Security Consultant Jobs in California
Security Consultant jobs in California are among the most active in the country, concentrated in technology, defense, financial services, and critical infrastructure sectors, with openings ranging from entry-level analyst roles through senior principal consultants. The largest hiring markets are Los Angeles, San Francisco, and San Diego, where employers such as Deloitte, SAIC, and Booz Allen Hamilton maintain significant California operations. The most in-demand specialties are cybersecurity risk assessment, physical security program management, and compliance consulting for regulated industries. Find a role that fits below and apply directly.
Find Security Consultant JobsOverview
Showing 5 of 25+ Security Consultant jobs











Your Role
The Information Security Team is seeking an Information Security Risk and Governance Specialist. In this role, you will be supporting Stellarus by helping translate regulatory, contractual, policy, and security requirements into sustainable and measurable governance and control practices.
Stellarus recognizes that IT Services are crucial, strategic, organizational assets and therefore we must invest appropriate levels of resource into the support, delivery and management of these critical IT Services and the IT systems that underpin them.
This position has responsivities within the Information Security Compliance organization, for maturing the Compliance function, ensuring IT audit-readiness with policy, regulations and control standards.
Your Work
In this role, you will:
GRC Program Operations & Reporting
- Maintain accurate information within GRC systems, control repositories, risk registers, policy repositories, and assurance trackers.
- Contribute to the development and maintenance of dashboards and reporting regarding security risks, control performance, exceptions, audit activity, findings, and remediation.
- Support development and continuous improvement of GRC processes, methodologies, templates, procedures, and operating standards.
Application & Technology Governance
- Support governance processes that establish visibility into applications, systems, infrastructure, data environments, and technology services subject to security requirements.
- Partner with technology teams to incorporate security governance requirements into the technology lifecycle, including implementation, material changes, and retirement.
- Maintain mappings between applications/technology assets and applicable risks, controls, owners, frameworks, and evidence.
- Assist in determining which applications and technology components are in scope for applicable regulatory and assurance frameworks.
Audit & Assessment Support
- Serve as a liaison between internal/external auditors/assessors and internal control owners.
- Coordinate information security evidence and responses for internal audits, external audits, customer assessments, regulatory reviews, and certification activities.
- Maintain organized, reusable evidence repositories to reduce duplicative requests and audit fatigue.
- Support readiness activities associated with SOC 2, NIST, HIPAA, HITRUST, and other applicable assessments.
Information Security Risk Management
- Support information security risk management program, including identification, assessment, documentation, treatment, monitoring, and reporting of technology and cybersecurity risks.
- Support development of security risk metrics, key risk indicators, dashboards, and management reporting.
- Monitor open risks, exceptions, findings, and remediation commitments and facilitate escalation of overdue or high-risk items.
- Facilitate security risk assessments for systems, applications, technologies, business processes, and organizational changes.
- Maintain security risk assessments for systems, applications, technologies, business processes, and organizational changes.
Control Assurance & Monitoring
- Perform or coordinate control self-assessments and evidence reviews.
- Evaluate whether controls are appropriately designed, implemented, documented, and supported by sufficient evidence.
- Track findings and remediation through closure and validate supporting evidence when appropriate.
- Identify control gaps and work with control owners to establish corrective action plans.
Your Knowledge and Experience
- Requires a bachelor's degree or equivalent experience
- Requires at least 7 years of prior relevant experience
- Understanding of and experience working with security assurance and trust frameworks (in particular NIST, HIPAA and SOC 2)
- Experience interacting with internal/external auditors and explaining technical concepts
- Ability to communicate effectively with customers and internal teams
- Superior organizational skills, extraordinary attention to detail, and an agile mindset that processes can always be improved
- Proven ability to manage projects and deliverables to completion
- Ability to understand and contextualize complex technical concepts into terms readily understandable by a non-technical audience
- Satisfactory knowledge and skills including technical or functional expertise, business acumen and financial analysis skills, risk management, critical thinking and decision-making skills.
- Intermediate understanding of healthcare information security governance, risk, and compliance practices
- Ability to learn and understand Stellarus’ security controls and to maintain a security knowledge base that can be used for multiple projects
Additionally, candidate must be able to:
- Demonstrate personal commitment to change through actions and words, and mobilize others to support change through times of stress and uncertainty
- Foster a team culture of continuous improvement, mentoring and learning, data driven decisions, and accountability for delivery of key metrics and deliverables
- Breakdown raw information and undefined problems into specific, workable components that in-turn clearly identifies the issues at hand
- Make logical conclusions, anticipates obstacles and considers different approaches that are relevant to the decision-making process Improve organizational performance though the application of original thinking to existing and emerging methods, processes, products and services
#LI-FB1
ABOUT THE TEAM
About Stellarus and the Ascendiun Family of Companies
Stellarus, launched in January 2025, is designed to scale innovative healthcare solutions that support customers in creating a health care experience deserving of their family, friends, and neighbors.
