Information Security Compliance Analyst
Oregon Metro
Information Security Compliance Analyst Metro is dedicated to shaping a better future for the greater Portland region. The Information Security Team seeks an Information Security Compliance Analyst to support the CISO in governance, risk, and compliance (GRC) functions, ensuring alignment with federal, state, and local regulations. Responsibilities Serve as the CISO’s operational extension for compliance and governance, translating strategy into policies, controls, procedures, and preparing materials for executive reporting, audits, and regulatory reviews. Develop, maintain, and manage the full lifecycle of information security policies and standards, mapping them to applicable frameworks and coordinating periodic reviews. Act as control owner delegate for NIST CSF, CIS Controls, and PCI DSS, leading framework alignment, gap analysis, and PCI compliance activities including CDE scoping, evidence collection, and QSA coordination. Lead governance of the vulnerability management program, including policy definition, SLA tracking, compliance reporting, and risk acceptance decisions. Conduct compliance reviews of software and technology assets, maintain accurate asset inventories, and support third‑party/vendor security reviews. Maintain and administer the enterprise risk register, support internal and external audits, and develop compliance metrics and dashboards. Support incident response through documentation, evidence collection, and regulatory notification, including after‑hours backup support for high‑severity alerts. Collaborate with IT Operations, Infrastructure, and Application Teams to integrate security controls and administer security tools (EDR, SIEM, email security, identity platforms). Contribute to system hardening and secure configuration baselines aligned with CIS Benchmarks, IAM best practices, and security awareness initiatives. Develop and mature data classification, handling, and protection standards, support privacy impact assessments, and help mature Metro’s cybersecurity program. Qualifications Strong knowledge of NIST CSF, CIS Controls, PCI DSS, and ability to translate framework requirements into practical controls. Detail‑oriented and highly organized with disciplined policy lifecycle management. Capable of independent work while exercising sound judgment and knowing when to escalate. Excellent written communication skills, translating technical concepts into clear policy and executive reporting. Collaborative mindset, building effective relationships across IT, infrastructure, applications, and business units. Analytical and risk‑aware, assessing control gaps, prioritizing remediation, and supporting risk acceptance discussions. Comfortable with ambiguity and program‑building in evolving governance structures. Basic technical fluency with SIEM, EDR, and identity platforms for compliance monitoring. Responsive backup support for high‑severity alerts, using sound judgment for escalation. Interest in continuous learning and staying current on evolving regulatory requirements and industry best practices. Minimum 4–6 years of progressive experience in IT, including 3–5 years in information security or compliance; bachelor’s degree in Cybersecurity, IT, or related field. Preferred certifications: CISA, CRISC, PCIP, Security+, SSCP, GSEC. Experience in public‑sector or government environments, PCI DSS compliance, cloud security compliance, vendor risk management, and GRC tools. Hybrid Telework This position is designated as hybrid telework. On‑site work is required and telework will be scheduled in consultation with the hiring manager. Employees must reside in Oregon or Washington. Compensation and Benefits The full salary range is step 1: $94,106.41 to step 7: $126,142.16. Appointment will likely be made between step 1 and step 4 based on the Oregon Pay Equity Act and internal equity review. This position is not eligible for overtime. Beneficiary representation is AFSCME 3580. Equal Employment Opportunity All qualified persons will be considered for employment without regard to race, color, religion, sex, national origin, age, marital status, familial status, gender identity and expression, sexual orientation, disability for which a reasonable accommodation can be made, or any other status protected by law. Non-Discrimination in Hiring Decisions Metro is committed to equal employment opportunity and complies with all applicable federal, state, and local civil rights laws. Employment decisions must not discriminate based on protected categories. Accommodation Metro will gladly provide a reasonable accommodation to anyone whose specific disability prevents them from completing this application or participating in this recruitment process. Contact the recruiter in advance to request assistance. Veterans' Preference Under Oregon Law, qualified veterans may be eligible for veterans' preference when applying for Metro positions. Provide qualifying documents as instructed during the application process. #J-18808-Ljbffr Oregon Metro
$100k - $150k
