1

Security Risk Management Jobs in California (NOW HIRING)

They are seeking a Senior Information Security Analyst to lead the enterprise Information Security Governance, Risk Management, and Strategy function, focusing on Responsible GenAI and ensuring ...

New

They are seeking a Senior Information Security Analyst to lead their enterprise Information Security Governance, Risk Management, and Strategy function, focusing on Responsible GenAI and ensuring ...

New

Information Security Analyst 4

Irvine, CA · On-site

$124K - $206K/yr

Embed GenAI risk evaluation into procurement, vendor risk management, and IT risk workflows ... Information Security GRC * Implement and mature enterprise information security risk management ...

New

Embed GenAI risk evaluation into procurement, vendor risk management, and IT risk workflows ... Information Security GRC * Implement and mature enterprise information security risk management ...

New

Risk Management and Decision Support Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. Translate ...

The ideal candidate will have extensive experience in information security, including experience with security risk management, incident response, and forensics. The vision for CorVel security ...

Senior Director Product Security

Irvine, CA

$250K - $261K/yr

Risk Management and Decision Support Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. Translate ...

Oversee coordination of risk management efforts related to physical security, safety, and operational continuity. * Partner with HR and Operations to ensure compliance with safety regulations and ...

Sr. Cybersecurity GRC Manager

Irvine, CA

$119K - $161K/yr

Strong knowledge of Information Security risk management frameworks, Governance, Risk, and Compliance process, IT general controls (e.g. asset classification, risk assessments, vulnerability and ...

next page

Showing results 1-20

Security Risk Management information

See California salary details

$10

$49

$69

How much do security risk management jobs pay per hour?

As of Jun 10, 2026, the average hourly pay for security risk management in California is $49.75, according to ZipRecruiter salary data. Most workers in this role earn between $40.34 and $59.33 per hour, depending on experience, location, and employer.

What are the typical challenges faced by professionals in Security Risk Management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is Security Risk Management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in Security Risk Management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What job categories do people searching Security Risk Management jobs in California look for? The top searched job categories for Security Risk Management jobs in California are:
What cities in California are hiring for Security Risk Management jobs? Cities in California with the most Security Risk Management job openings:
Infographic showing various Security Risk Management job openings in California as of June 2026, with employment types broken down into 4% As Needed, 88% Full Time, and 8% Part Time. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $103,475 per year, or $49.7 per hour.
VP, Lead Security Risk Analyst

VP, Lead Security Risk Analyst

Banc of California

Santa Ana, CA

Full-time

Posted 6 days ago


Job description

BANC OF CALIFORNIA AND YOUR CAREER

Banc of California, Inc. (NYSE: BANC) is a bank holding company with over $34 billion in assets and the parent company of Banc of California. Banc of California is one of the nation’s premier relationship-based business banks, providing banking and treasury management services to small, middle market, and venture backed businesses. As the largest independent bank headquartered in California, the bank offers a broad range of loan and deposit products and services through a network of full-service branches and regional offices, as well as through digital and nationwide capabilities. The bank also provides full-service payment processing solutions to its clients and serves the Community Association Management industry nationwide through its technology forward platform, SmartStreet™. Banc of California is committed to supporting its local communities through the Banc of California Charitable Foundation and by partnering with organizations that promote financial literacy, job training, small business support, affordable housing, and more.

At Banc of California, our success is powered by our people and a shared commitment to delivering meaningful results. We foster an environment where entrepreneurial thinking is encouraged, and accountability and operational excellence are expected. Our team members are empowered to take ownership, make informed decisions, and make a meaningful impact as the bank continues to grow and evolve. We are dedicated to supporting your growth and wellbeing through comprehensive benefits, robust development opportunities, and inclusive programs that enable you to perform at your best. Together we win!

THE OPPORTUNITY

The VP, Lead Security Risk Analyst leads enterprise-wide Information Security risk engagement across corporate initiatives, embedding security-by-design principles into business and technology decisions. This role drives the development and execution of the Information Security risk and GRC programs, conducting complex, high‑impact risk assessments across enterprise architecture, cloud, AI/ML, and third‑party environments. Serving as a senior advisor, the position partners with leadership, architects, and engineering teams to translate regulatory and security requirements into actionable architectural controls and secure design standards. The VP, Lead Security Risk Analyst also drives cross‑functional remediation efforts to ensure risks are effectively managed in alignment with the organization’s risk appetite. Performs all duties in accordance with the Company’s policies and procedures, all U.S. state and federal laws and regulations, wherein the Company operates.

