1

Cism Jobs in Oregon (NOW HIRING)

Security or compliance certifications (CISSP, CISM, Security+, AWS/Azure Security certifications). Cognitive/Mental Requirements: * Communicating with others to exchange information. * Problem ...

Hospital Chaplain

Hillsboro, OR · On-site

$33.27 - $47.56/hr

Participates on committees and projects such as CISM team, Employees Helping Employees EHE, Ethics as assigned. Performed occasionally but critical to successful performance of the job: Attends ...

Security+, CISSP, CISM, CISA, or equivalent Security certification * Confidence and depth of understanding to lead meetings with potential Vendors * Current experience in reviewing 3rd party security ...

Compliance Team Lead

OR · Remote

$156K/yr

CISA, CRISC, CISSP, CISM, or ISO 27001 Lead Auditor/Implementer General Skills * Strong project management skills with the ability to manage multiple concurrent client engagements independently

CISSP, CISM, or equivalent senior-level cybersecurity certification * Experience securing LLM, GenAI, or agentic AI systems, including data handling, prompt and tool-call risk, and model output ...

... CISM, or equivalent senior-level cybersecurity certification Experience securing LLM, GenAI, or agentic AI systems, including data handling, prompt and tool-call risk, and model output controls ...

Current professional certification in information security or technology risk management (CISSP, CISA, CRISC, CISM, or comparable) * Knowledge of AI/ML technology risk and related governance ...

GCIH, CISSP, CISM, or CRISC. * Hands-on experience with Tenable (Tenable ONE, Nessus, or Tenable.io), AquaSec, and CDM integration in a federal or large enterprise environment. * Working knowledge of ...

Compliance Team Lead

OR · Remote

$156K/yr

CISA, CRISC, CISSP, CISM, or ISO 27001 Lead Auditor/Implementer General Skills * Strong project management skills with the ability to manage multiple concurrent client engagements independently

Hospital Chaplain

Hillsboro, OR · On-site

$33.27 - $47.56/hr

Participates on committees and projects such as CISM team, Employees Helping Employees EHE, Ethics as assigned. Performed occasionally but critical to successful performance of the job: Attends ...

Certified Information Security Manager (CISM) * Certified Internal Auditor (CIA) * GIAC Systems and Network Auditor (GSNA) SKILLS/KNOWLEDGE/ABILITIES: * Understanding of and familiarity with ...

Sales Engineer

Beaverton, OR · On-site

$92K - $125K/yr

Preferred advanced technology domain certification (CISSP, CCIE, AWS Solutions Architect, PMP, CISM) • Broad understanding of IT concepts, architectures, and processes, with experience supporting ...

Showing results 21-40

Cism information

See Oregon salary details

$31.2K

$100.4K

$180.3K

How much do cism jobs pay per year?

As of Aug 8, 2026, the average yearly pay for cism in Oregon is $100,364.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,300.00 and $134,800.00 per year, depending on experience, location, and employer.

What are some common challenges faced by CISMs when implementing information security policies across different departments?

One of the main challenges CISMs encounter is ensuring consistent adoption of security policies across diverse departments with varying needs and priorities. Each department may have unique workflows or legacy systems that require tailored approaches, making it essential for CISMs to collaborate closely and communicate the importance of compliance. Balancing security requirements with business operations often requires negotiation and ongoing education, as well as staying updated on evolving threats to adjust policies accordingly. Building strong relationships and demonstrating the value of security initiatives are keys to overcoming resistance and ensuring organization-wide adherence.

What are the key skills and qualifications needed to thrive as a Certified Information Security Manager (CISM), and why are they important?

To thrive as a Certified Information Security Manager (CISM), you need a strong background in information security governance, risk management, and incident response, usually supported by a relevant degree and the CISM certification. Familiarity with industry-standard frameworks like ISO/IEC 27001, as well as tools for security monitoring, compliance, and risk assessment, is essential. Exceptional leadership, strategic thinking, and communication skills set successful CISM professionals apart by enabling effective collaboration and policy enforcement. These qualifications and skills are crucial for protecting organizational assets, ensuring regulatory compliance, and driving a robust information security strategy.

What is the difference between Cism vs CISSP?

