88 information security risk jobs at 68 companies in San Jose, CA
1mo
Save
Mark Applied
Hide
1mo
Security Risk Manager
San Francisco, California, United States
$194k-$220k/yrHybridFull Time
AsanaNYSE: ASAN: Software platform for team project management and workflow automation.
7+ YOE7+ years in information security with proven experience building security risk management programs, quantitative risk methodologies (e.g., FAIR), scripting/automation for risk monitoring, and knowledge of NIST, ISO, SOC 2, and FedRAMP.
ServiceNowNYSE: NOW: Enterprise cloud platform for digital workflow automation.
3+ YOERequires 3–5+ years in information or application security, CSA certification, cloud and security-tool expertise, Java/JavaScript knowledge, web proxy experience, application security, risk, compliance, and AI skills.
ServiceNow, Azure AI, AWS, SIEM, WAF, IDS/IPS, Java, JavaScript, OWASP Top Ten, NIST, CIS, GDPR, HIPAA, PCI DSS, ISO
Quanta ManufacturingTWSE: 2382: Electronics design and manufacturing services for global technology brands.
2+ YOEBachelor's degree in a related field, 2–5+ years of information security experience, ISO 27001 and TISAX experience, English and Mandarin proficiency, and security risk, vulnerability, architecture, and compliance expertise.
Dolby LaboratoriesNYSE: DLB: Develops audio and video signal processing and compression technologies.
8+ YOE8+ years in information/cybersecurity or related roles; experience across security domains and frameworks; strong stakeholder engagement, risk management, and security integration skills.
SOX, GDPR, ISO 27001, TISAX, NIST CSF, NIST 800-53, NIST 800-171, SOC, IR, GRC
United States or California or Washington or New York or New Jersey or Connecticut or Los Angeles or San Francisco
$146k-$225k/yrRemoteFull Time
AffirmNasdaq: AFRM: Financial platform providing installment loans for consumer purchases.
5+ YOE5+ years in information security or risk roles; hands-on with Python and agentic coding tools (Cursor, Claude, Copilot); familiarity with cloud (AWS/GCP/Azure), security frameworks, strong communication and project delivery skills.
Python, Cursor, Claude, Copilot, SQL, AWS, GCP, Azure, NIST Cyber Security Framework, ISO 2700x, SOC1, SOC2, SSAE18, PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, BI tools
DocuSignNASDAQ: DOCU: Provides electronic signature and agreement management software solutions.
8+ YOE8+ years in security risk management/GRC, bachelor’s in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and security domain expertise; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, FAIR, Tableau, Power BI
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yrOnsiteFull Time
SandiskNasdaq: SNDK: Designs and manufactures flash memory and data storage products.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
Dallas or Boston or San Bruno or Mountain View or Raleigh
$243k-$365k/yrHybridFull Time
Verily: Developing data-driven technologies for clinical research and precision health.
10+ YOE8+ MgmtProven security leader with management and technical experience in security engineering, cloud and enterprise security, governance/risk/compliance (ISO 27001, SOC 2), and hands-on work with Okta, Crowdstrike, Wiz, Synk and hyperscaler platforms.
Okta, Crowdstrike, Wiz, Synk, Google Cloud Platform, Amazon Web Services, Azure, ISO 27001, SOC 2
Business Information Security Officer (San Francisco, US)
San Francisco, California, United States
$171k-$234k/yrOnsiteFull Time
DolbyNYSE: DLB: Develops and licenses audio and visual entertainment technologies.
8+ YOE8+ years in information/cybersecurity or IT risk; experience with security domains; partner to business units; familiar with ISO/NIST frameworks.
Americas Regional Chief Information Security Officer (CISO)
New York City or San Jose
$250k-$376k/yrHybridFull Time
OKX: Global cryptocurrency exchange and Web3 digital wallet developer.
Security leader with strong GRC and risk experience, technical depth for architecture reviews, regulator engagement capability, and proven communication skills to work with executives and auditors.
Vice President, Information Systems & Chief Information Security Officer (CISO)
Toronto or Campbell
OnsiteFull Time
Centric Software: AI-driven product lifecycle management and retail planning platform.
15+ YOE15+ MgmtBachelor's degree,15+ years progressive IT and cybersecurity leadership, experience with cloud infrastructure, governance, risk, compliance, incident response, and stakeholder management.
Senior Manager, GPN Information Security Office Consultant
McLean or Plano or Richmond or New York City or San Francisco or Philadelphia or Canada or United Kingdom or Philippines
$209k-$262k/yrOnsiteFull Time
Capital OneNYSE: COF: A diversified financial services providing banking and credit products.
6+ YOERequires a high school diploma or GED, 6+ years in cybersecurity or IT, 5+ years in cyber guidance and risk assessments or architecture reviews, and 4+ years in cloud security. AWS, GCP, or Azure experience preferred.
Socure: Provide AI-driven identity verification and fraud prevention software.
Executive security leader required to oversee enterprise security, AI and data governance, compliance, risk, vendor security, customer assurance, and board reporting; CISSP, CIPT, FAIR, and CRISC required.
BILLNYSE: BILL: Automated financial operations software for small and midsize businesses.
7+ YOE7+ years in insider risk, investigations, forensics, or security operations; 2+ years managing insider risk programs; experience with forensics, EDR/SIEM/UEBA, cloud and collaboration logs; strong communication and judgment.
macOS, Windows, AWS, Google Workspace, SIEM, UEBA, EDR, email security, AI
Strava: Fitness tracking and social networking app for athletes.
8+ YOEBachelor's degree,8-12 years in security or technical risk,security certification (CISSP or CISM) preferred,experience building GRC/risk programs,AI/automation in security,team management and executive reporting.
Sierra: Conversational AI platform for building enterprise customer agents
10+ YOE10+ years in information security with vendor/third-party risk in regulated environments; cloud security; ISO 27001/NIST 800-53/SOC 2/PCI DSS; automation and AI security interest.