Information Security Compliance Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
- Serve as the CISO’s operational extension for compliance and governance, translating security strategy into actionable policies, controls, and procedures, and preparing materials for executive reporting, audits, and regulatory reviews.
- Develop, maintain, and manage the full lifecycle of information security policies and standards, mapping them to applicable frameworks and coordinating periodic reviews with stakeholders across IT and business units.
- Act as control owner delegate for NIST CSF, CIS Controls, and PCI DSS, leading framework alignment, gap analysis, and PCI compliance activities including CDE scoping, evidence collection, and QSA coordination.
- Lead governance of the vulnerability management program, including policy definition, SLA tracking, compliance reporting, and risk acceptance decisions, partnering with the Cybersecurity Analyst as execution lead.
- Conduct compliance reviews of software and technology assets, maintain accurate asset inventories, and support third-party/vendor security reviews to ensure audit readiness.
- Maintain and administer the enterprise risk register, support internal and external audits, and develop compliance metrics and dashboards to communicate risk and control effectiveness to leadership.
- Support incident response through documentation, evidence collection, and regulatory notification requirements, including secondary, after-hours backup support for high-severity security alerts in coordination with the Cybersecurity Analyst and SOC/MSSP providers.
- Collaborate with IT Operations, Infrastructure, and Application Teams to integrate security controls into operational processes, and assist in administering security tools (EDR, SIEM, email security, identity platforms) in support of compliance objectives.
- Contribute to system hardening and secure configuration baselines aligned with CIS Benchmarks, assist with IAM best practices, and coordinate security awareness and training initiatives.
- Develop and mature data classification, handling, and protection standards (including DLP and retention policies), support privacy impact assessments, and help mature Metro’s cybersecurity program through process improvement and continuous alignment with evolving threats and best practices., This position is designated as “hybrid telework.” You will be required to work onsite and at times have the option to work away from your assigned work location. The specific schedule and balance of onsite and telework will be discussed with the hiring manager at the time of offer. Employees must reside in Oregon or Washington to work at Metro. Please note, the designation of hybrid telework may be subject to change at a future time., + Compliance & Governance Experience - Describe your experience developing, maintaining, or operationalizing information security policies, controls, or GRC functions, including the frameworks you’ve worked with (e.g., NIST CSF, CIS Controls, PCI DSS) and any experience supporting regulatory requirements such as privacy, data protection, breach notification, or public records obligations.
- Independent Execution & Cross-Functional Influence - This role operates under the general direction of the CISO but requires independent judgment on day-to-day execution, along with the ability to drive compliance outcomes through collaboration with IT and business teams that don’t report to this position. Share an example that demonstrates both.
- Building Structure from Ambiguity - Metro’s information security program is still maturing. Describe a time you built or improved a process, policy, or program from an early or undefined state, and how you approached bringing structure to that ambiguity.
The selection process: We expect to evaluate candidates for this recruitment as follows. The selection process is subject to change.
- Initial review of minimum qualifications
- In-depth evaluation of application materials to identify the most qualified candidates
- Consideration of top candidates/interviews
- Testing/assessments
- Reference check
- Background records check for finalist candidate
Requirements
- Strong working knowledge of security and compliance frameworks (NIST CSF, CIS Controls, PCI DSS) with the ability to translate framework requirements into practical, auditable controls.
- Detail-oriented and highly organized, with the discipline to manage policy lifecycles, evidence packages, and audit documentation accurately and on schedule.
- Comfortable operating independently while working under general direction from the CISO, exercising sound judgment on when to escalate versus resolve.
- Strong written communication skills, able to translate technical security concepts into clear policies, procedures, and executive-ready reporting.
- Collaborative mindset with the ability to build effective working relationships across IT Operations, Infrastructure, Applications, and business stakeholders who don’t report to this role.
- Analytical and risk-aware, able to assess control gaps, prioritize remediation efforts, and support risk acceptance discussions with sound reasoning.
- Comfortable with ambiguity and program-building, given that governance structures, processes, and tooling are still actively being developed and refined.
- Basic technical fluency with security tools (SIEM, EDR, identity platforms) sufficient to support compliance monitoring without requiring deep engineering expertise.
- Reliable and responsive when serving as secondary, after-hours backup for high-severity alerts, with good judgment about when situations require escalation versus documentation.
- Genuine interest in continuous learning and staying current on evolving regulatory requirements, threats, and industry best practices in a public-sector context., * 4-6 years of progressive experience in information technology, including at least 3-5 years of experience in information security, IT security, or compliance-focused role, and
- A bachelor’s degree in Cybersecurity, Information Technology, or related field, or
- Any combination of education, professional, volunteer and lived experience that provides the necessary knowledge, skills, and abilities to perform the classification duties and responsibilities., You do not need to have the following preferred qualifications/transferable skills to qualify. However, keep in mind we may consider them when identifying the most qualified candidates. Your transferable skills are any skills you have gained through education, work experience, including the military, or life experience that are relevant for this position.
- Experience in public sector or government environments.
- Relevant certifications such as:
- CISA, CRISC (preferred for governance and risk)
- PCIP or equivalent PCI-related certification (strongly preferred)
- Security+, SSCP, or GSEC (foundational, optional)
- Direct experience with PCI DSS compliance programs, including CDE scoping, SAQ, or ROC processes.
- Experience supporting cloud security compliance and governance activities in Azure, AWS, or similar environments (e.g., control mapping, configuration review, audit support).
- Familiarity with privacy considerations, data protection principles, and applicable Oregon state requirements.
- Experience with vendor risk management, third-party assessments, or software asset compliance reviews.
- Familiarity with GRC tools or platforms used for risk management, control tracking, and audit management (e.g., ServiceNow GRC, Archer, or similar).
- Experience working with or overseeing third-party security providers (e.g., MSSP/SOC) in a compliance or audit capacity.
Benefits & conditions
4.14.1 out of 5 stars Oregon Hybrid work $94,106.41 - $126,142.16 a year - Full-time, Pulled from the full job description
- Paid parental leave
- Parental leave
- Health insurance
- Vision insurance
- Dental insurance
- Paid sick time
- Employee assistance program, The full-salary range for this position is step 1: $94,106.41 to step 7: $126,142.16. However, unless a candidate’s qualifications justify, based on the Oregon Pay Equity Act requirements and Metro’s internal equity review process, the appointment will likely be made between step 1: $94,106.41 to the equity range step 4: $108,947.96., Led by an elected council, this unique government gives all residents of greater Portland a voice in shaping the future and provides parks, venues, services, and tools at a regional scale. We find solutions for our area’s garbage and recycling that protect clean air and water; help plan land use and development to provide jobs and safe transportation; manage local venues that provide a connection to arts and culture and help keep the economy growing; protect 17,000 acres of parks and natural areas, and run the Oregon Zoo, to keep nature close to home.
As part of the Metro family, you play a vital role in serving the people of the greater Portland region.
Family members, including eligible spouses, domestic partners, and children, are covered under most of our benefits programs. Benefits vary depending on position and full-time, part-time, and variable hour status.
This is a budgeted, regular status position with a full-time schedule. The position is eligible for these benefits:
- Medical, dental and vision health insurance
- Paid sick leave
- Paid vacation, holiday, and other leave
- Paid parental leave
- Full contribution to Oregon PERS retirement
- No-cost TriMet Hop Pass
- Employee Assistance Program
- Training opportunities
- Flexible schedules depending on position and department
- Hybrid/Telework living in Oregon /Washington depending on position and department
About the company
Hello, we’re Metro! Metro is dedicated to shaping a better future for the greater Portland region. The work the people of Metro do every day benefits the lives of the people who live here, today, and tomorrow.
The Information Security Team is looking for an Information Security Compliance Analyst. This role serves as the primary support role to the CISO for Metro’s information security governance, risk, and compliance (GRC) function, operationalizing and maturing the program on the CISO’s behalf while ensuring alignment with applicable federal, state, and local regulations, including privacy, data protection, breach notification, and public records requirements. Acting as control owner delegate, this role ensures controls are properly defined, enforced, auditable, and aligned to business and regulatory requirements, with a clearly bounded (~30%) operational support component focused on control validation, audit readiness, and compliance alignment rather than primary ownership of security operations., At Metro, we strive to cultivate diversity, advance equity, and practice inclusion in all of its work. This means attracting and empowering a workforce that is inclusive of a broad range of human qualities. Workplace diversity is both a moral imperative and a business strength, essential to providing quality support and services to our region. Metro’s goal is to hire, develop and retain highly skilled and talented individuals across all departments and programs who best reflect the diversity of our community.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Best Paying Jobs in Technology