Cybersecurity Analyst Jobs in California
Cybersecurity Analyst jobs in California are among the most active in the country, with demand concentrated in technology, defense contracting, financial services, and healthcare across every level from entry-level SOC analyst through senior architect. The largest hiring hubs are the San Francisco Bay Area, Los Angeles, and San Diego, where established employers such as Northrop Grumman, Kaiser Permanente, and Wells Fargo consistently seek cybersecurity talent. Cloud security, threat intelligence, and compliance-focused roles tied to CCPA and federal frameworks are the most in-demand specialties statewide. Find a role that fits below and apply directly.
Find Cybersecurity Analyst JobsOverview
Showing 5 of 26+ Cybersecurity Analyst jobs











Location: San Francisco Bay Area
Hybrid: 2 days in office / 3 days remote per week
Primary Purpose and Function
Xantrion is seeking a Cybersecurity Compliance Analyst to support our Compliance Service offering and internal compliance programs. You will help assess client security controls, develop practical compliance documentation, evaluate vendor cybersecurity risk, and organize evidence that supports client requirements.
This role combines technical IT knowledge with strong analytical and writing skills to support our Client Strategy team across a diverse client base. The team leads client assessments, executive discussions, and remediation planning, while you provide supporting analysis and produce accurate, well-organized deliverables using established templates, standards, and guidance.
Travel: None required.
Roles and Responsibilities
Client Compliance and Documentation
- Support current-state and target-state cybersecurity assessments using NIST Cybersecurity Framework (CSF), CIS Controls, and Xantrion standards.
- Review IT configurations and supporting evidence against established templates and control requirements; document gaps and findings for virtual Chief Information Officer (vCIO) review.
- Draft and maintain incident response plans (IRPs), business continuity plans (BCPs), written information security programs (WISPs), and supporting security policies and procedures.
- Support business impact analyses, risk and gap assessments, cybersecurity risk registers, and risk-acceptance records.
- Prepare control crosswalks, prioritized remediation roadmaps, executive risk summaries, and reporting scorecards under vCIO direction.
- Conduct vendor cybersecurity risk reviews by evaluating questionnaires, audit reports, security documentation, and supporting evidence.
- Maintain software and vendor inventories, data inventories, data flow documentation, and evidence indexes.
- Maintain annual testing schedules and track documentation, review dates, and follow-up items.
- Translate technical findings into clear descriptions of risk, supporting evidence, and recommended actions.
- Improve reusable templates and assessment procedures that support consistent delivery across clients.
- Coordinate evidence collection and auditor requests for Xantrion’s annual SOC 2 Type II examination and ISO/IEC 27001 audit activities.
- Organize audit documentation, maintain request trackers, and follow up with internal control owners.
- Review evidence for completeness and consistency and identify missing or outdated documentation.
- Provide seasonal support during internal audit preparation and review periods.
Position Requirements
Required Qualifications
- Three or more years of combined experience in IT operations, cybersecurity, IT audit, or compliance, including at least one year supporting control assessments, audit evidence collection, or security documentation.
- Practical understanding of business IT environments, including identity and access management, endpoint security, email security, backups, networking, and cloud services.
- Experience reviewing technical configurations or administrative reports against documented standards.
- Working knowledge of NIST CSF and CIS Controls, with familiarity with NIST SP 800-53 and ISO/IEC 27001 control concepts.
- Strong writing skills and the ability to produce clear, accurate policies, procedures, assessment findings, and client documentation.
- Ability to distinguish documented policies from evidence that controls are implemented and operating.
- Strong organization, attention to detail, and the ability to manage deliverables across multiple clients.
- Ability to work independently on assigned tasks, identify questions or evidence gaps, and incorporate vCIO feedback.
- Professional communication skills and sound judgment when handling confidential client information.
- Experience supporting registered investment advisers (RIAs) or other financial services organizations.
