Conducting risk assessments across privacy, security, model risk, and misuse scenarios, including prompt injection, sensitive data exposure, excessive agency, and overreliance, and translating ...
Conducting risk assessments across privacy, security, model risk, and misuse scenarios, including prompt injection, sensitive data exposure, excessive agency, and overreliance, and translating ...
Lead Cloud Security Analyst
Portland, OR · On-site
Risk Assessment and Remediation: * Conduct comprehensive risk reviews for cloud and infrastructure ... Security Architecture * Business Partnership Qualifications Required: * Bachelor's Degree or ...
Lead Cloud Security Analyst
Portland, OR · On-site
Risk Assessment and Remediation: * Conduct comprehensive risk reviews for cloud and infrastructure ... Security Architecture * Business Partnership Qualifications Required: * Bachelor's Degree or ...
Embedded Security Manager
Wilsonville, OR · On-site
Embedded Security Manager Portland, Oregon On-Site at Client's Office in Downtown Portland Pay ... assessment, behavioral risk evaluation, training, reporting, documentation, and response ...
Quick apply
Embedded Security Manager
Wilsonville, OR · On-site
Embedded Security Manager Portland, Oregon On-Site at Client's Office in Downtown Portland Pay ... assessment, behavioral risk evaluation, training, reporting, documentation, and response ...
Embedded Security Manager
Wilsonville, OR · On-site
$80K - $95K/yr
Embedded Security Manager Portland, Oregon On-Site at Client's Office in Downtown Portland Pay ... assessment, behavioral risk evaluation, training, reporting, documentation, and response ...
Embedded Security Manager
Wilsonville, OR · On-site
$80K - $95K/yr
Embedded Security Manager Portland, Oregon On-Site at Client's Office in Downtown Portland Pay ... assessment, behavioral risk evaluation, training, reporting, documentation, and response ...
Embedded Security Manager Portland, Oregon On-Site at Client's Office in Downtown Portland Pay ... assessment, behavioral risk evaluation, training, reporting, documentation, and response ...
Embedded Security Manager Portland, Oregon On-Site at Client's Office in Downtown Portland Pay ... assessment, behavioral risk evaluation, training, reporting, documentation, and response ...
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
Senior Operations Engineer
Portland, OR · On-site
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
Senior Operations Engineer
Portland, OR · On-site
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
Senior Operations Engineer
Gresham, OR · On-site
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
Senior Operations Engineer
Gresham, OR · On-site
The Senior Operations Engineer reduces endpoint security risk across the enterprise by leading ... Review, assess, and prioritize vulnerabilities based on CVSS scores, exploitability, growth, and ...
Trade Compliance Risk & Supply Chain Analyst II
Portland, OR · Hybrid
$78K - $100K/yr
Responsible for supply chain security assessments, export compliance screening, forced labor due diligence, supplier risk monitoring, supply chain mapping, regulatory reporting, compliance ...
Trade Compliance Risk & Supply Chain Analyst II
Portland, OR · Hybrid
$78K - $100K/yr
Responsible for supply chain security assessments, export compliance screening, forced labor due diligence, supplier risk monitoring, supply chain mapping, regulatory reporting, compliance ...
Trade Compliance Risk & Supply Chain Analyst II
Portland, OR · On-site
$78K - $100K/yr
Responsible for supply chain security assessments, export compliance screening, forced labor due diligence, supplier risk monitoring, supply chain mapping, regulatory reporting, compliance ...
Trade Compliance Risk & Supply Chain Analyst II
Portland, OR · On-site
$78K - $100K/yr
Responsible for supply chain security assessments, export compliance screening, forced labor due diligence, supplier risk monitoring, supply chain mapping, regulatory reporting, compliance ...
Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires ... vendor due diligence). * Partner with Legal and Privacy on data protection, regulatory, and ...
Quick apply
Manage third-party/vendor risk assessments and questionnaires (customer security questionnaires ... vendor due diligence). * Partner with Legal and Privacy on data protection, regulatory, and ...
Agentic AI Security Engineer
OR · On-site +1
Build mechanisms for continuous AI risk assessment and operational visibility. Secure AI Development * Partner with software engineers to integrate AI security into development workflows. * Conduct ...
