Oversee completion of the FFIEC Cybersecurity Assessment Tool (CAT) or equivalent framework; conduct technology and security risk assessments; and provide independent oversight of technology and ...
Cover security, operational, regulatory, and counterparty risk, including the risk register, annual assessments, scenario analyses, and escalation framework across all entities. * Own the Information ...
Information Security Analyst [211364]
Salem, OR · On-site
$46 - $51/hr
Conduct formal risk assessments on partner and vendor connections * Validate data sharing arrangements and agreements * Review third-party SOC reports and security documentation * Establish risk ...
Information Security Analyst [211364]
Salem, OR · On-site
$46 - $51/hr
Conduct formal risk assessments on partner and vendor connections * Validate data sharing arrangements and agreements * Review third-party SOC reports and security documentation * Establish risk ...
Information Security Analyst
Salem, OR · On-site +1
$46 - $51/hr
Conduct formal risk assessments on partner and vendor connections * Validate data sharing arrangements and agreements * Review third-party SOC reports and security documentation * Establish risk ...
Information Security Analyst
Salem, OR · On-site +1
$46 - $51/hr
Conduct formal risk assessments on partner and vendor connections * Validate data sharing arrangements and agreements * Review third-party SOC reports and security documentation * Establish risk ...
... Security, Procurement, Legal, Privacy, Enterprise Risk, IT, Engineering, Finance, and business ... assess, quantify, and manage third party risks across cybersecurity, resiliency, financial ...
... Security, Procurement, Legal, Privacy, Enterprise Risk, IT, Engineering, Finance, and business ... assess, quantify, and manage third party risks across cybersecurity, resiliency, financial ...
Senior Information Security Engineer
$116K - $140K/yr
Conduct risk assessments for new technologies, projects, systems, and business initiatives to evaluate potential security and operational risks. * Provide effective challenge to first-line security ...
New
Senior Information Security Engineer
$116K - $140K/yr
Conduct risk assessments for new technologies, projects, systems, and business initiatives to evaluate potential security and operational risks. * Provide effective challenge to first-line security ...
New
Information Security Analyst
Beaverton, OR · On-site
Perform vendor information risk assessments, review third-party security documentation, and help establish remediation ownership for identified risks. * Assess systems and platforms against security ...
Information Security Analyst
Beaverton, OR · On-site
Perform vendor information risk assessments, review third-party security documentation, and help establish remediation ownership for identified risks. * Assess systems and platforms against security ...
Manager, Third Party Risk Management
OR · On-site +1
... assessment templates, and governance processes to support a scalable, risk-based program. * Partner with Legal, Compliance, Information Security, Affiliate Risk, and business stakeholders to ensure ...
Manager, Third Party Risk Management
OR · On-site +1
... assessment templates, and governance processes to support a scalable, risk-based program. * Partner with Legal, Compliance, Information Security, Affiliate Risk, and business stakeholders to ensure ...
Third-Party Risk Management Program Officer
Hillsboro, OR · On-site
$100K - $126K/yr
Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks. Oversees execution of third party inherent risk assessments, due ...
Third-Party Risk Management Program Officer
Hillsboro, OR · On-site
$100K - $126K/yr
Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks. Oversees execution of third party inherent risk assessments, due ...
Third-Party Risk Management Program Officer
Hillsboro, OR · On-site
$100K - $126K/yr
Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks. * Oversees execution of third party inherent risk assessments, due ...
Third-Party Risk Management Program Officer
Hillsboro, OR · On-site
$100K - $126K/yr
Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks. * Oversees execution of third party inherent risk assessments, due ...
... security posture improvement, and technology risk reduction. This role serves as a technology ... Drive PCI compliance, assessment, and remediation efforts across multiple technology teams. * Lead ...
... security posture improvement, and technology risk reduction. This role serves as a technology ... Drive PCI compliance, assessment, and remediation efforts across multiple technology teams. * Lead ...
Manager, Enterprise Risk Management (ERM)
$131K - $157K/yr
This role provides Second Line of Defense (2LOD) oversight through risk assessments, governance ... Partner with Compliance, Credit Risk, Information Security Risk, Financial Crimes, Internal Audit ...
Manager, Enterprise Risk Management (ERM)
$131K - $157K/yr
This role provides Second Line of Defense (2LOD) oversight through risk assessments, governance ... Partner with Compliance, Credit Risk, Information Security Risk, Financial Crimes, Internal Audit ...
Security Compliance Manager
OR · Remote
$140K - $170K/yr
Strong competency in gap analysis and risk assessment methodologies; able to translate results into prioritized remediation plans. * Working knowledge of security policy, procedure, and enforcement ...
