Information Security Compliance Analyst
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, Information Security, Data Security
Position Summary
Metro is dedicated to shaping a better future for the greater Portland region. The Information Security Team is looking for an Information Security Compliance Analyst. This role serves as the primary support function to the CISO for Metro's information security governance, risk, and compliance (GRC) function, operationalizing and maturing the program on the CISO’s behalf while ensuring alignment with applicable federal, state, and local regulations, including privacy, data protection, breach notification, and public records requirements.
Acting as a control owner delegate, this role ensures controls are properly defined, enforced, auditable, and aligned to business and regulatory requirements, with a clearly bounded (~30%) operational support component focused on control validation, audit readiness, and compliance alignment rather than primary ownership of security operations.
- Serve as the CISO’s operational extension for compliance and governance, translating security strategy into actionable policies, controls, and procedures, and preparing materials for executive reporting, audits, and regulatory reviews.
- Develop, maintain, and manage the full lifecycle of information security policies and standards, mapping them to applicable frameworks and coordinating periodic reviews with stakeholders across IT and business units.
- Act as control owner delegate for NIST CSF, CIS Controls, and PCI DSS, leading framework alignment, gap analysis, and PCI compliance activities including CDE scoping, evidence collection, and QSA coordination.
- Lead governance of the vulnerability management program, including policy definition, SLA tracking, compliance reporting, and risk acceptance decisions, partnering with the Cybersecurity Analyst as execution lead.
- Conduct compliance reviews of software and technology assets, maintain accurate asset inventories, and support third‑party/vendor security reviews to ensure audit readiness.
- Maintain and administer the enterprise risk register, support internal and external audits, and develop compliance metrics and dashboards to communicate risk and control effectiveness to leadership.
- Support incident response through documentation, evidence collection, and regulatory notification requirements, including secondary, after‑hours backup support for high‑severity security alerts in coordination with the Cybersecurity Analyst and SOC/MSSP providers.
- Collaborate with IT Operations, Infrastructure, and Application Teams to integrate security controls into operational processes, and assist in administering security tools (EDR, SIEM, email security, identity platforms) in support of compliance objectives.
- Contribute to system hardening and secure configuration baselines aligned with CIS Benchmarks, assist with IAM best practices, and coordinate security awareness and training initiatives.
- Develop and mature data classification, handling, and protection standards (including DLP and retention policies), support privacy impact assessments, and help mature Metro’s cybersecurity program through process improvement and continuous alignment with evolving threats and best practices.
- Strong working knowledge of security and compliance frameworks (NIST CSF, CIS Controls, PCI DSS) with the ability to translate framework requirements into practical, auditable controls.
- Detail‑oriented and highly organized, with the discipline to manage policy life cycles, evidence packages, and audit documentation accurately and on schedule.
- Comfortable operating independently while working under general direction from the CISO, exercising sound judgment on when to elevate versus resolve.
- Strong written communication skills, able to translate technical security concepts into clear policies, procedures, and executive‑ready reporting.
- Collaborative mindset with the ability to build effective working relationships across IT Operations, Infrastructure, Applications, and business stakeholders who don’t report to this role.
- Analytical and risk‑aware, able to assess control gaps, prioritize remediation efforts, and support risk acceptance discussions with sound reasoning.
- Comforta…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).