19 security risk analyst jobs at 16 companies in San Francisco, CA

1mo
Save
Mark Applied
Hide
Senior Security Analyst (Tier 3, Insider Risk) - Global Security Organization
San Jose, California, United States
$134k-$236k/yr OnsiteFull Time
TikTok
TikTok: Global short-form video hosting and social media platform.
Technical security analyst for insider risk investigations; strong log and telemetry analysis, IAM and cloud familiarity, EDR and endpoint/cloud/identity investigations, reporting and stakeholder communication.
Okta, Active Directory (AD), GCP, AWS, Azure, Ali Cloud, EDR, VPN, Slack, Microsoft Teams, Git, Python
1w
Save
Mark Applied
Hide
Security Analyst, Third-Party Ecosystem Risk Management
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam or United States or Canada or United Kingdom or Europe
$119k-$176k/yr HybridFull Time
Plaid
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
4+ YOERequires 4+ years in vendor risk management, third-party security assessments, risk lifecycle management, security frameworks, program maturation, documentation, communication, and AI-assisted tooling.
SOC 2, ISO 27001, NIST CSF, OneTrust, ProcessUnity, Whistic, SecurityScorecard
2mo
Save
Mark Applied
Hide
Agentic Risk Analyst
San Francisco, California, United States
$288k-$425k/yr HybridFull Time
OpenAI
OpenAI: Develops artificial intelligence models and generative AI software services.
7+ YOE7+ years experience in trust & safety, security, intelligence, or related fields; strong understanding of agentic AI systems; analytical judgment, technical fluency; experience synthesizing investigations and telemetry; SQL/Python a plus.
SQL, Python
6d
Save
Mark Applied
Hide
Senior Information Security Analyst
Santa Clara, California, United States
$128k-$217k/yr RemoteFull Time
ServiceNow
ServiceNowNYSE: NOW: Enterprise cloud platform for digital workflow automation.
3+ YOERequires 3–5+ years in information or application security, CSA certification, cloud and security-tool expertise, Java/JavaScript knowledge, web proxy experience, application security, risk, compliance, and AI skills.
ServiceNow, Azure AI, AWS, SIEM, WAF, IDS/IPS, Java, JavaScript, OWASP Top Ten, NIST, CIS, GDPR, HIPAA, PCI DSS, ISO
1mo
Save
Mark Applied
Hide
Senior Security GRC Analyst
San Mateo, California, United States
$224k-$272k/yr HybridFull Time
Roblox
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
2d
Save
Mark Applied
Hide
Governance Risk & Compliance Analyst
San Francisco or New York City or Los Angeles or Seattle
$175k-$230k/yr HybridFull Time
Whatnot
Whatnot: Social marketplace for buying and selling via live streams
8+ YOERequires 8+ years of security GRC experience, bachelor's degree in computer science or information security, audit experience, cloud compliance expertise, and knowledge of ISO 27001, SOC2, PCI, GDPR, and CCPA.
Okta, Terraform, AWS, Lumos, Cloudflare, Github
1mo
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
7+ YOE7+ years in security-focused TPRM, experience with vendor risk assessments, cloud/SaaS/AI security reviews, program building, audits, and remediation tracking; Bachelor's or Master's degree in related field.
CAIQ, SIG, SOC 2 Type 2, Penetration Test, NIST, ISO 27001, PCI-DSS, AWS, Azure, GCP, Covey Scout
1mo
Save
Mark Applied
Hide
Copy of Senior Security Assurance Analyst
New York or San Francisco
HybridFull Time
Rippling
Rippling: Unified platform managing workforce HR, IT, and finance operations
4+ YOE4+ years in security and compliance with vendor risk management experience; familiarity with ISO 27001, PCI DSS, SOC 2; cloud security best practices; strong communication skills.
2w
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
AWS, Azure, GCP, Covey
1mo
Save
Mark Applied
Hide
Lead Security Analysis
Dublin or New York City or Los Angeles or Boston
$125k-$213k/yr HybridFull Time
Ross Stores
Ross StoresNASDAQ: ROST: Operates an off-price retail chain selling clothing and home goods.
