As the Senior Manager, Technology Risk you will lead the second-line technology and information security risk oversight program for Upstart Bank. You will establish the bank's 2LOD technology risk ...
... analyses, and escalation framework across all entities. * Own the Information Security Compliance ... Senior Counsel on information security representations in commercial agreements. * Build ...
Information Risk Analyst - AI
Portland, OR · On-site
Information Risk Analyst - AI Duration: 12 Months - (Possible Extensions) Location: Portland, OR ... A Security Analyst orInformation Risk Analyst with exposure, training, and maybe 1-2 projectscould ...
Information Risk Analyst - AI
Portland, OR · On-site
Information Risk Analyst - AI Duration: 12 Months - (Possible Extensions) Location: Portland, OR ... A Security Analyst orInformation Risk Analyst with exposure, training, and maybe 1-2 projectscould ...
OR · On-site
$125K - $225K/yr
In this role, you will serve as the senior information security partner within designated business ... Strategic Alignment & Risk Management * Develop and execute cybersecurity strategies that align ...
Senior IT Security Engineer
OR · Remote
$130K - $155K/yr
... analysis and control design through evidence collection, audit coordination, and successful ... Build and mature NetBrain's GRC (Governance, Risk & Compliance) program - conduct risk assessments ...
Senior IT Security Engineer
OR · Remote
$130K - $155K/yr
... analysis and control design through evidence collection, audit coordination, and successful ... Build and mature NetBrain's GRC (Governance, Risk & Compliance) program - conduct risk assessments ...
Are you an experienced Security Data and Risk Analyst that wants to develop and create awareness ... You will be a leader in our Information Security Group which is a global team of experienced ...
Are you an experienced Security Data and Risk Analyst that wants to develop and create awareness ... You will be a leader in our Information Security Group which is a global team of experienced ...
Senior Principal Risk Analyst
Tualatin, OR · On-site
Senior/Principal Risk Analyst Duration: 12 Months Location: Tualatin, OR - Local Preffered Open to Remote caniddate from PST or MST time zones. Description PGE seeks a Senior or Principal Risk ...
Senior Principal Risk Analyst
Tualatin, OR · On-site
Senior/Principal Risk Analyst Duration: 12 Months Location: Tualatin, OR - Local Preffered Open to Remote caniddate from PST or MST time zones. Description PGE seeks a Senior or Principal Risk ...
Sr Third Party Risk Analyst (TPRM)
$87K - $111K/yr
As a Senior Third Party Risk Analyst , you'll play a critical role in ensuring the security ... information security, cybersecurity, or technical/analytical roles . * Experience operating in ...
Sr Third Party Risk Analyst (TPRM)
$87K - $111K/yr
As a Senior Third Party Risk Analyst , you'll play a critical role in ensuring the security ... information security, cybersecurity, or technical/analytical roles . * Experience operating in ...
This is a hands-on individual contributor role designed for a senior technical security ... Risk management: Identify, document, and track information security risks; propose mitigations and ...
This is a hands-on individual contributor role designed for a senior technical security ... Risk management: Identify, document, and track information security risks; propose mitigations and ...
Senior IT GRC Analyst
Hillsboro, OR · On-site
$80K - $165K/yr
Perform formal risk analysis and self-assessments for technology processes, leveraging industry ... Knowledge of risk management processes including internal audit and information security management.
Senior IT GRC Analyst
Hillsboro, OR · On-site
$80K - $165K/yr
Perform formal risk analysis and self-assessments for technology processes, leveraging industry ... Knowledge of risk management processes including internal audit and information security management.
The Business Information Security Officer (BISO) is responsible for driving security risk ... Strong analytical, decision-making, and problem-solving capabilities * Demonstrated ability to ...
The Business Information Security Officer (BISO) is responsible for driving security risk ... Strong analytical, decision-making, and problem-solving capabilities * Demonstrated ability to ...
OR · Hybrid
Collect, generate, and validate exposure data, loss runs, and other information for annual ... Limited travel may be required for meetings, training, or project support Security Clearance ...
Senior IT GRC Analyst
Hillsboro, OR · On-site
$80K - $165K/yr
Perform formal risk analysis and self-assessments for technology processes, leveraging industry ... Knowledge of risk management processes including internal audit and information security management.