Stellarus is part of a family of organizations that is overseen by a nonprofit corporate entity named Ascendiun. The Ascendiun Family of Companies also includes Blue Shield of California and its subsidiary, Blue Shield of California Promise Health Plan and Altais, a clinical services company.
Stellarus’ vision is to empower its customers to create a healthcare experience that is worthy of their family, friends, and neighbors. Stellarus’ objective is to offer innovative, modern, scalable solutions that challenge the health care status quo. This very closely aligns with Blue Shield of California’s vision by using innovation to improve quality, affordability, and experience for members.
To achieve our mission, we foster an environment where all employees can thrive and contribute fully to address the needs of the various communities we serve. We are committed to creating and maintaining a supportive workplace that upholds our values and advances our goals.
Our Values:
At Stellarus, our core values of agility, trust, drive, courage and service shape our approach to developing innovative product offerings.
Our Workplace Model:
We believe in fostering a workplace environment that balances purposeful in-person collaboration with flexibility - providing clear expectations while respecting the diverse needs of our workforce. Our workplace model is designed around intentional in-person interaction, collaboration, connection, creativity and flexibility:
For most teams, this means coming into the office two days per week.
Employees living more than 50 miles from an office location, out of state employees, and employees in certain member-facing roles should work with their manager to determine in-office time based on business need.
For employees with medical conditions that may impact their ability to work in-office, we are committed to engaging in an interactive process and providing reasonable accommodations to ensure their work environment is conducive to their success and well-being.
The Company reserves the right to require more presence in the office based on business needs, and requirements are subject to change with periodic reviews.
Physical Requirements:
Office Environment - roles involving part to full time schedule in Office Environment. Based in our physical offices and work from home office/deskwork - Activity level: Sedentary, frequency most of work day.
Equal Employment Opportunity:
External hires must pass a background check/drug screen. Qualified applicants with arrest records and/or conviction records will be considered for employment in a manner consistent with Federal, State and local laws, including but not limited to the San Francisco Fair Chance Ordinance. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, national origin, sexual orientation, gender identity, protected veteran status or disability status and any other classification protected by Federal, State and local laws.
See All 25 Security Consultant Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Security Consultant JobsSecurity Consultant Jobs by City in California
Where California roles are concentrated, by current openings.
Security Consultant Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Technology & Software
What California Employers Look For
The qualifications that appear most often in security consultant jobs across California.
- Active BSIS (Bureau of Security and Investigative Services) licensure or exemption recognized in California
- Bachelor's degree in cybersecurity, criminal justice, information systems, or a related field
- Certified Protection Professional (CPP) or Certified Information Systems Security Professional (CISSP) credential
- Demonstrated experience designing or assessing security programs for enterprise or government clients
- Familiarity with California privacy law requirements, including CCPA compliance frameworks
- Strong written communication skills for delivering risk assessments and executive-level reports
Security Consultant Jobs in California: Frequently Asked Questions
How do you become a security consultant in California?
Most California security consultants enter the field through a combination of a relevant bachelor's degree and a recognized professional credential. For roles involving physical security services, the California Bureau of Security and Investigative Services (BSIS) regulates licensing, and many employers require consultants to hold or be eligible for a BSIS Private Patrol Operator or Qualified Manager registration. Cybersecurity-focused roles typically prioritize credentials such as CISSP, CISM, or CompTIA Security+ alongside practical experience.
How much do security consultants make in California?
Security consultants in California earn a median of about $87,570 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $46,410 for the lowest 10% to over $169,160 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire security consultants in California?
Employers hiring security consultants in California right now include Everon, Google, and Deloitte, based on current listings on Migrate Mate as of October 2026. California's concentration of defense contractors, major financial institutions, and large technology firms creates particularly steady demand across both physical and cyber security consulting disciplines.
Which California cities have the most security consultant jobs?
San Francisco, Irvine, and Orange have the most security consultant openings in California. Los Angeles and San Francisco anchor the market through their density of corporate headquarters, financial services firms, and technology companies, while San Diego draws significant demand from the large defense and government contracting community based around its military installations and research institutions.
Are there remote security consultant jobs in California?
Yes, and more than many comparable roles. About 100% of security consultant openings tied to California are remote or hybrid as of October 2026, reflecting how much of the work involves policy development, risk analysis, and report writing that can be done off-site. Roles centered on physical site assessments or hands-on infrastructure reviews are more likely to require in-person presence.
How can I get hired as a security consultant in California with little or no experience?
The most realistic entry path is through a security analyst or junior risk analyst role at a large California employer, then moving into consulting once you have documented project experience. Major consulting firms with California offices, including those supporting the Bay Area tech sector and Los Angeles financial services market, run rotational analyst programs for recent graduates. Earning an entry-level credential such as CompTIA Security+ or completing a BSIS-approved training program strengthens applications, and internships with government contractors in San Diego or Sacramento can substitute for commercial experience.
Where can I find and apply to security consultant jobs in California?
You can find and apply to security consultant jobs in California on Migrate Mate, which lists current California openings across industries and experience levels. Find roles that fit your background and apply directly from each listing.
See All 25 Security Consultant Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Security Consultant Jobs