Agentic AI Security Engineer
OR · On-site +1
Build mechanisms for continuous AI risk assessment and operational visibility. Secure AI Development * Partner with software engineers to integrate AI security into development workflows. * Conduct ...
Staff Security Engineer (Blue Team)
OR · On-site +1
Reporting to the Security Engineering Director, the Staff Security Engineer will act as technical ... Oversee Vulnerability Management program including vulnerability assessments, risk scoring and ...
Staff Security Engineer (Blue Team)
OR · On-site +1
Reporting to the Security Engineering Director, the Staff Security Engineer will act as technical ... Oversee Vulnerability Management program including vulnerability assessments, risk scoring and ...
Cyber Security Analyst
Portland, OR · On-site
Conducts risk assessment and provides recommendations for application design. Involved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network ...
Cyber Security Analyst
Portland, OR · On-site
Conducts risk assessment and provides recommendations for application design. Involved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network ...
IT Risk and Compliance Analyst
Portland, OR · On-site
$99K - $100K/yr
This role involves supporting IT risk governance internal and external assessments and audits and ... security goals. * Provide independent oversight of the risk management activities of the Service ...
Quick apply
IT Risk and Compliance Analyst
Portland, OR · On-site
$99K - $100K/yr
This role involves supporting IT risk governance internal and external assessments and audits and ... security goals. * Provide independent oversight of the risk management activities of the Service ...
Principal Platform Security Engineer
OR · On-site +1
$142K/yr
Experience leading security architecture reviews or technical risk assessments for complex production systems. * Experience designing and implementing preventative security controls, guardrails, or ...
Principal Platform Security Engineer
OR · On-site +1
$142K/yr
Experience leading security architecture reviews or technical risk assessments for complex production systems. * Experience designing and implementing preventative security controls, guardrails, or ...
Director, Information Security
OR · On-site +1
Oversee risk assessments, privacy impact analyses, and security reviews. * Maintain and evolve the incident response program in partnership with Legal, Privacy, ISP, and Quality and Regulatory teams.
Director, Information Security
OR · On-site +1
Oversee risk assessments, privacy impact analyses, and security reviews. * Maintain and evolve the incident response program in partnership with Legal, Privacy, ISP, and Quality and Regulatory teams.
Security Risk Assessment information
See Oregon salary details
$10.93 - $16.66
2% of jobs
$16.66 - $22.39
0% of jobs
$22.39 - $28.12
1% of jobs
$28.12 - $33.85
1% of jobs
$33.85 - $39.58
1% of jobs
$43.88 is the 25th percentile. Wages below this are outliers.
$39.58 - $45.31
26% of jobs
$45.31 - $51.04
11% of jobs
The median wage is $53.09 / hr.
$51.04 - $56.77
22% of jobs
$56.77 - $62.50
9% of jobs
$62.95 is the 75th percentile. Wages above this are outliers.
$62.50 - $68.23
17% of jobs
$68.23 - $73.96
9% of jobs
$10
$53
$73
How much do security risk assessment jobs pay per hour?
What is a security risk assessment?
A Security Risk Assessment job involves identifying, analyzing, and mitigating potential security threats to an organization's systems, data, and operations. Professionals in this role evaluate vulnerabilities, assess risks, and recommend security controls to protect against cyber threats, fraud, and compliance issues. They work with IT teams, management, and stakeholders to ensure security measures align with business objectives and regulatory requirements. This job often requires knowledge of cybersecurity frameworks, risk management methodologies, and relevant industry standards.
What are the key skills and qualifications needed for security risk assessment?
To thrive in Security Risk Assessment, a strong background in risk analysis, information security principles, and regulatory compliance is essential, often supported by a degree in cybersecurity or related fields. Familiarity with risk assessment tools, frameworks like NIST or ISO 27001, and certifications such as CISSP or CISA are highly valued. Exceptional attention to detail, analytical thinking, and effective communication skills set top professionals apart in this role. These competencies enable accurate identification of potential security threats and development of strategic mitigation plans, which are crucial for safeguarding organizational assets.
What are some common challenges faced in a security risk assessment role?
