Senior Cybersecurity Analyst

Oregon Metro

Oregon (WI)

Hybrid

USD 120,000 - 180,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Oregon Metro in the Portland region is seeking a Senior Cybersecurity Analyst to lead security operations, detection engineering, and incident response across endpoints, identity, cloud, and network environments.

The role advances Metro's information security program, offering growth toward principal security leadership, with responsibilities spanning technical risk management, threat detection, and collaboration with IT and compliance teams.

Qualifications

  • 4-6 years of related professional experience in cybersecurity and security operations.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field.
  • Experience across multiple domains such as identity management, cloud security, and network security.

Responsibilities

  • Lead alert review, validation, escalation, and coordinated response for security events across Metro's environment.
  • Act as technical incident lead during security events, coordinating containment, eradication, recovery, and post-incident follow-up in partnership with the CISO, IT teams, and SOC/MSSP providers.
  • Develop, tune, and optimize detection content across SIEM, EDR, identity, cloud, and network security tools, incorporating threat intelligence and MITRE ATT&CK techniques.
  • Operate and improve vulnerability management processes, providing risk-based prioritization and partnering with the Compliance Analyst on remediation tracking and risk acceptance documentation.
  • Implement, configure, and monitor technical safeguards under NIST CSF, CIS Controls, and PCI DSS, generating evidence to support compliance validation and audit activities.
  • Own technical security review and ongoing oversight of third-party services, SaaS platforms, and vendor integrations, evaluating authentication, data flows, and integration risk.
  • Monitor Metro's identity security posture, tune identity threat detection tooling, and investigate identity-based threats such as credential theft and lateral movement.
  • Maintain secure configuration baselines using CIS Benchmarks, administer Metro's EDR platform, and participate in security architecture and design reviews for cloud and infrastructure changes.
  • Implement and operate data protection controls (DLP, data monitoring, and audit capabilities), investigating alerts and partnering with the Compliance Analyst to align technical enforcement with policy intent.
  • Contribute technical content to security standards and training materials, and identify opportunities to improve detection quality, control effectiveness, and operational efficiency.

Skills

Security operations
Detection engineering
Incident response
Vulnerability management
Identity and access management
Network security
Cloud security
MITRE ATT&CK

Education

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field

Tools

CrowdStrike Falcon
Palo Alto Networks
Microsoft Entra ID

Job description

Hello, we’re Metro!

Metro is dedicated to shaping a better future for the greater Portland region. The work the people of Metro do every day benefits the lives of the people who live here, today, and tomorrow.

The Information Security Team is looking for a Senior Cybersecurity Analyst to lead technical security operations, detection engineering, and incident response for Metro, protecting the systems, data, and services that people across the greater Portland region rely on every day.

The Senior Cybersecurity Analyst is the primary technical lead for Metro's security operations, detection engineering, and technical control execution, leading hands-on threat detection, incident response, and continuous improvement of Metro's security posture across endpoint, identity, cloud, and network environments.

This role serves as a senior technical control operator for compliance frameworks (NIST CSF, CIS Controls, PCI DSS) in partnership with the Information Security Compliance Analyst, who leads control definition and governance, and acts as the technical incident lead during security events, with formal incident declaration owned by the CISO. As Metro's Information Security program matures, this position offers a clear growth path toward a future Principal Cybersecurity Analyst role with broader ownership of security architecture, detection strategy, and technical risk leadership.

As the Senior Cybersecurity Analyst you will
  • Serve as the CISO's primary technical lead for security operations, leading alert review, validation, escalation, and coordinated response for security events across Metro's environment.
  • Act as technical incident lead during security events, coordinating containment, eradication, recovery, and post-incident follow-up in partnership with the CISO, IT teams, and SOC/MSSP providers.
  • Develop, tune, and optimize detection content across SIEM, EDR, identity, cloud, and network security tools, incorporating threat intelligence and MITRE ATT&CK techniques.
  • Operate and improve vulnerability management processes, providing risk-based prioritization and partnering with the Compliance Analyst on remediation tracking and risk acceptance documentation.
  • Implement, configure, and monitor technical safeguards under NIST CSF, CIS Controls, and PCI DSS, generating evidence to support compliance validation and audit activities.
  • Own technical security review and ongoing oversight of third-party services, SaaS platforms, and vendor integrations, evaluating authentication, data flows, and integration risk.
  • Monitor Metro's identity security posture, tune identity threat detection tooling, and investigate identity-based threats such as credential theft and lateral movement.
  • Maintain secure configuration baselines using CIS Benchmarks, administer Metro's EDR platform, and participate in security architecture and design reviews for cloud and infrastructure changes.
  • Implement and operate data protection controls (DLP, data monitoring, and audit capabilities), investigating alerts and partnering with the Compliance Analyst to align technical enforcement with policy intent.
  • Contribute technical content to security standards and training materials, and identify opportunities to improve detection quality, control effectiveness, and operational efficiency.
Attributes for success
  • Technically curious with a strong drive to learn, improve, and expand security capabilities across endpoint, identity, cloud, and network domains.
  • Detail-oriented with strong analytical skills and a disciplined approach to detection engineering, evidence collection, and documentation.
  • Comfortable leading technical incident response under pressure, exercising sound judgment about when to elevate versus resolve.
  • Strong working knowledge of security frameworks (NIST CSF, CIS Controls, PCI DSS) with the ability to translate requirements into practical technical controls.
  • Collaborative mindset with the ability to partner effectively with the Compliance Analyst, IT Infrastructure, Applications teams, Metro departments and business partners,and third-party SOC/MSSP providers.
  • Able to work independently on assigned technical priorities while communicating clearly with both technical and non-technical stakeholders.
  • Comfortable with ambiguity and program-building, given that tooling, processes, and governance structures are still actively maturing.
  • Reliable and responsive as a technical escalation point for high-severity or time-sensitive security events.
  • Growth-oriented, with the interest and capability to progress toward broader ownership of security architecture, detection strategy, and technical risk leadership.
  • Genuine interest in continuous learning and staying current on evolving threats, tooling, and best practices in a public-sector context.
DIVERSITY AND INCLUSION

At Metro, we striveto cultivate diversity, advance equity, and practice inclusion in all of its work. This means attracting and empowering a workforce that is inclusive of a broad range of human qualities. Workplace diversity is both a moral imperative and a business strength, essential to providing quality support and services to our region. Metro’s goal is to hire, develop and retain highly skilled and talented individuals across all departments and programs who best reflect the diversity of our community.

Learn more about how Metro is advancing diversity

TO QUALIFY

We will consider any combination of relevant work experience, volunteering, education, and transferable skills as qualifying unless an item or section is labeled required. Please be clear and specific in your application materials on how your background is relevant.

Minimum qualifications
  • 4-6 years of related professional experience in cybersecurity, security operations, detection engineering, incident response, vulnerability management, identity and access management, network security, cloud security, or a related technical field.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education, certification, and related professional experience.
  • Any combination of education, professional, volunteer and lived experience that provides the necessary knowledge, skills, and abilities to perform the classification duties and responsibilities.
If this statement is true for you, then you may be ineligible to apply

If you were terminated for cause during any employment with Metro, or resigned in lieu of termination, you may be ineligible for rehire for a minimum of 3 years.

Hybrid Telework

This position is designated as “hybrid telework.” You will be required to work onsite and at times have the option to work away from your assigned work location. The specific schedule and balance of onsite and telework will be discussed with the hiring manager at the time of offer.This position also requires off-hours response to security events, incidents, or urgent operational needs, which may include remote response and onsite response when necessary.Employees must reside in Oregon or Washington to work at Metro.Please note, the designation of hybrid telework may be subject to change at a future time.

Like to have qualifications

You do not need to have the following preferred qualifications/transferable skills to qualify. However, keep in mind we may consider them when identifying the most qualified candidates. Your transferable skills are any skills you have gained through education, work experience, including the military, or life experience that are relevant for this position.

  • Demonstrated experience with technical control implementation, endpoint protection, identity security, network security, cloud security, logging, monitoring, or compliance-related safeguards.
  • Working knowledge of cybersecurity frameworks and control practices, including NIST CSF, CIS Controls, PCI DSS, or similar risk-based security frameworks.
  • Strong written and verbal communication skills, including the ability to document findings, procedures, and technical recommendations for both technical and non-technical audiences.
  • 6 or more years of progressively responsible cybersecurity or closely related technical experience, including senior-level ownership of security operations, detection engineering, incident response, or enterprise security controls.
  • Demonstrated ability to grow into principal-level responsibility for security architecture, detection strategy, and technical risk leadership.
  • Experience in public sector, local government, or critical infrastructure security environments.
  • Hands-on experience with CrowdStrike Falcon modules (EDR, NG-SIEM, Identity Protection, or Exposure Management).
  • Familiarity with Palo Alto Networks firewall administration or network security monitoring.
  • Experience with Microsoft Entra ID, Active Directory, or cloud identity and access management in AWS or GCP environments.
  • Familiarity with the MITRE ATT&CK framework and its application to detection and threat hunting.
  • Preferred certification: CISSP. Other relevant certifications may include:
  • Security+, CySA+, SSCP, GSEC
  • GCIA, GCIH, or CEH
SCREENING AND EVALUATION

The selection process: We expect to evaluate candidates for this recruitment as follows. The selection process is subject to change.

  • Initial review of minimum qualifications
  • In-depth
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

City of Santa Fe Springs • Portland (OR)

Hybrid
USD 94,000 - 126,000
Hybrid/telework
Medical benefits
Paid leave
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Oregon Metro • Portland (OR)

Hybrid
USD 94,000 - 126,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Senior Cybersecurity Operations & Detection Lead
Senior Cybersecurity Operations & Detection Lead

City of Santa Fe Springs • Portland (OR)

Hybrid
USD 94,000 - 126,000
Hybrid/telework
Medical benefits
Paid leave
Senior Cybersecurity Analyst - Lead Detection & IR (Hybrid)
Senior Cybersecurity Analyst - Lead Detection & IR (Hybrid)

Oregon Metro • Oregon (WI)

Hybrid
USD 120,000 - 180,000
Senior Cybersecurity Analyst: Lead Security Ops & