Information Security Compliance Analyst
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, Information Security, Data Security
Information Security Compliance Analyst
Metro is dedicated to shaping a better future for the greater Portland region. The Information Security Team seeks an Information Security Compliance Analyst to support the CISO in governance, risk, and compliance (GRC) functions, ensuring alignment with federal, state, and local regulations.
Responsibilities- Serve as the CISO’s operational extension for compliance and governance, translating strategy into policies, controls, procedures, and preparing materials for executive reporting, audits, and regulatory reviews.
- Develop, maintain, and manage the full lifecycle of information security policies and standards, mapping them to applicable frameworks and coordinating periodic reviews.
- Act as control owner delegate for NIST CSF, CIS Controls, and PCI DSS, leading framework alignment, gap analysis, and PCI compliance activities including CDE scoping, evidence collection, and QSA coordination.
- Lead governance of the vulnerability management program, including policy definition, SLA tracking, compliance reporting, and risk acceptance decisions.
- Conduct compliance reviews of software and technology assets, maintain accurate asset inventories, and support third‑party/vendor security reviews.
- Maintain and administer the enterprise risk register, support internal and external audits, and develop compliance metrics and dashboards.
- Support incident response through documentation, evidence collection, and regulatory notification, including after‑hours backup support for high‑severity alerts.
- Collaborate with IT Operations, Infrastructure, and Application Teams to integrate security controls and administer security tools (EDR, SIEM, email security, identity platforms).
- Contribute to system hardening and secure configuration baselines aligned with CIS Benchmarks, IAM best practices, and security awareness initiatives.
- Develop and mature data classification, handling, and protection standards, support privacy impact assessments, and help mature Metro’s cybersecurity program.
- Strong knowledge of NIST CSF, CIS Controls, PCI DSS, and ability to translate framework requirements into practical controls.
- Detail‑oriented and highly organized with disciplined policy lifecycle management.
- Capable of independent work while exercising sound judgment and knowing when to escalate.
- Excellent written communication skills, translating technical concepts into clear policy and executive reporting.
- Collaborative mindset, building effective relationships across IT, infrastructure, applications, and business units.
- Analytical and risk‑aware, assessing control gaps, prioritizing remediation, and supporting risk acceptance discussions.
- Comfortable with ambiguity and program‑building in evolving governance structures.
- Basic technical fluency with SIEM, EDR, and identity platforms for compliance monitoring.
- Responsive backup support for high‑severity alerts, using sound judgment for escalation.
- Interest in continuous learning and staying current on evolving regulatory requirements and industry best practices.
- Minimum 4–6 years of progressive experience in IT, including 3–5 years in information security or compliance; bachelor’s degree in Cybersecurity, IT, or related field.
- Preferred certifications: CISA, CRISC, PCIP, Security+, SSCP, GSEC.
- Experience in public‑sector or government environments, PCI DSS compliance, cloud security compliance, vendor risk management, and GRC tools.
This position is designated as hybrid telework. On‑site work is required and telework will be scheduled in consultation with the hiring manager. Employees must reside in Oregon or Washington.
Compensation and BenefitsThe full salary range is step 1: $94,106.41 to step 7: $. Appointment will likely be made between step 1 and step 4 based on the Oregon Pay Equity Act and internal equity review. This position is not eligible for overtime. Beneficiary representation is AFSCME 3580.
Equal Employment OpportunityAll qualified persons will be considered for employment without regard to race, color, religion, sex, national origin, age, marital status, familial status, gender identity and expression, sexual orientation,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).