1

Cism Jobs in Oregon (NOW HIRING)

Hospital Chaplain

Hillsboro, OR · On-site

$33.27 - $47.56/hr

... as CISM team, Employees Helping Employees EHE, Ethics as assigned. Performed occasionally but critical to successful performance of the job: • Attends continuing education programs. • Other ...

Showing results 41-43

Cism information

See Oregon salary details

$31.2K

$100.4K

$180.3K

How much do cism jobs pay per year?

As of Aug 23, 2026, the average yearly pay for cism in Oregon is $100,364.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,300.00 and $134,800.00 per year, depending on experience, location, and employer.

What is a CISM?

CISM stands for Certified Information Security Manager. It is a globally recognized certification for professionals who manage, design, and oversee an enterprise’s information security program. Earning a CISM demonstrates expertise in information security governance, risk management, program development, and incident management. This credential is ideal for those pursuing or advancing careers in information security management, and is often required for senior security positions.

What jobs can I get with a CISM certification?

CISM stands for Certified Information Security Manager. CISM certification provides access to a variety of jobs, most of which focus on information security, governance, and risk analysis. In this field, you may help assess the digital security needs of your employer's data projects, review existing security measures, and propose new defenses to counter developing threats. You may also be required to study for other exam processes to stay current with security techniques and emerging technology. Most jobs that require CISM certification are relatively senior positions that only hire people who already have several years of industry experience, so certification alone may not be enough to qualify you a security position.

What are the key skills and qualifications needed to thrive as a Certified Information Security Manager (CISM), and why are they important?

To thrive as a Certified Information Security Manager (CISM), you need a strong background in information security governance, risk management, and incident response, usually supported by a relevant degree and the CISM certification. Familiarity with industry-standard frameworks like ISO/IEC 27001, as well as tools for security monitoring, compliance, and risk assessment, is essential. Exceptional leadership, strategic thinking, and communication skills set successful CISM professionals apart by enabling effective collaboration and policy enforcement. These qualifications and skills are crucial for protecting organizational assets, ensuring regulatory compliance, and driving a robust information security strategy.

What are some common challenges faced by CISMs when implementing information security policies across different departments?

One of the main challenges CISMs encounter is ensuring consistent adoption of security policies across diverse departments with varying needs and priorities. Each department may have unique workflows or legacy systems that require tailored approaches, making it essential for CISMs to collaborate closely and communicate the importance of compliance. Balancing security requirements with business operations often requires negotiation and ongoing education, as well as staying updated on evolving threats to adjust policies accordingly. Building strong relationships and demonstrating the value of security initiatives are keys to overcoming resistance and ensuring organization-wide adherence.

What is the difference between Cism vs CISSP?

CriteriaCismCISSP
CertificationsCertified Information Security Manager (CISM)Certified Information Systems Security Professional (CISSP)
FocusInformation security management and governanceBroad cybersecurity knowledge and security architecture
Work EnvironmentSecurity management roles, policy developmentSecurity analyst, architect, consultant roles
Industry UsageOrganizations emphasizing security managementOrganizations requiring comprehensive security expertise

The Cism and CISSP certifications are both highly valued in cybersecurity but serve different roles. Cism focuses on security management and governance, ideal for those leading security teams. CISSP covers a broad range of security topics, suitable for technical and strategic roles. Understanding these differences helps professionals choose the right certification for their career path.

Is CISM in demand?

CISM (Certified Information Security Manager) is a highly sought-after certification for information security managers, with strong demand in industries such as finance, healthcare, and government. Organizations value CISM professionals for their expertise in managing and governing enterprise security programs, leading to good job prospects and competitive salaries.

What are the most commonly searched types of Cism jobs in Oregon?

The most popular types of Cism jobs in Oregon are:

What are popular job titles related to Cism jobs in Oregon?

For Cism jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Cism jobs in Oregon look for?

The top searched job categories for Cism jobs in Oregon are:

What cities in Oregon are hiring for Cism jobs?

Cities in Oregon with the most Cism job openings:

Infographic showing various Cism job openings in Oregon as of August 2026, with employment types broken down into 86% Full Time, 9% Part Time, and 5% Contract. Highlights an 76% Physical, 10% Hybrid, and 14% Remote job distribution, with an average salary of $100,364 per year, or $48.3 per hour.

Senior IT SOX Audit Manager| United States | Remote

Grafana Labs

OR • On-site, Remote

$163K - $195K/yr

Full-time

Posted 19 days ago


Job description

The Opportunity:

We're looking for a Senior Manager, IT SOX Audit to help stand up Grafana Labs' IT SOX program from the ground up as we scale our controls and governance for our next stage of growth. This is a hands-on, high-visibility role reporting to the Head of Internal Audit, with direct exposure to Finance, IT, Engineering, Security, and senior leadership.

