Information Security Compliance Analyst

Oregon Metro
United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$94,106.0 - $126,142.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Identity and Access Management Information Technology Operations PCI Data Security Standards Smartsuite Security Information and Event Management Software Vulnerability Management Data Classification Information Technology
+2 more
CIS Benchmarks Servicenow

Job description

  • Serve as the CISO’s operational extension for compliance and governance, translating security strategy into actionable policies, controls, and procedures, and preparing materials for executive reporting, audits, and regulatory reviews.
  • Develop, maintain, and manage the full lifecycle of information security policies and standards, mapping them to applicable frameworks and coordinating periodic reviews with stakeholders across IT and business units.
  • Act as control owner delegate for NIST CSF, CIS Controls, and PCI DSS, leading framework alignment, gap analysis, and PCI compliance activities including CDE scoping, evidence collection, and QSA coordination.
  • Lead governance of the vulnerability management program, including policy definition, SLA tracking, compliance reporting, and risk acceptance decisions, partnering with the Cybersecurity Analyst as execution lead.
  • Conduct compliance reviews of software and technology assets, maintain accurate asset inventories, and support third-party/vendor security reviews to ensure audit readiness.
  • Maintain and administer the enterprise risk register, support internal and external audits, and develop compliance metrics and dashboards to communicate risk and control effectiveness to leadership.
  • Support incident response through documentation, evidence collection, and regulatory notification requirements, including secondary, after-hours backup support for high-severity security alerts in coordination with the Cybersecurity Analyst and SOC/MSSP providers.
  • Collaborate with IT Operations, Infrastructure, and Application Teams to integrate security controls into operational processes, and assist in administering security tools (EDR, SIEM, email security, identity platforms) in support of compliance objectives.
  • Contribute to system hardening and secure configuration baselines aligned with CIS Benchmarks, assist with IAM best practices, and coordinate security awareness and training initiatives.
  • Develop and mature data classification, handling, and protection standards (including DLP and retention policies), support privacy impact assessments, and help mature Metro’s cybersecurity program through process improvement and continuous alignment with evolving threats and best practices., This position is designated as “hybrid telework.” You will be required to work onsite and at times have the option to work away from your assigned work location. The specific schedule and balance of onsite and telework will be discussed with the hiring manager at the time of offer. Employees must reside in Oregon or Washington to work at Metro. Please note, the designation of hybrid telework may be subject to change at a future time., + Compliance & Governance Experience - Describe your experience developing, maintaining, or operationalizing information security policies, controls, or GRC functions, including the frameworks you’ve worked with (e.g., NIST CSF, CIS Controls, PCI DSS) and any experience supporting regulatory requirements such as privacy, data protection, breach notification, or public records obligations.
  • Independent Execution & Cross-Functional Influence - This role operates under the general direction of the CISO but requires independent judgment on day-to-day execution, along with the ability to drive compliance outcomes through collaboration with IT and business teams that don’t report to this position. Share an example that demonstrates both.
  • Building Structure from Ambiguity - Metro’s information security program is still maturing. Describe a time you built or improved a process, policy, or program from an early or undefined state, and how you approached bringing structure to that ambiguity.

The selection process: We expect to evaluate candidates for this recruitment as follows. The selection process is subject to change.

  • Initial review of minimum qualifications
  • In-depth evaluation of application materials to identify the most qualified candidates
  • Consideration of top candidates/interviews
  • Testing/assessments
  • Reference check
  • Background records check for finalist candidate