Professionals in Security Risk Assessment often face the challenge of keeping up with constantly evolving cyber threats and adapting assessment methodologies accordingly. Balancing thorough analysis with the need to provide timely recommendations can be demanding, especially when collaborating with multiple departments or stakeholders. Additionally, communicating complex risk findings to non-technical audiences requires both clarity and diplomacy. Overcoming these challenges is critical for delivering actionable insights that drive effective security decision-making and protect organizational assets.
What are the most commonly searched types of Security Risk Assessment jobs in Oregon?
The most popular types of Security Risk Assessment jobs in Oregon are:
What are popular job titles related to Security Risk Assessment jobs in Oregon?
For Security Risk Assessment jobs in Oregon, the most frequently searched job titles are:
What job categories do people searching Security Risk Assessment jobs in Oregon look for?
The top searched job categories for Security Risk Assessment jobs in Oregon are:

Deloitte rating
8.2
Based on 93 frontline employees who took The Breakroom Quiz
47th of 154 rated financial services
Job description
We are seeking an AI Governance and Privacy Consultant who can operationalize responsible AI in real systems-especially agentic AI and LLM-enabled applications. This role blends governance and privacy expertise with enough software development fluency to create developer-ready guidance, implement controls-as-code patterns, and stand up measurable evaluation and monitoring workflows.
As a Senior Consultant, you will help clients and internal delivery teams move from AI principles to practices: risk tiering, model and agent inventories, technical guardrails, governance workflows integrated into the SDLC, and evidence artifacts suitable for audits and regulators.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Consultant, Strategy, Growth and Transformation on the Cyber team, you will be responsible for:
- Designing and implementing AI governance operating models, intake workflows, risk tiering, approvals, documentation standards, exception handling, and audit-ready evidence processes for generative AI and agentic AI deployments.
- Building and maintaining inventories for models, agents, tools, data sources, and integrations, with defined ownership, intended use, risk classification, and change-control requirements.
- Conducting risk assessments across privacy, security, model risk, and misuse scenarios, including prompt injection, sensitive data exposure, excessive agency, and overreliance, and translating findings into implementable mitigations.
- Establishing technical control guidance for teams building agentic AI solutions, including human-in-the-loop patterns, tool access controls, retrieval and grounding practices, logging, monitoring, token and data minimization, and incident response playbooks.
- Integrating governance checkpoints into product and engineering delivery through architecture reviews, release gates, evaluation requirements, documentation automation, evidence capture, dashboards, and cross-functional collaboration with Cybersecurity, Privacy, Legal, Risk, Engineering, and Data Science teams.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
You will join a cross-functional group working at the intersection of cyber, privacy, governance, and emerging AI delivery. The team helps organizations scale AI responsibly by combining governance and engineering patterns so teams can innovate faster without compromising trust.
Qualifications
Required:
- Bachelor's degree or equivalent practical experience.
- 2+ years of experience in AI governance, data privacy, security risk management, compliance and controls, AI product risk, model risk management, or technology risk consulting.
- Experience translating policies and regulatory expectations into operational workflows and artifacts, including intake processes, inventories, decision logs, risk registers, responsibility assignment matrices, playbooks, privacy impact assessments, and data protection impact assessments.
- Experience assessing AI, machine learning, and LLM deployment patterns, including training, retrieval-augmented generation, fine-tuning, tool use, data dependencies, and integration patterns, and defining mitigations for privacy, security, model risk, and misuse.
- Experience prototyping or automating governance workflows using Python or Structured Query Language and working with continuous integration and continuous deployment pipelines and cloud deployment basics.
- Ability to travel 0-50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience in consulting or a Big 4 environment.
- Experience operationalizing AI governance aligned to the National Institute of Standards and Technology AI Risk Management Framework or ISO/IEC 42001.
- Experience with generative AI safety and evaluation practices, including prompt injection testing, jailbreak resilience, hallucination measurement, toxicity scoring, harm scoring, and grounding effectiveness.
- Experience with governance, workflow, or ticketing platforms, including OneTrust and governance, risk, and compliance systems, and integrating those platforms into engineering delivery processes.
- Certifications such as Certified Information Privacy Professional/United States, Certified Information Privacy Manager, International Association of Privacy Professionals AI Governance Professional, Certified Information Security Manager, or Certified Information Systems Security Professional.
- Experience in cyber or enterprise security environments, including data security, identity, audit logging, secure software development lifecycle practices, human-in-the-loop escalation pathways, exception handling, and automated safety protocols for autonomous systems.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600-$162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberDTP27
We are seeking an AI Governance and Privacy Consultant who can operationalize responsible AI in real systems-especially agentic AI and LLM-enabled applications. This role blends governance and privacy expertise with enough software development fluency to create developer-ready guidance, implement controls-as-code patterns, and stand up measurable evaluation and monitoring workflows.
As a Senior Consultant, you will help clients and internal delivery teams move from AI principles to practices: risk tiering, model and agent inventories, technical guardrails, governance workflows integrated into the SDLC, and evidence artifacts suitable for audits and regulators.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Consultant, Strategy, Growth and Transformation on the Cyber team, you will be responsible for:
- Designing and implementing AI governance operating models, intake workflows, risk tiering, approvals, documentation standards, exception handling, and audit-ready evidence processes for generative AI and agentic AI deployments.
- Building and maintaining inventories for models, agents, tools, data sources, and integrations, with defined ownership, intended use, risk classification, and change-control requirements.
- Conducting risk assessments across privacy, security, model risk, and misuse scenarios, including prompt injection, sensitive data exposure, excessive agency, and overreliance, and translating findings into implementable mitigations.
- Establishing technical control guidance for teams building agentic AI solutions, including human-in-the-loop patterns, tool access controls, retrieval and grounding practices, logging, monitoring, token and data minimization, and incident response playbooks.
- Integrating governance checkpoints into product and engineering delivery through architecture reviews, release gates, evaluation requirements, documentation automation, evidence capture, dashboards, and cross-functional collaboration with Cybersecurity, Privacy, Legal, Risk, Engineering, and Data Science teams.
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
You will join a cross-functional group working at the intersection of cyber, privacy, governance, and emerging AI delivery. The team helps organizations scale AI responsibly by combining governance and engineering patterns so teams can innovate faster without compromising trust.
Qualifications
Required:
- Bachelor's degree or equivalent practical experience.
- 2+ years of experience in AI governance, data privacy, security risk management, compliance and controls, AI product risk, model risk management, or technology risk consulting.
- Experience translating policies and regulatory expectations into operational workflows and artifacts, including intake processes, inventories, decision logs, risk registers, responsibility assignment matrices, playbooks, privacy impact assessments, and data protection impact assessments.
- Experience assessing AI, machine learning, and LLM deployment patterns, including training, retrieval-augmented generation, fine-tuning, tool use, data dependencies, and integration patterns, and defining mitigations for privacy, security, model risk, and misuse.
- Experience prototyping or automating governance workflows using Python or Structured Query Language and working with continuous integration and continuous deployment pipelines and cloud deployment basics.
- Ability to travel 0-50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- Experience in consulting or a Big 4 environment.
- Experience operationalizing AI governance aligned to the National Institute of Standards and Technology AI Risk Management Framework or ISO/IEC 42001.
- Experience with generative AI safety and evaluation practices, including prompt injection testing, jailbreak resilience, hallucination measurement, toxicity scoring, harm scoring, and grounding effectiveness.
- Experience with governance, workflow, or ticketing platforms, including OneTrust and governance, risk, and compliance systems, and integrating those platforms into engineering delivery processes.
- Certifications such as Certified Information Privacy Professional/United States, Certified Information Privacy Manager, International Association of Privacy Professionals AI Governance Professional, Certified Information Security Manager, or Certified Information Systems Security Professional.
- Experience in cyber or enterprise security environments, including data security, identity, audit logging, secure software development lifecycle practices, human-in-the-loop escalation pathways, exception handling, and automated safety protocols for autonomous systems.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600-$162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
#CyberDTP27
About Deloitte
Sourced by ZipRecruiter
Industry
Finance and insurance and business management consulting
Company size
10,000+ Employees
Headquarters location
Orlando, FL, US