1

Cyber Risk Analyst Jobs in Portland, OR (NOW HIRING)

Analyze processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...

New

Analyst, Cybersecurity

Portland, OR · On-site

$88K - $132K/yr

... cyber risk reduction for the agency. Example actions include, but are not limited to, enterprise vulnerability management, third party risk management, managing reported and detected phishing emails ...

New

Analyst, Cybersecurity

Portland, OR · On-site

$88K - $132K/yr

... cyber risk reduction for the agency. Example actions include, but are not limited to, enterprise vulnerability management, third party risk management, managing reported and detected phishing emails ...

Analyst, Cybersecurity

Portland, OR · On-site

$88K - $132K/yr

... cyber risk reduction for the agency. Example actions include, but are not limited to, enterprise vulnerability management, third party risk management, managing reported and detected phishing emails ...

next page

Showing results 1-20

Cyber Risk Analyst information

See Portland, OR salary details

$47.2K

$114K

$160.2K

How much do cyber risk analyst jobs pay per year?

As of Sep 12, 2026, the average yearly pay for cyber risk analyst in Portland, OR is $114,043.00, according to ZipRecruiter salary data. Most workers in this role earn between $97,000.00 and $134,200.00 per year, depending on experience, location, and employer.

How does a cyber risk analyst typically collaborate with other departments to improve an organization's security posture?

Cyber Risk Analysts work closely with various departments, such as IT, compliance, and business units, to identify and assess potential security threats. They often facilitate risk assessments, conduct training sessions to raise awareness, and help develop incident response plans. Regular communication and collaboration are essential, as analysts must ensure that security recommendations align with business goals and regulatory requirements. This cross-functional teamwork creates a more resilient security environment and helps integrate cybersecurity best practices throughout the organization.

What are the key skills and qualifications needed to thrive as a cyber risk analyst, and why are they important?

To thrive as a Cyber Risk Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and often a degree in cybersecurity, computer science, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), vulnerability assessment tools, and security information and event management (SIEM) systems is typically required, along with certifications like CISSP or CISM. Analytical thinking, attention to detail, and strong communication skills are essential soft skills for this role. These competencies ensure accurate identification, evaluation, and mitigation of cyber risks to protect organizational assets and maintain regulatory compliance.

What is the difference between Cyber Risk Analyst vs Cyber Security Analyst?

AspectCyber Risk AnalystCyber Security Analyst
CertificationsCertified Information Systems Security Professional (CISSP), Certified Risk and Information Systems Control (CRISC)CompTIA Security+, Certified Ethical Hacker (CEH)
Work EnvironmentRisk assessment, policy development, complianceNetwork monitoring, threat detection, incident response
Employer & IndustryFinancial, healthcare, government sectors focusing on risk managementIT departments, cybersecurity firms, tech companies

While both roles focus on cybersecurity, a Cyber Risk Analyst primarily assesses and manages potential risks to an organization’s information assets, whereas a Cyber Security Analyst concentrates on defending systems from threats and responding to security incidents. The roles often overlap but differ in their core focus areas.

How much does a cyber risk analyst make?

The average salary for a cyber risk analyst typically ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries, especially in industries with high cybersecurity needs.

What does a cyber risk analyst do?

A cyber risk analyst evaluates an organization's cybersecurity threats and vulnerabilities to identify potential risks. They analyze security data, develop risk mitigation strategies, and often use tools like risk assessment frameworks and security information and event management (SIEM) systems to protect digital assets.

What are popular job titles related to Cyber Risk Analyst jobs in Portland, OR?

For Cyber Risk Analyst jobs in Portland, OR, the most frequently searched job titles are:

What job categories do people searching Cyber Risk Analyst jobs in Portland, OR look for?

The top searched job categories for Cyber Risk Analyst jobs in Portland, OR are:

Infographic showing various Cyber Risk Analyst job openings in Portland, OR as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 12% Part Time, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $114,027 per year, or $54.8 per hour.

Senior Information Security & Cyber Risk Analyst (Compliance, CISSP, CISM, CBCP, CHPS, CISA, HI[...]

Vancouver, WA • On-site

Downtown Boulder Partnership
11 - 50 employees

$104K - $135K/yr

Other

Posted 10 days ago


Key responsibilities

  • Collaborate with functional teams and senior management to develop and implement information security and cyber risk policies, procedures, standards, and controls.

  • Lead and support enterprise-wide cyber risk assessments, security risk evaluations, and security-related investigations.

  • Develop, monitor, and report on cyber risk metrics and promote information security awareness across PeaceHealth.


Job description

Senior Information Security & Cyber Risk Analyst

Location: Vancouver, WA.

Full‑time, permanent position. Salary: Excellent compensation with benefits, relocation assistance, and interview travel reimbursement.

Job Summary

Responsible for planning and implementing information security and cyber risk policies, procedures, standards, and controls across PeaceHealth. Facilitates cyber risk management activities, security risk assessments, and information security awareness. Evaluates ongoing use and performance of information security programs and processes. Provides support for internal and external security assessments, including gathering evidence, discussing findings, and tracking remediation activities.

Essential Functions
  • Collaborate with functional teams on cyber risks and PeaceHealth information security initiatives; solicit involvement of senior management to achieve cyber risk management goals.
  • Lead and support enterprise‑wide information security and cyber risk assessments with technical and non‑technical teams.
  • Identify and develop recommendations for information security and cyber risk issues and vulnerabilities; work with privacy, compliance, internal audit, legal, HR, IT, and other teams.
  • Serve as an advisor and subject‑matter expert on identified information security and cyber risk matters, projects, or any other PeaceHealth initiative with security implications.
  • Facilitate information security committees and work groups—schedule, coordinate, follow up, and report.
  • Perform cyber management activities, security risk assessments, security‑related investigations, and provide information security awareness; conduct internal security and confidential information investigations and usage audits.
  • Develop and maintain relevant cyber risk metrics to promote transparency; measure, monitor, and report on information security risks via governance committees and other meetings at PeaceHealth.
  • Promote information security education and awareness across PeaceHealth.
  • Perform other duties as assigned.
Qualifications
  • Minimum 5–7 years of experience managing information security, cyber risk, and/or compliance activities.
  • Experience working with security frameworks such as NIST CSF and HIPAA.
  • Demonstrated experience across information security and cyber risk domains.
  • Health‑care experience preferred.
  • Experience in information security investigations preferred.
Education
  • Bachelor’s Degree in Information Systems, Information Technology, Computer Science, Information Security, or related field.
  • Equivalent knowledge and skills obtained through a combination of education, training, and experience may also qualify.
Licenses / Certifications
  • CISSP, CISM, CBCP, CHPS, CISA, or equivalent certification required.
  • Must obtain one of these certifications within 12 months of hire if not already held.
Knowledge, Skills, and Abilities
  • Excellent project management and written and oral communication skills.
  • Ability to present information in textual, graphical, and statistical formats.
  • Ability to collect and analyze data to guide decision making under pressure during security incidents.
  • Collaborative skills with broad constituencies and effective solution orientation.
  • Capability to work on highly sensitive and confidential matters with professionalism and discretion.
  • Ability to work independently with limited supervision and guidance.
  • Proficient with standard software (Microsoft, Windows, Outlook).
Screening Questions
  • Do you have at least five years of experience in managing information security, cyber risk, and/or compliance activities?
  • Do you have healthcare experience?
  • Do you have experience working with security frameworks such as NIST CSF or HIPAA?
  • Do you have experience in information security investigations?
  • Do you have demonstrated experience across information security and cyber risk domains?
Additional Information

PeaceHealth is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or veteran status.

#J-18808-Ljbffr