1

Sr Risk And Vulnerability Analyst Jobs in California

RISK MANAGEMENT ANALYST

Beverly Hills, CA · On-site

$38.46 - $43.27/hr

... senior risk management review * In support of Kennedy Wilson's Debit Investment Group, work with ... Strong analytical skills and attention to detail * Proficient in Microsoft Excel; exposure to ...

Vulnerability Management, Third Party Risk, Product Security, Detection and Response, etc ... Analyze risk data to identify trends, root causes, and control gaps, and recommend changes to ...

As a Senior Risk Consultant based in the Los Angeles/Orange County area, you will be the primary ... Conduct loss analysis and trending to identify client focus areas and demonstrate measurable ...

As a Senior Risk Consultant based in the Los Angeles/Orange County area, you will be the primary ... Conduct loss analysis and trending to identify client focus areas and demonstrate measurable ...

As a Senior Risk Consultant based in the Los Angeles/Orange County area, you will be the primary ... Conduct loss analysis and trending to identify client focus areas and demonstrate measurable ...

Sr. Risk Manager (28696)

San Jose, CA · On-site

$123 - $140/hr

Sr. Risk Manager Date: May 5, 2026 Location: San Jose, California, United States Company: Super ... Analyze insurance costs and identify opportunities for cost savings. * Prepare comprehensive ...

The Sr. Insider Risk Analyst will support the Insider Risk Program by monitoring insider-risk alerts, conducting multi-source analysis, and coordinating with various departments to mitigate threats ...

Showing results 21-40

Sr Risk And Vulnerability Analyst information

What are the key skills and qualifications needed to thrive as a Sr Risk and Vulnerability Analyst, and why are they important?

To thrive as a Sr Risk and Vulnerability Analyst, you need in-depth knowledge of cybersecurity principles, risk assessment methodologies, and a relevant degree or certifications such as CISSP or CEH. Proficiency with vulnerability scanning tools (e.g., Nessus, Qualys), SIEM systems, and risk management frameworks (like NIST or ISO 27001) is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex data and collaborate across teams. These competencies are vital for identifying threats, reducing organizational risk, and ensuring robust security defenses.

What are some common challenges faced by a Sr Risk and Vulnerability Analyst, and how can they be addressed?

Sr Risk and Vulnerability Analysts often encounter challenges such as staying updated with rapidly evolving threats, managing a large volume of vulnerabilities, and effectively communicating risks to non-technical stakeholders. Addressing these challenges involves continuous learning, leveraging automated tools for vulnerability management, and developing strong reporting and presentation skills to translate technical findings into actionable business insights. Collaboration with IT, security teams, and business leaders is essential to prioritize and remediate risks efficiently.

What is the difference between Sr Risk And Vulnerability Analyst vs Risk Analyst?

AspectSr Risk And Vulnerability AnalystRisk Analyst
CertificationsCertifications like CISSP, CISA often preferredSimilar certifications, often entry to mid-level
Work EnvironmentFocus on cybersecurity vulnerabilities and risk management in ITBroader risk assessment across financial, operational, or strategic areas
Employer & Industry UsageCommon in cybersecurity, IT, finance sectorsUsed across various industries including finance, insurance, and consulting

The Sr Risk And Vulnerability Analyst specializes in identifying and mitigating cybersecurity vulnerabilities, often requiring advanced certifications and experience. In contrast, a Risk Analyst has a broader scope, assessing risks across multiple business areas. Both roles require analytical skills but differ in focus and industry application.

What does a Sr Risk and Vulnerability Analyst do?

A Sr Risk and Vulnerability Analyst is responsible for identifying, assessing, and mitigating risks and vulnerabilities within an organization’s information systems and processes. They conduct security assessments, analyze potential threats, and recommend strategies to protect assets and data. Their role often involves collaborating with IT, compliance, and management teams to develop risk management policies and respond to emerging security issues. Additionally, they may lead vulnerability testing and ensure the organization meets regulatory and industry standards for cybersecurity.
What cities in California are hiring for Sr Risk And Vulnerability Analyst jobs? Cities in California with the most Sr Risk And Vulnerability Analyst job openings:

Senior Director of Subject Matter Expert - CTEM, RBVM, ASPM - Risk Operation Center (ROC)

Qualys

Foster City, CA • On-site

Other

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Job Description: Senior Director of Subject Matter Expert - CTEM, RBVM, ASPM - Risk Operation Center (ROC)

Date posted: March 2026

About the job

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Senior Director of Subject Matter Expert - CTEM, RBVM, CAASM - Risk Operation Center

Location: Foster City, CA, USA
Organization: Product GTM & SME
Reports To: SVP of Product Management

Role Overview

We are seeking a Senior Director - Subject Matter Expert (SME) to lead deep technical expertise and field architecture & deployment for the Qualys Enterprise TruRisk Management (ETM) platform and Risk Operations Center (ROC) operating model.

This role is a hands-on technical SME leadership position responsible for driving the architecture, deployment strategy, and customer adoption of Qualys exposure management solutions including:

* Enterprise TruRisk Management (ETM)
* Risk Operations Center (ROC)

* Cyber Risk Quantification (CRQ)
* VMDR (Vulnerability Management Detection & Response)
* CyberSecurity Asset Management (CSAM)
* External Attack Surface Management (EASM)

The Senior Director will serve as a technical authority and practitioner working directly with engineering, product management, and enterprise customers to operationalize Continuous Threat Exposure Management (CTEM) and modern risk-centric security operations - ROC

This role will lead a small elite team of 5-6 technical SMEs responsible for architecture guidance, field enablement, customer advisory, leading POC/POV and feedback into the product roadmap.

Key Responsibilities

Technical Leadership & Architecture

Act as the deep technical authority for Qualys exposure management architecture including:

* ETM risk correlation and prioritization
* ROC operational workflows
* Vulnerability management and remediation orchestration
* ASPM & CNAPP integration to Exposure Management Platform (ETM)
* Cross-domain exposure analytics across infrastructure, cloud, identity, and applications

Design and guide enterprise implementations that integrate:

* VMDR vulnerability telemetry
* Asset intelligence from CSAM
* External attack surface data from EASM
* Cloud posture insights from TotalCloud
* Application security insights from ASPM / TotalAppSec

* 3rd Party (Non-Qualys) Ecosystems such as CNAPP, AppSec, IoT/OT, Identity, CMDB, etc.

Lead the development of reference architectures and deployment models for large global enterprises.

Outbound Customer and Sales enablement Responsibilities:

  • Develop sales enablement collateral, including customer product presentations, decks and demo scripts.
  • Help develop messaging and product positioning in collaboration with PM and PMMs leads.
  • Research the competitive landscape, determine how competitors are positioned and develop optimized positioning strategies and support documents for the CTEM, CAASM, CRQ, and RBVM.
  • Educate the sales team on how to address competitors in the field with Qualys' unique positioning.
  • Develop collateral and be an expert on CTEM and RBVM technology and terminology.
  • Be an expert in explaining the product to sales and be involved with demos and presentations to customers.
  • Foster strong relationships with customers to gather feedback, understand pain points, and translate insights into product requirements.
  • Design, deliver, and train the Qualys Sales Team on value-based demonstration of our products

Hands-On Platform Expertise

Work directly with engineering and product teams to:

* Prototype new ETM and ROC capabilities
* Validate exposure management workflows
* Test integrations with DevSecOps pipelines and CI/CD environments
* Provide technical feedback on product architecture and scalability

Provide deep expertise in:

* Vulnerability lifecycle management
* Exposure prioritization and TruRisk scoring
* Attack path analysis
* Cyber Risk quantification
* Remediation orchestration
* ASPM and application risk correlation.

Risk Operations Center (ROC) Strategy

Define how enterprises implement the Risk Operations Center model using Qualys ETM.

Develop best practices and implementation playbooks for:

* Cross-team risk prioritization
* Exposure triage workflows
* Remediation SLAs
* Executive risk reporting
* Operationalizing CTEM across security teams.

Customer Advisory & Strategic Engagement

Act as a trusted technical advisor to CISOs, security architects, and DevSecOps leaders.

Lead architecture workshops, executive technical briefings, strategic customer advisory sessions and proof-of-concept deployments.

Support major strategic and enterprise accounts globally and complex deployments

Team Leadership

Lead, mentor, and grow a team of 5-6 highly skilled technical SMEs, setting clear priorities, fostering a high-performance culture, and ensuring a strong execution rhythm.

Build and deliver scalable and repeatable playbooks for:

* Field architecture guidance
* ETM and ROC technical enablement
* ASPM, CNAPP adoption and DevSecOps integration
* Product feedback and innovation.

Build a center of excellence for exposure management architecture within the company

Product Collaboration

Partner closely with Product Management and Engineering to:

* Influence product roadmap
* Validate new capabilities
* Translate customer needs into platform improvements
* Accelerate innovation across exposure management and application security.

Required Qualifications

* 12-15+ years' experience in cybersecurity architecture, product strategy, or technical leadership
* Deep expertise in vulnerability management and exposure management platforms
* Strong hands-on experience with application security,ASPM, and CNAPP ecosystems
* Experience designing security architectures for large enterprise environments
* Strong knowledge of cloud platforms (AWS, Azure, GCP)
* Familiarity with DevSecOps pipelines and developer security workflows
* Experience integrating security platforms across:

  • Exposure Management
  • Vulnerability management
  • Application security
  • Cloud security
  • Asset management
  • Identity security.

* Demonstrated ability to lead technical teams and influence cross-functional stakeholders.

Preferred Experience

* Experience working with platforms similar to Qualys and competitive vendor landscape focusing on RBVM, CTEM, AppSec, ASPM, CNAPP etc.

* Familiarity with frameworks such as:

  • Continuous Threat Exposure Management (CTEM)
  • Zero Trust
  • NIST Cybersecurity Framework
  • MITRE ATT&CK.

* Experience working directly with enterprise CISOs and security leadership teams.

**********************************************************************************************************************

The salary range for this position is $200,000 - $235,000 per year. Final compensation will be determined based on several factors, including but not limited to skills, relevant experience, and work location. Please note this range reflects base salary and does not include incentive compensation or potential equity grants. We also offer a comprehensive and highly competitive benefits package.

Qualys is an Equal Opportunity Employer, please see our EEO policy.