CriteriaCismCISSP
CertificationsCertified Information Security Manager (CISM)Certified Information Systems Security Professional (CISSP)
FocusInformation security management and governanceBroad cybersecurity knowledge and security architecture
Work EnvironmentSecurity management roles, policy developmentSecurity analyst, architect, consultant roles
Industry UsageOrganizations emphasizing security managementOrganizations requiring comprehensive security expertise

The Cism and CISSP certifications are both highly valued in cybersecurity but serve different roles. Cism focuses on security management and governance, ideal for those leading security teams. CISSP covers a broad range of security topics, suitable for technical and strategic roles. Understanding these differences helps professionals choose the right certification for their career path.

What jobs can I get with a CISM certification?

CISM stands for Certified Information Security Manager. CISM certification provides access to a variety of jobs, most of which focus on information security, governance, and risk analysis. In this field, you may help assess the digital security needs of your employer's data projects, review existing security measures, and propose new defenses to counter developing threats. You may also be required to study for other exam processes to stay current with security techniques and emerging technology. Most jobs that require CISM certification are relatively senior positions that only hire people who already have several years of industry experience, so certification alone may not be enough to qualify you a security position.

What is a CISM?

CISM stands for Certified Information Security Manager. It is a globally recognized certification for professionals who manage, design, and oversee an enterprise’s information security program. Earning a CISM demonstrates expertise in information security governance, risk management, program development, and incident management. This credential is ideal for those pursuing or advancing careers in information security management, and is often required for senior security positions.

Is CISM in demand?

CISM (Certified Information Security Manager) is a highly sought-after certification for information security managers, with strong demand in industries such as finance, healthcare, and government. Organizations value CISM professionals for their expertise in managing and governing enterprise security programs, leading to good job prospects and competitive salaries.
What are the most commonly searched types of Cism jobs in Oregon? The most popular types of Cism jobs in Oregon are:
What are popular job titles related to Cism jobs in Oregon? For Cism jobs in Oregon, the most frequently searched job titles are:
What job categories do people searching Cism jobs in Oregon look for? The top searched job categories for Cism jobs in Oregon are:
What cities in Oregon are hiring for Cism jobs? Cities in Oregon with the most Cism job openings:
Infographic showing various Cism job openings in Oregon as of August 2026, with employment types broken down into 76% Full Time, 18% Part Time, and 6% Contract. Highlights an 77% Physical, 8% Hybrid, and 15% Remote job distribution, with an average salary of $100,364 per year, or $48.3 per hour.

Information Systems Security Manager

Cotiviti

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


Cotiviti rating

8.3

Company rating: 8.3 out of 10

Based on 33 frontline employees who took The Breakroom Quiz

50th of 223 rated it services


Job description

Overview

The Information Systems Security Manager (ISSM), FedRAMP is responsible for overseeing and sustaining the security authorization and continuous compliance of cloud-based information systems supporting United States Federal Government customers. This role is accountable for ensuring the confidentiality, integrity, availability, privacy, auditability, and accountability of government information systems and associated data. 

The ISSM partners closely with Business Operations, Engineering, R&D, Product, Legal, and Information Security leadership to ensure information systems deliver required business functionality while being designed, implemented, and maintained in accordance with FedRAMP, NIST SP 800-53, the NIST Risk Management Framework (RMF), and all applicable federal and agency-specific requirements. 

This position owns overall FedRAMP strategy, authorization execution, continuous monitoring, and Authority to Operate (ATO) sustainment, ensuring ongoing compliance and continuous audit readiness throughout the system lifecycle. In addition, the role supports broader Government (GOV) system security and compliance activities, helping ensure consistent governance and adherence to regulatory requirements across all in-scope federal and state environments.

