Information Security Analyst Jobs in California
Information Security Analyst jobs in California are among the most active in the country, concentrated in technology, financial services, defense contracting, and healthcare across seniority levels from entry-level to principal analyst. The largest hiring markets are San Francisco, Los Angeles, and San Diego, where established employers such as Google, Kaiser Permanente, and Northrop Grumman maintain significant security operations. The most in-demand specialties are cloud security, threat intelligence, and security operations center analysis. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 96+ Information Security Analyst jobs











Description
Leidos' Corporate Information Security Office (CISO), reporting through our Digital sector, is seeking an Information Systems Security Manager in our San Diego, CA Campus Point office.
In this role, you will oversee Information Systems supporting Special Access Programs (SAPs) and maintain system authorization and cybersecurity compliance throughout the system lifecycle in accordance with the Joint Special Access Program Implementation Guide (JSIG), Risk Management Framework (RMF), applicable DoD SAP security requirements, and customer-specific guidance.
As the ISSM, you will serve as a Subject Matter Expert (SME) within the Information Assurance (IA) technical domain, supporting SAP Information Systems and enclaves across the enterprise. You will oversee day-to-day information system security operations, manage IA and IT personnel supporting SAP environments, resolve complex cybersecurity challenges, and develop innovative solutions to meet evolving program, customer, and security requirements.
The ideal candidate must be able to work independently while effectively collaborating with cybersecurity analysts, system administrators, engineers, program management, security personnel, site leadership, Program Security Officers (PSOs), Security Control Assessors (SCAs), and Authorizing Official (AO) representatives.
Location: All work will be performed on-site at our San Diego, CA office.
Clearance: You must currently hold an active Top Secret security clearance and be eligible for Special Access Program (SAP) clearance.
Primary Responsibilities
This role may include a combination of duties to protect SAP information, maintain cybersecurity controls, manage risk, and ensure Information Systems operate in accordance with approved authorization documentation and applicable SAP cybersecurity requirements.
Develop, implement, maintain, and enforce cybersecurity policies, procedures, Standard Operating Procedures (SOPs), and system-specific security documentation supporting SAP Information Systems.
Develop and conduct cybersecurity education and training for Information System users, privileged users, Information System Security Officers (ISSOs), system administrators, and other personnel supporting SAP environments.
Mentor ISSOs, system administrators, and other Information Assurance professionals regarding JSIG, RMF, secure system administration, vulnerability management, configuration management, and cybersecurity best practices.
Coordinate technical training on cybersecurity tools, software, technologies, and procedures used within SAP Information System environments.
Develop and lead training related to cybersecurity incident response, including identification, reporting, containment, remediation, recovery, documentation, and lessons learned.
Develop and lead Information Security projects from conceptualization through implementation, authorization, deployment, and operational acceptance.
Provide cybersecurity risk information and recommendations to program and senior site leadership to support risk-informed decisions regarding SAP Information Systems.
Demonstrated experience managing the cybersecurity and compliance posture of complex, multi-site Wide Area Networks (WANs), including interconnected systems across geographically dispersed locations.
Experience applying RMF, NIST, and applicable DoD security requirements to WAN architectures, boundary protections, network infrastructure, continuous monitoring, vulnerability management, and authorization activities.
Basic Qualifications
Must currently hold an active DoD Top Secret clearance to be considered and you must be able to meet applicable eligibility and access requirements for Special Access Program information.
Bachelor’s degree in an IT-related subject matter area from an accredited college or university and 12+ years of experience in an operational cybersecurity-specific role (e.g., Information Systems Security Manager, Information Systems Security Officer, cybersecurity specialist), or 16+ years of experience in an IT-related position with at least 10 years in an operational cybersecurity-specific role.
At least 10 years of Information Assurance/Cybersecurity management experience.
Current DoD 8570/8140 CISSP or CISM certification.
Previous ISSM and/or senior ISSO experience supporting classified Information Systems.
Detailed understanding and practical application of the Risk Management Framework (RMF), Joint Special Access Program Implementation Guide (JSIG), National Institute of Standards and Technology (NIST) security controls, and Committee on National Security Systems Instruction (CNSSI) 1253 requirements.
Working knowledge of DoD Special Access Program cybersecurity requirements, policies, processes, and procedures applicable to the authorization and operation of SAP Information Systems.
Experience developing, maintaining, and managing RMF authorization packages and associated cybersecurity documentation, including SSPs, security control implementation statements, POA&Ms, risk assessments, continuous monitoring artifacts, and supporting Body of Evidence.
Experience preparing Information Systems for cybersecurity assessments and supporting Security Control Assessors (SCAs), Authorizing Officials (AOs), Program Security Officers (PSOs), and customer cybersecurity representatives throughout the authorization process.
Familiarity with network technologies (LAN and WAN), network architecture, encryption technologies, key management, and cybersecurity best practices within classified and SAP environments.
Working knowledge of Microsoft Windows workstation/server and Linux operating systems within secure network environments.
Experience implementing and validating DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security configuration baselines, and system hardening requirements.
Experience with compliance, security monitoring, and vulnerability assessment tools such as Tenable/Nessus, ACAS, Splunk, and STIG Viewer.
Experience with workflow, documentation, configuration management, and change management tools such as JIRA and Confluence, as well as applicable RMF authorization management tools.
Ability to evaluate vulnerabilities, system changes, security control deficiencies, and cybersecurity risks and develop appropriate mitigation and remediation strategies.
Must be able to work in a constantly changing regulatory and mission environment with short-, mid-, and long-term timelines for resolving cybersecurity risks and compliance deficiencies.
Must work effectively within multidisciplinary teams and adapt quickly to changing program, customer, and mission requirements.
Excellent verbal and written communication skills with the ability to communicate cybersecurity risks and technical information to technical and non-technical stakeholders.
Preferred Qualifications
Experience working directly with PSOs, SCAs, AOs/DAOs, government cybersecurity representatives, and SAP program management.
Experience supporting SAP Information System Assessment and Authorization activities from initial system design through ATO and continuous monitoring.
Experience developing JSIG/RMF authorization documentation and providing supporting artifacts and evidence for security control assessments.
Experience with SAP cybersecurity assessments, compliance inspections, and remediation of assessment findings.
Proficient with Microsoft Windows and Linux operating systems, virtualization technologies, and secure computing environments.
Experience with network security architecture, classified network design, secure communications, encryption, and key management.
Experience developing cybersecurity policies, procedures, SOPs, CONOPS, and other technical documentation supporting SAP Information Systems.
Experience using JIRA and Confluence for cybersecurity workflow, continuous monitoring, vulnerability tracking, POA&M management, and documentation.
Experience leading or mentoring ISSOs, system administrators, cybersecurity analysts, and other technical personnel supporting SAP Information Systems.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
September 17, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $107,900.00 - $195,050.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
See All 96 Information Security Analyst Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find JobsInformation Security Analyst Jobs by City in California
Where California roles are concentrated, by current openings.
Information Security Analyst Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Electronics & Hardware
- Technology & Software
- Retail
- Education
- Manufacturing
What California Employers Look For
The qualifications that appear most often in information security analyst jobs across California.
- Bachelor's degree in computer science, cybersecurity, information technology, or a related field
- Active CompTIA Security+, CISSP, CISM, or equivalent industry certification
- Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, or IBM QRadar
- Familiarity with NIST, ISO 27001, SOC 2, or CIS security frameworks and compliance requirements
- Demonstrated ability to conduct vulnerability assessments, penetration testing, or incident response
- Experience securing cloud environments on AWS, Google Cloud, or Microsoft Azure
Information Security Analyst Jobs in California: Frequently Asked Questions
How do you become a information security analyst in California?
California does not require a state-issued license to work as an information security analyst, so the path starts with a bachelor's degree in computer science, cybersecurity, or information systems. From there, earning a recognized certification such as CompTIA Security+, CISSP, or CEH is the most consistent way to meet California employer requirements. Candidates who pair a degree with hands-on lab experience or a cybersecurity bootcamp recognized by California community colleges significantly strengthen their applications.
How much do information security analysts make in California?
Information security analysts in California earn a median of about $138,570 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $66,070 for the lowest 10% to over $221,000 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire information security analysts in California?
Employers hiring information security analysts in California right now include Lam Research, Apple, and Raytheon, based on current listings on Migrate Mate as of September 2026. California's concentration of technology headquarters, defense contractors, and large health systems means consistent demand from both private-sector firms and government-adjacent organizations.
Which California cities have the most information security analyst jobs?
San Diego, San Francisco, and Fremont have the most information security analyst openings in California. San Francisco and the broader Bay Area lead because of the density of technology headquarters and financial institutions, Los Angeles draws demand from entertainment, aerospace, and healthcare employers, and San Diego's openings are driven heavily by defense contractors and biotech firms based there.
Are there remote information security analyst jobs in California?
Yes, and more than most fields. Information security analysis is largely desk and systems-based work, making it well suited to remote and hybrid arrangements. About 51% of information security analyst openings tied to California are remote or hybrid as of September 2026, reflecting how broadly California tech and finance employers have adopted flexible work policies. Roles focused on cloud security, threat analysis, and compliance tend to be the most remote-friendly, while positions requiring hands-on lab or on-site data center access are more likely to be in person.
How can I get hired as a information security analyst in California with little or no experience?
The most realistic entry path is a junior security analyst or IT support role that gives direct exposure to security tools and processes. Large California employers such as Kaiser Permanente, Northrop Grumman, and major Bay Area technology companies run new-graduate and rotational programs that include security operations placements. Starting in adjacent roles such as IT helpdesk, network administrator, or systems administrator is a common lateral move. Earning CompTIA Security+ before applying and building a home-lab portfolio demonstrating SIEM or vulnerability scanning experience gives candidates a concrete edge with California hiring teams.
Where can I find and apply to information security analyst jobs in California?
You can find and apply to information security analyst jobs in California on Migrate Mate, which lists current California openings updated regularly. Search the listings to find roles that match your experience level and specialization, then apply directly to the ones that fit.
See All 96 Information Security Analyst Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Jobs