Security Compliance Manager
OR · Remote
$140K - $170K/yr
Strong competency in gap analysis and risk assessment methodologies; able to translate results into prioritized remediation plans. * Working knowledge of security policy, procedure, and enforcement ...
Manager Information Security - Cyber Threat Exposure
OR · Remote
$104K - $140K/yr
What We Look For in a Candidate Minimum Qualifications: * 5+ years of experience in information security, vulnerability management, security risk assessment, application security, system security ...
Manager Information Security - Cyber Threat Exposure
OR · Remote
$104K - $140K/yr
What We Look For in a Candidate Minimum Qualifications: * 5+ years of experience in information security, vulnerability management, security risk assessment, application security, system security ...
Information Security Analyst 2
Beaverton, OR · On-site
Information Security Analyst 2 Reference ID: 26-03235 Location: Beaverton, OR. Duration: 08 months ... Third party risk assessment * Auditing * ServiceNow experience * JIRA * Microsoft Office Suite ...
Information Security Analyst 2
Beaverton, OR · On-site
Information Security Analyst 2 Reference ID: 26-03235 Location: Beaverton, OR. Duration: 08 months ... Third party risk assessment * Auditing * ServiceNow experience * JIRA * Microsoft Office Suite ...
Network Security Architecture Risk Lead
$141K - $237K/yr
Identify, assess, and document controls and risks across Network and Security Architecture ... Support Tech Risk teams responsible for risk monitoring, periodic controls testing, evidence ...
New
Network Security Architecture Risk Lead
$141K - $237K/yr
Identify, assess, and document controls and risks across Network and Security Architecture ... Support Tech Risk teams responsible for risk monitoring, periodic controls testing, evidence ...
New
Senior Security Analyst
OR · Remote
$95K - $125K/yr
Participate in security risk assessments, gap analyses, and audits (internal and external), including support for third-party assessments. Develop and maintain security policies, standards, and ...
Senior Security Analyst
OR · Remote
$95K - $125K/yr
Participate in security risk assessments, gap analyses, and audits (internal and external), including support for third-party assessments. Develop and maintain security policies, standards, and ...
Senior Security Analyst
OR · Remote
$95K - $125K/yr
Participate in security risk assessments, gap analyses, and audits (internal and external), including support for third-party assessments. Develop and maintain security policies, standards, and ...
Quick apply
Senior Security Analyst
OR · Remote
$95K - $125K/yr
Participate in security risk assessments, gap analyses, and audits (internal and external), including support for third-party assessments. Develop and maintain security policies, standards, and ...
Information Risk Analyst - AI
Portland, OR · On-site
... * 5 IRM team members whoperform Risk assessments for applications and projects ... A Security Analyst orInformation Risk Analyst with exposure, training, and maybe 1-2 projectscould ...
Information Risk Analyst - AI
Portland, OR · On-site
... * 5 IRM team members whoperform Risk assessments for applications and projects ... A Security Analyst orInformation Risk Analyst with exposure, training, and maybe 1-2 projectscould ...
Info Security Engineer II
$87K - $134K/yr
System security assessments * Vulnerability management * Security risk management * Experience with FIPS, NIST 800-53/CSF, or other relevant frameworks * Notable cloud security experience * Relevant ...
Info Security Engineer II
$87K - $134K/yr
System security assessments * Vulnerability management * Security risk management * Experience with FIPS, NIST 800-53/CSF, or other relevant frameworks * Notable cloud security experience * Relevant ...
Security Risk Assessment information
See Oregon salary details
$10.93 - $16.66
2% of jobs
$16.66 - $22.39
0% of jobs
$22.39 - $28.12
1% of jobs
$28.12 - $33.85
1% of jobs
$33.85 - $39.58
1% of jobs
$43.88 is the 25th percentile. Wages below this are outliers.
$39.58 - $45.31
26% of jobs
$45.31 - $51.04
11% of jobs
The median wage is $53.09 / hr.
$51.04 - $56.77
22% of jobs
$56.77 - $62.50
9% of jobs
$62.95 is the 75th percentile. Wages above this are outliers.
$62.50 - $68.23
17% of jobs
$68.23 - $73.96
9% of jobs
$10
$53
$73
How much do security risk assessment jobs pay per hour?
What is a Security Risk Assessment job?
A Security Risk Assessment job involves identifying, analyzing, and mitigating potential security threats to an organization's systems, data, and operations. Professionals in this role evaluate vulnerabilities, assess risks, and recommend security controls to protect against cyber threats, fraud, and compliance issues. They work with IT teams, management, and stakeholders to ensure security measures align with business objectives and regulatory requirements. This job often requires knowledge of cybersecurity frameworks, risk management methodologies, and relevant industry standards.
What are the key skills and qualifications needed to thrive in the Security Risk Assessment position, and why are they important?
