Information Security Analyst

Vanderhouwen & Associates, Inc.
Salem, OR, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$102,606.0
Working hours
Regular working hours

Tech stack

Microsoft Excel Data Analysis JIRA Cyber Security Microsoft Office Microsoft PowerPoint Information Technology Servicenow

Job description

  • Conduct third-party and vendor information security risk assessments to identify, evaluate, and document potential cybersecurity risks.
  • Perform security control reviews, control validation activities, and compliance assessments to help strengthen the organization’s overall security posture.
  • Analyze risk assessment findings, recommend remediation strategies, and partner with business and technology teams to address identified issues.
  • Review vendor security documentation, including audit reports and supporting evidence, to evaluate security practices and compliance with organizational standards.
  • Support risk metrics, reporting, and data analysis to provide meaningful insights into cybersecurity risks, trends, and control effectiveness.
  • Maintain accurate assessment documentation and risk records using governance and project management tools such as ServiceNow and Jira.
  • Collaborate with cross-functional stakeholders to support risk management initiatives, improve assessment processes, and ensure consistent execution of security programs.
  • Communicate technical security risks, assessment results, and recommendations to both technical and non-technical audiences in a clear and effective manner.
  • Stay informed on evolving cybersecurity threats, industry standards, and best practices to continuously enhance assessment methodologies and risk management processes.

Requirements

Our client is seeking a Senior Information Security Analyst to support enterprise information risk management initiatives by evaluating cybersecurity risks, strengthening security controls, and partnering with stakeholders across the organization. This role is ideal for a collaborative professional with strong analytical skills who can translate complex technical concepts into actionable business insights while helping drive effective risk management practices.

This role is a hybrid model in Beaverton, Oregon. Applicants who can work a hybrid model are preferred but fully remote applicants will be considered., * Minimum of 2-5 years of experience in information security, cybersecurity, technology, risk management, or a related field.

  • Hands-on experience performing third-party or vendor risk assessments and evaluating information security controls.
  • Experience conducting audits, compliance reviews, or security control assessments within an enterprise environment.
  • Proficiency with ServiceNow, Jira, and Microsoft Office Suite, including Excel and PowerPoint.
  • Strong analytical, organizational, and problem-solving skills with the ability to interpret complex technical information.
  • Excellent written and verbal communication skills, with the ability to explain technical concepts to business stakeholders.
  • Experience working collaboratively across multiple teams and managing relationships with diverse stakeholders.
  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Business, or a related discipline preferred; equivalent professional experience will also be considered.
  • Professional certifications such as CRISC, CISSP, or similar information security credentials are preferred but not required.
  • Experience in enterprise risk management, retail, supply chain, or related industries is a plus.
  • Demonstrated adaptability, intellectual curiosity, a commitment to continuous learning, and the ability to handle sensitive information with professionalism and discretion.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.vanderhouwen.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella · World Congress 2023

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

1:36 min

Performing exploratory data analysis to uncover underlying patterns

Julian Joseph · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

Videos

See all

Related articles

See all