1

Senior Risk Manager Jobs in Oregon (NOW HIRING)

Senior VCISO

OR · On-site +1

Risk Assessment and Management: * Utilizing principles from a formal framework (such as RMF as an ... Prepare regular reports on compliance and risk status for senior management and external regulators.

Upstart's Risk Capital team manages the co-investments that Upstart engages with its funding ... Ability to explain complex deals and numbers in plain language for senior leaders and investors.

The Sr. Manager of Stop-Loss Operations is responsible for building and leading the stop-loss function that underpins Point C's self-funded health plan business, ensuring accuracy, compliance, and ...

About the Role As Senior Manager, Public Sector at Armada, you will lead a team while developing and executing strategic business plans across Armada's public sector partner ecosystem, spanning ...

Senior Researcher

OR · On-site +1

... management responsibilities. Another potential pathway is to transition into a Senior Program ... Officer role, which is a lateral move-we don't conceptualize the Senior Researcher role as a ...

The majority of our staff, including senior management, work flexibly in one way or another. * Visa Sponsorship: If you want to work in the United States and need a work visa, we'll do our best to ...

Risk Officer

OR · On-site +1

... to senior leadership and the Board of Directors. What You'll Contribute: Enterprise Risk Management Leadership * Develop, maintain, and enhance the Bank's enterprise risk management framework ...

Proven experience in operations management or a related field. * Strong leadership and communication skills. Benefits * Paid time off for work-life balance. * Health, dental, and vision insurance for ...

Senior Leader

Portland, OR · On-site

$64K/yr

Proven experience in operations management or a related field. * Strong leadership and communication skills. Benefits * Paid time off for work-life balance. * Health, dental, and vision insurance for ...

Showing results 21-40

Senior Risk Manager information

See Oregon salary details

$23.8K

$125K

$222K

How much do senior risk manager jobs pay per year?

As of Sep 11, 2026, the average yearly pay for senior risk manager in Oregon is $125,033.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,300.00 and $153,300.00 per year, depending on experience, location, and employer.

What does a senior risk manager do?

A Senior Risk Manager identifies, assesses, and mitigates potential risks that could impact an organization's financial health, operations, or reputation. They develop risk management strategies, ensure compliance with industry regulations, and collaborate with various departments to implement risk controls. Additionally, they analyze market trends and internal processes to proactively address potential threats. Their goal is to minimize risk exposure while supporting business objectives and long-term sustainability.

What are the key skills and qualifications needed to thrive as a senior risk manager?

To excel as a Senior Risk Manager, you need strong analytical capabilities, a deep understanding of risk assessment methodologies, and a relevant degree such as finance, economics, or business administration. Familiarity with risk modeling software, governance frameworks (like COSO or ISO 31000), and industry certifications such as FRM or CRM are highly valued. Exceptional communication, leadership, and decision-making skills help distinguish top performers in this role. These abilities are essential for effectively identifying, evaluating, and mitigating potential risks while supporting organizational objectives.

What does a typical day look like for a senior risk manager?

A Senior Risk Manager’s day often includes analyzing complex data to assess potential financial, operational, or strategic risks and developing mitigation strategies accordingly. You’ll regularly collaborate with business leaders across departments, provide expert advice during project planning, and prepare detailed risk reports for executive management or compliance committees. Additionally, you may oversee junior risk team members, guide audit processes, and participate in risk review meetings. This role offers dynamic daily challenges that require both independent analysis and team-oriented communication, making it ideal for those who enjoy both strategic thinking and hands-on collaboration.

How much do senior risk managers make in the US?

Senior risk managers in the US typically earn a median annual salary of around $120,000 to $150,000, with higher compensation possible in large financial institutions or with extensive experience and certifications such as FRM or CRM. Salaries can vary based on industry, location, and the complexity of risk management responsibilities.

What are popular job titles related to Senior Risk Manager jobs in Oregon?

For Senior Risk Manager jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Senior Risk Manager jobs in Oregon look for?

The top searched job categories for Senior Risk Manager jobs in Oregon are:

What are popular job titles related to Senior Risk Manager jobs in OR?

For Senior Risk Manager jobs in OR, the most frequently searched job titles are:

Infographic showing various Senior Risk Manager job openings in Oregon as of September 2026, with employment types broken down into 68% Full Time, 31% Part Time, and 1% Contract. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $125,033 per year, or $60.1 per hour.

Senior VCISO

OR • On-site, Remote

VC3, Inc.
IT Services • 51 - 200 employees

Full-time

Retirement

Posted 14 days ago


Job description

At VC3, we don't just solve IT problems - we own them. We serve hundreds of municipalities and organizations across the United States and Canada, bringing IT to the people who need it most. We believe in earning trust, having a growth mindset, and delivering excellence every single time. 
 