Senior IT GRC Analyst
Hillsboro, OR · On-site
$80K - $165K/yr
Perform formal risk analysis and self-assessments for technology processes, leveraging industry ... Knowledge of risk management processes including internal audit and information security management.
OR · On-site
Be ready to: * conduct information security risk assessments of vendors and vendor software, based ... cost analysis, audit support and coordination, product renewals, and performance monitoring Be ...
OR · On-site
Be ready to: * conduct information security risk assessments of vendors and vendor software, based ... cost analysis, audit support and coordination, product renewals, and performance monitoring Be ...
Senior Governance, Risk, and Compliance(GRC) Process Analyst Company: The Boeing Company Boeing is ... This role will partner with Information Security, IT&O, Internal Audit, Compliance, SOX, External ...
Senior Governance, Risk, and Compliance(GRC) Process Analyst Company: The Boeing Company Boeing is ... This role will partner with Information Security, IT&O, Internal Audit, Compliance, SOX, External ...
Senior Governance, Risk, and Compliance(GRC) Process Analyst Company: The Boeing Company Boeing is ... This role will partner with Information Security, IT&O, Internal Audit, Compliance, SOX, External ...
Senior Governance, Risk, and Compliance(GRC) Process Analyst Company: The Boeing Company Boeing is ... This role will partner with Information Security, IT&O, Internal Audit, Compliance, SOX, External ...
Risk Analyst
Beaverton, OR · On-site
* Knowledge of information securityprinciples and practices, general procedures and guidelines. * A ... The ability to appropriately communicatecomplex security risks to non-technical staff * Must be ...
Risk Analyst
Beaverton, OR · On-site
* Knowledge of information securityprinciples and practices, general procedures and guidelines. * A ... The ability to appropriately communicatecomplex security risks to non-technical staff * Must be ...
OR · Hybrid
A Security Architect is a senior technical leader responsible for the design and continuous ... and risk tradeoffs. Internally, this role mentors security engineers and analysts to develop ...
Information Security VM Analyst
Tualatin, OR · On-site
More broadly, this role also contributes to risk management and compliance efforts, helping ensure ... Who we're looking for Knowledge of information security industry and regulatory obligations (ISO ...
Information Security VM Analyst
Tualatin, OR · On-site
More broadly, this role also contributes to risk management and compliance efforts, helping ensure ... Who we're looking for Knowledge of information security industry and regulatory obligations (ISO ...
EFT Risk Analyst
OR · On-site +1
$44K - $65K/yr
Present reporting and findings to senior & executive management monthly. * Perform self-testing of ... Please see the description of benefits included with this job posting for additional information.
EFT Risk Analyst
OR · On-site +1
$44K - $65K/yr
Present reporting and findings to senior & executive management monthly. * Perform self-testing of ... Please see the description of benefits included with this job posting for additional information.
Senior Information Security Risk Analyst information
See Oregon salary details
$33.80 - $37.98
6% of jobs
$37.98 - $42.17
5% of jobs
$42.17 - $46.35
8% of jobs
$48.33 is the 25th percentile. Wages below this are outliers.
$46.35 - $50.53
11% of jobs
$50.53 - $54.71
12% of jobs
The median wage is $58.63 / hr.
$54.71 - $58.89
8% of jobs
$58.89 - $63.08
7% of jobs
$63.08 - $67.26
9% of jobs
$69.15 is the 75th percentile. Wages above this are outliers.
$67.26 - $71.44
17% of jobs
$71.44 - $75.62
8% of jobs
$75.62 - $79.80
7% of jobs
$33
$61
$79
How much do senior information security risk analyst jobs pay per hour?
What is the difference between Senior Information Security Risk Analyst vs Information Security Analyst?
| Aspect | Senior Information Security Risk Analyst | Information Security Analyst |
|---|---|---|
| Certifications | CISSP, CISA, CRISC | CISSP, Security+, CEH |
| Work Environment | Focus on risk assessment, policy development, and strategic planning | Implementing security measures, monitoring, and incident response |
| Employer & Industry Usage | Financial, healthcare, and large enterprises with complex security needs | Variety of industries, including tech, retail, and government |
Senior Information Security Risk Analysts typically handle advanced risk assessments and strategic security planning, often requiring certifications like CISSP or CISA. Information Security Analysts focus on implementing security controls and monitoring systems. Both roles are vital in maintaining organizational security but differ in scope and seniority.
How does a Senior Information Security Risk Analyst typically collaborate with other departments to manage organizational risk?
What are the key skills and qualifications needed to thrive as a Senior Information Security Risk Analyst, and why are they important?
What does a Senior Information Security Risk Analyst do?

Job description
The Team:Â
Upstart's Risk team is enhancing its second line of defense function in support of our application to establish Upstart Bank, N.A., a de novo national bank. The Risk team is responsible for Upstart's enterprise risk management program and risk governance, and for providing independent oversight and credible challenge across all core risk categories- including operational risk, third party risk, technology and information security risk, and treasury risk. We partner with first-line business functions, senior and executive leadership, and the board of directors to ensure effective identification, assessment, monitoring, reporting, and control of material risks, in alignment with OCC, FDIC, and FFIEC regulatory expectations.
As the Senior Manager, Technology Risk you will lead the second-line technology and information security risk oversight program for Upstart Bank. You will establish the bank's 2LOD technology risk framework- leveraging and enhancing Upstart's existing technology and information security risk infrastructure to meet bank regulatory standards- and will provide independent oversight and credible challenge of the first-line technology and information security functions across all technology domains, including IT operations, cybersecurity, cloud infrastructure, affiliate-provided technology, and core banking systems. This role reports to the head of third party and technology risk and manages a team of two technology and security risk professionals.Â
How you'll make an impact
- Provide independent second-line review and credible challenge of first-line technology and information security activities, including but not limited to: cybersecurity controls, software development lifecycle (SDLC) and incident response programs, technology resiliency and third-party arrangements
- Oversee completion of the FFIEC Cybersecurity Assessment Tool (CAT) or equivalent framework; conduct technology and security risk assessments; and provide independent oversight of technology and security risks in alignment with OCC guidance on cloud computing
- Serve as a primary second-line point of contact for OCC examiners, internal audit, and other external stakeholders on technology risk and information security program topics and inquiries; prepare and deliver technology risk reporting to risk committees, the CRO, and the board.Â
- Build and lead a growing Technology Risk team, shaping how the bank identifies, prioritizes, and responds to its most important technology and security risks in alignment with applicable industry regulations
- Partner with first-line IT and cybersecurity teams, TPRM, ERM, Legal, and Compliance to ensure technology and information security risk is integrated into enterprise risk programs, cross-functional risk assessments, and the bank's overall 2LOD reporting and governance structure
Minimum QualificationsÂ
- Bachelor's degree or equivalent practical experience in information technology, cybersecurity, or a related field
- 8+ years of experience in technology risk, information security risk management, IT audit, or GRC in a banking or financial services environment
- 3+ years of direct people management experience leading technology risk, information security governance, risk, and compliance, or information technology audit professionals
- Demonstrated experience applying FFIEC IT Examination Handbook standards and OCC guidance on technology risk and information security in a bank or federally regulated institution
- Experience engaging banking regulators (OCC, FDIC, or Federal Reserve) on technology risk, cybersecurity, or IT controls examination matters
Preferred Qualifications
- Experience building or significantly enhancing a technology risk or information security GRC program in a de novo bank, early-stage bank, or similar environment where the program required meaningful design and build-out
- Knowledge of cloud risk management and OCC/FFIEC guidance on cloud computing (OCC Bulletin 2020-46), particularly in cloud-native or fintech-adjacent technology environments
- Familiarity with affiliate technology risk oversight, including independent oversight of bank-affiliate technology service arrangements, associated data segregation requirements, and Regulation W implications
- Experience with GRC tool implementation or administration in a bank regulatory context
- Current professional certification in information security or technology risk management (CISSP, CISA, CRISC, CISM, or comparable)
- Knowledge of AI/ML technology risk and related governance considerations in a fintech, lending, or model-intensive operating environment
Position location This role is available in the following locations: RemoteÂ
Travel requirements As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S but are encouraged to to still spend high quality time in-person collaborating via regular onsites. The in-person sessions' cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.
#LI-REMOTE
#LI-MidSeniorÂ