1

Cybersecurity Governance Risk Compliance Jobs in Portland, OR

Cyber Data Protection/PKI Manager

Portland, OR · On-site

$117K - $159K/yr

... governance, and risk assessments. Qualifications Required: * Bachelor's degree in Cybersecurity ... and compliance monitoring programs * Strong client leadership skills, including executive ...

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

See Portland, OR salary details

$24.4K

$120.6K

$159.6K

How much do cybersecurity governance risk compliance jobs pay per year?

As of Aug 9, 2026, the average yearly pay for cybersecurity governance risk compliance in Portland, OR is $120,584.00, according to ZipRecruiter salary data. Most workers in this role earn between $106,000.00 and $136,800.00 per year, depending on experience, location, and employer.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Portland, OR? For Cybersecurity Governance Risk Compliance jobs in Portland, OR, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Portland, OR look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Portland, OR are:
Infographic showing various Cybersecurity Governance Risk Compliance job openings in Portland, OR as of August 2026, with employment types broken down into 93% Full Time, 2% Part Time, 2% Temporary, and 3% Contract. Highlights an 78% In-person, 11% Hybrid, and 11% Remote job distribution, with an average salary of $120,584 per year, or $58 per hour.

Cybersecurity Risk Analyst (REMOTE)

Armavel, LLC

Portland, OR • Remote

$90K - $100K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 29 days ago


Job description

The experienced Risk Analyst role executes the VA Enterprise Risk Analysis process using a custom ERA tool to identify key cyber security risk factors in network connected medical devices and Special Purpose Systems (e.g., building automation systems, physical security systems, operational technology). These risk factors are summarized, evaluated, and reported using quantitative and qualitative scores to provide a VA authorizing official with awareness of the residual cyber risk prior to connecting these devices to the VA network. The Risk Analyst must acquire, review and leverage system documentation and data gathered through questionnaires and interviews with customers in the field and vendor/manufacturer representatives to accurately document critical security posture elements in a common reporting format. These elements include hardware/software inventory, communications profile, system interconnections, data types and stores, and the presence or lack of security controls, settings and mechanisms for a given device type. The Risk Analyst performs annual reviews to support effective continuous monitoring and to ensure documented residual risks are current, accurate, and complete. The analyst works within a Risk Management team and is expected to collaborate with Federal and contractor team mates to achieve best outcomes for the ERA process.

What Makes You Great

  • Experience with Cybersecurity, risk management, or risk assessment for complex systems
  • Experience with NIST SP 800-53 and NIST SP 800-30
  • Experience with documenting and depicting network topology and network protocols
  • Ability to engage directly with clients, and third parties to facilitate enterprise risk analysis
  • Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
  • Bachelor’s degree in Computer Science, Mathematics, Engineering or technical discipline and 10 years of relevant work experience or 18 years of relevant work experience in lieu of degree

Nice If You Have

  • Experience with cybersecurity analysis of medical technology or Internet of Things (IoT)
  • Experience with Governance, Risk, and Compliance (GRC)
  • Experience with Assessment and Authorization (A&A) and eMASS
  • Experience with Excel and Visio
  • CompTIA Security+ or Certified Risk Management Professional (CRISC) or Certified in Risk and Information Systems Control (CRISC)
  • Experience working in the Federal space
  • Excellent communication skills
  • Attention to detail and ability to critically
  • Willingness to learn and strong ability to research
  • Strong organizational skills
  • You must be a US citizen and have the ability to obtain and maintain a government clearance.

Why this position is rewarding

  • Fully remote workforce – work from anywhere in the US!
  • You’ll get lots of work done, and work with a team that likes to hustle.
  • You get to play a big part in important technologies being brought to an entirely new audience and get to work with some cool technology companies.
  • Your work will benefit veterans.

Company Description

Armavel is a fast-growing IT consulting firm that has built a culture founded on a values-first philosophy. We are passionate about delivering results that are timely and world class via an environment that has all the ingredients for our people to thrive. With this in mind, we seek out candidates that demonstrate the following characteristics: honesty, humility, hustle, empathy, resilience, and positivity. These attributes are vital to our company’s growth and are our first priority in our hiring decisions.