5+ YOEFive years of IT experience, including three in security or risk management; bachelor's degree preferred; security governance, compliance, risk management, analytical, communication, and project management skills required.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint, UNIX, Windows, Firewalls, VPN, PKI, IPS, Oracle, MS SQL
1mo
Save
Mark Applied
Hide
Governance, Risk, Compliance & Trust Analyst
Oakland, California, United States
$140k-$178k/yr HybridFull Time
Everlaw
Everlaw: Provides a cloud-based litigation platform for legal teams.
5+ YOE5+ years GRC experience; strong knowledge of FedRAMP, SOC 2, ISO frameworks; audit readiness, vendor reviews, customer security questionnaires, trust portals, and producing clear, audit-ready deliverables.
FedRAMP, SOC 2, ISO 27001, ISO 27017, ISO 27018, Covey, Covey Scout, Modern Health
1mo
Save
Mark Applied
Hide
Lead Security Analysis
Dublin, California, United States
$125k-$213k/yr HybridFull Time
Ross Stores
Ross StoresNASDAQ: ROST: Discount retail chain selling brand-name apparel and home fashions
5+ YOE5+ years IT experience (minimum 3 in security/risk), strong security governance and risk management knowledge, proficient with Microsoft Word/Excel/PowerPoint, project management, analytical and communication skills; CISSP/CRISC preferred.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint, UNIX, Windows, Firewalls, VPN, PKI, IPS, Oracle, MS SQL
1mo
Save
Mark Applied
Hide
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yr OnsiteFull Time
Sandisk
SandiskNasdaq: SNDK: Designs and manufactures flash memory and data storage products.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
2d
Save
Mark Applied
Hide
API Security and Governance Analyst
Charlotte or San Leandro
$77k-$145k/yr HybridFull Time
Wells Fargo
Wells FargoNYSE: WFC: Global provider of banking, investment, and mortgage financial services.
4+ YOERequires 4+ years in controls, operations, compliance, risk, governance, audit, technology operations, or project coordination, plus reporting, process management, analytical, organizational, and communication skills.
Microsoft Excel, Power BI, Microsoft SharePoint
1w
Save
Mark Applied
Hide
Senior Analyst
Cambridge or New York City or Washington or Atlanta or San Francisco
$119k-$193k/yr OnsiteFull Time
Forrester
ForresterNASDAQ: FORR: Provides market research and business advisory services to global leaders.
5+ YOERequires 5+ years of security and risk experience, BA/BS or equivalent, strong research, critical thinking, writing, presentation, and business skills; must be a US citizen and travel 30%-50%.
Managed Detection and Response (MDR), Managed Security Services (MSS), Zero Trust
4w
Save
Mark Applied
Hide
GRC Analyst
San Francisco, California, United States
$95k-$150k/yr HybridFull Time
Zip
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
1d
Save
Mark Applied
Hide
IT Governance Analyst
Palo Alto, California, United States
$150k-$160k/yr HybridFull Time
TabaPay
TabaPay: Instant payment processing and money movement for fintech companies.
5+ YOEBachelor’s degree and 5–7 years in IT governance, risk, or compliance within US financial services; 3+ years with high-volume payment rails; at least two governance, risk, audit, or security certifications preferred.
PCI-DSS, FFIEC, SOC 1/2, GLBA, COBIT 2019, NIST CSF, CIS, AWS, SDLC, FedNow, ACH, Fedwire, Real-Time Payments (RTP), KPIs, KRIs, CAB
4w
Save
Mark Applied
Hide
Cybersecurity Governance Analyst & Enablement Intern
San Jose or United States
$18-$20/hr RemoteFull Time
Harmonic
Harmonic: Provides virtualized broadband and video delivery technology solutions.
Pursuing a degree in Cybersecurity/Information Systems/IT, familiarity with security and risk concepts, strong documentation and organizational skills, able to work remotely, and proficient with Microsoft 365 apps.
Microsoft 365, Microsoft Excel, Microsoft PowerPoint, Microsoft Word
1d
Save
Mark Applied
Hide
Global Threat Analyst, Protective Intelligence
Sunnyvale or Mountain View
$105k-$151k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
4+ YOEBachelor's degree or equivalent experience; 4 years leading security intelligence analysis and risk mitigation plus 4 years in close protection operations. AI, investigative, and OSINT experience preferred.
AI, Open Source Intelligence (OSINT)