Job Description The Senior Information Security Compliance Analyst is a key member of the SRO Compliance & Portfolio Management team, responsible for ensuring the organization maintains compliance with applicable regulatory, statutory, and contractual requirements, as well...SuggestedWork experience placement- Title: Senior Information Security Analyst Location: Beaverton, OR | Open to Remote, US Duration: 7 months contract WHO ARE WE LOOKING FOR?... ...to information security policies and standards. Perform compliance control validation testing to determine the operating effectiveness...SuggestedContract workRemote work
- Overview The Cyber Threat Analytics Analyst is responsible for identifying, developing, and improving... ...malicious behavior, suspicious activity, and security anomalies across the enterprise. This role is part of the Information Security team focused on bringing detection...SuggestedRemote workFlexible hours2 days per week3 days per week1 day per week
- Nike is seeking a Senior Information Security Analyst located in Beaverton, OR, who will work with the Information Risk Management team within Corporate Information Security. The role focuses on assessing vendor risks and evaluating systems against security standards....SuggestedRemote job
- Senior Information Security & Cyber Risk Analyst (Compliance, CISSP, CISM, CBCP, CHPS, CISA, HIPPA, NIST CSF) in Vancouver, WA CHPS, CISA, CISM, CISSP, compliance, Cyber Risk, HIPAA, Information Security, NIST CSF, Security Frameworks Location: Washington Job Function...SuggestedPermanent employmentFull timeRemote workRelocation
- Mercury is seeking an IT Support Analyst based in New York to ensure the security and maintenance of employee systems. In this role, you will manage IT support tasks, oversee asset management, and collaborate with various teams to solve IT challenges. Ideal candidates...Remote job
$60 - $65 per hour
A leading technology consulting firm in Vancouver, WA, is seeking a Security Control Assessor to support compliance with cybersecurity standards. This full-time position requires a Bachelor's degree in a relevant field and a minimum of 6 years of related experience. Responsibilities...Hourly payFull time- ...are also affordable and accessible to all. Staff Network Security Operations Analyst Work Schedule: Hybrid - 3 days in office / 2 days WFH On... ...teams who rely on the platforms you manage. Compliance Support: Contribute to initiatives supporting NERC CIP regulatory...Work at officeWork from homeNight shift
$33 - $39 per hour
A leading consulting company is seeking an Operations Analyst to support their Personnel and Information Security organization. This role includes program analysis, project management, and onboarding support. The ideal candidate will have relevant experience, with a focus...Hourly pay$95k
...right things right. Our Senior Financial Analyst is a core member of a tight-knit FP&A... ...& Engineering, Facilities, IT, & Information Security — leading budgeting and forecasting cycles... ...global leader in integrated risk and compliance management software, trusted by more than...- ...companies and recruiters to obtain personal information from job seekers. Please be vigilant... ...sensitive information such as Social Security numbers or bank details during the initial... ..., or disability status. For OFCCP compliance, the taxable entity associated with this...Overseas
- Oregon Metro is seeking an Information Security Compliance Analyst to support the CISO in governance, risk, and compliance (GRC) activities. You will translate strategy into policies, manage policy lifecycle, and coordinate audits and regulatory reviews. Role requires knowledge...Remote work
$93k - $140k
...a detail-oriented and highly organized Finance Controls and Compliance Analyst to join our team. In this role, you’ll support our SOX (Sarbanes... ...protection and a 401K retirement plan, so that you can feel secure in your health and financial future. Unlimited Flextime and...Local area- Metro in the Portland area seeks an Information Security Compliance Analyst to support the CISO's GRC program, translating strategy into auditable policies, controls, and procedures, and preparing materials for audits and regulatory reviews. You will lead framework alignment...
$33.72 - $46.19 per hour
Gresham-Barlow School District 10J in Gresham, Oregon, is seeking a qualified candidate for the position involving support for business and curriculum systems. The role includes overseeing data management, system operations, and providing extensive user support. Ideal candidates...Hourly payPart time$200k - $275k
...Director Of Information Security We are a renewable energy and ocean technology company committed to rapidly developing and deploying technologies that will ensure a sustainable future for Earth by unlocking the vast energy potential of its oceans. Our focus is on...Full timeWork at officeRelocation packageFlexible hours$172k - $250k
...Grant Thornton is seeking a Director of Information Security Audit & Compliance to join the team. Approved office locations can be found below. We are seeking a Director of Information Security Audit & Compliance to lead and scale a global audit and compliance practice...InternshipSeasonal workWork at officeLocal areaFlexible hours3 days per week- Ampere Computing is seeking a Senior Director of Information Security to lead the information security function. This role will define and execute Ampere's security strategy, ensuring the protection of its critical assets while bridging IT and InfoSec. Successful candidates...
