Haystack
← Back to Jobs
Administrative
JG

Network Security Risk & Compliance Analyst

Judge Group, Inc.Newport Beach, CA🇺🇸United StatesPosted Sep 18, 2026

Quick Overview

Salary
$58 - $62/hr
Seniority
Mid Senior
Work mode
Hybrid
Location
Newport Beach, CA, United States
Posted
Yesterday
Stakeholder Management

Job Description

Location: Newport Beach, CA Salary: $58.00 USD Hourly - $62.00 USD Hourly Description: Our client is currently seeking a Network Security Risk & Compliance Analyst
Network Security Risk & Compliance Analyst
Location: Newport Beach, CA (4 days onsite and 1 day remote)
Duration: 6+ Months (Contract-to-hire)
About the job
The Network Security Risk & Compliance Analyst serves as the primary liaison between Network Security, Cyber Risk, Operational Risk & Resilience (OR&R), Audit, Vulnerability Management, and Security Operations teams. This role is responsible for driving the maturity, effectiveness, and compliance of the Network Security program through control assessments, risk management, vulnerability remediation oversight, incident response coordination, and security assurance activities.
Note: This is not a traditional SOC analyst or firewall administration role. Success in this position requires experience with cybersecurity governance, control assurance, risk management, vulnerability remediation, incident response coordination, and cross-functional security program leadership.
The ideal candidate possesses a blend of cybersecurity governance, risk management, compliance, vulnerability management, incident response, and network security experience, with the ability to influence outcomes across technical and business stakeholders.
Responsibilities
Governance, Risk & Control Assurance
  • Act as the Network Security representative for OR&R, Cyber Risk, Audit, and Compliance activities.
  • Support assessments and ongoing effectiveness reviews of Network Security controls within the Enterprise Control Model.
  • Coordinate evidence collection, remediation activities, issue tracking, and risk treatment plans.
  • Identify control gaps and partner with engineering and operations teams to drive corrective actions.

Vulnerability & Security Assessment Management
  • Coordinate remediation activities for vulnerabilities impacting network security platforms and services.
  • Partner with Vulnerability Management teams to ensure timely mitigation of critical and high-risk findings.
  • Support internal and external penetration testing activities and drive remediation efforts resulting from assessment findings.
  • Track risk exceptions and remediation commitments through closure.

Incident Response & Operational Resilience
  • Participate in network security-related incident response and post-incident review activities.
  • Coordinate Network Security participation in tabletop exercises, cyber resilience testing, and maturity assessments.
  • Identify opportunities to improve operational readiness, security posture, and control effectiveness.

Risk Reporting & Program Maturity
  • Participate in quarterly Key Risk Indicator (KRI) reviews and risk governance forums.
  • Develop reporting and metrics related to control effectiveness, vulnerabilities, risk posture, and remediation progress.
  • Identify and implement automation opportunities across security workflows to improve efficiency and response times.
  • Support continuous improvement initiatives aligned to NIST Cybersecurity Framework (CSF) and CIS Controls.

Minimum Qualifications and Experience
  • 5+ years of experience in Cybersecurity, Risk Management, Governance & Compliance, Security Operations, or Network Security.
  • Experience supporting audits, risk assessments, control testing, or compliance programs.
  • Experience working with vulnerability management, penetration testing, incident response, or security assurance programs.
  • Strong understanding of cybersecurity risk management and control frameworks.
  • Excellent communication and stakeholder management skills.
  • Ability to drive remediation efforts across multiple teams and technical disciplines.
  • Knowledge of enterprise network security technologies including firewalls, web application firewalls, proxies, remote access, and Zero Trust solutions.

Preferred Qualifications
  • NIST Cybersecurity Framework (CSF), CIS Critical Security Controls
  • Cybersecurity Governance, Risk & Compliance (GRC)
  • Control effectiveness assessment and evidence management
  • Vulnerability management and remediation programs
  • Incident response and operational resilience.

Preferred Certifications
  • GSEC, CISSP, CRISC, CISA, CGRC

What Success Looks Like
  • Serves as the trusted Network Security partner for OR&R, Cyber Risk, Audit, and Vulnerability Management teams.
  • Drives successful completion of control assessments and remediation activities.
  • Improves visibility into network security risk, compliance, and control effectiveness.
  • Advances Network Security program maturity through measurable improvements in governance, resilience, and risk management.

Medical, dental, and vision insurance are available to qualified candidates who meet eligibility requirements.
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact:
This job and many more are available through The Judge Group. Please apply with us today!

Similar jobs