Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Compliance Analyst

City of Santa Fe Springs

Position Summary Metro is dedicated to shaping a better future for the greater Portland region. The Information Security Team is looking for an Information Security Compliance Analyst. This role serves as the primary support function to the CISO for Metro's information security governance, risk, and compliance (GRC) function, operationalizing and maturing the program on the CISO’s behalf while ensuring alignment with applicable federal, state, and local regulations, including privacy, data protection, breach notification, and public records requirements. Acting as a control owner delegate, this role ensures controls are properly defined, enforced, auditable, and aligned to business and regulatory requirements, with a clearly bounded (~30%) operational support component focused on control validation, audit readiness, and compliance alignment rather than primary ownership of security operations. Responsibilities Serve as the CISO’s operational extension for compliance and governance, translating security strategy into actionable policies, controls, and procedures, and preparing materials for executive reporting, audits, and regulatory reviews. Develop, maintain, and manage the full lifecycle of information security policies and standards, mapping them to applicable frameworks and coordinating periodic reviews with stakeholders across IT and business units. Act as control owner delegate for NIST CSF, CIS Controls, and PCI DSS, leading framework alignment, gap analysis, and PCI compliance activities including CDE scoping, evidence collection, and QSA coordination. Lead governance of the vulnerability management program, including policy definition, SLA tracking, compliance reporting, and risk acceptance decisions, partnering with the Cybersecurity Analyst as execution lead. Conduct compliance reviews of software and technology assets, maintain accurate asset inventories, and support third‑party/vendor security reviews to ensure audit readiness. Maintain and administer the enterprise risk register, support internal and external audits, and develop compliance metrics and dashboards to communicate risk and control effectiveness to leadership. Support incident response through documentation, evidence collection, and regulatory notification requirements, including secondary, after‑hours backup support for high‑severity security alerts in coordination with the Cybersecurity Analyst and SOC/MSSP providers. Collaborate with IT Operations, Infrastructure, and Application Teams to integrate security controls into operational processes, and assist in administering security tools (EDR, SIEM, email security, identity platforms) in support of compliance objectives. Contribute to system hardening and secure configuration baselines aligned with CIS Benchmarks, assist with IAM best practices, and coordinate security awareness and training initiatives. Develop and mature data classification, handling, and protection standards (including DLP and retention policies), support privacy impact assessments, and help mature Metro’s cybersecurity program through process improvement and continuous alignment with evolving threats and best practices. Attributes for Success Strong working knowledge of security and compliance frameworks (NIST CSF, CIS Controls, PCI DSS) with the ability to translate framework requirements into practical, auditable controls. Detail‑oriented and highly organized, with the discipline to manage policy lifecycles, evidence packages, and audit documentation accurately and on schedule. Comfortable operating independently while working under general direction from the CISO, exercising sound judgment on when to elevate versus resolve. Strong written communication skills, able to translate technical security concepts into clear policies, procedures, and executive‑ready reporting. Collaborative mindset with the ability to build effective working relationships across IT Operations, Infrastructure, Applications, and business stakeholders who don’t report to this role. Analytical and risk‑aware, able to assess control gaps, prioritize remediation efforts, and support risk acceptance discussions with sound reasoning. Comfortable with ambiguity and program building, given that governance structures, processes, and tooling are still actively being developed and refined. Basic technical fluency with security tools (SIEM, EDR, identity platforms) sufficient to support compliance monitoring without requiring deep engineering expertise. Reliable and responsive when serving as secondary, after‑hours backup for high‑severity alerts, with good judgment about when situations require escalation versus documentation. Genuine interest in continuous learning and staying current on evolving regulatory requirements, threats, and industry best practices in a public‑sector context. Minimum Qualifications 4–6 years of progressive experience in information technology, including at least 3–5 years in information security, IT security, or a compliance‑focused role. A bachelor’s degree in Cybersecurity, Information Technology, or a related field, or an equivalent combination of education, professional, volunteer, and lived experience that provides the necessary knowledge, skills, and abilities. Preferred Qualifications Experience in public sector or government environments. Relevant certifications such as CISA, CRISC (preferred for governance and risk), PCIP or equivalent PCI‑related certification (strongly preferred), Security+, SSCP, or GSEC (foundational, optional). Direct experience with PCI DSS compliance programs, including CDE scoping, SAQ, or ROC processes. Experience supporting cloud security compliance and governance activities in Azure, AWS, or similar environments (e.g., control mapping, configuration review, audit support). Familiarity with privacy considerations, data protection principles, and applicable Oregon state requirements. Experience with vendor risk management, third‑party assessments, or software asset compliance reviews. Familiarity with GRC tools or platforms used for risk management, control tracking, and audit management (e.g., ServiceNow GRC, Archer, or similar). Experience working with or overseeing third‑party security providers (e.g., MSSP/SOC) in a compliance or audit capacity. Hybrid Telework This position is designated as “hybrid telework.” You will be required to work onsite and, at times, have the option to work away from your assigned work location. The specific schedule and balance of onsite and telework will be discussed with the hiring manager at the time of offer. Employees must reside in Oregon or Washington to work at Metro. Please note that the designation of hybrid telework may be subject to change. Compensation and Benefits The full‑salary range for this position is step 1: $94,106.41 to step 7: $126,142.16. The appointment will likely be made between step 1: $94,106.41 and the equity range step 4: $108,947.96, in accordance with the Oregon Pay Equity Act requirements and Metro’s internal equity review process. Medical, dental and vision health insurance Paid sick leave Paid vacation, holiday, and other leave Paid parental leave Full contribution to Oregon PERS retirement No‑cost TriMet Hop Pass Employee Assistance Program Training opportunities Flexible schedules depending on position and department Equal Employment Opportunity All qualified persons will be considered for employment without regard to race, color, religion, sex, national origin, age, marital status, familial status, gender identity and expression, sexual orientation, disability for which a reasonable accommodation can be made, or any other status protected by law. Metro is committed to equal employment opportunity and complies with all applicable federal, state, and local civil rights laws. Metro employment decisions – including recruitment, screening, interviewing, selection, promotion, compensation, and separation – must not discriminate based on race, color, national origin, ethnicity, religion, sex, sexual orientation, gender identity, disability, age, veteran status, or any other protected class. Metro will gladly provide a reasonable accommodation to anyone whose specific disability prevents them from completing this application or participating in this recruitment process. Please contact the recruiter outlined in the job announcement in advance to request assistance. Under Oregon Law, qualified veterans may be eligible for veterans’ preference when applying for Metro positions. If you are a veteran and would like to be considered for veterans’ preference for this job, please provide qualifying documents as instructed during the application process. Contact: Carrie Gundermann – View email address on click.appcast.io #J-18808-Ljbffr City of Santa Fe Springs

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Information Security Compliance Analyst in Portland, OR vacancy
  • $100k - $150k

    Job Description The Senior Information Security Compliance Analyst is a key member of the SRO Compliance & Portfolio Management team, responsible for ensuring the organization maintains compliance with applicable regulatory, statutory, and contractual requirements, as well... 
    Suggested
    Work experience placement

    Motorola Solutions

    Portland, OR
    12 hours ago
  • Title: Senior Information Security Analyst Location: Beaverton, OR | Open to Remote, US Duration: 7 months contract WHO ARE WE LOOKING FOR?...  ...to information security policies and standards. Perform compliance control validation testing to determine the operating effectiveness... 
    Suggested
    Contract work
    Remote work

    NIKE

    Beaverton, OR
    3 days ago
  • Overview The Cyber Threat Analytics Analyst is responsible for identifying, developing, and improving...  ...malicious behavior, suspicious activity, and security anomalies across the enterprise. This role is part of the Information Security team focused on bringing detection... 
    Suggested
    Remote work
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Lam Research

    Tualatin, OR
    1 day ago
  • Nike is seeking a Senior Information Security Analyst located in Beaverton, OR, who will work with the Information Risk Management team within Corporate Information Security. The role focuses on assessing vendor risks and evaluating systems against security standards.... 
    Suggested
    Remote job

    Nike

    Beaverton, OR
    13 days ago
  • Senior Information Security & Cyber Risk Analyst (Compliance, CISSP, CISM, CBCP, CHPS, CISA, HIPPA, NIST CSF) in Vancouver, WA CHPS, CISA, CISM, CISSP, compliance, Cyber Risk, HIPAA, Information Security, NIST CSF, Security Frameworks Location: Washington Job Function... 
    Suggested
    Permanent employment
    Full time
    Remote work
    Relocation

    DBA Web Technologies

    Vancouver, WA
    more than 2 months ago
  • Mercury is seeking an IT Support Analyst based in New York to ensure the security and maintenance of employee systems. In this role, you will manage IT support tasks, oversee asset management, and collaborate with various teams to solve IT challenges. Ideal candidates... 
    Remote job

    Mercury

    Portland, OR
    12 hours ago
  • $60 - $65 per hour

    A leading technology consulting firm in Vancouver, WA, is seeking a Security Control Assessor to support compliance with cybersecurity standards. This full-time position requires a Bachelor's degree in a relevant field and a minimum of 6 years of related experience. Responsibilities... 
    Hourly pay
    Full time

    Azad Technology Partners

    Vancouver, WA
    15 days ago
  •  ...are also affordable and accessible to all. Staff Network Security Operations Analyst Work Schedule: Hybrid - 3 days in office / 2 days WFH On...  ...teams who rely on the platforms you manage. Compliance Support: Contribute to initiatives supporting NERC CIP regulatory... 
    Work at office
    Work from home
    Night shift

    Portland General Electric

    Tualatin, OR
    2 days ago
  • $33 - $39 per hour

    A leading consulting company is seeking an Operations Analyst to support their Personnel and Information Security organization. This role includes program analysis, project management, and onboarding support. The ideal candidate will have relevant experience, with a focus... 
    Hourly pay

    Azad Technology Partners

    Vancouver, WA
    3 days ago
  • $95k

     ...right things right. Our Senior Financial Analyst is a core member of a tight-knit FP&A...  ...& Engineering, Facilities, IT, & Information Security — leading budgeting and forecasting cycles...  ...global leader in integrated risk and compliance management software, trusted by more than... 

    NetClaim

    Lake Oswego, OR
    12 hours ago
  • Oregon Metro is seeking an Information Security Compliance Analyst to support the CISO in governance, risk, and compliance (GRC) activities. You will translate strategy into policies, manage policy lifecycle, and coordinate audits and regulatory reviews. Role requires knowledge... 
    Remote work

    Oregon Metro

    Portland, OR
    2 days ago
  • $93k - $140k

     ...a detail-oriented and highly organized Finance Controls and Compliance Analyst to join our team. In this role, you’ll support our SOX (Sarbanes...  ...protection and a 401K retirement plan, so that you can feel secure in your health and financial future. Unlimited Flextime and... 
    Local area

    Ampere Computing

    Portland, OR
    3 days ago
  • Metro in the Portland area seeks an Information Security Compliance Analyst to support the CISO's GRC program, translating strategy into auditable policies, controls, and procedures, and preparing materials for audits and regulatory reviews. You will lead framework alignment... 

    City of Santa Fe Springs

    Portland, OR
    2 days ago
  • $33.72 - $46.19 per hour

    Gresham-Barlow School District 10J in Gresham, Oregon, is seeking a qualified candidate for the position involving support for business and curriculum systems. The role includes overseeing data management, system operations, and providing extensive user support. Ideal candidates...
    Hourly pay
    Part time

    Gresham-Barlow School District

    Gresham, OR
    12 hours ago
  • $200k - $275k

     ...Director Of Information Security We are a renewable energy and ocean technology company committed to rapidly developing and deploying technologies that will ensure a sustainable future for Earth by unlocking the vast energy potential of its oceans. Our focus is on... 
    Full time
    Work at office
    Relocation package
    Flexible hours

    Panthalassa

    Portland, OR
    3 days ago
  • $172k - $250k

     ...Grant Thornton is seeking a Director of Information Security Audit & Compliance to join the team. Approved office locations can be found below. We are seeking a Director of Information Security Audit & Compliance to lead and scale a global audit and compliance practice... 
    Internship
    Seasonal work
    Work at office
    Local area
    Flexible hours
    3 days per week

    Grant Thornton

    Portland, OR
    4 days ago
  • $105.79k - $141.05k

     ...network and connected ecosystem. We enable secure, high‑performance connectivity across...  ...us today. The Role The Manager of Information Security—Cyber Threat Exposure Management...  ...backlog, mean time to remediate, SLA compliance, exception trends, asset coverage, and external... 
    Full time
    Temporary work
    Remote work

    Lumen

    Portland, OR
    3 days ago
  • Ampere Computing is seeking a Senior Director of Information Security to lead the information security function. This role will define and execute Ampere's security strategy, ensuring the protection of its critical assets while bridging IT and InfoSec. Successful candidates... 

    Ampere Computing

    Portland, OR
    12 hours ago
  • $150k - $170k

     ...seeking a highly accomplished and strategic Senior Manager, Information Security to join our team in Seattle, WA (Open to Portland, OR and...  ...Partner with cross-functional leaders (IT, Product, Legal, Compliance, and Operations) to embed security into business processes,... 
    Full time

    Stanley-1913

    Portland, OR
    2 days ago
  • $347k

    About the Role Ampere is seeking a Senior Director of Information Security to lead our information security function. This leader will define...  ...teams on security best practices where needed. Support compliance, customer assurance, and third‑party security activities related... 
    Local area
    Shift work

    Ampere

    Portland, OR
    12 hours ago
  •  ...and Border Protection and the Bureau of Industry and Security Export Administration Regulations. The role involves...  ...detail is required to troubleshoot and investigate information, resolve issues, and identify compliance risks. The Specialist will play a key role in process... 
    Temporary work
    Work at office
    Local area
    Remote work
    Worldwide

    Ichor Systems

    Portland, OR
    7 hours ago
  • $69.7k - $94.3k

     ...Overview Compliance Analyst I, II or III Hybrid role (3 days/week in office) at our Portland, Medford, Fargo, Burlington, Vancouver, Renton...  ...organizations work and how to get things done through formal and informal channels. Practical familiarity with legal requirements... 
    Work at office
    Immediate start
    Work from home
    Flexible hours
    3 days per week

    Cambia Health Solutions

    Vancouver, WA
    3 days ago
  •  ...A leading trade compliance consulting firm is seeking a professional to develop effective communication and conduct research on Customs regulations. The role involves preparing analysis reports, performing audits, and ensuring compliance with U.S. Customs. Candidates... 

    Tradewin

    Portland, OR
    3 days ago
  • $69.7k - $94.3k

     ...Position Overview Compliance Analyst (Levels I, II or III) – Hybrid role (3 days/week in office). Candidates must be able to commute to one of the following locations: Portland, Medford, Fargo, Burlington, Vancouver, Renton, Boise, Lewiston, or Salt Lake City. The role... 
    Work at office
    Remote work
    3 days per week

    Cambia Health Solutions

    Portland, OR
    4 days ago
  • $60k

     ...Compliance Analyst - Supervision This position uses independent judgement and discretion to ensure all Registered Representatives adhere...  ...for Supervision matters. What you'll do: Compile information related to office inspections and provide to inspectors.... 
    Work experience placement
    Summer work
    Work at office
    Flexible hours

    ACA Group

    Clackamas, OR
    1 day ago
  • $75k - $90k

     ...Northmarq was voted by Real Estate Forum as one of The Best Places to Work in Commercial Real Estate! Northmarq is seeking a Compliance Analyst to join the Legal & Compliance team at our Portland, OR office. This position plays a key role in supporting the company’s... 
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    NorthMarq

    Portland, OR
    12 hours ago
  •  ...ABOUT These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing on the information...  ...analyzing maritime activities that pose a threat to national security, such as drug smuggling, illegal immigration, arms transfers,... 
    Part time
    Worldwide

    U.S. Navy

    Portland, OR
    1 day ago
  •  ...assistance if necessary. Complete incident reports to document all Security/Loss Prevention related incidents. Handle all interruptions...  .../Loss Prevention and property reports/documents; release information only to authorized individuals. Conduct investigations and gather... 
    Work experience placement
    Worldwide
    Shift work

    Marriott International Inc

    Portland, OR
    1 day ago
  • $16.8 - $20.4 per hour

     ...flexible schedule to support business needs ~0-2 years retail or security experience Benefits include: Associate discount; EAP;...  ...from time to time. Contact your TJX representative for more information. In addition to our open door policy and supportive work... 
    Hourly pay
    Temporary work
    Local area
    Home office
    Flexible hours

    TJX

    Portland, OR
    7 days ago
  • $26 - $27 per hour

     ...Job Description - Overview Do you have EXPERIENCE IN RETAIL LOSS PREVENTION or SECURITY and want to work for a company that still believes in keeping a safe environment for staff and customers? JOIN OUR TEAM! The Loss Prevention Department for Hobby Lobby is... 
    Hourly pay
    Full time
    Local area
    Flexible hours

    Hobby Lobby

    Clackamas, OR
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Compliance Analyst. Be the first to apply!