Information Security Compliance Analyst
City of Santa Fe Springs
Position Summary Metro is dedicated to shaping a better future for the greater Portland region. The Information Security Team is looking for an Information Security Compliance Analyst. This role serves as the primary support function to the CISO for Metro's information security governance, risk, and compliance (GRC) function, operationalizing and maturing the program on the CISO’s behalf while ensuring alignment with applicable federal, state, and local regulations, including privacy, data protection, breach notification, and public records requirements. Acting as a control owner delegate, this role ensures controls are properly defined, enforced, auditable, and aligned to business and regulatory requirements, with a clearly bounded (~30%) operational support component focused on control validation, audit readiness, and compliance alignment rather than primary ownership of security operations. Responsibilities Serve as the CISO’s operational extension for compliance and governance, translating security strategy into actionable policies, controls, and procedures, and preparing materials for executive reporting, audits, and regulatory reviews. Develop, maintain, and manage the full lifecycle of information security policies and standards, mapping them to applicable frameworks and coordinating periodic reviews with stakeholders across IT and business units. Act as control owner delegate for NIST CSF, CIS Controls, and PCI DSS, leading framework alignment, gap analysis, and PCI compliance activities including CDE scoping, evidence collection, and QSA coordination. Lead governance of the vulnerability management program, including policy definition, SLA tracking, compliance reporting, and risk acceptance decisions, partnering with the Cybersecurity Analyst as execution lead. Conduct compliance reviews of software and technology assets, maintain accurate asset inventories, and support third‑party/vendor security reviews to ensure audit readiness. Maintain and administer the enterprise risk register, support internal and external audits, and develop compliance metrics and dashboards to communicate risk and control effectiveness to leadership. Support incident response through documentation, evidence collection, and regulatory notification requirements, including secondary, after‑hours backup support for high‑severity security alerts in coordination with the Cybersecurity Analyst and SOC/MSSP providers. Collaborate with IT Operations, Infrastructure, and Application Teams to integrate security controls into operational processes, and assist in administering security tools (EDR, SIEM, email security, identity platforms) in support of compliance objectives. Contribute to system hardening and secure configuration baselines aligned with CIS Benchmarks, assist with IAM best practices, and coordinate security awareness and training initiatives. Develop and mature data classification, handling, and protection standards (including DLP and retention policies), support privacy impact assessments, and help mature Metro’s cybersecurity program through process improvement and continuous alignment with evolving threats and best practices. Attributes for Success Strong working knowledge of security and compliance frameworks (NIST CSF, CIS Controls, PCI DSS) with the ability to translate framework requirements into practical, auditable controls. Detail‑oriented and highly organized, with the discipline to manage policy lifecycles, evidence packages, and audit documentation accurately and on schedule. Comfortable operating independently while working under general direction from the CISO, exercising sound judgment on when to elevate versus resolve. Strong written communication skills, able to translate technical security concepts into clear policies, procedures, and executive‑ready reporting. Collaborative mindset with the ability to build effective working relationships across IT Operations, Infrastructure, Applications, and business stakeholders who don’t report to this role. Analytical and risk‑aware, able to assess control gaps, prioritize remediation efforts, and support risk acceptance discussions with sound reasoning. Comfortable with ambiguity and program building, given that governance structures, processes, and tooling are still actively being developed and refined. Basic technical fluency with security tools (SIEM, EDR, identity platforms) sufficient to support compliance monitoring without requiring deep engineering expertise. Reliable and responsive when serving as secondary, after‑hours backup for high‑severity alerts, with good judgment about when situations require escalation versus documentation. Genuine interest in continuous learning and staying current on evolving regulatory requirements, threats, and industry best practices in a public‑sector context. Minimum Qualifications 4–6 years of progressive experience in information technology, including at least 3–5 years in information security, IT security, or a compliance‑focused role. A bachelor’s degree in Cybersecurity, Information Technology, or a related field, or an equivalent combination of education, professional, volunteer, and lived experience that provides the necessary knowledge, skills, and abilities. Preferred Qualifications Experience in public sector or government environments. Relevant certifications such as CISA, CRISC (preferred for governance and risk), PCIP or equivalent PCI‑related certification (strongly preferred), Security+, SSCP, or GSEC (foundational, optional). Direct experience with PCI DSS compliance programs, including CDE scoping, SAQ, or ROC processes. Experience supporting cloud security compliance and governance activities in Azure, AWS, or similar environments (e.g., control mapping, configuration review, audit support). Familiarity with privacy considerations, data protection principles, and applicable Oregon state requirements. Experience with vendor risk management, third‑party assessments, or software asset compliance reviews. Familiarity with GRC tools or platforms used for risk management, control tracking, and audit management (e.g., ServiceNow GRC, Archer, or similar). Experience working with or overseeing third‑party security providers (e.g., MSSP/SOC) in a compliance or audit capacity. Hybrid Telework This position is designated as “hybrid telework.” You will be required to work onsite and, at times, have the option to work away from your assigned work location. The specific schedule and balance of onsite and telework will be discussed with the hiring manager at the time of offer. Employees must reside in Oregon or Washington to work at Metro. Please note that the designation of hybrid telework may be subject to change. Compensation and Benefits The full‑salary range for this position is step 1: $94,106.41 to step 7: $126,142.16. The appointment will likely be made between step 1: $94,106.41 and the equity range step 4: $108,947.96, in accordance with the Oregon Pay Equity Act requirements and Metro’s internal equity review process. Medical, dental and vision health insurance Paid sick leave Paid vacation, holiday, and other leave Paid parental leave Full contribution to Oregon PERS retirement No‑cost TriMet Hop Pass Employee Assistance Program Training opportunities Flexible schedules depending on position and department Equal Employment Opportunity All qualified persons will be considered for employment without regard to race, color, religion, sex, national origin, age, marital status, familial status, gender identity and expression, sexual orientation, disability for which a reasonable accommodation can be made, or any other status protected by law. Metro is committed to equal employment opportunity and complies with all applicable federal, state, and local civil rights laws. Metro employment decisions – including recruitment, screening, interviewing, selection, promotion, compensation, and separation – must not discriminate based on race, color, national origin, ethnicity, religion, sex, sexual orientation, gender identity, disability, age, veteran status, or any other protected class. Metro will gladly provide a reasonable accommodation to anyone whose specific disability prevents them from completing this application or participating in this recruitment process. Please contact the recruiter outlined in the job announcement in advance to request assistance. Under Oregon Law, qualified veterans may be eligible for veterans’ preference when applying for Metro positions. If you are a veteran and would like to be considered for veterans’ preference for this job, please provide qualifying documents as instructed during the application process. Contact: Carrie Gundermann – View email address on click.appcast.io #J-18808-Ljbffr City of Santa Fe Springs
$100k - $150k
Job Description The Senior Information Security Compliance Analyst is a key member of the SRO Compliance & Portfolio Management team, responsible for ensuring the organization maintains compliance with applicable regulatory, statutory, and contractual requirements, as well...SuggestedWork experience placement- Title: Senior Information Security Analyst Location: Beaverton, OR | Open to Remote, US Duration: 7 months contract WHO ARE WE LOOKING FOR?... ...to information security policies and standards. Perform compliance control validation testing to determine the operating effectiveness...SuggestedContract workRemote work
- Overview The Cyber Threat Analytics Analyst is responsible for identifying, developing, and improving... ...malicious behavior, suspicious activity, and security anomalies across the enterprise. This role is part of the Information Security team focused on bringing detection...SuggestedRemote workFlexible hours2 days per week3 days per week1 day per week
- Nike is seeking a Senior Information Security Analyst located in Beaverton, OR, who will work with the Information Risk Management team within Corporate Information Security. The role focuses on assessing vendor risks and evaluating systems against security standards....SuggestedRemote job
- Senior Information Security & Cyber Risk Analyst (Compliance, CISSP, CISM, CBCP, CHPS, CISA, HIPPA, NIST CSF) in Vancouver, WA CHPS, CISA, CISM, CISSP, compliance, Cyber Risk, HIPAA, Information Security, NIST CSF, Security Frameworks Location: Washington Job Function...SuggestedPermanent employmentFull timeRemote workRelocation
- Mercury is seeking an IT Support Analyst based in New York to ensure the security and maintenance of employee systems. In this role, you will manage IT support tasks, oversee asset management, and collaborate with various teams to solve IT challenges. Ideal candidates...Remote job
$60 - $65 per hour
A leading technology consulting firm in Vancouver, WA, is seeking a Security Control Assessor to support compliance with cybersecurity standards. This full-time position requires a Bachelor's degree in a relevant field and a minimum of 6 years of related experience. Responsibilities...Hourly payFull time- ...are also affordable and accessible to all. Staff Network Security Operations Analyst Work Schedule: Hybrid - 3 days in office / 2 days WFH On... ...teams who rely on the platforms you manage. Compliance Support: Contribute to initiatives supporting NERC CIP regulatory...Work at officeWork from homeNight shift
$33 - $39 per hour
A leading consulting company is seeking an Operations Analyst to support their Personnel and Information Security organization. This role includes program analysis, project management, and onboarding support. The ideal candidate will have relevant experience, with a focus...Hourly pay$95k
...right things right. Our Senior Financial Analyst is a core member of a tight-knit FP&A... ...& Engineering, Facilities, IT, & Information Security — leading budgeting and forecasting cycles... ...global leader in integrated risk and compliance management software, trusted by more than...- Oregon Metro is seeking an Information Security Compliance Analyst to support the CISO in governance, risk, and compliance (GRC) activities. You will translate strategy into policies, manage policy lifecycle, and coordinate audits and regulatory reviews. Role requires knowledge...Remote work
$93k - $140k
...a detail-oriented and highly organized Finance Controls and Compliance Analyst to join our team. In this role, you’ll support our SOX (Sarbanes... ...protection and a 401K retirement plan, so that you can feel secure in your health and financial future. Unlimited Flextime and...Local area- Metro in the Portland area seeks an Information Security Compliance Analyst to support the CISO's GRC program, translating strategy into auditable policies, controls, and procedures, and preparing materials for audits and regulatory reviews. You will lead framework alignment...
$33.72 - $46.19 per hour
Gresham-Barlow School District 10J in Gresham, Oregon, is seeking a qualified candidate for the position involving support for business and curriculum systems. The role includes overseeing data management, system operations, and providing extensive user support. Ideal candidates...Hourly payPart time$200k - $275k
...Director Of Information Security We are a renewable energy and ocean technology company committed to rapidly developing and deploying technologies that will ensure a sustainable future for Earth by unlocking the vast energy potential of its oceans. Our focus is on...Full timeWork at officeRelocation packageFlexible hours$172k - $250k
...Grant Thornton is seeking a Director of Information Security Audit & Compliance to join the team. Approved office locations can be found below. We are seeking a Director of Information Security Audit & Compliance to lead and scale a global audit and compliance practice...InternshipSeasonal workWork at officeLocal areaFlexible hours3 days per week$105.79k - $141.05k
...network and connected ecosystem. We enable secure, high‑performance connectivity across... ...us today. The Role The Manager of Information Security—Cyber Threat Exposure Management... ...backlog, mean time to remediate, SLA compliance, exception trends, asset coverage, and external...Full timeTemporary workRemote work- Ampere Computing is seeking a Senior Director of Information Security to lead the information security function. This role will define and execute Ampere's security strategy, ensuring the protection of its critical assets while bridging IT and InfoSec. Successful candidates...
$150k - $170k
...seeking a highly accomplished and strategic Senior Manager, Information Security to join our team in Seattle, WA (Open to Portland, OR and... ...Partner with cross-functional leaders (IT, Product, Legal, Compliance, and Operations) to embed security into business processes,...Full time$347k
About the Role Ampere is seeking a Senior Director of Information Security to lead our information security function. This leader will define... ...teams on security best practices where needed. Support compliance, customer assurance, and third‑party security activities related...Local areaShift work- ...and Border Protection and the Bureau of Industry and Security Export Administration Regulations. The role involves... ...detail is required to troubleshoot and investigate information, resolve issues, and identify compliance risks. The Specialist will play a key role in process...Temporary workWork at officeLocal areaRemote workWorldwide
$69.7k - $94.3k
...Overview Compliance Analyst I, II or III Hybrid role (3 days/week in office) at our Portland, Medford, Fargo, Burlington, Vancouver, Renton... ...organizations work and how to get things done through formal and informal channels. Practical familiarity with legal requirements...Work at officeImmediate startWork from homeFlexible hours3 days per week- ...A leading trade compliance consulting firm is seeking a professional to develop effective communication and conduct research on Customs regulations. The role involves preparing analysis reports, performing audits, and ensuring compliance with U.S. Customs. Candidates...
$69.7k - $94.3k
...Position Overview Compliance Analyst (Levels I, II or III) – Hybrid role (3 days/week in office). Candidates must be able to commute to one of the following locations: Portland, Medford, Fargo, Burlington, Vancouver, Renton, Boise, Lewiston, or Salt Lake City. The role...Work at officeRemote work3 days per week$60k
...Compliance Analyst - Supervision This position uses independent judgement and discretion to ensure all Registered Representatives adhere... ...for Supervision matters. What you'll do: Compile information related to office inspections and provide to inspectors....Work experience placementSummer workWork at officeFlexible hours$75k - $90k
...Northmarq was voted by Real Estate Forum as one of The Best Places to Work in Commercial Real Estate! Northmarq is seeking a Compliance Analyst to join the Legal & Compliance team at our Portland, OR office. This position plays a key role in supporting the company’s...Work experience placementWork at officeRemote workFlexible hours- ...ABOUT These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing on the information... ...analyzing maritime activities that pose a threat to national security, such as drug smuggling, illegal immigration, arms transfers,...Part timeWorldwide
- ...assistance if necessary. Complete incident reports to document all Security/Loss Prevention related incidents. Handle all interruptions... .../Loss Prevention and property reports/documents; release information only to authorized individuals. Conduct investigations and gather...Work experience placementWorldwideShift work
$16.8 - $20.4 per hour
...flexible schedule to support business needs ~0-2 years retail or security experience Benefits include: Associate discount; EAP;... ...from time to time. Contact your TJX representative for more information. In addition to our open door policy and supportive work...Hourly payTemporary workLocal areaHome officeFlexible hours$26 - $27 per hour
...Job Description - Overview Do you have EXPERIENCE IN RETAIL LOSS PREVENTION or SECURITY and want to work for a company that still believes in keeping a safe environment for staff and customers? JOIN OUR TEAM! The Loss Prevention Department for Hobby Lobby is...Hourly payFull timeLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Compliance Analyst. Be the first to apply!
- data solutions analyst Portland, OR
- entry level data analyst no experience Portland, OR
- data analyst - r python sql Portland, OR
- data integrity analyst Portland, OR
- data analyst supply chain analytics Portland, OR
- data analyst part time work from home Portland, OR
- senior data governance analyst Portland, OR
- senior data management analyst Portland, OR
- data analyst bank Portland, OR
- remote data analyst intern Portland, OR


