report to the Senior Manager, Technology External Assurance. In this role, you will be a key individual contributor to the ...
IT Security Risk and Compliance Analyst - Hybrid - 139800
San Diego, CA · On-site
$105K - $132K/yr
Exposure to vulnerability management programs, including risk based prioritization, remediation ... Ability to apply security risk assessment practices to third party/vendor reviews, including ...
IT Security Risk and Compliance Analyst - Hybrid - 139800
San Diego, CA · On-site
$105K - $132K/yr
Exposure to vulnerability management programs, including risk based prioritization, remediation ... Ability to apply security risk assessment practices to third party/vendor reviews, including ...
The ideal candidate will have extensive experience in information security, including experience with security risk management, incident response, and forensics. The vision for CorVel security ...
The ideal candidate will have extensive experience in information security, including experience with security risk management, incident response, and forensics. The vision for CorVel security ...
Senior Director Product Security
$273K - $286K/yr
Risk Management and Decision Support Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. Translate ...
Senior Director Product Security
$273K - $286K/yr
Risk Management and Decision Support Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. Translate ...
The ideal candidate will have extensive experience in information security, including experience with security risk management, incident response, and forensics. The vision for CorVel security ...
The ideal candidate will have extensive experience in information security, including experience with security risk management, incident response, and forensics. The vision for CorVel security ...
Senior Director Product Security
$250K - $261K/yr
Risk Management and Decision Support Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. Translate ...
Senior Director Product Security
$250K - $261K/yr
Risk Management and Decision Support Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. Translate ...
Risk Management, Compliance & Controls * Ensure digital solutions meet regulatory, risk, and compliance requirements across regions (including EU and APAC). * Partner with Security Architecture ...
Risk Management, Compliance & Controls * Ensure digital solutions meet regulatory, risk, and compliance requirements across regions (including EU and APAC). * Partner with Security Architecture ...
Director, Risk Management
Diamond Bar, CA · On-site
Oversee coordination of risk management efforts related to physical security, safety, and operational continuity. * Partner with HR and Operations to ensure compliance with safety regulations and ...
Director, Risk Management
Diamond Bar, CA · On-site
Oversee coordination of risk management efforts related to physical security, safety, and operational continuity. * Partner with HR and Operations to ensure compliance with safety regulations and ...
Sr. Cybersecurity GRC Manager
Irvine, CA · On-site
$119K - $161K/yr
Qualifications What You Will Bring • Minimum 8 years progressive experience in cybersecurity governance, risk management, or compliance with a deep understanding of security risk management, system ...
Sr. Cybersecurity GRC Manager
Irvine, CA · On-site
$119K - $161K/yr
Qualifications What You Will Bring • Minimum 8 years progressive experience in cybersecurity governance, risk management, or compliance with a deep understanding of security risk management, system ...
Senior Director Product Security
Santa Clara, CA · On-site
$273K - $286K/yr
Risk Management and Decision Support • Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. • ...
Senior Director Product Security
Santa Clara, CA · On-site
$273K - $286K/yr
Risk Management and Decision Support • Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. • ...
Sr. Cybersecurity GRC Manager
$119K - $161K/yr
Strong knowledge of Information Security risk management frameworks, Governance, Risk, and Compliance process, IT general controls (e.g. asset classification, risk assessments, vulnerability and ...
Sr. Cybersecurity GRC Manager
$119K - $161K/yr
Strong knowledge of Information Security risk management frameworks, Governance, Risk, and Compliance process, IT general controls (e.g. asset classification, risk assessments, vulnerability and ...
Security Risk Management information
See California salary details
$10.20 - $15.55
2% of jobs
$15.55 - $20.90
0% of jobs
$20.90 - $26.25
1% of jobs
$26.25 - $31.60
1% of jobs
$31.60 - $36.94
1% of jobs
$40.96 is the 25th percentile. Wages below this are outliers.
$36.94 - $42.29
26% of jobs
$42.29 - $47.64
11% of jobs
The median wage is $49.55 / hr.
$47.64 - $52.99
22% of jobs
$52.99 - $58.34
9% of jobs
$58.76 is the 75th percentile. Wages above this are outliers.
$58.34 - $63.69
17% of jobs
$63.69 - $69.04
9% of jobs
$10
$49
$69
How much do security risk management jobs pay per hour?
