88 information security risk jobs at 68 companies in San Jose, CA

1mo
Save
Mark Applied
Hide
Security Risk Manager
San Francisco, California, United States
$194k-$220k/yr HybridFull Time
Asana
AsanaNYSE: ASAN: Software platform for team project management and workflow automation.
7+ YOE7+ years in information security with proven experience building security risk management programs, quantitative risk methodologies (e.g., FAIR), scripting/automation for risk monitoring, and knowledge of NIST, ISO, SOC 2, and FedRAMP.
FAIR, SIEMs, vulnerability scanners, cloud security tooling, NIST CSF, NIST SP 800-30, ISO 27001, SOC 2, FedRAMP
5d
Save
Mark Applied
Hide
Senior Information Security Analyst
Santa Clara, California, United States
$128k-$217k/yr RemoteFull Time
ServiceNow
ServiceNowNYSE: NOW: Enterprise cloud platform for digital workflow automation.
3+ YOERequires 3–5+ years in information or application security, CSA certification, cloud and security-tool expertise, Java/JavaScript knowledge, web proxy experience, application security, risk, compliance, and AI skills.
ServiceNow, Azure AI, AWS, SIEM, WAF, IDS/IPS, Java, JavaScript, OWASP Top Ten, NIST, CIS, GDPR, HIPAA, PCI DSS, ISO
1w
Save
Mark Applied
Hide
Senior Information Security Engineer
Fremont, California, United States
$140k-$170k/yr OnsiteFull Time
Quanta Manufacturing
Quanta ManufacturingTWSE: 2382: Electronics design and manufacturing services for global technology brands.
2+ YOEBachelor's degree in a related field, 2–5+ years of information security experience, ISO 27001 and TISAX experience, English and Mandarin proficiency, and security risk, vulnerability, architecture, and compliance expertise.
ISO 27001, TISAX
3mo
Save
Mark Applied
Hide
Business Information Security Officer
San Francisco, California, United States
$171k-$234k/yr OnsiteFull Time
Dolby Laboratories
Dolby LaboratoriesNYSE: DLB: Develops audio and video signal processing and compression technologies.
8+ YOE8+ years in information/cybersecurity or related roles; experience across security domains and frameworks; strong stakeholder engagement, risk management, and security integration skills.
SOX, GDPR, ISO 27001, TISAX, NIST CSF, NIST 800-53, NIST 800-171, SOC, IR, GRC
2mo
Save
Mark Applied
Hide
Security Risk Management Lead
United States or California or Washington or New York or New Jersey or Connecticut or Los Angeles or San Francisco
$146k-$225k/yr RemoteFull Time
Affirm
AffirmNasdaq: AFRM: Financial platform providing installment loans for consumer purchases.
5+ YOE5+ years in information security or risk roles; hands-on with Python and agentic coding tools (Cursor, Claude, Copilot); familiarity with cloud (AWS/GCP/Azure), security frameworks, strong communication and project delivery skills.
Python, Cursor, Claude, Copilot, SQL, AWS, GCP, Azure, NIST Cyber Security Framework, ISO 2700x, SOC1, SOC2, SSAE18, PCI DSS, NIST-800-53, FFIEC Cybersecurity Assessment Tool, SANS Top 20, BI tools
1mo
Save
Mark Applied
Hide
Senior Security Risk Manager
San Francisco, California, United States
$146k-$235k/yr HybridFull Time
DocuSign
DocuSignNASDAQ: DOCU: Provides electronic signature and agreement management software solutions.
8+ YOE8+ years in security risk management/GRC, bachelor’s in CS/InfoSec, experience with cloud (AWS/Azure/GCP), GRC platforms, risk quantification (FAIR), and security domain expertise; CISSP/CRISC/CISM preferred.
AWS, Azure, GCP, ServiceNow IRM, OneTrust, FAIR, Tableau, Power BI
4w
Save
Mark Applied
Hide
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yr OnsiteFull Time
Sandisk
SandiskNasdaq: SNDK: Designs and manufactures flash memory and data storage products.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
1mo
Save
Mark Applied
Hide
Chief Information Security Officer
Dallas or Boston or San Bruno or Mountain View or Raleigh
$243k-$365k/yr HybridFull Time
Verily
Verily: Developing data-driven technologies for clinical research and precision health.
10+ YOE8+ MgmtProven security leader with management and technical experience in security engineering, cloud and enterprise security, governance/risk/compliance (ISO 27001, SOC 2), and hands-on work with Okta, Crowdstrike, Wiz, Synk and hyperscaler platforms.
Okta, Crowdstrike, Wiz, Synk, Google Cloud Platform, Amazon Web Services, Azure, ISO 27001, SOC 2
3mo
Save
Mark Applied
Hide
Business Information Security Officer (San Francisco, US)
San Francisco, California, United States
$171k-$234k/yr OnsiteFull Time
Dolby
DolbyNYSE: DLB: Develops and licenses audio and visual entertainment technologies.
8+ YOE8+ years in information/cybersecurity or IT risk; experience with security domains; partner to business units; familiar with ISO/NIST frameworks.
3w
Save
Mark Applied
Hide
Americas Regional Chief Information Security Officer (CISO)
New York City or San Jose
$250k-$376k/yr HybridFull Time
OKX
OKX: Global cryptocurrency exchange and Web3 digital wallet developer.