- Familiarity with cybersecurity and information protection requirements relevant to financial services, including SEC Regulation S-P, the FTC Safeguards Rule under GLBA, and applicable FINRA requirements.
- Experience working for a managed service provider or supporting multiple client environments.
- Hands-on familiarity with Microsoft 365, Entra ID, Intune, and common endpoint and security management tools.
- Experience conducting vendor cybersecurity reviews and evaluating SOC 2 reports.
- Experience supporting SOC 2 Type II examinations or ISO/IEC 27001 audits.
- Familiarity with additional requirements and programs such as HIPAA, CJIS, NIST SP 800-171, CMMC, or FedRAMP.
- Relevant certifications, such as Security+, CGRC, CISA, or an ISO/IEC 27001 credential.
- A relevant degree or certification is welcome but is not required. Equivalent practical experience will be considered.
The Cybersecurity Compliance Analyst performance success will be based on the following criteria:
- Client deliverables are accurate, clearly written, tailored to the client, and completed on schedule.
- Assessment findings are supported by evidence and clearly describe gaps for vCIO review.
- Risk registers, crosswalks, and supporting documentation remain organized and current.
- Internal audit requests are tracked and supported with complete, accessible evidence.
- Templates and processes improve the consistency and efficiency of Xantrion’s compliance services.
- Sitting or Standing for Long Periods: Ability to remain seated or standing at a workstation for extended durations, with regular breaks to prevent fatigue.
- Viewing a Computer Monitor: Sustained ability to focus on a computer screen for tasks such as reading, typing, and data entry, with appropriate lighting and screen settings to reduce eye strain.
- Digital Dexterity and Hand/Eye Coordination: Proficient use of hands and fingers to operate office equipment, including frequent alpha/numeric keyboarding, mouse usage, and handling other peripherals.
- Oral Communications: Engaging in clear and effective verbal communication over the phone, video calls, and occasionally in person, requiring strong speech and active listening skills.
- Use of Peripheral Devices: Handling and operating devices such as a mouse, headset, and other computer accessories with precision.
- Basic Ergonomic Adjustments: Ability to adjust seating, monitor height, and other workstation elements to maintain comfort and reduce physical strain.
- Environmental Awareness: Maintaining a workspace free from excessive noise and distractions to ensure focus and productivity.
- Occasional Lifting and Moving: Ability to lift and move light objects, such as laptops, documents, and office supplies, as needed.
- Periodic Travel to Xantrion’s Office: Willingness and ability to travel to Xantrion's office or shared workspace as needed, which may involve air travel, driving, ride-sharing, or using public transportation.
- Follow and support company policies and procedures as well as all local, state, and federal laws.
- Always maintain confidentiality of company and customer records and information.
- Maintain a professional image, adhering to Xantrion’s dress code.
- Must have an existing cell phone (running current Android or iOS).
- If applicable Xantrion will provide a cell phone, internet connection, and home office equipment allowance. See the Xantrion Handbook for details.
- Must have a reliable, high-speed internet connection that effectively supports work responsibilities, including video conferencing.
- Must have a dedicated, secure, and private workspace. Unless arranged by Xantrion, shared work environments, such as coworking spaces, are unacceptable. Client information must always be kept private.
- Must use Xantrion-provided PC and headset to execute job functions.
- Salary range $100-120K; depending on experience.
- 100% of medical, dental, and vision for you and your family.
- 401K with company match up to 4% of salary.
- Certification reimbursement and annual training budget.
- 17 Days PTO per year in addition to paid training days.
- Bonuses for referring new clients or employees.
Equal Opportunity Employer
Xantrion is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, age, color, sex, religion, sexual orientation, national origin, disability, medical condition, genetic information, pregnancy, military or veteran status, or any other protected characteristic as outlined by federal, state, or local laws. All employment is decided on the basis of qualifications, merit, and business needs at the time.
AI Disclosure for Recruitment
We use AI to support our recruiting team, improve the candidate experiences, and allow our teams to spend more time on meaningful candidate interactions. Our use of AI is limited to administrative tasks such as organizing application information and taking or summarizing interview notes. AI does not screen, advance, or reject candidates, and it does not make hiring or any significant decisions. Applications and candidate qualifications are reviewed by our recruiting team, and all decisions about interviews, advancement, offers, and hiring are made by our recruiters and hiring managers.
jloBCYiMSY
See All 26 Cybersecurity Analyst Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Cybersecurity Analyst JobsCybersecurity Analyst Jobs by City in California
Where California roles are concentrated, by current openings.
Cybersecurity Analyst Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Technology & Software
What California Employers Look For
The qualifications that appear most often in cybersecurity analyst jobs across California.
- Bachelor's degree in cybersecurity, computer science, or a related technical field
- Industry certification such as CompTIA Security+, CISSP, or CEH required or strongly preferred
- Hands-on experience with SIEM platforms, endpoint detection tools, and vulnerability scanning
- Familiarity with California Consumer Privacy Act compliance and relevant federal security frameworks
- Ability to obtain and maintain a security clearance for defense and government contractor roles
- Strong written communication skills for incident reporting and cross-functional stakeholder briefings
Cybersecurity Analyst Jobs in California: Frequently Asked Questions
How do you become a cybersecurity analyst in California?
California does not require a state-issued license to work as a cybersecurity analyst, so the path runs through education and industry credentials. Most employers expect at least a bachelor's degree in cybersecurity, computer science, or information systems, paired with a recognized certification such as CompTIA Security+, CISSP, or CEH. California's dense tech and defense ecosystem means candidates who can demonstrate hands-on lab work, a home lab portfolio, or a relevant internship move through hiring faster than credentials alone.
How much do cybersecurity analysts make in California?
Cybersecurity analysts in California earn a median of about $138,570 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $66,070 for the lowest 10% to over $221,000 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire cybersecurity analysts in California?
Employers hiring cybersecurity analysts in California right now include Saalex, COLSA, and Skechers, based on current listings on Migrate Mate as of September 2026. California's mix of major defense contractors in San Diego, large health systems across the state, and enterprise technology companies in the Bay Area means cybersecurity openings appear across a wide range of industries year-round.
Which California cities have the most cybersecurity analyst jobs?
San Diego, Santa Ana, and Manhattan Beach have the most cybersecurity analyst openings in California. The Bay Area's concentration of technology headquarters and financial institutions drives the highest overall volume, while Los Angeles draws demand from entertainment, aerospace, and healthcare, and San Diego's sizable defense contracting and biotech sectors keep hiring activity consistent there even outside the major metros.
Are there remote cybersecurity analyst jobs in California?
Yes, and more than most fields, since a large portion of cybersecurity analyst work involves monitoring dashboards, analyzing logs, and writing reports rather than physically accessing hardware. About 45% of cybersecurity analyst openings tied to California are remote or hybrid as of September 2026, reflecting the desk-based nature of many analyst functions. Threat monitoring, security operations center analysis, and compliance advisory roles are the positions most commonly listed as fully remote.
How can I get hired as a cybersecurity analyst in California with little or no experience?
The most realistic entry path is a junior SOC analyst or IT security associate role, which many California employers use as a feeder position for senior analyst tracks. Large California health systems and defense contractors such as those concentrated in San Diego often post associate-level security roles that accept candidates with an IT helpdesk or network technician background. A CompTIA Security+ certification paired with a documented home lab or capture-the-flag competition history gives early-career applicants a concrete edge when competing against candidates who hold only a degree.
Where can I find and apply to cybersecurity analyst jobs in California?
You can find and apply to cybersecurity analyst jobs in California on Migrate Mate, which lists current California openings updated regularly. Search the listings, find roles that match your experience and target location, and apply directly to each one without creating a profile or signing up.
See All 26 Cybersecurity Analyst Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Cybersecurity Analyst Jobs