$105.79k - $141.05k
...network and connected ecosystem. We enable secure, high‑performance connectivity across... ...us today. The Role The Manager of Information Security—Cyber Threat Exposure Management... ...backlog, mean time to remediate, SLA compliance, exception trends, asset coverage, and external...Full timeTemporary workRemote work$347k
...apply! About the Role Ampere is seeking a Senior Director of Information Security to lead our information security function. This leader will... .... You will partner closely with IT, Engineering, Legal and Compliance, HR, Finance, business and engineering leadership, and...Local areaShift work$150k - $170k
...seeking a highly accomplished and strategic Senior Manager, Information Security to join our team in Seattle, WA (Open to Portland, OR and... ...Partner with cross-functional leaders (IT, Product, Legal, Compliance, and Operations) to embed security into business processes,...Full time- ...and Border Protection and the Bureau of Industry and Security Export Administration Regulations. The role involves... ...detail is required to troubleshoot and investigate information, resolve issues, and identify compliance risks. The Specialist will play a key role in process...Temporary workWork at officeLocal areaRemote workWorldwide
$50 - $60 per hour
DataAnnotation is committed to creating high-quality AI. Enjoy the flexibility of remote work and the freedom to set your own schedule. This is an opportunity to work with us as an independent contractor. We're currently expanding into an exciting new area – teaching...Hourly payContract workFor contractorsWork experience placementRemote work- ...A leading trade compliance consulting firm is seeking a professional to develop effective communication and conduct research on Customs regulations. The role involves preparing analysis reports, performing audits, and ensuring compliance with U.S. Customs. Candidates...
$69.7k - $94.3k
...Overview Compliance Analyst I, II or III Hybrid role (3 days/week in office) at our Portland, Medford, Fargo, Burlington, Vancouver, Renton... ...organizations work and how to get things done through formal and informal channels. Practical familiarity with legal requirements...Work at officeImmediate startWork from homeFlexible hours3 days per week$69.7k - $94.3k
...Position Overview Compliance Analyst (Levels I, II or III) – Hybrid role (3 days/week in office). Candidates must be able to commute to one of the following locations: Portland, Medford, Fargo, Burlington, Vancouver, Renton, Boise, Lewiston, or Salt Lake City. The role...Work at officeRemote work3 days per week$75k - $90k
...Northmarq was voted by Real Estate Forum as one of The Best Places to Work in Commercial Real Estate! Northmarq is seeking a Compliance Analyst to join the Legal & Compliance team at our Portland, OR office. This position plays a key role in supporting the company’s...Work experience placementWork at officeRemote workFlexible hours$60k
...Compliance Analyst - Supervision This position uses independent judgement and discretion to ensure all Registered Representatives adhere... ...for Supervision matters. What you'll do: Compile information related to office inspections and provide to inspectors....Work experience placementSummer workWork at officeFlexible hours- ...ABOUT These careers bring the expertise in all facets of Information Operations, making sure our fleet is capitalizing on the information... ...analyzing maritime activities that pose a threat to national security, such as drug smuggling, illegal immigration, arms transfers,...Part timeWorldwide
- ...assistance if necessary. Complete incident reports to document all Security/Loss Prevention related incidents. Handle all interruptions... .../Loss Prevention and property reports/documents; release information only to authorized individuals. Conduct investigations and gather...Work experience placementWorldwideShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Compliance Analyst. Be the first to apply!
- data solutions analyst Portland, OR
- entry level data analyst no experience Portland, OR
- data analyst - r python sql Portland, OR
- data integrity analyst Portland, OR
- data analyst supply chain analytics Portland, OR
- data analyst part time work from home Portland, OR
- senior data governance analyst Portland, OR
- senior data management analyst Portland, OR
- data analyst bank Portland, OR
- remote data analyst intern Portland, OR