To thrive in Security Risk Assessment, a strong background in risk analysis, information security principles, and regulatory compliance is essential, often supported by a degree in cybersecurity or related fields. Familiarity with risk assessment tools, frameworks like NIST or ISO 27001, and certifications such as CISSP or CISA are highly valued. Exceptional attention to detail, analytical thinking, and effective communication skills set top professionals apart in this role. These competencies enable accurate identification of potential security threats and development of strategic mitigation plans, which are crucial for safeguarding organizational assets.
What are some common challenges faced in a Security Risk Assessment role?
Professionals in Security Risk Assessment often face the challenge of keeping up with constantly evolving cyber threats and adapting assessment methodologies accordingly. Balancing thorough analysis with the need to provide timely recommendations can be demanding, especially when collaborating with multiple departments or stakeholders. Additionally, communicating complex risk findings to non-technical audiences requires both clarity and diplomacy. Overcoming these challenges is critical for delivering actionable insights that drive effective security decision-making and protect organizational assets.

Job description
The Team:Â
Upstart's Risk team is enhancing its second line of defense function in support of our application to establish Upstart Bank, N.A., a de novo national bank. The Risk team is responsible for Upstart's enterprise risk management program and risk governance, and for providing independent oversight and credible challenge across all core risk categories- including operational risk, third party risk, technology and information security risk, and treasury risk. We partner with first-line business functions, senior and executive leadership, and the board of directors to ensure effective identification, assessment, monitoring, reporting, and control of material risks, in alignment with OCC, FDIC, and FFIEC regulatory expectations.
As the Senior Manager, Technology Risk you will lead the second-line technology and information security risk oversight program for Upstart Bank. You will establish the bank's 2LOD technology risk framework- leveraging and enhancing Upstart's existing technology and information security risk infrastructure to meet bank regulatory standards- and will provide independent oversight and credible challenge of the first-line technology and information security functions across all technology domains, including IT operations, cybersecurity, cloud infrastructure, affiliate-provided technology, and core banking systems. This role reports to the head of third party and technology risk and manages a team of two technology and security risk professionals.Â
How you'll make an impact
- Provide independent second-line review and credible challenge of first-line technology and information security activities, including but not limited to: cybersecurity controls, software development lifecycle (SDLC) and incident response programs, technology resiliency and third-party arrangements
- Oversee completion of the FFIEC Cybersecurity Assessment Tool (CAT) or equivalent framework; conduct technology and security risk assessments; and provide independent oversight of technology and security risks in alignment with OCC guidance on cloud computing
- Serve as a primary second-line point of contact for OCC examiners, internal audit, and other external stakeholders on technology risk and information security program topics and inquiries; prepare and deliver technology risk reporting to risk committees, the CRO, and the board.Â
- Build and lead a growing Technology Risk team, shaping how the bank identifies, prioritizes, and responds to its most important technology and security risks in alignment with applicable industry regulations
- Partner with first-line IT and cybersecurity teams, TPRM, ERM, Legal, and Compliance to ensure technology and information security risk is integrated into enterprise risk programs, cross-functional risk assessments, and the bank's overall 2LOD reporting and governance structure
Minimum QualificationsÂ
- Bachelor's degree or equivalent practical experience in information technology, cybersecurity, or a related field
- 8+ years of experience in technology risk, information security risk management, IT audit, or GRC in a banking or financial services environment
- 3+ years of direct people management experience leading technology risk, information security governance, risk, and compliance, or information technology audit professionals
- Demonstrated experience applying FFIEC IT Examination Handbook standards and OCC guidance on technology risk and information security in a bank or federally regulated institution
- Experience engaging banking regulators (OCC, FDIC, or Federal Reserve) on technology risk, cybersecurity, or IT controls examination matters
Preferred Qualifications
- Experience building or significantly enhancing a technology risk or information security GRC program in a de novo bank, early-stage bank, or similar environment where the program required meaningful design and build-out
- Knowledge of cloud risk management and OCC/FFIEC guidance on cloud computing (OCC Bulletin 2020-46), particularly in cloud-native or fintech-adjacent technology environments
- Familiarity with affiliate technology risk oversight, including independent oversight of bank-affiliate technology service arrangements, associated data segregation requirements, and Regulation W implications
- Experience with GRC tool implementation or administration in a bank regulatory context
- Current professional certification in information security or technology risk management (CISSP, CISA, CRISC, CISM, or comparable)
- Knowledge of AI/ML technology risk and related governance considerations in a fintech, lending, or model-intensive operating environment
Position location This role is available in the following locations: RemoteÂ
Travel requirements As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S but are encouraged to to still spend high quality time in-person collaborating via regular onsites. The in-person sessions' cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.
#LI-REMOTE
#LI-MidSeniorÂ