1

Technology Risk Manager Jobs in Oregon (NOW HIRING)

Risk Officer

OR · On-site +1

You possess strong knowledge of banking operations, regulatory expectations, internal controls, and enterprise risk management principles. Tech-Forward and Analytical Thinking - You learn new tools ...

Enterprise Risk Analyst - AI Risk

OR · On-site +1

$68K - $127K/yr

The opportunity to help shape and mature AI risk management practices at a leading financial institution. * Exposure to Emerging Technologies: Work with cutting-edge AI technologies, including ...

next page

Showing results 1-20

Technology Risk Manager information

See Oregon salary details

$54.5K

$117.9K

$179.7K

How much do technology risk manager jobs pay per year?

As of Sep 10, 2026, the average yearly pay for technology risk manager in Oregon is $117,947.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,200.00 and $136,400.00 per year, depending on experience, location, and employer.

What is a technology risk manager?

Technology Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with information technology systems and processes within an organization. They ensure that IT operations comply with regulations and best practices while safeguarding data and technology assets from threats such as cyberattacks, data breaches, and system failures. Their work involves developing risk management strategies, conducting risk assessments, and collaborating with other departments to ensure the organization's technology infrastructure is secure and resilient.

What are some common challenges technology risk managers face when working across different departments?

Technology Risk Managers often encounter challenges in aligning risk management strategies with the priorities of various business units. Departments may have differing levels of risk tolerance, technical understanding, and resource availability, which can make establishing consistent policies and controls difficult. Success in the role relies on strong communication and negotiation skills, as well as the ability to educate stakeholders about the importance of risk mitigation while balancing business objectives. Building collaborative relationships and maintaining flexibility are key to overcoming these cross-departmental challenges.

What are the key skills and qualifications needed to thrive as a technology risk manager, and why are they important?

To thrive as a Technology Risk Manager, you need expertise in risk assessment, cybersecurity principles, and regulatory compliance, often supported by a degree in information security or related fields. Familiarity with risk management frameworks (such as NIST or ISO 27001), GRC (governance, risk, and compliance) tools, and certifications like CISM or CISSP are typically required. Strong analytical thinking, communication, and stakeholder management skills help you translate technical risks into business terms and coordinate mitigation efforts. These abilities are critical to proactively identifying threats and ensuring organizational resilience against evolving technology risks.

What is the difference between Technology Risk Manager vs Cybersecurity Analyst?

AspectTechnology Risk ManagerCybersecurity Analyst
CertificationsCRISC, CISSP, CISACISSP, CEH, Security+
Work EnvironmentRisk assessment, policy development, complianceMonitoring security threats, incident response, vulnerability analysis
Industry UsageFinancial, healthcare, technology firmsIT security teams, government agencies, corporations

The Technology Risk Manager focuses on identifying and mitigating overall technology risks and ensuring compliance, while the Cybersecurity Analyst concentrates on protecting systems from security threats and responding to incidents. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

Infographic showing various Technology Risk Manager job openings in Oregon as of August 2026, with employment types broken down into 84% Full Time, 15% Part Time, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $117,947 per year, or $56.7 per hour.

IT Risk and Compliance Analyst

Portland, OR • On-site

Noblesoft Technologies
Software Development • 51 - 200 employees

$99K - $100K/yr

Contractor

Re-posted 6 days ago


Job description

Job Description:

We are seeking a highly motivated and detail-oriented IT Risk and Compliance Analyst to join our team. The ideal candidate will be responsible for ensuring that IT risk management processes are embedded in the enterprise, enabling optimal risk assessments returns. This role involves supporting IT risk governance internal and external assessments and audits and working on problems of diverse scope where analysis of data requires evaluation.

Job Duration: Minimum six months with option to renew.

Key Responsibilities:

• Provide Consulting for IT Risk Management, Compliance & Metrics

• Monitor & Report on IT Controls Compliance - monitor first line of defense.

• Facilitate Assessments and Audits – represent customer’s Info Sec Program for regulators and customers.

• Contribute to the Establishment & Maintenance of Primary Common Controls that align with business, regulatory and information security goals.

• Provide independent oversight of the risk management activities of the Service Owners.

• Perform independent validation to evaluate the adequacy and effectiveness of key controls.

Qualifications:

• Bachelor's degree in Information Technology, Risk Management, or a related field.

• Minimum of 5 years of experience in IT risk management and compliance.

• Strong understanding of IT risk governance principles and practices.

• Experience with cybersecurity regulation requirements and industry standards.

• Excellent analytical and problem-solving skills.

• Strong communication and interpersonal skills.

• Project Leadership

Preferred Qualifications:

• Experience with on prem and cloud platforms.

• Knowledge of SOC 1, SOC 2, ISO 27001:2022, and HIPAA regulations.

• CISA certification.

• CRISC certification.