Requirements

  • Strong working knowledge of security and compliance frameworks (NIST CSF, CIS Controls, PCI DSS) with the ability to translate framework requirements into practical, auditable controls.
  • Detail-oriented and highly organized, with the discipline to manage policy lifecycles, evidence packages, and audit documentation accurately and on schedule.
  • Comfortable operating independently while working under general direction from the CISO, exercising sound judgment on when to escalate versus resolve.
  • Strong written communication skills, able to translate technical security concepts into clear policies, procedures, and executive-ready reporting.
  • Collaborative mindset with the ability to build effective working relationships across IT Operations, Infrastructure, Applications, and business stakeholders who don’t report to this role.
  • Analytical and risk-aware, able to assess control gaps, prioritize remediation efforts, and support risk acceptance discussions with sound reasoning.
  • Comfortable with ambiguity and program-building, given that governance structures, processes, and tooling are still actively being developed and refined.
  • Basic technical fluency with security tools (SIEM, EDR, identity platforms) sufficient to support compliance monitoring without requiring deep engineering expertise.
  • Reliable and responsive when serving as secondary, after-hours backup for high-severity alerts, with good judgment about when situations require escalation versus documentation.
  • Genuine interest in continuous learning and staying current on evolving regulatory requirements, threats, and industry best practices in a public-sector context., * 4-6 years of progressive experience in information technology, including at least 3-5 years of experience in information security, IT security, or compliance-focused role, and
  • A bachelor’s degree in Cybersecurity, Information Technology, or related field, or
  • Any combination of education, professional, volunteer and lived experience that provides the necessary knowledge, skills, and abilities to perform the classification duties and responsibilities., You do not need to have the following preferred qualifications/transferable skills to qualify. However, keep in mind we may consider them when identifying the most qualified candidates. Your transferable skills are any skills you have gained through education, work experience, including the military, or life experience that are relevant for this position.
  • Experience in public sector or government environments.
  • Relevant certifications such as:
  • CISA, CRISC (preferred for governance and risk)
  • PCIP or equivalent PCI-related certification (strongly preferred)
  • Security+, SSCP, or GSEC (foundational, optional)
  • Direct experience with PCI DSS compliance programs, including CDE scoping, SAQ, or ROC processes.
  • Experience supporting cloud security compliance and governance activities in Azure, AWS, or similar environments (e.g., control mapping, configuration review, audit support).
  • Familiarity with privacy considerations, data protection principles, and applicable Oregon state requirements.
  • Experience with vendor risk management, third-party assessments, or software asset compliance reviews.
  • Familiarity with GRC tools or platforms used for risk management, control tracking, and audit management (e.g., ServiceNow GRC, Archer, or similar).
  • Experience working with or overseeing third-party security providers (e.g., MSSP/SOC) in a compliance or audit capacity.

Benefits & conditions

4.14.1 out of 5 stars Oregon Hybrid work $94,106.41 - $126,142.16 a year - Full-time, Pulled from the full job description

  • Paid parental leave
  • Parental leave
  • Health insurance
  • Vision insurance
  • Dental insurance
  • Paid sick time
  • Employee assistance program, The full-salary range for this position is step 1: $94,106.41 to step 7: $126,142.16. However, unless a candidate’s qualifications justify, based on the Oregon Pay Equity Act requirements and Metro’s internal equity review process, the appointment will likely be made between step 1: $94,106.41 to the equity range step 4: $108,947.96., Led by an elected council, this unique government gives all residents of greater Portland a voice in shaping the future and provides parks, venues, services, and tools at a regional scale. We find solutions for our area’s garbage and recycling that protect clean air and water; help plan land use and development to provide jobs and safe transportation; manage local venues that provide a connection to arts and culture and help keep the economy growing; protect 17,000 acres of parks and natural areas, and run the Oregon Zoo, to keep nature close to home.

As part of the Metro family, you play a vital role in serving the people of the greater Portland region.

Family members, including eligible spouses, domestic partners, and children, are covered under most of our benefits programs. Benefits vary depending on position and full-time, part-time, and variable hour status.

This is a budgeted, regular status position with a full-time schedule. The position is eligible for these benefits:

  • Medical, dental and vision health insurance
  • Paid sick leave
  • Paid vacation, holiday, and other leave
  • Paid parental leave
  • Full contribution to Oregon PERS retirement
  • No-cost TriMet Hop Pass
  • Employee Assistance Program
  • Training opportunities
  • Flexible schedules depending on position and department
  • Hybrid/Telework living in Oregon /Washington depending on position and department

About the company

Hello, we’re Metro! Metro is dedicated to shaping a better future for the greater Portland region. The work the people of Metro do every day benefits the lives of the people who live here, today, and tomorrow.

The Information Security Team is looking for an Information Security Compliance Analyst. This role serves as the primary support role to the CISO for Metro’s information security governance, risk, and compliance (GRC) function, operationalizing and maturing the program on the CISO’s behalf while ensuring alignment with applicable federal, state, and local regulations, including privacy, data protection, breach notification, and public records requirements. Acting as control owner delegate, this role ensures controls are properly defined, enforced, auditable, and aligned to business and regulatory requirements, with a clearly bounded (~30%) operational support component focused on control validation, audit readiness, and compliance alignment rather than primary ownership of security operations., At Metro, we strive to cultivate diversity, advance equity, and practice inclusion in all of its work. This means attracting and empowering a workforce that is inclusive of a broad range of human qualities. Workplace diversity is both a moral imperative and a business strength, essential to providing quality support and services to our region. Metro’s goal is to hire, develop and retain highly skilled and talented individuals across all departments and programs who best reflect the diversity of our community.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all