We're a team of doers, builders, and tech whisperers who live by 4 core values:
 Go Beyond | Own It | Be Curious| Serve as One 
We pride ourselves on making IT personal, making IT easy, and getting IT right. And it all starts with our talented team that is committed to raising the bar.   
The Impact you will have:   

The Virtual Chief Information Security Officer(vCISO) will provide strategic leadership and oversight for the information security programs of VC3 managed clients. This role involves having a deep understanding of each client's unique business environment to develop tailored strategies that mitigate risks and align with client business objectives. The vCISO is a top security expert that works with existing management and technical teams both within client environments and VC3. This role also assists in providing strategy for the Managed Security space to drive growth, delivery with consistency and excellence, and the desired level of profitability for the organization. Key focus areas are innovation, staying at or ahead of world events that are relevant, consistent excellence, proactiveness, and driving efficiency. By measuring progress and adjusting processes accordingly, the vCISO keeps the clients under their purview on track. 

The Managed Security department at VC3 is responsible for ensuring our clients have the right security tools, policies and processes to thrive in today's fast-moving threat landscape. They ensure that our internal teams are equipped with the training and knowledge to support our clients and make sure that effective security is a key aspect of everything we do within VC3. 

In order to ensure an exceptional result, you will need to have a clear understanding of the challenges and opportunities our clients face and how our teams as a whole combine to deliver our promise. Providing services in a proactive, professional manner while ensuring key parties are kept informed is critical. We are a data driven company and analysis for decision making and overall strategy is ongoing.
The "VC3 Way" is our set of people, process and technology, that produce a predictable result for our clients. You must be aware of, and maintain this standard, understanding that it is a living guide; Always updating and always changing based on influence from our team and the needs of our clients. 
 
Responsibilities: 
 
  • Risk Assessment and Management: 
    • Utilizing principles from a formal framework (such as RMF as an example) create a roadmap for our clients 
    • Assist in driving risk assessments for various projects and business processes. 
    • Assist in the development and implementation of risk mitigation strategies. 
    • For clients that contract for that level of service, maintain and update a risk register to reflect current status and changes. 
    • Assist in overseeing risk assessments and mitigation strategies for clients as assigned and VC3 when asked 
  • Compliance Activities: 
    • Advise clients on adhering to published polices and legal standards. 
    • Prepare and manage documentation for compliance activities, such as audits, controls, and compliance checks. 
    • Monitor changes in relevant legislation and the regulatory environment and take appropriate actions. 
    • For clients that contract the proper level of service, maintain the GRC platform and collaborate with the client on pursuing their GRC goals for alignment (vs compliance) 
    • Record, manage, and analyze compliance data to support reporting and decision-making. 
    • Develop and maintain comprehensive documentation of compliance and risk management activities. 
    • Prepare regular reports on compliance and risk status for senior management and external regulators. 
  • Data Management and Reporting: 
    • Provide regular reports summarizing activity and posture 
    • Provide cyber-security trends and insights 
  • Client Interaction: 
    • Assist the VCISO in daily tasks involving client interactions related to GRC issues. 
    • Provide clients with compliance and risk management guidance and support. 
    • Participate in client meetings and presentations as required. 
  • Technical Documentation and Presentations: 
    • Analyze and interpret technical documentation, such as vulnerability scans, and present findings to clients clearly and effectively. 
    • Develop and brief clients on technical documentation to ensure understanding and compliance. 
  • Engage and provide consulting services to mid-market and enterprise clients, including that have the contracted obligation: 
    • Provide strategic leadership in translating complex cybersecurity concepts into non-technical terms for clients to clearly understand specific applications to their business priorities. 
    • Understand and align with the client organization's overall strategy and business environment to ensure cybersecurity initiatives support business objectives 
    • Partner with cross-functional teams to integrate security into product design and implementation, and to develop security solution offerings for clients. 
    • Drive the creation and execution of a robust cybersecurity plan and program within client environments, ensuring alignment with industry best practices as asked or contracted for. 
    • Assist in the development of the information security incident response program. 
    • Strategically develop and enhance client specific incident response programs as needed based on the development of Business Continuity and Disaster Recovery practices liaising with internal VC3 Departments as necessary. 
    • Lead comprehensive cybersecurity risk assessments based on the client organization's assets, identify vulnerabilities, and recommend remediation strategies. 
    • Collaborate with clients to assist with vendor selection, providing guidance and checklists to ensure third party security compliance 
  • Project Support: 
    • Support various cybersecurity-related projects, ensuring that they meet compliance and risk requirements. 
    • Collaborate as needed to ensure that cybersecurity principles are integrated into all facets of operations. 
 Additional Responsibilities: 
  • Engage with industry peers and continuously analyze and review new security technologies and practices as informed by industry best practice. 
  • Work closely with internal stakeholders to stay informed of planned changes to technologies, practices, and business activities that could impact security. 
  • Collaborate across all VC3 departments to maximize our client security posture and experience during onboarding, system design, strategy and ongoing support 
  • Maintain precise and up-to-date timesheets, and document notes on troubleshooting steps and client communications. 
  • Actively seek and reflect on feedback from stakeholders, colleagues, and management using it to drive improvement. 
  • Escalate complex issues to senior resources or relevant teams when necessary. 
  • Engage actively in team huddles, L10 meetings, and other collaboratively structured meetings. 
  • Develop and revise documentation promptly to reflect changes or new findings. 
  • Attend company-based meetings as required 
  • Additional duties as assigned 