HOW YOU’LL MAKE A DIFFERENCE

  • Lead enterprise Information Security engagement across all enterprise-wide corporate projects, championing security by design principles, influencing security decisions without direct authority and driving alignment across multiple business and technology domains.
  • Contribute to the development, management, and ongoing improvement of the Information Security risk program, compliance initiatives, and overall security risk posture.
  • Partner with senior management to design and implement maturity strategies and operations into the Information Security GRC team.
  • Maintain Information Security risk register, report monthly to appropriately address key risk areas.
  • Support policies and procedures maintenance aligned with in-scope security frameworks, regulations, and internal standards to manage identified risk effectively.
  • Conduct regular risk assessments to identify potential threats and vulnerabilities across the organization analyzing their impact and likelihood of occurrence.
  • Generate reports on risk assessments, compliance status, and control effectiveness to communicate findings to stakeholders at various levels within the organization.
  • Lead and deliver enterprise and domain risk assessments (at least annually, or event driven) using consistent methodology that complies with regulatory requirements
  • Conduct and lead the bank’s most complex and high-impact risk assessments, including those involving enterprise architecture, modernization initiatives, AI/ML platforms, cloud deployments, or third-party integrations.
  • Drive cross-functional remediation initiatives, ensuring timely resolution of identified issues and alignment with enterprise risk appetite.
  • Act as the primary GRC representative and senior advisor in enterprise security architecture projects, ensuring that security, compliance, and risk considerations are embedded in design decisions for cloud, infrastructure, and applications.
  • Lead architecture-focused risk assessments for new technologies, major system integrations, cloud migrations, and high-impact projects to identify systemic risks and required compensating controls.
  • Translate security policies, standards, regulatory requirements and control frameworks into detailed architectural requirements, control patterns, and secure design standards consumable by engineering and application teams.
  • Advise solution architects, engineers, and product teams on secure design patterns, identity and access architecture, encryption frameworks, data protection requirements, and logging/monitoring standards.
  • Evaluate the security implications of modernization initiatives, and system migrations ensuring risks are documented and mitigated through appropriate design.
  • Define architecture-aligned security requirements and control baselines that engineering and architecture teams use to build secure-by-design systems.
  • Partner with detection engineering and cloud teams to ensure logging, auditability, and monitoring capabilities are embedded in the technology stack.
  • Lead complex and technical vendor security reviews, including onboarding assessments, and high-risk assessments involving cloud platforms, data integrations, and critical infrastructure providers.
  • Follow all established policies and procedures.
  • Perform other duties and projects as assigned.

WHAT YOU’LL BRING

  • Bachelor’s degree in information systems, engineering, business, risk management, or related field; and related certifications (e.g., CISSP ISSAP, SABSA, CCSP, GCAD, CRISC, CISSP).
  • 7-9+ years of experience in GRC, cybersecurity, risk management or related fields, and most importantly cloud/security architecture, particularly in highly regulated industries such as financial, or professional services.
  • Demonstrated history of influencing architectural decisions and driving enterprise-level security program improvements.
  • High technical knowledge across Cybersecurity domains, including Security Operations, Incident
  • Response, Security Engineering, Cloud Security, Artificial Intelligence (AI), Data Security, Configuration
  • Management, Log Generation, Security Risk Assessments/testing methodologies, Secure Software Development Lifecycle, evaluating the adequacy and efficiency of internal controls.
  • Advanced knowledge of cloud architecture, application security, identity governance, encryption, secure design patterns, network architecture, and telemetry design.
  • Experience translating requirements into architectural controls and technical standards.
  • Expert knowledge of GRC frameworks and regulations (e.g., PCI-DSS, GDPR, CCPA, GLBA, NIST, ISO 27001).
  • Strong knowledge in OWASP, CIS and/or other security standards and secure configuration baselines.
  • Excellent analytical skills with the ability to assess complex risks and develop effective mitigation security strategies.
  • Comfortable solving ambiguous, enterprise-scale problems.
  • Proven ability to lead multi-team initiatives and drive results in a fast-paced environment.
  • Excellent communication and interpersonal skills, with the ability to influence senior engineers, architects, and business leaders
  • High School diploma or equivalent required

HOW WE’LL SUPPORT YOU

  • Financial Security: You will be eligible to participate in the company’s 401k plan which includes a company match and immediate vesting.
  • Health & Well-Being: We offer comprehensive insurance options including medical, dental, vision, AD&D, supplemental life, long-term disability, pre-tax Health Savings Account with employer contributions, and pre-tax Flexible Spending Account (FSA).
  • Building & Supporting Your Family: Banc of California partners with providers that offer adoption, surrogacy, and fertility assistance as well as paid parental leave and family support solutions including care options for your family.
  • Paid Time Away: Eligible team members receive paid vacation days, holidays, and volunteer time off.
  • Career Growth Opportunities: To support career growth of our team members, we offer tuition reimbursement, an annual mentorship program, leadership development resources, access to LinkedIn Learning, and more.

SALARY RANGE

The base salary ultimately offered is determined through a review of education, industry experience, training, knowledge, skills, abilities of the applicant in alignment with market data and other factors.

Banc of California is an equal opportunity employer committed to creating a diverse workforce. All qualified applicants will receive consideration for employment without regard to their actual or perceived race (including traits associated with race, such as hair texture, hair type or protective hairstyles), religion or religious creed (including religious dress and grooming practices), color, sex (including pregnancy, childbirth, breastfeeding and related medical conditions), sexual orientation, gender, gender identity, gender expression, gender transitioning, citizenship status, national origin, ancestry, age, marital status, military or veteran status, medical condition, genetic information, or disability (mental or physical), requests for accommodation and any additional protected categories set forth in applicable federal, state or local laws. If you require reasonable accommodation as part of the application process, please contact Talent Acquisition.