Cybersecurity Analyst
City of Santa Fe Springs
Position Summary Hello, we’re Metro! Metro is dedicated to shaping a better future for the greater Portland region. The work the people of Metro do every day benefits the lives of the people who live here, today, and tomorrow. The Information Security Team is looking for a Senior Cybersecurity Analyst to lead technical security operations, detection engineering, and incident response for Metro, protecting the systems, data, and services that people across the greater Portland region rely on every day. The Senior Cybersecurity Analyst is the primary technical lead for Metro's security operations, detection engineering, and technical control execution, leading hands‑on threat detection, incident response, and continuous improvement of Metro's security posture across endpoint, identity, cloud, and network environments. This role serves as a senior technical control operator for compliance frameworks (NIST CSF, CIS Controls, PCI DSS) in partnership with the Information Security Compliance Analyst, who leads control definition and governance, and acts as the technical incident lead during security events, with formal incident declaration owned by the CISO. As Metro's Information Security program matures, this position offers a clear growth path toward a future Principal Cybersecurity Analyst role with broader ownership of security architecture, detection strategy, and technical risk leadership. As the Senior Cybersecurity Analyst you will Serve as the CISO's primary technical lead for security operations, leading alert review, validation, escalation, and coordinated response for security events across Metro's environment. Act as technical incident lead during security events, coordinating containment, eradication, recovery, and post‑incident follow‑up in partnership with the CISO, IT teams, and SOC/MSSP providers. Develop, tune, and optimize detection content across SIEM, EDR, identity, cloud, and network security tools, incorporating threat intelligence and MITRE ATT&CK techniques. Operate and improve vulnerability management processes, providing risk‑based prioritization and partnering with the Compliance Analyst on remediation tracking and risk acceptance documentation. Implement, configure, and monitor technical safeguards under NIST CSF, CIS Controls, and PCI DSS, generating evidence to support compliance validation and audit activities. Own technical security review and ongoing oversight of third‑party services, SaaS platforms, and vendor integrations, evaluating authentication, data flows, and integration risk. Monitor Metro's identity security posture, tune identity threat detection tooling, and investigate identity‑based threats such as credential theft and lateral movement. Maintain secure configuration baselines using CIS Benchmarks, administer Metro's EDR platform, and participate in security architecture and design reviews for cloud and infrastructure changes. Implement and operate data protection controls (DLP, data monitoring, and audit capabilities), investigating alerts and partnering with the Compliance Analyst to align technical enforcement with policy intent. Contribute technical content to security standards and training materials, and identify opportunities to improve detection quality, control effectiveness, and operational efficiency. Attributes for success Technically curious with a strong drive to learn, improve, and expand security capabilities across endpoint, identity, cloud, and network domains. Detail‑oriented with strong analytical skills and a disciplined approach to detection engineering, evidence collection, and documentation. Comfortable leading technical incident response under pressure, exercising sound judgment about when to elevate versus resolve. Strong working knowledge of security frameworks (NIST CSF, CIS Controls, PCI DSS) with the ability to translate requirements into practical technical controls. Collaborative mindset with the ability to partner effectively with the Compliance Analyst, IT Infrastructure, Applications teams, Metro departments and business partners, and third‑party SOC/MSSP providers. Able to work independently on assigned technical priorities while communicating clearly with both technical and non‑technical stakeholders. Comfortable with ambiguity and program‑building, given that tooling, processes, and governance structures are still actively maturing. Reliable and responsive as a technical escalation point for high‑severity or time‑sensitive security events. Growth‑oriented, with the interest and capability to progress toward broader ownership of security architecture, detection strategy, and technical risk leadership. Genuine interest in continuous learning and staying current on evolving threats, tooling, and best practices in a public‑sector context. DIVERSITY AND INCLUSION At Metro, we strive to cultivate diversity, advance equity, and practice inclusion in all of its work. This means attracting and empowering a workforce that is inclusive of a broad range of human qualities. Workplace diversity is both a moral imperative and a business strength, essential to providing quality support and services to our region. Metro’s goal is to hire, develop and retain highly skilled and talented individuals across all departments and programs who best reflect the diversity of our community. TO QUALIFY We will consider any combination of relevant work experience, volunteering, education, and transferable skills as qualifying unless an item or section is labeled required. Please be clear and specific in your application materials on how your background is relevant. Minimum Qualifications 4-6 years of related professional experience in cybersecurity, security operations, detection engineering, incident response, vulnerability management, identity and access management, network security, cloud security, or a related technical field. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education, certification, and related professional experience. Any combination of education, professional, volunteer and lived experience that provides the necessary knowledge, skills, and abilities to perform the classification duties and responsibilities. If this statement is true for you, then you may be ineligible to apply If you were terminated for cause during any employment with Metro, or resigned in lieu of termination, you may be ineligible for rehire for a minimum of 3 years. Hybrid Telework This position is designated as “hybrid telework.” You will be required to work onsite and at times have the option to work away from your assigned work location. The specific schedule and balance of onsite and telework will be discussed with the hiring manager at the time of offer. This position also requires off‑hours response to security events, incidents, or urgent operational needs, which may include remote response and onsite response when necessary. Employees must reside in Oregon or Washington to work at Metro. Please note, the designation of hybrid telework may be subject to change at a future time. Like To Have Qualifications You do not need to have the following preferred qualifications/transferable skills to qualify. However, keep in mind we may consider them when identifying the most qualified candidates. Your transferable skills are any skills you have gained through education, work experience, including the military, or life experience that are relevant for this position. Demonstrated experience with technical control implementation, endpoint protection, identity security, network security, cloud security, logging, monitoring, or compliance‑related safeguards. Working knowledge of cybersecurity frameworks and control practices, including NIST CSF, CIS Controls, PCI DSS, or similar risk‑based security frameworks. Strong written and verbal communication skills, including the ability to document findings, procedures, and technical recommendations for both technical and non‑technical audiences. 6 or more years of progressively responsible cybersecurity or closely related technical experience, including senior‑level ownership of security operations, detection engineering, incident response, or enterprise security controls. Demonstrated ability to grow into principal‑level responsibility for security architecture, detection strategy, and technical risk leadership. Experience in public sector, local government, or critical infrastructure security environments. Hands‑on experience with CrowdStrike Falcon modules (EDR, NG‑SIEM, Identity Protection, or Exposure Management). Familiarity with Palo Alto Networks firewall administration or network security monitoring. Experience with Microsoft Entra ID, Active Directory, or cloud identity and access management in AWS or GCP environments. Familiarity with the MITRE ATT&CK framework and its application to detection and threat hunting. Preferred certification: CISSP. Other relevant certifications may include: Security+, CySA+, SSCP, GSEC GCIA, GCIH, or CEH SCREENING AND EVALUATION The application packet: The application packet consists of the following required documents. Please ensure that you upload these documents in your online application. Make sure your application is complete, missing any part of these items could result in an incomplete application and will not be moved forward in the recruitment. A completed online application Responses to supplemental questions The selection process: Initial review of minimum qualifications In‑depth evaluation of application materials to identify the most qualified candidates Consideration of top candidates/interviews Testing/assessments Reference check Background records check Compensation, Benefits And Representation The full‑salary range for this position is step 1: $94,106.41 to step 7: $126,142.16. However, unless a candidate’s qualifications justify, based on the Oregon Pay Equity Act requirements and Metro’s internal equity review process, the appointment will likely be made between step 1: $94,106.41 to the equity range step 4: $108,947.96. This position is not eligible for overtime and represented by AFSCME 3580 union. It is classified as a Systems Administrator III position. Classification descriptions are typically written broadly and do not include the specific duties and responsibilities of the positions. View the classification description. Additional Information Equal employment opportunity All qualified persons will be considered for employment without regard to race, color, religion, sex, national origin, age, marital status, familial status, gender identity and expression, sexual orientation, disability for which a reasonable accommodation can be made, or any other status protected by law. Non-discrimination?in hiring decisions Metro is committed to equal employment?opportunity?and?complies with?all applicable federal, state, and local civil rights laws. Metro employment decisions – including recruitment, screening, interviewing, selection, promotion, compensation, and separation – must not discriminate based on race, color, national origin, ethnicity, religion, sex, sexual orientation, gender identity, disability, age, veteran status, or any other protected class.?? Accommodation Metro will gladly provide a reasonable accommodation to anyone whose specific disability prevents them from completing this application or participating in this recruitment process. Please contact the recruiter outlined in the job announcement in advance to request assistance. Veterans' preference Under Oregon Law, qualified veterans may be eligible for veterans' preference when applying for Metro positions. If you are a veteran and would like to be considered for a veterans' preference for this job, please provide qualifying documents as instructed during the application process. Hybrid Telework This position is designated as “hybrid telework.” You will be required to work onsite and at times have the option to work away from your assigned work location. The specific schedule and balance of onsite and telework will be discussed with the hiring manager at the time of offer. This position also requires off‑hours response to security events, incidents, or urgent operational needs, which may include remote response and onsite response when necessary. Employees must reside in Oregon or Washington to work at Metro. Please note, the designation of hybrid telework may be subject to change at a future time. Pay equity at Metro No matter who you are or where you work at Metro, you deserve to be paid fairly for the work you do. Every worker must get equal pay for equal work regardless of your gender, race, age, or other protected characteristics. Metro has established processes and conducts routine pay equity reviews as part of the hiring process to ensure compliance with the 2017 Oregon Pay Equity Act. Online applications Metro accepts job applications online. If you need assistance or accommodation with your application, or access to a computer, please contact the recruiter outlined in the job announcement in advance to request assistance. Metro Led by an elected council, this unique government gives all residents of greater Portland a voice in shaping the future and provides parks, venues, services, and tools at a regional scale. We find solutions for our area’s garbage and recycling that protect clean air and water; help plan land use and development to provide jobs and safe transportation; manage local venues that provide a connection to arts and culture and help keep the economy growing; protect 17,000 acres of parks and natural areas, and run the Oregon Zoo, to keep nature close to home. As part of the Metro family, you play a vital role in serving the people of the greater Portland region. Family members, including eligible spouses, domestic partners, and children, are covered under most of our benefits programs. Benefits vary depending on position and full‑time, part‑time, and variable hour status. This is a budgeted, regular status position with a full‑time schedule. The position is eligible for these benefits: Medical, dental and vision health insurance Paid sick leave Paid vacation, holiday, and other leave Paid parental leave Full contribution to Oregon PERS retirement No-cost TriMet Hop Pass Employee Assistance Program Training opportunities Flexible schedules depending on position and department Hybrid/Telework living in Oregon /Washington depending on position and department Metro also offers a variety of perks for all employees, including free admission to the Oregon Zoo (including ZooLights!), Oxbow and Blue Lake Regional Parks, membership discount at Lloyd Athletic Club, credit union eligibility and more. Employees also receive access to financial wellness and legal consultation services, as well as first‑time home buying and ownership counseling. Benefits Learn more about employee benefits. Some positions are represented by a union and have additional benefits. View union contracts here. 01 Describe your experience supporting or responding to a cybersecurity incident. What was your role, what actions did you take, how did you coordinate with others, and what was the outcome or lesson learned? 02 Describe your experience with security monitoring and detection improvement. Include examples of tuning detections, improving alert quality, or working with tools such as EDR, SIEM, identity, cloud, or network security platforms. 03 Describe your approach to vulnerability management. How do you assess risk, prioritize remediation, communicate findings, and track follow‑through? 04 Describe your experience implementing, supporting, or assessing technical security controls. You may reference frameworks such as NIST CSF, CIS Controls, PCI DSS, or similar standards if applicable. 05 Provide an example of how you have communicated technical security risks, recommendations, or tradeoffs to non‑technical partners or leadership. 06 Metro requires employees to reside in Oregon or Washington. This position also requires off‑hours response to security events, incidents, or urgent operational needs, which may include remote or onsite response when necessary. By checking "Yes" below you are acknowledging that you understand this role requires off hours and remote responses when necessary. Yes Required Question #J-18808-Ljbffr
- ...benefits the lives of the people who live here, today, and tomorrow. The Information Security Team is looking for a Senior Cybersecurity Analyst to lead technical security operations, detection engineering, and incident response for Metro, protecting the systems, data,...SuggestedWork experience placementLocal areaRemote work
$82.6k - $162.8k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions...SuggestedLocal areaVisa sponsorship$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions...SuggestedLocal area$82.6k - $162.8k
Position Summary Join our Deloitte Cyber team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience...SuggestedLocal areaVisa sponsorship$155.6k - $306.8k
...a changing threat landscape.QualificationsRequired:Bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field; alternatively, equivalent demonstrated experience7+ experience in one or more Digital Trust & Privacy domains...SuggestedLocal areaVisa sponsorship- Windsor Solutions in Portland, OR is seeking Systems Analysts at multiple experience levels to help government agencies implement enterprise software solutions. You\'ll work with clients to understand their business needs, configure Windsor\'s software, solve technical...
- ...technical expertise, curiosity, and collaboration to solve complex problems that make a meaningful difference. We're looking for Systems Analysts at multiple experience levels to help our clients successfully implement enterprise software solutions. Whether your background is...
- ...provide a return on investment to shareholders. • To promote employee development.Job DescriptionThe Corporate Reporting Developer/Analyst is responsible for designing / developing / testing complex reporting to support business initiatives, goal setting, performance management...
$118.7k - $218.6k
...PKI Specialist - Senior ConsultantOur Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful...Work experience placementLocal areaVisa sponsorship- Job SummaryThe Cyber Threat Analytics Analyst is responsible for identifying, developing, and improving the organization’s ability to... ...We’re Looking ForWe are looking for an analytical and curious cybersecurity professional who enjoys finding patterns in large volumes of...Local areaRemote workFlexible hours2 days per week3 days per week1 day per week
$155.6k - $306.8k
Position Summary Deloitte Cyber understands the unique challenges and opportunities businesses face in cybersecurity. Deloitte’s Cyber team helps our clients navigate the ever-changing threat landscape. We simplify complexity, and enable businesses to operate with...Local areaVisa sponsorship$84.2k - $113.9k
Programmer Analyst IHybrid role (3 days/week in office) at our Portland, Medford, Fargo, Burlington, Spokane, Vancouver, Renton, Boise, Lewiston or Salt Lake City offices. Candidates must reside within commutable distance of that location.Build a career with purpose. Join...Full timeWork experience placementWork at officeImmediate startWork from homeFlexible hours3 days per week- Azad Technology Partners is seeking a full-time Network Administrator 3 to support critical control center systems in Vancouver, Washington. This role requires a Bachelor's degree and 10 years of relevant experience, focusing on network security and infrastructure engineering...Full timeContract work
$92.7k - $125.4k
Provider Reimbursement Systems Analyst Hybrid role (3 days/week in office) at our Burlington, Renton, Spokane, Vancouver, Portland, Medford, Salt Lake City, Boise, Lewiston, Fargo offices. Candidates must reside within commutable distance of that location or be willing...Full timeWork at officeImmediate startWork from homeRelocationFlexible hours3 days per week- DescriptionOur KP HealthConnect Solution Consulting team works primarily in the Revenue Cycle space to deliver solutions across all of Kaiser Permanente’s markets on large investment projects, programs, and enhancements. As an IT consultant, you will participate in all ...Work experience placement
- ...PCI, or CJIS is preferred. An associate or bachelors degree in cybersecurity or IT, or equivalent practical experience, is preferred. MSP... ...Alert Response Playbook and elevate appropriately to the Senior Analyst or vCSO. You will serve as the primary first‑line owner of the...Full timeRemote work
- Who You’ll Work WithSlalom is seeking an Enterprise Architect who can bring the art of the possible to life across large, complex client programs. This person combines broad technology depth, strong business judgment, and a practical delivery mindset to help clients turn...Temporary workLocal area
- The City of Vancouver is seeking a skilled Digital Forensics Investigator to provide technical expertise in support of law enforcement investigations. You will identify, preserve, and analyze digital evidence in cases including violent crimes and internet crimes against...
- Company DescriptionXinnovit is a global leader in technology consulting, outsourcing, and workforce management solutions.Our mission is to enable our clients to become more agile and competitive with the help of innovative technologies. We empower our clients to respond...
- Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014 ...
- Chief Information Security Officer (CISO), Growth About the Company Accomplished provider of top-tier security services Industry Security and Investigations Type Privately Held About the Role The Company is seeking a Chief Information Security Officer (CISO) with a strong...
- Senior Information Security & Cyber Risk Analyst Location: Vancouver, WA. Full‑time, permanent position. Salary: Excellent compensation with benefits, relocation assistance, and interview travel reimbursement. Job Summary Responsible for planning and implementing information...Permanent employmentFull timeRelocation package
- ...regulators, and enterprise customers. Applicants for the CISO position at the company should have a minimum of 10 years' experience in cybersecurity, with at least 5 years in senior security leadership, preferably as a CISO at an enterprise SaaS or cloud company. The role...
- Job DescriptionECS is seeking a Cyber Forensics Analyst to work in our Portland, OR office. Note: This position is contingent upon contract... ...document technical evidence. The ideal candidate has solid cybersecurity experience, strong written communication skills, and the...Contract workWork at office
$105.4k - $207.8k
...and cloud feedsCollaborating with security operations center analysts and threat detection engineers to prioritize, develop, and tune... ..., mentoring junior team members, and staying current on cybersecurity threats, vulnerabilities, and compliance trendsA successful candidate...Local areaVisa sponsorship$97.61k - $188.38k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions...Local areaVisa sponsorship$105.4k - $207.8k
...customer experiences. Our work brings together digital trust, online protection, privacy, AI governance, identity, data protection, cybersecurity, and regulatory compliance capabilities.The Full Stack Engineer team is a multidisciplinary engineering group that turns these...Local areaVisa sponsorship- Position Summary:Prevent and reduce loss due to bad debt, cash over/short and civil liabilities; reduce shrink and improve margins. Fred Meyer also requires that all associates perform all tasks in a safe manner consistent with corporate policies and state and federal laws...Work at officeShift workWeekend work
$105.4k - $207.8k
Position Summary Our Deloitte Cyber team helps organizations address evolving cybersecurity challenges across identity, access, and platform security. Join our team to deliver solutions that help clients strengthen resilience, modernize identity environments, and...Local areaVisa sponsorship- ...innovative tools and services by welcoming new talent to our growing team. Position Overview We are seeking an experienced Solutions Analyst - Lab Applications to join our Implementation/ Install Team, this role will support the mission of OCHIN by configuring and...Full timeFor contractorsWork at officeRemote workWork from homeHome office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Analyst. Be the first to apply!
- cybersecurity software engineer Portland, OR
- cybersecurity administrator Portland, OR
- remote cyber security Portland, OR
- cyber security lead Portland, OR
- cyber security Portland, OR
- cybersecurity specialist Portland, OR
- cybersecurity certificate Portland, OR
- cybersecurity policy and compliance analyst Portland, OR
- cyber security intern Portland, OR
- senior cybersecurity engineer Portland, OR

