1

Vendor Risk Jobs in Oregon (NOW HIRING)

Lead Security & Compliance Analyst

OR · On-site +1

$80K - $135K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Run third-party/vendor risk assessments and respond to customer security assessments and external inquiries * Deliver HIPAA and security awareness training and measure control effectiveness through ...

Support vendor risk assessments and third-party security reviews. * Assist with internal and external audits, evidence collection, and remediation of findings. Security Program & Collaboration

OR · On-site

$60K - $70K/yr

Risk, Audit & Compliance (GRC) * Conduct risk and impact analyses; gather evidence and inform ... Vendor Due Diligence: assess new and renewing vendors (software, apps, contractors) handling ...

General Counsel

OR · On-site +1

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Oversee Waymark's information security function, partnering with technology teams on security policy, incident response, and vendor risk management. * Enterprise Risk Management: Establish and manage ...

Staff Information Security Engineer - AI First

OR · On-site +1

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Support third-party and vendor risk assessments, with a focus on vendors who process data through AI pipelines. * Automate repetitive security workflows (evidence collection, access reviews, alert ...

Support policy reviews and document management. * Assist with vendor risk assessments and client compliance questionnaires. * Maintain Business Associate Agreements (BAAs), Data Processing Agreements ...

Sprinto autonomously executes tasks needed to maintain trust across compliance, audits, risk management, vendor risk, privacy, and AI governance, enabling organizations to maintain a strong, reliable ...

Field CISO

OR · On-site +1

  • Medical

  • Dental

  • Vision

Sprinto autonomously executes tasks needed to maintain trust across compliance, audits, risk management, vendor risk, privacy, and AI governance, enabling organizations to maintain a strong, reliable ...

Conduct risk-based reviews and analysis of proposed projects, vendors, and issue remediation efforts, and provide recommendations for consideration. Who You Are You're a kind, passionate and ...

Engineering Manager

Portland, OR · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Network Management: experience with compliance/vetting systems, carrier or vendor risk data, entity-resolution or "trust score" style platforms. * Broker Success: experience with marketplace matching ...

Engineering Manager

Portland, OR · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Network Management: experience with compliance/vetting systems, carrier or vendor risk data, entity-resolution or "trust score" style platforms. * Broker Success: experience with marketplace matching ...

Enterprise Account Executive - US

OR · On-site +1

$200K - $280K/yr

Sprinto autonomously executes tasks needed to maintain trust across compliance, audits, risk management, vendor risk, privacy, and AI governance, enabling organizations to maintain a strong, reliable ...

Engineering Manager

Portland, OR

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Network Management: experience with compliance/vetting systems, carrier or vendor risk data, entity-resolution or "trust score" style platforms. * Broker Success: experience with marketplace matching ...

Engineering Manager

Portland, OR · On-site

$192 - $261/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Network Management: experience with compliance/vetting systems, carrier or vendor risk data, entity-resolution or "trust score" style platforms. * Broker Success: experience with marketplace matching ...

New

Showing results 21-40

Vendor Risk information

What is the difference between Vendor Risk vs Vendor Compliance?

AspectVendor RiskVendor Compliance
FocusIdentifying and mitigating risks associated with vendorsEnsuring vendors meet regulatory and contractual requirements
CertificationsRisk management certifications (e.g., CRISC, FAIR)Compliance certifications (e.g., ISO 27001, SOC 2)
Work EnvironmentRisk assessment teams, procurement, security departmentsLegal, compliance, audit teams
Industry UsageFinancial, healthcare, technology sectorsFinancial services, healthcare, regulated industries

Vendor Risk and Vendor Compliance roles often overlap but serve different purposes. Vendor Risk focuses on identifying and mitigating potential risks posed by vendors, while Vendor Compliance ensures vendors adhere to legal and contractual standards. Both are essential for managing vendor relationships effectively and maintaining organizational security and compliance.

What are the most commonly searched types of Vendor Risk jobs in Oregon?

The most popular types of Vendor Risk jobs in Oregon are:

Infographic showing various Vendor Risk job openings in Oregon as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Lead Security & Compliance Analyst

Parachute Health

OR • On-site, Remote

$80K - $135K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 20 days ago


Job description

About the Role

This is a hybrid role: roughly half security compliance and audit, half hands-on technical security. You'll own our compliance audit cycle end-to-end (SOC 1, SOC 2, HITRUST CSF, HITRUST AI), and you'll also work directly on the technical side: vulnerability management, security findings remediation, cloud security reviews, and third-party risk.

Responsibilities

Compliance & Audit

  • Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation
  • Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations
  • Manage our compliance automation and trust platforms (Drata, SafeBase), including control monitoring and responses to customer security questionnaires.
  • Coordinate with external vendors and clients to gather information needed for compliance reviews, validations, and audits
  • Run third-party/vendor risk assessments and respond to customer security assessments and external inquiries
  • Deliver HIPAA and security awareness training and measure control effectiveness through internal audits

Technical Security

  • Run the vulnerability management program: scanning, triage, prioritization, and driving remediation with engineering teams
  • Investigate and remediate security findings across our AWS environment (EKS, WAF, Shield, CloudFront, IAM) and SaaS stack
  • Review external attack surface findings (e.g., SecurityScorecard) and implement fixes from CSP headers to subresource integrity to TLS configuration
  • Support security incident response: log analysis, forensic evidence collection, and containment
  • Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters
  • Improve our security tooling and automate evidence collection, using scripting (Python, Bash) where manual work can be eliminated

What We're Looking For

  • 4+ years combined experience across security compliance/GRC and hands-on technical security
  •  Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits - you've been through at least one full audit cycle
  • Working knowledge of HIPAA Security and Privacy requirements
  • Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues)
  • Familiarity with AWS security concepts (IAM, security groups, logging, WAF)
  • Ability to write clear policies and procedures and equally clear remediation tickets

Nice to Have

  • Experience with compliance automation platforms (Drata, Vanta, or similar)
  • Experience in healthcare or another regulated industry
  • Certifications such as CISSP, CISA, CRISC, HITRUST CCSFP, or CISM
  • Experience with SIEM tools and log analysis
  • Experience with forensic log analysis, fraud investigations, or supporting legal/eDiscovery requests

Benefits

  • Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums.
  • Employer HSA Contribution: Company-funded contributions to your Health Savings Account.
  • 401(k) Retirement Plan
  • Equity Incentive Plan
  • Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance.
  • Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces.
  • Flexible Vacation Policy
  • Summer Fridays: 5 additional Fridays off during the summer (separate from PTO).
  • Home Office and Wellness Stipend
  • Monthly Internet Stipend
  • Annual Learning and Development Stipend

Base Salary Band (based on experience and level)

$80,000 - $135,000