1

Cybersecurity Governance Risk Compliance Jobs in Oregon

Experience supporting RMF, ATO, continuous monitoring, risk management, and federal compliance ... cybersecurity requirements. Knowledge of DISA STIGs, secure configuration baselines, system ...

Principal Software Engineer

OR · On-site +1

$134K - $180K/yr

Experience building security automation, governance, risk and compliance (GRC) platforms, or operational workflow systems. * Familiarity with regulated industries such as financial services, banking ...

Senior Software Engineer

OR · On-site +1

$122K - $161K/yr

Knowledge of governance, risk, and compliance (GRC) platforms, security tooling, or operational controls. * Ability to navigate ambiguous requirements and collaborate effectively with both technical ...

VP, Risk & Pharmacy Compliance - Fuze Health

OR · On-site +1

$125K - $168K/yr

Enterprise Compliance Leadership & Governance * Establish and lead an enterprise-wide pharmacy compliance and risk management program aligned with organizational objectives and regulatory ...

Translating client business objectives, risk requirements, and policy expectations into technical ... privacy, AI governance, identity, data protection, cybersecurity, and regulatory compliance ...

Governance, Risk & Compliance * Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF)

Showing results 41-60

Cybersecurity Governance Risk Compliance information

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Oregon?

For Cybersecurity Governance Risk Compliance jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Oregon look for?

The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Oregon are:

What cities in Oregon are hiring for Cybersecurity Governance Risk Compliance jobs?

Cities in Oregon with the most Cybersecurity Governance Risk Compliance job openings:

Third-Party Risk Management Program Officer

Heritage Bank NW

Hillsboro, OR • On-site

$100.88 - $151.33/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago

New


Job description

Third-Party Risk Management Program Officer

Heritage Bank is seeking a Third-Party Risk Management Program Officer to join the Risk and Compliance team. The officer will design, execute, and continuously improve the bank’s third‑party risk management program across the full vendor lifecycle, from onboarding through offboarding.

The role operates within the Second Line of Defense (2LoD) and provides governance and oversight to ensure operational alignment of the bank’s third‑party risk management processes across Information Security, Legal, Procurement, Business Units, and Internal Audit.

Key responsibilities include ensuring third‑party risks—cybersecurity, operational, compliance, reputational, and concentration risks—are appropriately identified, assessed, and monitored in alignment with regulatory expectations.

Geographic locations:

  • Tacoma, WA
  • Seattle, WA
  • Spokane, WA
  • Portland, OR

Base Salary Range: $100,884.00 - $126,105.00 - $151,326.00 annual

The Role at a Glance
  • Leads and manages the Third-Party Risk Management (TPRM) Program, including development and continuous refinement of policies, procedures, risk tiering, segmentation models, risk rating methodologies, and vendor lifecycle control checkpoints.
  • Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks.
  • Oversees execution of inherent risk assessments, due diligence reviews, and control assessments across all third‑party risk domains (cybersecurity, privacy, operational resilience, etc.).
  • Ensures appropriate engagement of cross‑functional subject matter experts and that roles and responsibilities are clearly defined within established processes.
  • Defines and maintains program tools, templates, escalation protocols, and residual risk acceptance processes.
  • Integrates and aligns TPRM program with related programs (Vendor Management, procurement, Business Continuity Planning, Information Security Risk Assessments, Cloud Governance, AI/Model Risk).
  • Establishes and tracks key risk indicators (KRIs).
  • Provides executive‑level reporting on third‑party risk posture, program maturity, and systemic exposures (e.g., concentration risk, critical service dependency).
  • Monitors and escalates open risk issues, overdue assessments, and policy exceptions.
  • Serves as the primary contact for regulatory exams and internal/external audits related to third‑party risk.
  • Performs continuous monitoring of Critical and High risk third parties.
  • Maintains audit‑ready documentation, evidence of program execution, and continuous improvement roadmap.
  • Monitors regulatory changes (OCC Bulletins, FFIEC updates, DORA, NYDFS, etc.) and updates program controls to align with evolving requirements.
Core Skills and Qualifications
  • Bachelor’s degree in Business, Risk Management, Information Security or related field preferred.
  • 5+ years of recent experience in vendor risk management, third‑party oversight, or enterprise risk program role within a financial services environment required.
  • Proven experience leading the development, implementation, and ongoing management of an enterprise‑scale third‑party risk management program.
  • Professional certifications such as CISA, CRISC, or equivalent preferred.
  • Equivalent combination of education, training, certifications, and/or relevant work experience may be considered.
  • Exceptional service orientation for internal and external customers, with ability to build and maintain positive, professional relationships across all levels of management and functional areas.
  • Highly effective listening, verbal, written, and telephone etiquette with strong questioning, negotiation, and presentation skills.
  • Strategic approach to program design, problem solving, and decision‑making with ability to focus on key issues under time pressure.
  • Risk‑based mindset with strong analytical and critical thinking skills; ability to independently assess risk decisions and challenge assumptions.
  • Comprehensive knowledge of regulatory frameworks (FFIEC, GLBA, PCI‑DSS, SOX, HIPAA, etc.) and standards (NIST CSF, ISO 27001, COBIT, COSO, vendor risk management frameworks).
  • Strong knowledge of information security assessment, auditing practices, and ability to evaluate technical and business controls using established frameworks.
  • Knowledge of statutory banking compliance regulations issued by FDIC, FinCEN, Federal Reserve Board, and privacy laws (GLBA, SOX).
  • Excellent project management, planning, organization, time management, and follow‑up skills, with a strong sense of urgency and ability to execute quickly and efficiently.
  • Unquestionable integrity in handling sensitive and confidential information.
  • Proficient use of MS Office (Word, Excel, Outlook) and ability to learn new technologies quickly.
  • Proficient use of third‑party risk management software (e.g., UpGuard, Tandem, Gartner).
Work Environment / Conditions
  • Climate controlled office environment.
  • Work involves concentrating on tasks amid occasional distractions and frequent employee/customer contacts and interruptions.
Physical Demands / Effort
  • Constant use of computer screens, reading reports, and sitting throughout the day.
  • Operating a computer keyboard, multi‑line telephone, photocopier, scanner, and fax machine requiring dexterity of hands and fingers.
  • Typically sitting at a desk or table; occasional standing, stooping, bending, walking, climbing, kneeling or crouching to file materials.
  • Occasional lifting up to 20 lbs. (files, boxes, etc.).

At Heritage Bank, you’ll enjoy a total rewards package that includes a base salary based on role, experience, and skill set, along with an exceptional benefits package—medical, dental, vision, life insurance, 401(k), community volunteer time—and generous time‑off policy. Full‑time team members receive a minimum of ten paid vacation days annually (pro‑rated from start date and/or hours worked) and eight hours of paid sick leave per month, along with eleven paid holidays each calendar year and an annual float day.

Heritage Bank is an Equal Opportunity Employer

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other basis protected by applicable law.

Job applicants have certain legal rights. Please click for information regarding these rights.

If you need assistance completing the online application, please email HBRecruiting@HeritageBankNW.com.

Salary Range Disclaimer

The base salary range represents Heritage Bank’s current salary range for the position. Actual salaries will vary depending on qualifications, experience, and job performance. The range listed is one component of the total compensation package for full‑time and part‑time employees. Depending on position, other total compensation rewards may include monthly, quarterly, or annual incentive and/or bonuses.

#J-18808-Ljbffr