1

Senior Information Security Risk Analyst Jobs in California

Security Risk Manager

San Francisco, CA ยท On-site

$194K - $220K/yr

This is a senior role for someone who goes beyond frameworks and checklists - you will engineer the ... About you * 7+ years of experience in information security with a strong focus on security risk ...

About the Role The Information Security Officer will have end-to-end ownership of MEDvidi ... You will inherit a completed Security Risk Analysis and be responsible for turning identified risks ...

... risk frameworks and server architecture - Knowledge of network concepts, host-based security ... and analytical skills - Ability to work under tight deadlines and prioritize responsibilities ...

... risk frameworks and server architecture - Knowledge of network concepts, host-based security ... and analytical skills - Ability to work under tight deadlines and prioritize responsibilities ...

... risk frameworks and server architecture - Knowledge of network concepts, host-based security ... and analytical skills - Ability to work under tight deadlines and prioritize responsibilities ...

Showing results 41-60

Senior Information Security Risk Analyst information

See California salary details

$31

$57

$74

How much do senior information security risk analyst jobs pay per hour?

As of Sep 2, 2026, the average hourly pay for senior information security risk analyst in California is $57.69, according to ZipRecruiter salary data. Most workers in this role earn between $44.86 and $64.76 per hour, depending on experience, location, and employer.

What does a senior information security risk analyst do?

A Senior Information Security Risk Analyst is responsible for identifying, evaluating, and mitigating risks to an organization's information systems and data. They conduct risk assessments, develop security policies, and recommend measures to protect against cyber threats and vulnerabilities. Additionally, they work closely with IT and business teams to ensure compliance with regulations and industry standards, and they often play a key role in incident response and security awareness training.

What are the key skills and qualifications needed to thrive as a senior information security risk analyst?

A Senior Information Security Risk Analyst requires a deep understanding of cybersecurity frameworks, risk assessment methodologies, and regulatory compliance, usually backed by a degree in information security or a related field. Familiarity with tools like risk management software (e.g., Archer, RSA), SIEM systems, and certifications such as CISSP, CISM, or CRISC are typically expected. Exceptional analytical thinking, attention to detail, and strong communication skills set top performers apart in this role. These competencies are crucial to effectively identify, evaluate, and mitigate security risks, ensuring the organization's information assets remain protected against evolving threats.

How does a senior information security risk analyst typically collaborate with other departments to manage organizational risk?

A Senior Information Security Risk Analyst regularly works with various departments such as IT, legal, compliance, and business units to identify and address security risks. This collaboration often includes conducting risk assessments, reviewing new projects for potential vulnerabilities, and providing guidance on security best practices. Effective communication skills are essential, as the analyst must translate technical risks into business impacts and help teams implement appropriate controls. Close teamwork ensures that security is integrated into all business processes and that the organization remains compliant with relevant regulations.

What is the difference between Senior Information Security Risk Analyst vs Information Security Analyst?

AspectSenior Information Security Risk AnalystInformation Security Analyst
CertificationsCISSP, CISA, CRISCCISSP, Security+, CEH
Work EnvironmentFocus on risk assessment, policy development, and strategic planningImplementing security measures, monitoring, and incident response
Employer & Industry UsageFinancial, healthcare, and large enterprises with complex security needsVariety of industries, including tech, retail, and government

Senior Information Security Risk Analysts typically handle advanced risk assessments and strategic security planning, often requiring certifications like CISSP or CISA. Information Security Analysts focus on implementing security controls and monitoring systems. Both roles are vital in maintaining organizational security but differ in scope and seniority.

What are popular job titles related to Senior Information Security Risk Analyst jobs in California?

For Senior Information Security Risk Analyst jobs in California, the most frequently searched job titles are:

What job categories do people searching Senior Information Security Risk Analyst jobs in California look for?

The top searched job categories for Senior Information Security Risk Analyst jobs in California are:

What cities in California are hiring for Senior Information Security Risk Analyst jobs?

Cities in California with the most Senior Information Security Risk Analyst job openings:

Infographic showing various Senior Information Security Risk Analyst job openings in California as of August 2026, with employment types broken down into 1% As Needed, 69% Full Time, 25% Part Time, and 5% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $119,985 per year, or $57.7 per hour.

Senior Information Security Analyst

Goldbelt, Inc.

Petaluma, CA โ€ข On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 28 days ago


Job description

Overview
Please note that this position is contingent upon the successful award of a contract currently under bid.
Peregrine is a pioneer within the cybersecurity industrial control systems and the Internet of Things, supporting many federal and commercial customers. Peregrine's experienced staff knows the cybersecurity and operational technology environment and provides these capabilities for our customers daily.
Summary:
The Senior Information Security Analyst is responsible for the overall cybersecurity of assigned networks and devices. They must have intimate knowledge of federal government, Department of Defense, and U.S. Coast Guard cybersecurity requirements.
Responsibilities
Essential Job Functions:
  • Aggressively manage Cyber security accreditation requirements by working closely with the Program Manager, system administrators, database administrators and other key personnel to ensure all system accreditations remain current.
  • Ensure that all initial and recurring certification and accreditation activities are completed in accordance with DoDI 8500.01, Cyber Security, and DoDI 8510.01, Risk Management Framework (RMF) for assigned information systems, as well as maintaining compliance with the Federal Information Security Management Act (FISMA) of 2002 and other applicable directives for the assigned information systems
  • Working directly with leadership, developers, engineers, system and database administrators to track changes to the system configurations and software, conducting regular reviews, updates and maintenance of certification and accreditation plans, topology drawings, and associated documents, and uploading completed documents to eMASS.
  • Schedule, oversee and document information system compliance testing, to include weekly Assured Compliance Assessment Solution (ACAS) scans and annual execution and testing of the Contingency Plans.
  • Manage accreditation and annual compliance actions using eMASS and the U.S. Coast Guard tracking tools to ensure annual reviews, control tests and contingency plan tests are completed on schedule to comply with FSMA requirements and keep the Program Manager informed of compliance and status of ATO efforts via updates to the PM's Drumbeat and Metrics products.
  • Conduct a continuous review of all applications and database tools that make up the family of systems to ensure all software versions are registered and approved for use by the U.S. Coast Guard.
  • Conduct an annual review and update of all parent and child system profiles in the DHS approved repository system to ensure system's registrations are complete and accurate, and that essential waivers for Data-At-Rest (DAR) and unsupported Commercial-Off-The-Shelf (COTS) software are documented and approved by U.S. Coast Guard CIO so that accreditations are not adversely affected.
  • Serve as Information Assurance Officer (IAO)/Information Systems Security Officer (ISSO), directly advising and assisting the Program Manager, developers, engineers, system and database administrators and staff on all cyber security policy, configuration and compliance matters.
    • This includes all aspects of cyber security that may affect the system security posture, to include emerging threats published in Cyber Alerts, Communication Tasking Orders, and vulnerability alerts and bulletins issued under the Information Assurance Vulnerability Management program.
  • As IAO/ISSO, advise the team on ports, protocols and services (PPS) approved for use by the U.S. Coast Guard, and register new PPS in the U.S. Coast Guard PPS Management Registry.
  • Prior to testing, identify Security Technical Implementation Guides (STIGs) to be applied to systems under development and test, and identify appropriate vulnerability scanning tools to be used during testing, to include the ACAS and Security Content Automation Protocol (SCAP) Compliance Checker automated scanning tools.
  • The IAO/ISSO will assist during scanning and advise the team on the remediation of findings identified during testing.
  • Following testing, the IAO will collect, collate, review and validate all test results and prepare supporting documentation, reports and artifacts to support the certification and accreditation of the system. Following accreditation, the IAO/ISSO will track and manage open findings in the Risk Assessment Report until mitigated or closed.
  • Provide expert advice in support of special projects, to include the development of an automated Cross Domain Solution (CDS) for use by the program and closely coordinate actions with the U.S. Coast Guard Cross Domain Solutions Office (USCGCDSO) and the Department of Homeland Security Unified Cross Domain Management Office (UCDMO).
    • This support includes authoring and submitting detailed system documentation and architectural drawings and working closely with both USCGCDSO and UCDMO personnel to navigate through a complex and highly technical approval process.
  • On a daily and weekly basis, provide authoritative cyber security advice during Internal Review Boards and make recommendations on open Configuration Change Requests (CCRs); Application Change Requests (ACRs), Database Change Requests (DBCRs), QA Trouble Reports (QTRs), Problem Reports (PRs), and Program Trouble Reports (PTRs).

Qualifications
Necessary Skills and Knowledge:
  • Proven record of honesty and integrity in all relationships.
  • Demonstrated leadership and organizational skills.
  • Excellent interpersonal skills and a collaborative management style.
  • Excellent communication skills, both verbal and written.
  • Excellent computer skills and proficient in Excel, Word, PowerPoint, Outlook, Visio, and Access.

Minimum Qualifications:
  • Minimum of five (5) years relevant experience.
  • Detailed knowledge of DoD Risk Management Framework
  • Experience in an IAO/ISSO or Information Assurance Manager (IAM)/Information Systems Security Manager (ISSM) position.
  • Appropriate professional certifications per DoD 8570.01 (CISSP, GSLC or equivalent).
  • Must be eligible for a federal Public Trust clearance.

Preferred Qualifications:
  • Bachelors degree in cybersecurity or related degree
  • CISSP Certification

Pay and Benefits
The annual salary range for this position is $100,000 to $140,000.
At Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.