1

Senior Information Security Risk Analyst Jobs in Oregon

As the Senior Manager, Technology Risk you will lead the second-line technology and information security risk oversight program for Upstart Bank. You will establish the bank's 2LOD technology risk ...

... analyses, and escalation framework across all entities. * Own the Information Security Compliance ... Senior Counsel on information security representations in commercial agreements. * Build ...

OR · On-site

$125K - $225K/yr

In this role, you will serve as the senior information security partner within designated business ... Strategic Alignment & Risk Management * Develop and execute cybersecurity strategies that align ...

Senior IT Security Engineer

OR · Remote

$130K - $155K/yr

... analysis and control design through evidence collection, audit coordination, and successful ... Build and mature NetBrain's GRC (Governance, Risk & Compliance) program - conduct risk assessments ...

As a Senior Third Party Risk Analyst , you'll play a critical role in ensuring the security ... information security, cybersecurity, or technical/analytical roles . * Experience operating in ...

OR · Hybrid

Collect, generate, and validate exposure data, loss runs, and other information for annual ... Limited travel may be required for meetings, training, or project support Security Clearance ...

OR · On-site

Be ready to: * conduct information security risk assessments of vendors and vendor software, based ... cost analysis, audit support and coordination, product renewals, and performance monitoring Be ...

OR · Hybrid

A Security Architect is a senior technical leader responsible for the design and continuous ... and risk tradeoffs. Internally, this role mentors security engineers and analysts to develop ...

EFT Risk Analyst

OR · On-site +1

$44K - $65K/yr

Present reporting and findings to senior & executive management monthly. * Perform self-testing of ... Please see the description of benefits included with this job posting for additional information.

next page

Showing results 1-20

Senior Information Security Risk Analyst information

See Oregon salary details

$33

$61

$79

How much do senior information security risk analyst jobs pay per hour?

As of Jun 11, 2026, the average hourly pay for senior information security risk analyst in Oregon is $61.80, according to ZipRecruiter salary data. Most workers in this role earn between $48.03 and $69.38 per hour, depending on experience, location, and employer.

What is the difference between Senior Information Security Risk Analyst vs Information Security Analyst?

AspectSenior Information Security Risk AnalystInformation Security Analyst
CertificationsCISSP, CISA, CRISCCISSP, Security+, CEH
Work EnvironmentFocus on risk assessment, policy development, and strategic planningImplementing security measures, monitoring, and incident response
Employer & Industry UsageFinancial, healthcare, and large enterprises with complex security needsVariety of industries, including tech, retail, and government

Senior Information Security Risk Analysts typically handle advanced risk assessments and strategic security planning, often requiring certifications like CISSP or CISA. Information Security Analysts focus on implementing security controls and monitoring systems. Both roles are vital in maintaining organizational security but differ in scope and seniority.

How does a Senior Information Security Risk Analyst typically collaborate with other departments to manage organizational risk?

A Senior Information Security Risk Analyst regularly works with various departments such as IT, legal, compliance, and business units to identify and address security risks. This collaboration often includes conducting risk assessments, reviewing new projects for potential vulnerabilities, and providing guidance on security best practices. Effective communication skills are essential, as the analyst must translate technical risks into business impacts and help teams implement appropriate controls. Close teamwork ensures that security is integrated into all business processes and that the organization remains compliant with relevant regulations.

What are the key skills and qualifications needed to thrive as a Senior Information Security Risk Analyst, and why are they important?

A Senior Information Security Risk Analyst requires a deep understanding of cybersecurity frameworks, risk assessment methodologies, and regulatory compliance, usually backed by a degree in information security or a related field. Familiarity with tools like risk management software (e.g., Archer, RSA), SIEM systems, and certifications such as CISSP, CISM, or CRISC are typically expected. Exceptional analytical thinking, attention to detail, and strong communication skills set top performers apart in this role. These competencies are crucial to effectively identify, evaluate, and mitigate security risks, ensuring the organization's information assets remain protected against evolving threats.

What does a Senior Information Security Risk Analyst do?

A Senior Information Security Risk Analyst is responsible for identifying, evaluating, and mitigating risks to an organization's information systems and data. They conduct risk assessments, develop security policies, and recommend measures to protect against cyber threats and vulnerabilities. Additionally, they work closely with IT and business teams to ensure compliance with regulations and industry standards, and they often play a key role in incident response and security awareness training.
What are popular job titles related to Senior Information Security Risk Analyst jobs in Oregon? For Senior Information Security Risk Analyst jobs in Oregon, the most frequently searched job titles are:
What job categories do people searching Senior Information Security Risk Analyst jobs in Oregon look for? The top searched job categories for Senior Information Security Risk Analyst jobs in Oregon are:
What cities in Oregon are hiring for Senior Information Security Risk Analyst jobs? Cities in Oregon with the most Senior Information Security Risk Analyst job openings:
Infographic showing various Senior Information Security Risk Analyst job openings in Oregon as of June 2026, with employment types broken down into 55% Full Time, 43% Part Time, 1% Contract, and 1% Nights. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution, with an average salary of $128,541 per year, or $61.8 per hour.
Senior Manager, Technology Risk

Senior Manager, Technology Risk

Upstart

OR

Other

Posted 3 days ago


Job description

The Team: 

Upstart's Risk team is enhancing its second line of defense function in support of our application to establish Upstart Bank, N.A., a de novo national bank. The Risk team is responsible for Upstart's enterprise risk management program and risk governance, and for providing independent oversight and credible challenge across all core risk categories- including operational risk, third party risk, technology and information security risk, and treasury risk. We partner with first-line business functions, senior and executive leadership, and the board of directors to ensure effective identification, assessment, monitoring, reporting, and control of material risks, in alignment with OCC, FDIC, and FFIEC regulatory expectations.

As the Senior Manager, Technology Risk you will  lead the second-line technology and information security risk oversight program for Upstart Bank. You  will establish the bank's 2LOD technology risk framework-  leveraging and enhancing Upstart's existing technology and information security risk infrastructure to meet bank regulatory standards- and will provide independent oversight and credible challenge of the first-line technology and information security functions across all technology domains, including IT operations, cybersecurity, cloud infrastructure, affiliate-provided technology, and core banking systems. This role reports to the head of third party and technology risk and manages a team of two technology and security risk professionals. 

How you'll make an impact

  • Provide independent second-line review and credible challenge of first-line technology and information security activities, including but not limited to: cybersecurity controls, software development lifecycle (SDLC) and incident response programs, technology resiliency  and third-party arrangements
  • Oversee completion of the FFIEC Cybersecurity Assessment Tool (CAT) or equivalent framework; conduct technology and security  risk assessments; and provide independent oversight of technology and security risks in alignment with OCC guidance on cloud computing
  • Serve as a primary second-line point of contact for OCC examiners, internal audit, and other external stakeholders on technology risk and information security program topics and inquiries; prepare and deliver technology risk reporting to risk committees, the CRO, and the board. 
  • Build and lead a growing Technology Risk team, shaping how the bank identifies, prioritizes, and responds to its most important technology and security risks in alignment with applicable industry regulations
  • Partner with first-line IT and cybersecurity teams, TPRM, ERM, Legal, and Compliance to ensure technology and information security risk is integrated into enterprise risk programs, cross-functional risk assessments, and the bank's overall 2LOD reporting and governance structure

Minimum Qualifications 

  • Bachelor's degree or equivalent practical experience in information technology, cybersecurity, or a related field
  • 8+ years of experience in technology risk, information security risk management, IT audit, or GRC in a banking or financial services environment
  • 3+ years of direct people management experience leading technology risk, information security governance, risk, and compliance, or information technology audit professionals
  • Demonstrated experience applying FFIEC IT Examination Handbook standards and OCC guidance on technology risk and information security in a bank or federally regulated institution
  • Experience engaging banking regulators (OCC, FDIC, or Federal Reserve) on technology risk, cybersecurity, or IT controls examination matters

Preferred Qualifications

  • Experience building or significantly enhancing a technology risk or information security GRC program in a de novo bank, early-stage bank, or similar environment where the program required meaningful design and build-out
  • Knowledge of cloud risk management and OCC/FFIEC guidance on cloud computing (OCC Bulletin 2020-46), particularly in cloud-native or fintech-adjacent technology environments
  • Familiarity with affiliate technology risk oversight, including independent oversight of bank-affiliate technology service arrangements, associated data segregation requirements, and Regulation W implications
  • Experience with GRC tool implementation or administration in a bank regulatory context
  • Current professional certification in information security or technology risk management (CISSP, CISA, CRISC, CISM, or comparable)
  • Knowledge of AI/ML technology risk and related governance considerations in a fintech, lending, or model-intensive operating environment

Position location This role is available in the following locations: Remote 

Travel requirements As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S but are encouraged to to still spend high quality time in-person collaborating via regular onsites. The in-person sessions' cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.

#LI-REMOTE

#LI-MidSeniorÂ