Senior Cybersecurity Analyst

Oregon MetroMetro Regional Center, OR
Hybrid

About The Position

Metro is seeking a Senior Cybersecurity Analyst to lead technical security operations, detection engineering, and incident response. This role is crucial for protecting the systems, data, and services relied upon by the greater Portland region. The Senior Cybersecurity Analyst will be the primary technical lead, responsible for hands-on threat detection, incident response, and continuous improvement of Metro's security posture across endpoint, identity, cloud, and network environments. This position also serves as a senior technical control operator for compliance frameworks like NIST CSF, CIS Controls, and PCI DSS, working in partnership with the Information Security Compliance Analyst. The role acts as the technical incident lead during security events, with formal incident declaration owned by the CISO. As Metro's Information Security program matures, this position offers a growth path toward a Principal Cybersecurity Analyst role with broader ownership of security architecture, detection strategy, and technical risk leadership.

Requirements

  • 4-6 years of related professional experience in cybersecurity, security operations, detection engineering, incident response, vulnerability management, identity and access management, network security, cloud security, or a related technical field.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education, certification, and related professional experience.
  • Any combination of education, professional, volunteer and lived experience that provides the necessary knowledge, skills, and abilities to perform the classification duties and responsibilities.

Nice To Haves

  • Demonstrated experience with technical control implementation, endpoint protection, identity security, network security, cloud security, logging, monitoring, or compliance-related safeguards.
  • Working knowledge of cybersecurity frameworks and control practices, including NIST CSF, CIS Controls, PCI DSS, or similar risk-based security frameworks.
  • Strong written and verbal communication skills, including the ability to document findings, procedures, and technical recommendations for both technical and non-technical audiences.
  • 6 or more years of progressively responsible cybersecurity or closely related technical experience, including senior-level ownership of security operations, detection engineering, incident response, or enterprise security controls.
  • Demonstrated ability to grow into principal-level responsibility for security architecture, detection strategy, and technical risk leadership.
  • Experience in public sector, local government, or critical infrastructure security environments.
  • Hands-on experience with CrowdStrike Falcon modules (EDR, NG-SIEM, Identity Protection, or Exposure Management).
  • Familiarity with Palo Alto Networks firewall administration or network security monitoring.
  • Experience with Microsoft Entra ID, Active Directory, or cloud identity and access management in AWS or GCP environments.
  • Familiarity with the MITRE ATT&CK framework and its application to detection and threat hunting.
  • Preferred certification: CISSP.
  • Other relevant certifications may include: Security+, CySA+, SSCP, GSEC GCIA, GCIH, or CEH.

Responsibilities

  • Serve as the CISO's primary technical lead for security operations, leading alert review, validation, escalation, and coordinated response for security events across Metro's environment.
  • Act as technical incident lead during security events, coordinating containment, eradication, recovery, and post-incident follow-up in partnership with the CISO, IT teams, and SOC/MSSP providers.
  • Develop, tune, and optimize detection content across SIEM, EDR, identity, cloud, and network security tools, incorporating threat intelligence and MITRE ATT&CK techniques.
  • Operate and improve vulnerability management processes, providing risk-based prioritization and partnering with the Compliance Analyst on remediation tracking and risk acceptance documentation.
  • Implement, configure, and monitor technical safeguards under NIST CSF, CIS Controls, and PCI DSS, generating evidence to support compliance validation and audit activities.
  • Own technical security review and ongoing oversight of third-party services, SaaS platforms, and vendor integrations, evaluating authentication, data flows, and integration risk.
  • Monitor Metro's identity security posture, tune identity threat detection tooling, and investigate identity-based threats such as credential theft and lateral movement.
  • Maintain secure configuration baselines using CIS Benchmarks, administer Metro's EDR platform, and participate in security architecture and design reviews for cloud and infrastructure changes.
  • Implement and operate data protection controls (DLP, data monitoring, and audit capabilities), investigating alerts and partnering with the Compliance Analyst to align technical enforcement with policy intent.
  • Contribute technical content to security standards and training materials, and identify opportunities to improve detection quality, control effectiveness, and operational efficiency.

Benefits

  • Health insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Disability insurance
  • Paid holidays
  • Flexible scheduling
  • Professional development
  • Learning and development program
  • Tuition reimbursement
  • Wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service