Information Security Compliance Analyst

Oregon MetroMetro Regional Center, OR
Hybrid

About The Position

Metro is seeking an Information Security Compliance Analyst to serve as the primary support role to the CISO for Metro's information security governance, risk, and compliance (GRC) function. This role will operationalize and mature the GRC program, ensuring alignment with applicable federal, state, and local regulations, including privacy, data protection, breach notification, and public records requirements. The position acts as a control owner delegate, ensuring controls are properly defined, enforced, auditable, and aligned with business and regulatory requirements. There is a clearly bounded (~30%) operational support component focused on control validation, audit readiness, and compliance alignment, rather than primary ownership of security operations. The Information Security Compliance Analyst will be the CISO's operational extension for compliance and governance, translating security strategy into actionable policies, controls, and procedures, and preparing materials for executive reporting, audits, and regulatory reviews.

Requirements

  • 4–6 years of progressive experience in information technology, including at least 3–5 years of experience in information security, IT security, or compliance-focused role
  • A bachelor’s degree in Cybersecurity, Information Technology, or related field, or Any combination of education, professional, volunteer and lived experience that provides the necessary knowledge, skills, and abilities to perform the classification duties and responsibilities.

Nice To Haves

  • Experience in public sector or government environments.
  • Relevant certifications such as: CISA, CRISC (preferred for governance and risk)
  • PCIP or equivalent PCI-related certification (strongly preferred)
  • Security+, SSCP, or GSEC (foundational, optional)
  • Direct experience with PCI DSS compliance programs, including CDE scoping, SAQ, or ROC processes.
  • Experience supporting cloud security compliance and governance activities in Azure, AWS, or similar environments (e.g., control mapping, configuration review, audit support).
  • Familiarity with privacy considerations, data protection principles, and applicable Oregon state requirements.
  • Experience with vendor risk management, third-party assessments, or software asset compliance reviews.
  • Familiarity with GRC tools or platforms used for risk management, control tracking, and audit management (e.g., ServiceNow GRC, Archer, or similar).
  • Experience working with or overseeing third-party security providers (e.g., MSSP/SOC) in a compliance or audit capacity.

Responsibilities

  • Serve as the CISO's operational extension for compliance and governance, translating security strategy into actionable policies, controls, and procedures, and preparing materials for executive reporting, audits, and regulatory reviews.
  • Develop, maintain, and manage the full lifecycle of information security policies and standards, mapping them to applicable frameworks and coordinating periodic reviews with stakeholders across IT and business units.
  • Act as control owner delegate for NIST CSF, CIS Controls, and PCI DSS, leading framework alignment, gap analysis, and PCI compliance activities including CDE scoping, evidence collection, and QSA coordination.
  • Lead governance of the vulnerability management program, including policy definition, SLA tracking, compliance reporting, and risk acceptance decisions, partnering with the Cybersecurity Analyst as execution lead.
  • Conduct compliance reviews of software and technology assets, maintain accurate asset inventories, and support third-party/vendor security reviews to ensure audit readiness.
  • Maintain and administer the enterprise risk register, support internal and external audits, and develop compliance metrics and dashboards to communicate risk and control effectiveness to leadership.
  • Support incident response through documentation, evidence collection, and regulatory notification requirements, including secondary, after-hours backup support for high-severity security alerts in coordination with the Cybersecurity Analyst and SOC/MSSP providers.
  • Collaborate with IT Operations, Infrastructure, and Application Teams to integrate security controls into operational processes, and assist in administering security tools (EDR, SIEM, email security, identity platforms) in support of compliance objectives.
  • Contribute to system hardening and secure configuration baselines aligned with CIS Benchmarks, assist with IAM best practices, and coordinate security awareness and training initiatives.
  • Develop and mature data classification, handling, and protection standards (including DLP and retention policies), support privacy impact assessments, and help mature Metro's cybersecurity program through process improvement and continuous alignment with evolving threats and best practices.

Benefits

  • The full-salary range for this position is step 1: $94,106.41 to step 7: $126,142.16. However, unless a candidate’s qualifications justify, based on the Oregon Pay Equity Act requirements and Metro’s internal equity review process, the appointment will likely be made between step 1: $94,106.41 to the equity range step 4: $108,947.96.
  • This position is not eligible for overtime and is represented by AFSCME 3580.
  • Equal employment opportunity
  • Non-discrimination in hiring decisions
  • Accommodation
  • Veterans' preference
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service