31 information security risk analyst jobs at 22 companies in California
2w
Save
Mark Applied
Hide
2w
Senior Information Security Governance, Risk & Compliance Analyst
Northridge or Georgia or Minnesota or Texas
$121k-$205k/yrOnsiteFull Time
MedtronicNYSE: MDT: Global leader in medical technology and healthcare solutions.
7+ YOEBachelor’s degree or equivalent experience, 7+ years in information security GRC, risk, SOX ITGC, audit, access governance, or internal controls; SAP GRC certifications and advanced governance expertise required.
SAP GRC Access Control, SAP GRC Process Control, SAP GRC Risk Management, SAP, Oracle, Workday, ServiceNow, SailPoint, Entra ID, NIST Cybersecurity Framework, NIST Risk Management Framework, NIST AI Risk Management Framework, ISO 27001, ISO 31000, ISO 42001, COBIT, COSO Internal Control Framework, SOX 404 IT General Controls, HIPAA
United States or Colorado or Hawaii or Illinois or Maryland or Massachusetts or Minnesota or Vermont or District of Columbia or New York or New Jersey or Washington or California or Connecticut or Pennsylvania
$129k-$189k/yrRemoteFull Time
TwilioNYSE: TWLO: Cloud communications platform for building personalized customer experiences.
5+ YOE5+ years security-focused risk management experience with industry risk frameworks, quantitative and qualitative risk analysis, automation and AI tooling, cross-functional collaboration, and strong communication skills.
The Marvin Group: Privately held aerospace and defense manufacturer serving governments, military services, and defense prime contractors.
Requires cybersecurity certification or equivalent experience, security policy knowledge, vulnerability and risk assessment skills, SIEM, cloud, network and endpoint security expertise, and strong analytical and communication skills.
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yrOnsiteFull Time
SanDiskNASDAQ: SNDK: Specialist in NAND flash memory and data storage solutions.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
State of California: The constitutional government of the U.S. State of California.
Requires Information Technology Specialist I eligibility through current classification, lateral transfer, reinstatement, examination, or related eligibility; degree or transcripts may be needed to verify eligibility.
security controls, security tools, risk assessments, incident response, Information Security Engineering, Information Technology Project Management, State Application STD Form 678, CalCareers
Inland Empire Health Plan: Public health plan managing Medi-Cal, Medicare-Medicaid, and Covered California coverage for Riverside and San Bernardino County residents.
5+ YOE5 years cybersecurity experience focused on governance, compliance and risk; bachelor\u0002s in information systems security or related required; CISSP preferred; knowledge of cybersecurity/privacy laws and ability to apply principles.
Inland Empire Health Plan: Public health plan managing Medi-Cal, Medicare-Medicaid, and Covered California coverage for Riverside and San Bernardino County residents.
5+ YOEBachelor's in information systems security or related field, 5+ years cybersecurity experience focused on governance/compliance/risk, CISSP preferred, knowledge of cybersecurity/privacy laws and principles, leadership and project management experience.
Family Health Centers of San Diego: Provides affordable healthcare and supportive services.
4+ YOE3–5 years supporting internal investigations, eDiscovery, compliance, security operations, or digital forensics; 2+ years coordinating with HR/Legal on sensitive matters; healthcare/regulatory experience preferred.
eDiscovery tools, DLP, Legal hold systems, ESI review platforms
Confie: National personal lines insurance brokerage and retail agency.
4+ YOE4+ years IT security experience; perform risk assessments, security analysis, remediation planning, server administration, and incident response. Knowledge of network security, UTM/IPS/IDS, Linux, VMware, and Microsoft Active Directory.
Linux, VMware ESX/Vsphere, Microsoft Windows Active Directory, UTM, IPS, IDS, TCP/IP, MPLS, VoIP, Firewalls, routers, PCO, SOX
SalesforceNYSE: CRM: The #1 AI CRM driving customer success together.
3+ YOERequires 3+ years in consulting or complex corporate IT, security control methodologies, risk identification and mitigation, and NIST SP 800-53 control implementation and testing. CISSP, CISA, PMP, or CISM preferred.
Tableau, Microsoft Visio, NIST SP 800-53, Cybersecurity Framework (CSF)
Southland Credit Union: Member-owned, not-for-profit credit union providing banking, savings, loans, and financial services to Los Angeles and Orange County communities.
4+ YOERequires 4–6 years in information security, cybersecurity, risk, compliance, or IT audit; security risk assessment and governance experience; and a bachelor's degree or equivalent experience. Professional certification preferred.
NIST, ISO 27001, Governance, Risk, and Compliance (GRC) platforms
ICW Group: Privately held national property-and-casualty carrier serving businesses with workers’ compensation and specialty insurance.
5+ YOEBachelor’s degree in finance, data science, information security, or related field; 5–7 years’ experience with third-party contracts, information security documentation, or financial documentation; strong analytical and communication skills.
Microsoft Excel, Microsoft Word, Microsoft Visio, Microsoft PowerPoint
IT - Governance Risk and Compliance - IT - Gov Analyst
Sacramento, California, United States
$93k-$120k/yrHybridFull Time
Golden 1 Credit Union: Member-owned not-for-profit financial cooperative providing banking and lending services.
5+ YOERequires 5+ years in cybersecurity, including 2–3+ years with security frameworks, technology risk, security or compliance experience, risk management and controls assurance, and knowledge of information security and regulatory frameworks.
San Francisco or New York City or Los Angeles or Seattle
$175k-$230k/yrHybridFull Time
Whatnot: Live shopping marketplace connecting buyers and sellers.
8+ YOERequires 8+ years of security GRC experience, bachelor's degree in computer science or information security, audit experience, cloud compliance expertise, and knowledge of ISO 27001, SOC2, PCI, GDPR, and CCPA.
Ross StoresNASDAQ: ROST: Off-price retailer of apparel and home fashion.
5+ YOEFive years of IT experience, including three in security or risk management; bachelor's degree preferred; security governance, compliance, risk management, analytical, communication, and project management skills required.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint, UNIX, Windows, Firewalls, VPN, PKI, IPS, Oracle, MS SQL
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
3+ YOE3+ years DoD/IT experience, RMF/A&A and eMASS experience, implementing security controls, performing vulnerability assessments, DoD 8140 certification, Secret clearance, and a relevant Bachelor's degree.
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
4+ YOERequires 4+ years supporting DoD or government IT systems, 4+ years Navy RMF and A&A, 3+ years security controls and vulnerability analysis, Secret clearance, high school diploma/GED, and DoD 8140 certification.
Assured Compliance Assessment Solution (ACAS), DoD STIG, Evaluate-STIG, eMASS, Windows, Linux, network firewalls, web application firewalls, web proxy, intrusion prevention systems, vulnerability scanners
Ross StoresNASDAQ: ROST: Off-price retailer of apparel and home fashion.
5+ YOE5+ years IT experience (minimum 3 in security/risk), strong security governance and risk management knowledge, proficient with Microsoft Word/Excel/PowerPoint, project management, analytical and communication skills; CISSP/CRISC preferred.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint, UNIX, Windows, Firewalls, VPN, PKI, IPS, Oracle, MS SQL
HarmonicThe Nasdaq Global Select Market: HLIT: Public U.S. broadband technology providing virtualized access solutions to cable and telecommunications operators.
Pursuing a degree in Cybersecurity/Information Systems/IT, familiarity with security and risk concepts, strong documentation and organizational skills, able to work remotely, and proficient with Microsoft 365 apps.
Microsoft 365, Microsoft Excel, Microsoft PowerPoint, Microsoft Word