1

Cism Jobs in Portland, OR (NOW HIRING)

... CISM, Azure Security Engineer). Company : Diverselynx IT Consulting Services Founded in 2002, the company is headquartered in Princeton, USA, with a team of 1001-5000 employees. The company is ...

SOX Compliance Lead

Vancouver, WA · On-site

$164K/yr

CISA, CISM, CRISC, CISSPor similar certifications RequiredKnowledge & Skills * BusinessProcesses * ICOFR * IT General Controls * IT Audit * System and Organization Controls (SOC) reports Preferred ...

next page

Showing results 1-20

Cism information

See Portland, OR salary details

$31.3K

$100.7K

$180.8K

How much do cism jobs pay per year?

As of Sep 5, 2026, the average yearly pay for cism in Portland, OR is $100,669.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,500.00 and $135,200.00 per year, depending on experience, location, and employer.

What is a CISM?

CISM stands for Certified Information Security Manager. It is a globally recognized certification for professionals who manage, design, and oversee an enterprise’s information security program. Earning a CISM demonstrates expertise in information security governance, risk management, program development, and incident management. This credential is ideal for those pursuing or advancing careers in information security management, and is often required for senior security positions.

What jobs can I get with a CISM certification?

CISM stands for Certified Information Security Manager. CISM certification provides access to a variety of jobs, most of which focus on information security, governance, and risk analysis. In this field, you may help assess the digital security needs of your employer's data projects, review existing security measures, and propose new defenses to counter developing threats. You may also be required to study for other exam processes to stay current with security techniques and emerging technology. Most jobs that require CISM certification are relatively senior positions that only hire people who already have several years of industry experience, so certification alone may not be enough to qualify you a security position.

What are the key skills and qualifications needed to thrive as a Certified Information Security Manager (CISM), and why are they important?

To thrive as a Certified Information Security Manager (CISM), you need a strong background in information security governance, risk management, and incident response, usually supported by a relevant degree and the CISM certification. Familiarity with industry-standard frameworks like ISO/IEC 27001, as well as tools for security monitoring, compliance, and risk assessment, is essential. Exceptional leadership, strategic thinking, and communication skills set successful CISM professionals apart by enabling effective collaboration and policy enforcement. These qualifications and skills are crucial for protecting organizational assets, ensuring regulatory compliance, and driving a robust information security strategy.

What are some common challenges faced by CISMs when implementing information security policies across different departments?

One of the main challenges CISMs encounter is ensuring consistent adoption of security policies across diverse departments with varying needs and priorities. Each department may have unique workflows or legacy systems that require tailored approaches, making it essential for CISMs to collaborate closely and communicate the importance of compliance. Balancing security requirements with business operations often requires negotiation and ongoing education, as well as staying updated on evolving threats to adjust policies accordingly. Building strong relationships and demonstrating the value of security initiatives are keys to overcoming resistance and ensuring organization-wide adherence.

What is the difference between Cism vs CISSP?

CriteriaCismCISSP
CertificationsCertified Information Security Manager (CISM)Certified Information Systems Security Professional (CISSP)
FocusInformation security management and governanceBroad cybersecurity knowledge and security architecture
Work EnvironmentSecurity management roles, policy developmentSecurity analyst, architect, consultant roles
Industry UsageOrganizations emphasizing security managementOrganizations requiring comprehensive security expertise

The Cism and CISSP certifications are both highly valued in cybersecurity but serve different roles. Cism focuses on security management and governance, ideal for those leading security teams. CISSP covers a broad range of security topics, suitable for technical and strategic roles. Understanding these differences helps professionals choose the right certification for their career path.

Is CISM in demand?

CISM (Certified Information Security Manager) is a highly sought-after certification for information security managers, with strong demand in industries such as finance, healthcare, and government. Organizations value CISM professionals for their expertise in managing and governing enterprise security programs, leading to good job prospects and competitive salaries.

What are the most commonly searched types of Cism jobs in Portland, OR?

The most popular types of Cism jobs in Portland, OR are:

What are popular job titles related to Cism jobs in Portland, OR?

For Cism jobs in Portland, OR, the most frequently searched job titles are:

What cities near Portland, OR are hiring for Cism jobs?

Cities near Portland, OR with the most Cism job openings:

Infographic showing various Cism job openings in Portland, OR as of August 2026, with employment types broken down into 87% Full Time, 9% Part Time, and 4% Contract. Highlights an 76% Physical, 9% Hybrid, and 15% Remote job distribution, with an average salary of $100,669 per year, or $48.4 per hour.

Senior Information Security & Cyber Risk Analyst (Compliance, CISSP, CISM, CBCP, CHPS, CISA, HI[...]

Downtown Boulder Partnership

Vancouver, WA • On-site

$130 - $170/hr

Other

Posted 4 days ago


Key responsibilities

  • Collaborate with functional teams and senior management to develop and implement information security and cyber risk policies, procedures, standards, and controls.

  • Lead and support enterprise-wide cyber risk assessments, security risk evaluations, and security-related investigations.

  • Develop, monitor, and report on cyber risk metrics and promote information security awareness across PeaceHealth.


Job description

Senior Information Security & Cyber Risk Analyst

Location: Vancouver, WA.

Full‑time, permanent position. Salary: Excellent compensation with benefits, relocation assistance, and interview travel reimbursement.

Job Summary

Responsible for planning and implementing information security and cyber risk policies, procedures, standards, and controls across PeaceHealth. Facilitates cyber risk management activities, security risk assessments, and information security awareness. Evaluates ongoing use and performance of information security programs and processes. Provides support for internal and external security assessments, including gathering evidence, discussing findings, and tracking remediation activities.

Essential Functions
  • Collaborate with functional teams on cyber risks and PeaceHealth information security initiatives; solicit involvement of senior management to achieve cyber risk management goals.
  • Lead and support enterprise‑wide information security and cyber risk assessments with technical and non‑technical teams.
  • Identify and develop recommendations for information security and cyber risk issues and vulnerabilities; work with privacy, compliance, internal audit, legal, HR, IT, and other teams.
  • Serve as an advisor and subject‑matter expert on identified information security and cyber risk matters, projects, or any other PeaceHealth initiative with security implications.
  • Facilitate information security committees and work groups—schedule, coordinate, follow up, and report.
  • Perform cyber management activities, security risk assessments, security‑related investigations, and provide information security awareness; conduct internal security and confidential information investigations and usage audits.
  • Develop and maintain relevant cyber risk metrics to promote transparency; measure, monitor, and report on information security risks via governance committees and other meetings at PeaceHealth.
  • Promote information security education and awareness across PeaceHealth.
  • Perform other duties as assigned.
Qualifications
  • Minimum 5–7 years of experience managing information security, cyber risk, and/or compliance activities.
  • Experience working with security frameworks such as NIST CSF and HIPAA.
  • Demonstrated experience across information security and cyber risk domains.
  • Health‑care experience preferred.
  • Experience in information security investigations preferred.
Education
  • Bachelor’s Degree in Information Systems, Information Technology, Computer Science, Information Security, or related field.
  • Equivalent knowledge and skills obtained through a combination of education, training, and experience may also qualify.
Licenses / Certifications
  • CISSP, CISM, CBCP, CHPS, CISA, or equivalent certification required.
  • Must obtain one of these certifications within 12 months of hire if not already held.
Knowledge, Skills, and Abilities
  • Excellent project management and written and oral communication skills.
  • Ability to present information in textual, graphical, and statistical formats.
  • Ability to collect and analyze data to guide decision making under pressure during security incidents.
  • Collaborative skills with broad constituencies and effective solution orientation.
  • Capability to work on highly sensitive and confidential matters with professionalism and discretion.
  • Ability to work independently with limited supervision and guidance.
  • Proficient with standard software (Microsoft, Windows, Outlook).
Screening Questions
  • Do you have at least five years of experience in managing information security, cyber risk, and/or compliance activities?
  • Do you have healthcare experience?
  • Do you have experience working with security frameworks such as NIST CSF or HIPAA?
  • Do you have experience in information security investigations?
  • Do you have demonstrated experience across information security and cyber risk domains?
Additional Information

PeaceHealth is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or veteran status.

#J-18808-Ljbffr