Security leader with strong GRC and risk experience, technical depth for architecture reviews, regulator engagement capability, and proven communication skills to work with executives and auditors.
1mo
Save
Mark Applied
Hide
Vice President, Information Systems & Chief Information Security Officer (CISO)
Toronto or Campbell
OnsiteFull Time
Centric Software
Centric Software: AI-driven product lifecycle management and retail planning platform.
15+ YOE15+ MgmtBachelor's degree,15+ years progressive IT and cybersecurity leadership, experience with cloud infrastructure, governance, risk, compliance, incident response, and stakeholder management.
1w
Save
Mark Applied
Hide
Senior Manager, GPN Information Security Office Consultant
McLean or Plano or Richmond or New York City or San Francisco or Philadelphia or Canada or United Kingdom or Philippines
$209k-$262k/yr OnsiteFull Time
Capital One
Capital OneNYSE: COF: A diversified financial services providing banking and credit products.
6+ YOERequires a high school diploma or GED, 6+ years in cybersecurity or IT, 5+ years in cyber guidance and risk assessments or architecture reviews, and 4+ years in cloud security. AWS, GCP, or Azure experience preferred.
IaaS, PaaS, SaaS, AWS, GCP, Azure, HSMs, ATM, Mainframe, HPNS, PCI
6d
Save
Mark Applied
Hide
Deputy Chief Information Security Officer
United States or San Francisco or Carson City
$200k-$250k/yr HybridFull Time
Socure
Socure: Provide AI-driven identity verification and fraud prevention software.
Executive security leader required to oversee enterprise security, AI and data governance, compliance, risk, vendor security, customer assurance, and board reporting; CISSP, CIPT, FAIR, and CRISC required.
Okta, CrowdStrike, EDR/XDR, AI, AI/ML
1mo
Save
Mark Applied
Hide
Senior Strategic Risk Manager - Account Security
Cupertino, California, United States
OnsiteFull Time
Apple
AppleNASDAQ: AAPL: Designs and sells consumer electronics, software, and online services.
Manage security needs for services, build and integrate security controls and frameworks, and mitigate risks to systems and customer data.
6d
Save
Mark Applied
Hide
Security Analyst, Third-Party Ecosystem Risk Management
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam or United States or Canada or United Kingdom or Europe
$119k-$176k/yr HybridFull Time
Plaid
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
4+ YOERequires 4+ years in vendor risk management, third-party security assessments, risk lifecycle management, security frameworks, program maturation, documentation, communication, and AI-assisted tooling.
SOC 2, ISO 27001, NIST CSF, OneTrust, ProcessUnity, Whistic, SecurityScorecard
3w
Save
Mark Applied
Hide
Cyber Risk Lead
Houston or New York City or San Francisco or Seattle
$180k-$210k/yr OnsiteFull Time
Nscale
Nscale: Vertically integrated AI infrastructure provider for high-performance computing.
8+ YOE8+ years enterprise security risk experience, expertise in risk quantification (FAIR/NIST/ISO), SQL/scripting familiarity, experience driving remediation and building risk automation, strong cloud and IaC knowledge.
SQL, Terraform
3w
Save
Mark Applied
Hide
Staff Insider Risk Engineer
San Jose or Draper or United States
$156k-$220k/yr HybridFull Time
BILL
BILLNYSE: BILL: Automated financial operations software for small and midsize businesses.
7+ YOE7+ years in insider risk, investigations, forensics, or security operations; 2+ years managing insider risk programs; experience with forensics, EDR/SIEM/UEBA, cloud and collaboration logs; strong communication and judgment.
macOS, Windows, AWS, Google Workspace, SIEM, UEBA, EDR, email security, AI
4w
Save
Mark Applied
Hide
Senior Manager, Cybersecurity Stratey & Risk
San Francisco, California, United States
$270k-$290k/yr HybridFull Time
Strava
Strava: Fitness tracking and social networking app for athletes.
8+ YOEBachelor's degree,8-12 years in security or technical risk,security certification (CISSP or CISM) preferred,experience building GRC/risk programs,AI/automation in security,team management and executive reporting.
5d
Save
Mark Applied
Hide
IT Cybersecurity Specialist (Information Security)
Oakland or Washington or Hines or Eatontown or Albany or Philadelphia or Austin or Salt Lake City or Martinsburg or Shepherdstown
$91k-$118k/yr HybridFull Time
Department of Veterans Affairs
Department of Veterans Affairs: Provides healthcare and benefits to United States military veterans.
1+ YOEOne year of GS-12-equivalent specialized experience in network security, vulnerability patching, security reviews, risk management, cyber defense applications, routing, load balancing, firewalls, IDS/IPS, or packet brokers.
NIST RMF, intrusion detection/protection systems, antivirus, content blacklists, IDS/IPS, packet brokers, USA Hire, USAJOBS
2mo
Save
Mark Applied
Hide
Vendor Security Manager
San Francisco, California, United States
OnsiteFull Time
Sierra
Sierra: Conversational AI platform for building enterprise customer agents
10+ YOE10+ years in information security with vendor/third-party risk in regulated environments; cloud security; ISO 27001/NIST 800-53/SOC 2/PCI DSS; automation and AI security interest.
AWS, GCP, IAM, VPC, encryption, logging, monitoring, GRC tooling