This is a player-coach individual contributor role today. You'll architect and execute the IT SOX program yourself and with external consultant support, influencing through expertise rather than direct reports. As the function matures, you'll have the opportunity to broaden your scope into technology and IT audit and to build and lead a team over time.

Success here isn't measured by control test completion rates or a tally of audit projects. It's measured by whether Grafana is more risk-intelligent, better controlled, and able to continue to scale because of your work. This is ideal for someone who enjoys building from scratch, partnering closely with stakeholders, and leveraging modern tools, including AI, to deliver efficient, high-impact assurance.

What You'll Be Doing:

  • Partner with the Head of Internal Audit to build and operate Grafana's IT SOX program from the ground up: scoping, risk assessment, control design, and testing across IT general controls (ITGCs) and key application controls tied to financial reporting.
  • Design and execute all phases of IT SOX activity: walkthroughs, design and operating effectiveness testing, documentation, status tracking, deficiency identification, and remediation validation.
  • Assess ITGCs and application controls across key financial systems and Grafana's cloud/SaaS environment (e.g., NetSuite, Salesforce, Workday]).
  • Own the IT SOX documentation library in partnership with the Business Process / Finance SOX lead (narratives, flowcharts, and IT risk-and-control matrices (RCMs), and keep it audit-ready at all times.
  • Drive deficiency management conversations with control owners, advocating for automation-first, scalable remediation over manual, siloed patches.
  • Own the relationship with external IT auditors, ensuring testing methodologies and documentation meet PCAOB standards and align with external auditor expectations to create the foundation for a future reliance strategy.
  • Leverage AI and automation to enhance scoping, testing, and continuous monitoring, building capabilities and operationalizing insights, not just running checklists.
  • Evaluate the IT control impact of new systems, tools, operations, and policies as Grafana scales.
  • Manage co-source partner resources while maintaining quality and driving consistency across the program.
  • Report on IT SOX status, risks, deficiencies, and remediation to the Head of Internal Audit and senior leadership.
  • Over time, help extend the function beyond SOX into broader technology and IT audit, and build, mentor, and scale a team as the organization grows.

What Makes You a Great Fit:

  • 10+ years of progressive experience in IT SOX compliance, IT audit, or IT risk advisory in Big 4 (or similar) and/or an in-house audit, compliance, or risk management function.
  • Proven hands-on expertise in COSO, SOX 404, ITGCs, ITACs, and PCAOB audit standards.
  • Experience standing up, scaling, or transforming an IT SOX program, ideally in a pre-IPO or newly public, high-growth SaaS environment.
  • Experience auditing cloud-native, SaaS environments and modern ERPs and business applications (e.g., NetSuite, Salesforce, Workday).
  • Track record of implementing or optimizing AI and automated compliance and audit capabilities.
  • Fluency in key frameworks such as COSO, COBIT, NIST CSF, and ISO 27001.
  • Experience with GRC / audit tools, or building home-grown solutions.
  • Strong project management and organizational skills with the ability to oversee complex programs and prioritize ruthlessly.
  • Proven ability to inform and influence senior management stakeholders. You can influence without authority and make technical risk clear, urgent, and actionable.
  • CISA, CPA, CIA, or CISSP strongly preferred.
  • High integrity, ownership, curiosity, and a continuous-improvement mindset.

Bonus Points For:

  • A blend of both Big 4 (or similar) and in-house audit, compliance, or risk management leadership experience.
  • Experience in a pre-IPO and/or newly public, high-growth, consumption/usage-based SaaS technology company.
  • Additional certifications that signal breadth and depth: CPA, CISM, CRISC, or CGEIT.
  • ISACA AAIA (Advanced in AI Audit), or a demonstrated track record of investing in AI governance and audit innovation.
  • Experience broadening an audit function beyond SOX into technology, operational, or advisory assurance.
  • Experience working in globally distributed organizations.

Compensation & Rewards:

In the United States, the base compensation range for this role is $163,000 - $195,000. Actual compensation may vary based on level, experience, and skillset as assessed throughout the interview process. All of our roles include Restricted Stock Units (RSUs), giving every team member ownership in Grafana Labs' success. We believe in shared outcomes; RSUs help us stay aligned and invested as we scale globally.

#LI-Remote

Compensation ranges are country specific. If you are applying for this role from a different location than listed above, your recruiter will discuss your specific market's defined pay range & benefits at the beginning of the process.