1

Security Risk Management Jobs in California (NOW HIRING)

Lead Security Analysis

Dublin, CA · Hybrid

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Lead Security Analysis

Dublin, CA · On-site

$124K - $212K/yr

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group responsible for leading and executing IT security risk management and governance processes within the ...

Senior Director Product Security

Irvine, CA

$250K - $261K/yr

Risk Management and Decision Support Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. Translate ...

Risk Management and Decision Support Establish an enterprise product security risk management framework that enables consistent identification, prioritization, and treatment of risk. Translate ...

Risk Management Specialist

Ukiah, CA · On-site

$78K - $116K/yr

Risk Management, Claims, Legal, Patient Safety, Quality, Accreditation, Regulatory, and Licensing ... Facilities, Safety, Nursing, Pharmacy, Security, and Patient Relations). Works with Safety ...

Risk Management, Claims, Legal, Patient Safety, Quality, Accreditation, Regulatory, and Licensing ... Facilities, Safety, Nursing, Pharmacy, Security, and Patient Relations). Works with Safety ...

Oversee coordination of risk management efforts related to physical security, safety, and operational continuity. * Partner with HR and Operations to ensure compliance with safety regulations and ...

Showing results 41-60

Security Risk Management information

See California salary details

$10

$49

$69

How much do security risk management jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for security risk management in California is $49.75, according to ZipRecruiter salary data. Most workers in this role earn between $40.34 and $59.33 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.

What are popular job titles related to Security Risk Management jobs in California?

For Security Risk Management jobs in California, the most frequently searched job titles are:

What job categories do people searching Security Risk Management jobs in California look for?

The top searched job categories for Security Risk Management jobs in California are:

What cities in California are hiring for Security Risk Management jobs?

Cities in California with the most Security Risk Management job openings:

Infographic showing various Security Risk Management job openings in California as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $103,475 per year, or $49.7 per hour.

Lead Security Analysis

Ross Stores, Inc

Dublin, CA • Hybrid

$124K - $212K/yr

Full-time

Re-posted 2 days ago


Key responsibilities

  • Lead and execute IT security risk management and governance processes within the organization.

  • Perform risk assessments, track mitigation efforts, and develop risk metrics and reports.

  • Lead security risk related projects and enhance programs such as business process risk assessments, insider threat management, and security awareness programs.


Job description

GENERAL PURPOSE:  
The Lead, Security Analysis is the senior member of the Cybersecurity Risk Management group 
responsible for leading and executing IT security risk management and governance processes 
within the organization. This includes performing risk assessments, tracking mitigation efforts 
and developing risk metrics and risk reports. This position is also responsible for leading security 
risk related projects and enhancing programs, such as business process risk assessments, insider 
threat management, updating security policies and standards and executing security awareness 
programs for corporate as well as overseas offices.

The base salary range for this role is $124,700 - $212,800. The base salary range is 
dependent on factors including, but not limited to, experience, skills, qualifications, relevant 
education, certifications, seniority, and location. The range listed is just one component of 
the total compensation package for employees. Other rewards vary by position and 
location.

ESSENTIAL FUNCTIONS:
Provides subject matter expertise in all aspects of risk management including performing 
risk assessments to proactively identify current and future security issues/vulnerabilities 
and recommend remediation strategies. 
Leads insider risk programs by identifying improvements and establishing supporting 
processes across the enterprise. 
Identifies and implements improvements to enhance the Cybersecurity Risk Management 
program through optimization of processes, solutions, policies, procedures KPIs and other 
techniques.
Develops standards to support vendor selection and RFP process and participates in 
product and vendor selection process to provide subject matter expertise on Information 
security risk and compliance.
Maintains risk register and develops Cybersecurity Risk Management metrics and reports. 
Collaborates with Compliance Manager, Secure SDLC Manager, Information Security, 
and IT groups to gather and analyze metrics.
Leads information security awareness programs by regularly conducting exercise to 
educate employees of information security and best practices.
Monitors current and proposed laws, regulations, industry standards, and ethical 
requirements related to information security and privacy.
Lead and perform end-to-end risk assessments across business processes, applications, 
infrastructure, cloud environments, and third-party/vendor eco-systems.

COMPETENCIES:
People
Building Effective Teams 
Developing Talent
Collaboration
Self
Leading by Example
Communicates Effectively
Ensures Accountability and Execution
Manages Conflict
Business
Business Acumen
Plans, Aligns and Prioritizes
Organizational Agility
With particular emphasis on the following specific position-related competencies:
Technical Competence and Expertise 
Analysis / Judgement
Communication 
Customer Service

QUALIFICATIONS AND SPECIAL SKILLS REQUIRED:
Five years of experience within Information Technology with at least 3 in Security and/or 
Risk Management.
Bachelor's degree preferred or equivalent combination of education and relevant experience
Strong understanding of security governance, compliance and risk management principles.
Proficient in Microsoft Word, Excel, PowerPoint
Excellent analytical, organizational and communication skills
Strong Project Management skills
PREFERRED QUALIFICATIONS:
CISSP (Certified Information Systems Security Professional) 
CRISC (Certified in Risk and Information Systems Control (CRISC)
Working knowledge of UNIX and Windows
Firewalls, VPN, PKI, IPS, 
Oracle, MS SQL
Virtualization Security
Software programming skills

PHYSICAL REQUIREMENTS/ADA:
Job requires ability to work in an office environment, primarily on a computer.
Requires sitting, standing, walking, hearing, talking on the telephone, attending in-person 
meetings, typing, and working with paper/files, etc. 
Consistent timeliness and regular attendance.
Vision requirements: Ability to see information in print and/or electronically.
This role requires regular in-office presence, including to engage in in-person team interaction, 
meetings and collaboration, client support, mentoring, coaching, and/or feedback. However, this 
role can perform duties effectively using a combination of in-office and remote work. #LI-Hybrid

SUPERVISORY RESPONSIBILITIES:
N/A

DISCLAIMER:
This job description is a summary of the primary duties and responsibilities of the job and position. 
It is not intended to be a comprehensive or all-inclusive listing of duties and responsibilities. 
Contents are subject to change at management's discretion.

Ross is an equal employment opportunity employer. We consider individuals for employment or 
promotion according to their skills, abilities and experience. We believe that it is an essential part 
of the Company's overall commitment to attract, hire and develop a strong, talented and diverse 
workforce. Ross is committed to complying with all applicable laws prohibiting discrimination 
based on race, color, religious creed, age, national origin, ancestry, physical, mental or 
developmental disability, sex (which includes pregnancy, childbirth, breastfeeding and medical 
conditions related to pregnancy, childbirth or breastfeeding), veteran status, military status, marital 
or registered domestic partnership status, medical condition (including cancer or genetic 
characteristics), genetic information, gender, gender identity, gender expression, sexual 
orientation, as well as any other category protected by federal, state or local laws.


Ross Stores logo

About Ross Stores

Sourced by ZipRecruiter

We’re big as the nation’s largest off-price retail chain, we have a great deal of purchasing power. We’re savvy our buyers search the globe for the best brands and latest styles. We work directly with manufacturers to negotiate the best deals! We believe in “no frills”, no window displays, mannequins, fancy fixtures or decorations in our stores so we can pass more savings on to our customers. We love new buys, we keep it simple so we can get the great buys into our stores quickly, which means almost every day!

Industry

Retail and apparel and accessories stores

Company size

10,000+ Employees

Headquarters location

Dublin, CA, US