What are the typical challenges faced by professionals in Security Risk Management, and how can they be addressed?
What is Security Risk Management?
What are the key skills and qualifications needed to thrive in Security Risk Management, and why are they important?
What is the difference between Security Risk Management vs Security Analyst?
| Aspect | Security Risk Management | Security Analyst |
|---|---|---|
| Certifications | CRISC, CISSP, CISM | CompTIA Security+, CISSP, CEH |
| Work Environment | Strategic, policy-focused, risk assessment | Operational, monitoring, incident response |
| Employer & Industry Usage | Organizations managing enterprise security risks | Security teams, cybersecurity firms, IT departments |
Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

Job description
BANC OF CALIFORNIA AND YOUR CAREER
Banc of California, Inc. (NYSE: BANC) is a bank holding company with over $34 billion in assets and the parent company of Banc of California. Banc of California is one of the nation’s premier relationship-based business banks, providing banking and treasury management services to small, middle market, and venture backed businesses. As the largest independent bank headquartered in California, the bank offers a broad range of loan and deposit products and services through a network of full-service branches and regional offices, as well as through digital and nationwide capabilities. The bank also provides full-service payment processing solutions to its clients and serves the Community Association Management industry nationwide through its technology forward platform, SmartStreet™. Banc of California is committed to supporting its local communities through the Banc of California Charitable Foundation and by partnering with organizations that promote financial literacy, job training, small business support, affordable housing, and more.
At Banc of California, our success is powered by our people and a shared commitment to delivering meaningful results. We foster an environment where entrepreneurial thinking is encouraged, and accountability and operational excellence are expected. Our team members are empowered to take ownership, make informed decisions, and make a meaningful impact as the bank continues to grow and evolve. We are dedicated to supporting your growth and wellbeing through comprehensive benefits, robust development opportunities, and inclusive programs that enable you to perform at your best. Together we win!
THE OPPORTUNITY
The VP, Lead Security Risk Analyst leads enterprise-wide Information Security risk engagement across corporate initiatives, embedding security-by-design principles into business and technology decisions. This role drives the development and execution of the Information Security risk and GRC programs, conducting complex, high‑impact risk assessments across enterprise architecture, cloud, AI/ML, and third‑party environments. Serving as a senior advisor, the position partners with leadership, architects, and engineering teams to translate regulatory and security requirements into actionable architectural controls and secure design standards. The VP, Lead Security Risk Analyst also drives cross‑functional remediation efforts to ensure risks are effectively managed in alignment with the organization’s risk appetite. Performs all duties in accordance with the Company’s policies and procedures, all U.S. state and federal laws and regulations, wherein the Company operates.
HOW YOU’LL MAKE A DIFFERENCE
- Lead enterprise Information Security engagement across all enterprise-wide corporate projects, championing security by design principles, influencing security decisions without direct authority and driving alignment across multiple business and technology domains.
- Contribute to the development, management, and ongoing improvement of the Information Security risk program, compliance initiatives, and overall security risk posture.
- Partner with senior management to design and implement maturity strategies and operations into the Information Security GRC team.
- Maintain Information Security risk register, report monthly to appropriately address key risk areas.
- Support policies and procedures maintenance aligned with in-scope security frameworks, regulations, and internal standards to manage identified risk effectively.
- Conduct regular risk assessments to identify potential threats and vulnerabilities across the organization analyzing their impact and likelihood of occurrence.
- Generate reports on risk assessments, compliance status, and control effectiveness to communicate findings to stakeholders at various levels within the organization.
- Lead and deliver enterprise and domain risk assessments (at least annually, or event driven) using consistent methodology that complies with regulatory requirements
- Conduct and lead the bank’s most complex and high-impact risk assessments, including those involving enterprise architecture, modernization initiatives, AI/ML platforms, cloud deployments, or third-party integrations.
- Drive cross-functional remediation initiatives, ensuring timely resolution of identified issues and alignment with enterprise risk appetite.
- Act as the primary GRC representative and senior advisor in enterprise security architecture projects, ensuring that security, compliance, and risk considerations are embedded in design decisions for cloud, infrastructure, and applications.
- Lead architecture-focused risk assessments for new technologies, major system integrations, cloud migrations, and high-impact projects to identify systemic risks and required compensating controls.
- Translate security policies, standards, regulatory requirements and control frameworks into detailed architectural requirements, control patterns, and secure design standards consumable by engineering and application teams.
- Advise solution architects, engineers, and product teams on secure design patterns, identity and access architecture, encryption frameworks, data protection requirements, and logging/monitoring standards.
- Evaluate the security implications of modernization initiatives, and system migrations ensuring risks are documented and mitigated through appropriate design.
- Define architecture-aligned security requirements and control baselines that engineering and architecture teams use to build secure-by-design systems.
- Partner with detection engineering and cloud teams to ensure logging, auditability, and monitoring capabilities are embedded in the technology stack.
- Lead complex and technical vendor security reviews, including onboarding assessments, and high-risk assessments involving cloud platforms, data integrations, and critical infrastructure providers.
- Follow all established policies and procedures.
- Perform other duties and projects as assigned.
WHAT YOU’LL BRING
- Bachelor’s degree in information systems, engineering, business, risk management, or related field; and related certifications (e.g., CISSP ISSAP, SABSA, CCSP, GCAD, CRISC, CISSP).
- 7-9+ years of experience in GRC, cybersecurity, risk management or related fields, and most importantly cloud/security architecture, particularly in highly regulated industries such as financial, or professional services.
- Demonstrated history of influencing architectural decisions and driving enterprise-level security program improvements.
- High technical knowledge across Cybersecurity domains, including Security Operations, Incident
- Response, Security Engineering, Cloud Security, Artificial Intelligence (AI), Data Security, Configuration
- Management, Log Generation, Security Risk Assessments/testing methodologies, Secure Software Development Lifecycle, evaluating the adequacy and efficiency of internal controls.
- Advanced knowledge of cloud architecture, application security, identity governance, encryption, secure design patterns, network architecture, and telemetry design.
- Experience translating requirements into architectural controls and technical standards.
- Expert knowledge of GRC frameworks and regulations (e.g., PCI-DSS, GDPR, CCPA, GLBA, NIST, ISO 27001).
- Strong knowledge in OWASP, CIS and/or other security standards and secure configuration baselines.
- Excellent analytical skills with the ability to assess complex risks and develop effective mitigation security strategies.
- Comfortable solving ambiguous, enterprise-scale problems.
- Proven ability to lead multi-team initiatives and drive results in a fast-paced environment.
- Excellent communication and interpersonal skills, with the ability to influence senior engineers, architects, and business leaders
- High School diploma or equivalent required
HOW WE’LL SUPPORT YOU
- Financial Security: You will be eligible to participate in the company’s 401k plan which includes a company match and immediate vesting.
- Health & Well-Being: We offer comprehensive insurance options including medical, dental, vision, AD&D, supplemental life, long-term disability, pre-tax Health Savings Account with employer contributions, and pre-tax Flexible Spending Account (FSA).
- Building & Supporting Your Family: Banc of California partners with providers that offer adoption, surrogacy, and fertility assistance as well as paid parental leave and family support solutions including care options for your family.
- Paid Time Away: Eligible team members receive paid vacation days, holidays, and volunteer time off.
- Career Growth Opportunities: To support career growth of our team members, we offer tuition reimbursement, an annual mentorship program, leadership development resources, access to LinkedIn Learning, and more.
SALARY RANGE
The base salary ultimately offered is determined through a review of education, industry experience, training, knowledge, skills, abilities of the applicant in alignment with market data and other factors.
Banc of California is an equal opportunity employer committed to creating a diverse workforce. All qualified applicants will receive consideration for employment without regard to their actual or perceived race (including traits associated with race, such as hair texture, hair type or protective hairstyles), religion or religious creed (including religious dress and grooming practices), color, sex (including pregnancy, childbirth, breastfeeding and related medical conditions), sexual orientation, gender, gender identity, gender expression, gender transitioning, citizenship status, national origin, ancestry, age, marital status, military or veteran status, medical condition, genetic information, or disability (mental or physical), requests for accommodation and any additional protected categories set forth in applicable federal, state or local laws. If you require reasonable accommodation as part of the application process, please contact Talent Acquisition.
About Banc of California
Sourced by ZipRecruiter
Industry
Commercial banking
Company size
501 - 1,000 Employees
Headquarters location
Santa Ana, CA, US
Year founded
1941