1

Security Risk Management Jobs in California (NOW HIRING)

GRC Risk Management Analyst

San Jose, CA ยท On-site

$68.97 - $72.80/hr

Bachelor's degree in Information Security, Risk Management, Business, Computer Science, or a related field. Experience: 1 4 years in enterprise risk, third-party risk, GRC, information security, or a ...

GRC Risk Management Analyst

San Jose, CA ยท On-site

$68 - $72/hr

Bachelor's degree in Information Security, Risk Management, Business, Computer Science, or a related field. * Experience: 1-4 years in enterprise risk, third-party risk, GRC, information security, or ...

MUST HAVE SKILLS: Data Governance, AI development and Governance, Security Risk Management The GRC Engineer will contribute to the development and operational execution of the program.

Lead Security Analysis

Dublin, CA ยท On-site

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Lead Security Analysis

Dublin, CA ยท On-site

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Lead Security Analysis

Dublin, CA ยท Hybrid

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Showing results 21-40

Security Risk Management information

See California salary details

$10

$49

$69

How much do security risk management jobs pay per hour?

As of Aug 17, 2026, the average hourly pay for security risk management in California is $49.75, according to ZipRecruiter salary data. Most workers in this role earn between $40.34 and $59.33 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.

What job categories do people searching Security Risk Management jobs in California look for?

The top searched job categories for Security Risk Management jobs in California are:

What cities in California are hiring for Security Risk Management jobs?

Cities in California with the most Security Risk Management job openings:

Infographic showing various Security Risk Management job openings in California as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $103,475 per year, or $49.7 per hour.

Information Security Risk Analyst

AllSTEM Connections

San Francisco, CA โ€ข On-site

$153K/yr

Temporary

Medical, Dental, Vision, Retirement

Re-posted 6 days ago


Job description

JOB SUMMARY
Are you passionate about strengthening security through risk insight and strategic partnership? We are seeking an experienced Information Security Risk Analyst to help identify, assess, and reduce cybersecurity risk across cloud and on-prem environments.
In this role, you will partner closely with application development teams, technical stakeholders, and leadership to evaluate security controls, advise on secure cloud and DevSecOps practices, and translate complex technical risks into actionable business guidance. This is an opportunity to play a highly visible role in improving enterprise security posture while influencing modern development practices, third-party risk management, and emerging AI/GenAI governance considerations.
If you thrive in collaborative environments and enjoy combining technical depth with risk strategy and communication, this role offers meaningful impact and professional growth.
KEY RESPONSIBILITIES
โ€ข Support enterprise risk strategies by identifying security risks in processes and technologies and leading initiatives to reduce exposure.
โ€ข Apply and interpret security policies and contribute insights to ongoing policy and control improvements.
โ€ข Partner with business and technical teams to help them understand and implement security controls, policies, and procedures.
โ€ข Establish trusted relationships across assigned business areas to understand operational and technical requirements and enable secure outcomes.
โ€ข Advise application development teams on Secure Cloud Development and DevSecOps best practices to mature security practices.
โ€ข Assess technical implementations in both cloud and on-prem environments to evaluate security risk and recommend control enhancements or compensating controls.
โ€ข Perform complex security analyses and provide clear, practical mitigation recommendations.
โ€ข Evaluate third-party service providers, identify associated risks, and clarify shared security responsibilities.
โ€ข Conduct formal security control assessments and prepare detailed assessment reports documenting scope, methodology, findings, risk impact, and remediation recommendations.
โ€ข Communicate security risks and business implications to stakeholders at all levels, including executive leadership.
โ€ข Collaborate cross-functionally, manage multiple initiatives simultaneously, and navigate ambiguity in a fast-paced, results-driven environment.
REQUIRED QUALIFICATIONS
โ€ข Experience performing security control assessments aligned to NIST 800-37 (SCA and CMCA).
โ€ข Hands-on experience conducting assessments using NIST 800-53 controls.
โ€ข Experience reviewing and evaluating FedRAMP authorization packages.
โ€ข Experience mapping OWASP Top Ten risks within DevSecOps environments to strengthen security operations.
โ€ข Strong understanding of cloud security principles and secure development practices.
โ€ข Ability to analyze complex technical security issues and translate them into clear, actionable risk narratives.
PREFERRED QUALIFICATIONS
โ€ข Experience in DevSecOps environments, including governance and security automation.
โ€ข Exposure to AI / GenAI-related cybersecurity governance and risk considerations.
โ€ข Experience working in regulated or compliance-driven environments.
KEY COMPETENCIES
โ€ข Strong verbal and written communication skills with the ability to convey risk to both technical and non-technical stakeholders.
โ€ข Excellent relationship-building and stakeholder partnership skills.
โ€ข Strategic thinking with practical, solutions-oriented execution.
โ€ข Ability to manage competing priorities while maintaining accountability and delivering results. Equal Opportunity Employer / Disabled / Protected Veterans
The Know Your Rights poster is available here:
https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12.pdf
The pay transparency policy is available here:
https://www.dol.gov/sites/dolgov/files/ofccp/pdf/pay-transp_%20English_formattedESQA508c.pdf
For temporary assignments lasting 13 weeks or longer, AllSTEM Connections is pleased to offer major medical, dental, vision, 401k and any statutory sick pay where required.
We are committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please contact your staffing representative who will reach out to our HR team.
AllSTEM Connections participates in the E-Verify program in certain locations as required by law. Learn more about the E-Verify program.
https://e-verify.uscis.gov/web/media/resourcesContents/E-Verify_Participation_Poster_ES.pdf
We also consider for employment qualified applicants regardless of criminal histories, consistent with legal requirements, including, if applicable, the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance. Pursuant to applicable state and municipal Fair Chance Laws and Ordinances, we will consider for employment-qualified applicants with arrest and conviction records, including, if applicable, the San Francisco Fair Chance Ordinance. For Los Angeles, CA applicants: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Additional Skills
(none specified)
AllSTEM Representative Contact Info
Account Executive:
IN HOUSE
Branch Phone:
(909) 244-1777
Location:
Ontario, CA