Responsibilities
  • Manage and oversee end-to-end FedRAMP authorization activities, including planning, execution, resourcing, and stakeholder coordination. 
  • Own the development, maintenance, and quality of all FedRAMP-required security documentation, including the System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), Plan of Action & Milestones (POA&M), and Continuous Monitoring artifacts. 
  • Oversee monthly POA&M management, including vulnerability prioritization, remediation tracking, and risk acceptance coordination. 
  • Lead and coordinate independent security control assessments, vulnerability management, penetration testing, contingency plan testing, and other required security activities. 
  • Direct FedRAMP Continuous Monitoring (ConMon) activities, ensuring timely and accurate submission of monthly, quarterly, and annual deliverables, including scan results, incident reports, and compliance attestations. 
  • Serve as the primary point of contact for sponsoring agencies, 3PAOs, and internal stakeholders on all FedRAMP-related matters. 
  • Oversee research and response efforts related to government security bulletins, vulnerability advisories, and federal data calls, ensuring timely and accurate responses. 
  • Ensure accurate and up-to-date system, software, and hardware inventories for government-authorized environments. 
  • Provide strategic guidance on secure cloud architecture and compliance-driven design decisions across AWS, Azure, and/or GCP environments. 
  • Evaluate system changes for FedRAMP impact and ensure adherence to change management, configuration management, and incident response requirements. 
  • Interpret evolving FedRAMP, NIST, and agency-specific requirements and translate them into actionable guidance for technical and business teams. 
  • Coach and educate internal teams on FedRAMP obligations, audit expectations, and security best practices. 
  • Identify and implement process improvements to enhance compliance efficiency, reduce risk, and strengthen audit readiness. 
  • Develop and deliver status reporting and metrics to leadership on authorization posture, risk exposure, and overall compliance health. 
  • Complete all responsibilities as outlined in the annual performance review and/or goal setting.  
  • Complete all special projects and other duties as assigned.  
  • Must be able to perform duties with or without reasonable accommodation.  

This job description is intended to describe the general nature and level of work being performed and is not to be construed as an exhaustive list of responsibilities, duties and skills required. This job description does not constitute an employment agreement and is subject to change as the needs of Cotiviti and requirements of the job change.  

Qualifications
  • 8+ years of information security, risk, or compliance experience, including interaction with senior leadership, auditors, and regulators. 
  • Demonstrated experience leading or managing FISMA Moderate or High authorizations and ongoing ATO maintenance. 
  • Strong working knowledge of FedRAMP framework, NIST SP 800-53, and NIST RMF 
  • Experience managing SSPs, POA&Ms, vulnerability remediation, audits, and Continuous Monitoring programs. 
  • Hands-on experience with cloud service providers (AWS, Azure, GCP) and SaaS environments. 
  • Proven ability to lead cross-functional initiatives across technical and non-technical team. 
  • Excellent written and verbal communication skills, with the ability to translate complex regulatory requirements for varied audiences. 
  • Strong organizational skills and ability to prioritize effectively in a highly regulated environment. 
  • Security or compliance certifications (CISSP, CISM, Security+, AWS/Azure Security certifications). 

Cognitive/Mental Requirements: 

  • Communicating with others to exchange information. 
  • Problem-solving and thinking critically. 
  • Completing tasks independently. 
  • Interpreting data. 
  • Making timely decisions in the context of a workflow. 
  • Maintaining focus. 
  • Assessing the accuracy, neatness and thoroughness of the work assigned. 
  • Learning new tasks and completing tasks in situations that have a speed or productivity quota. 
  • Remembering and adhering to processes and protocols. 
  • Applying established protocols in a timely manner. 

Working Conditions and Physical Requirements: 

  • Must be able to provide high-speed internet access / connectivity and office setup and maintenance.  
  • Remaining in a stationary position, often standing or sitting for prolonged periods. 
  • Repeating motions that may include the wrists, hands and/or fingers. 
  • Must be able to provide a dedicated, secure work area. 
  • Must be able to provide high-speed internet access / connectivity and office setup and maintenance. 
  • No adverse environmental conditions expected. 

Base compensation ranges from $135,000 to $155,000 per year. Specific offers are determined by various factors, such as experience, education, skills, certifications, and other business needs. This role is eligible for discretionary bonus consideration.

Cotiviti offers team members a competitive benefits package to address a wide range of personal and family needs, including medical, dental, vision, disability, and life insurance coverage, 401(k) savings plans, paid family leave, 9 paid holidays per year, and 17-27 days of Paid Time Off (PTO) per year, depending on specific level and length of service with Cotiviti. For information about our benefits package, please refer to our Careers page.

Date of Posting:  8/04/2026

We anticipate that the application window will close on 10/04/2026, but the application window may change depending on the volume of applications received or close immediately if a qualified candidate is selected.

#LI-REMOTE

#LI-MC1

#senior

Employment Type: OTHER

What Cotiviti employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom