31 information security risk analyst jobs at 22 companies in California

2w
Save
Mark Applied
Hide
Senior Information Security Governance, Risk & Compliance Analyst
Northridge or Georgia or Minnesota or Texas
$121k-$205k/yr OnsiteFull Time
Medtronic
MedtronicNYSE: MDT: Global leader in medical technology and healthcare solutions.
7+ YOEBachelor’s degree or equivalent experience, 7+ years in information security GRC, risk, SOX ITGC, audit, access governance, or internal controls; SAP GRC certifications and advanced governance expertise required.
SAP GRC Access Control, SAP GRC Process Control, SAP GRC Risk Management, SAP, Oracle, Workday, ServiceNow, SailPoint, Entra ID, NIST Cybersecurity Framework, NIST Risk Management Framework, NIST AI Risk Management Framework, ISO 27001, ISO 31000, ISO 42001, COBIT, COSO Internal Control Framework, SOX 404 IT General Controls, HIPAA
1mo
Save
Mark Applied
Hide
Senior Analyst, Security Risk
United States or Colorado or Hawaii or Illinois or Maryland or Massachusetts or Minnesota or Vermont or District of Columbia or New York or New Jersey or Washington or California or Connecticut or Pennsylvania
$129k-$189k/yr RemoteFull Time
Twilio
TwilioNYSE: TWLO: Cloud communications platform for building personalized customer experiences.
5+ YOE5+ years security-focused risk management experience with industry risk frameworks, quantitative and qualitative risk analysis, automation and AI tooling, cross-functional collaboration, and strong communication skills.
NIST RMF, AI RMF, COSO, ISO 31000, GRC, AI
3w
Save
Mark Applied
Hide
INFORMATION SECURITY ANALYST II (1381)
Inglewood, California, United States
$90k-$120k/yr OnsiteFull Time
The Marvin Group
The Marvin Group: Privately held aerospace and defense manufacturer serving governments, military services, and defense prime contractors.
Requires cybersecurity certification or equivalent experience, security policy knowledge, vulnerability and risk assessment skills, SIEM, cloud, network and endpoint security expertise, and strong analytical and communication skills.
SIEM
1mo
Save
Mark Applied
Hide
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yr OnsiteFull Time
SanDisk
SanDiskNASDAQ: SNDK: Specialist in NAND flash memory and data storage solutions.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
3d
Save
Mark Applied
Hide
Security Analyst
Sacramento County or Sacramento
$7k-$11k/mo HybridFull Time
State of California
State of California: The constitutional government of the U.S. State of California.
Requires Information Technology Specialist I eligibility through current classification, lateral transfer, reinstatement, examination, or related eligibility; degree or transcripts may be needed to verify eligibility.
security controls, security tools, risk assessments, incident response, Information Security Engineering, Information Technology Project Management, State Application STD Form 678, CalCareers
2w
Save
Mark Applied
Hide
Security Analyst, Third-Party Ecosystem Risk Management
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam or United States or Canada or United Kingdom or Europe
$119k-$176k/yr HybridFull Time
Plaid
Plaid: Fintech data network connecting consumers’ financial accounts to apps and services.
4+ YOERequires 4+ years in vendor risk management, third-party security assessments, risk lifecycle management, security frameworks, program maturation, documentation, communication, and AI-assisted tooling.
SOC 2, ISO 27001, NIST CSF, OneTrust, ProcessUnity, Whistic, SecurityScorecard
1mo
Save
Mark Applied
Hide
Engineer III - Cybersecurity Risk Analyst
Rancho Cucamonga, California, United States
$135k-$179k/yr HybridFull Time
Inland Empire Health Plan
Inland Empire Health Plan: Public health plan managing Medi-Cal, Medicare-Medicaid, and Covered California coverage for Riverside and San Bernardino County residents.
5+ YOE5 years cybersecurity experience focused on governance, compliance and risk; bachelor\u0002s in information systems security or related required; CISSP preferred; knowledge of cybersecurity/privacy laws and ability to apply principles.
1mo
Save
Mark Applied
Hide
Engineer III - Cybersecurity Risk Analyst
Rancho Cucamonga, California, United States
$135k-$179k/yr HybridFull Time
Inland Empire Health Plan
Inland Empire Health Plan: Public health plan managing Medi-Cal, Medicare-Medicaid, and Covered California coverage for Riverside and San Bernardino County residents.
5+ YOEBachelor's in information systems security or related field, 5+ years cybersecurity experience focused on governance/compliance/risk, CISSP preferred, knowledge of cybersecurity/privacy laws and principles, leadership and project management experience.
3mo
Save
Mark Applied
Hide
Insider Risk Analyst
San Diego, California, United States
$80k-$120k/yr OnsiteFull Time
Family Health Centers of San Diego
Family Health Centers of San Diego: Provides affordable healthcare and supportive services.
4+ YOE3–5 years supporting internal investigations, eDiscovery, compliance, security operations, or digital forensics; 2+ years coordinating with HR/Legal on sensitive matters; healthcare/regulatory experience preferred.
eDiscovery tools, DLP, Legal hold systems, ESI review platforms
2mo
Save
Mark Applied
Hide
IT Security Analyst
Huntington Beach or Farmers Branch
$110k-$130k/yr HybridFull Time
Confie
Confie: National personal lines insurance brokerage and retail agency.
4+ YOE4+ years IT security experience; perform risk assessments, security analysis, remediation planning, server administration, and incident response. Knowledge of network security, UTM/IPS/IDS, Linux, VMware, and Microsoft Active Directory.
Linux, VMware ESX/Vsphere, Microsoft Windows Active Directory, UTM, IPS, IDS, TCP/IP, MPLS, VoIP, Firewalls, routers, PCO, SOX
4d
Save
Mark Applied
Hide
Enterprise Security Senior Analyst, Security Partner
New York City or Bellevue or San Francisco
$117k-$177k/yr OnsiteFull Time
Salesforce
SalesforceNYSE: CRM: The #1 AI CRM driving customer success together.
3+ YOERequires 3+ years in consulting or complex corporate IT, security control methodologies, risk identification and mitigation, and NIST SP 800-53 control implementation and testing. CISSP, CISA, PMP, or CISM preferred.
Tableau, Microsoft Visio, NIST SP 800-53, Cybersecurity Framework (CSF)
2w
Save
Mark Applied
Hide
IS Analyst
Los Alamitos, California, United States
$79k-$95k/yr OnsiteFull Time
Southland Credit Union
Southland Credit Union: Member-owned, not-for-profit credit union providing banking, savings, loans, and financial services to Los Angeles and Orange County communities.
4+ YOERequires 4–6 years in information security, cybersecurity, risk, compliance, or IT audit; security risk assessment and governance experience; and a bachelor's degree or equivalent experience. Professional certification preferred.
NIST, ISO 27001, Governance, Risk, and Compliance (GRC) platforms
1w
Save
Mark Applied
Hide
Senior Third Party Risk Analyst
San Diego or United States
$79k-$133k/yr HybridFull Time
ICW Group
ICW Group: Privately held national property-and-casualty carrier serving businesses with workers’ compensation and specialty insurance.
5+ YOEBachelor’s degree in finance, data science, information security, or related field; 5–7 years’ experience with third-party contracts, information security documentation, or financial documentation; strong analytical and communication skills.
Microsoft Excel, Microsoft Word, Microsoft Visio, Microsoft PowerPoint
1w
Save
Mark Applied
Hide
IT - Governance Risk and Compliance - IT - Gov Analyst
Sacramento, California, United States
$93k-$120k/yr HybridFull Time
Golden 1 Credit Union
Golden 1 Credit Union: Member-owned not-for-profit financial cooperative providing banking and lending services.
5+ YOERequires 5+ years in cybersecurity, including 2–3+ years with security frameworks, technology risk, security or compliance experience, risk management and controls assurance, and knowledge of information security and regulatory frameworks.
NIST Cyber Security Framework, ISO 27001, SOC 1/2, COBIT, ITIL, Sarbanes-Oxley, CCPA, GDPR, PCI, SOX, HIPAA, HITRUST, GLBA
1w
Save
Mark Applied
Hide
Governance Risk & Compliance Analyst
San Francisco or New York City or Los Angeles or Seattle
$175k-$230k/yr HybridFull Time
Whatnot
Whatnot: Live shopping marketplace connecting buyers and sellers.
8+ YOERequires 8+ years of security GRC experience, bachelor's degree in computer science or information security, audit experience, cloud compliance expertise, and knowledge of ISO 27001, SOC2, PCI, GDPR, and CCPA.
Okta, Terraform, AWS, Lumos, Cloudflare, Github
1mo
Save
Mark Applied
Hide
Lead Security Analysis
Dublin or New York City or Los Angeles or Boston
$125k-$213k/yr HybridFull Time
Ross Stores
Ross StoresNASDAQ: ROST: Off-price retailer of apparel and home fashion.
5+ YOEFive years of IT experience, including three in security or risk management; bachelor's degree preferred; security governance, compliance, risk management, analytical, communication, and project management skills required.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint, UNIX, Windows, Firewalls, VPN, PKI, IPS, Oracle, MS SQL
2mo
Save
Mark Applied
Hide
Cybersecurity Engineer and Risk Analyst
San Diego, California, United States
$62k-$141k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
3+ YOE3+ years DoD/IT experience, RMF/A&A and eMASS experience, implementing security controls, performing vulnerability assessments, DoD 8140 certification, Secret clearance, and a relevant Bachelor's degree.
eMASS, Assured Compliance Assessment Solution (ACAS), DoD Security Technical Implementation Guides (STIG), Evaluate-STIG, Windows, Linux, cloud, virtualization, DevSecOps
2w
Save
Mark Applied
Hide
Cybersecurity Engineer and Risk Analyst
San Diego, California, United States
$69k-$158k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
4+ YOERequires 4+ years supporting DoD or government IT systems, 4+ years Navy RMF and A&A, 3+ years security controls and vulnerability analysis, Secret clearance, high school diploma/GED, and DoD 8140 certification.
Assured Compliance Assessment Solution (ACAS), DoD STIG, Evaluate-STIG, eMASS, Windows, Linux, network firewalls, web application firewalls, web proxy, intrusion prevention systems, vulnerability scanners
1mo
Save
Mark Applied
Hide
Lead Security Analysis
Dublin, California, United States
$125k-$213k/yr HybridFull Time
Ross Stores
Ross StoresNASDAQ: ROST: Off-price retailer of apparel and home fashion.
5+ YOE5+ years IT experience (minimum 3 in security/risk), strong security governance and risk management knowledge, proficient with Microsoft Word/Excel/PowerPoint, project management, analytical and communication skills; CISSP/CRISC preferred.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint, UNIX, Windows, Firewalls, VPN, PKI, IPS, Oracle, MS SQL
1mo
Save
Mark Applied
Hide
Cybersecurity Governance Analyst & Enablement Intern
San Jose or United States
$18-$20/hr RemoteFull Time
Harmonic
HarmonicThe Nasdaq Global Select Market: HLIT: Public U.S. broadband technology providing virtualized access solutions to cable and telecommunications operators.
Pursuing a degree in Cybersecurity/Information Systems/IT, familiarity with security and risk concepts, strong documentation and organizational skills, able to work remotely, and proficient with Microsoft 365 apps.
Microsoft 365, Microsoft Excel, Microsoft PowerPoint, Microsoft Word