Performance Deliverables: 

Each employee's performance is tracked through both leading and lagging key performance metrics: 
  • Client Cyber Security Incidents 
  • Client Utilization 
  • Security MRR Growth 
  • Client Security Awareness Education 
  • Security scoring done 
  • Roadmaps delivered 


  • Bachelor's Degree or Master's Degree (preferred) in an IT-based curriculum, or at least 10 years' experience in risk management, information security, or programming. 
  • One or more of the following qualifications are highly desirable: Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified Information systems Auditor (CISA), or Certified Risk & Information Security Controls (CRISC), or CMMC RP (or higher) 
  • Extensive experience in cybersecurity strategy development, risk management, and program administration. 
  • Deep knowledge of common cybersecurity frameworks (CMMC, CIS, NIST, MITRE ATT&CK) 
  • Expertise with compliance and regulatory requirements 
  • An understanding of SIEM platforms, perimeter security, endpoint detection and response platforms, vulnerability management solutions, all aspects of IT infrastructure (compute, route/switch, security) and cloud security 
  • Possesses a high level of self-motivation and initiative, consistently taking ownership of tasks and projects. 
  • Demonstrate a strong sense of autonomy and resourcefulness, capable of making independent decisions and solving problems without relying heavily on coaching or direction. 
  • Exhibit excellent time management and organizational skills, effectively prioritizing tasks and allocating resources to meet deadlines and achieve objectives without extensive oversight. 
  • Displays a proactive and self-directed approach to learning and staying updated on industry trends, seeking out relevant information and resources to enhance their knowledge and skills. 
  • Shows the ability to adapt and thrive in ambiguous or uncertain situations, quickly assessing and navigating challenges. 
  • Possesses strong critical thinking and decision-making abilities, evaluating complex situations and determining the best course of action, while considering the broader organizational goals and objectives. 
  • Demonstrates effective communication skills, both written and verbal, articulating ideas and expectations clearly and concisely, minimizing the need for frequent guidance or clarification. 
  •  Ability to build and manage relationships with clients (internal and external) through consistent and proactive communication. 
  • Extraordinarily strong interpersonal skills, able to build effective working relationships, solicit co-operation and collaborate with various stakeholders internally and externally. 
 
Additional Information: 
  • Applicant selected will be subject to a criminal and department of motor vehicles background checks and must meet Criminal Justice Information Systems (CJIS) requirements post-employment. 
  • Available for domestic and international travel as required. 
  Well-being & Support - Caring for our team goes beyond the workday. We offer a range of benefits to support your overall well-being, from mental health and leave support through our Employee and Family Assistance Program, to financial wellness through company-matched 401(k)/RRSP plans. Whether it's today's needs or tomorrow's goals, we've got you covered. 
Grow with Us - Whether you're just getting started or ready to take the next step, we are committed to investing in your growth. We offer structured development through our Leadership Academy, monthly learning sessions, mentorship programs, learning reimbursements, internal career fairs, job shadowing, and personalized career-pathing to support internal mobility.  
People-First Culture - We live our values, support each other, and create a space where everyone belongs. We have a common goal of doing work that matters, with autonomy, recognition, and a mission to serve those who serve. 
Transparent Leadership - From open communication to clear company goals, our leaders are involved, and our managers are here to support your growth every step of the way. 
 
Applicant selected will be subject to a criminal and department of motor vehicles background checks and must meet Criminal Justice Information Systems (CJIS) requirements post-employment 
 
Thank you for your interest in VC3. We appreciate all applications; however, only those candidates selected for an interview will be contacted.  
 
Learn more about VC3 by visiting our website and follow us on LinkedIn to stay informed!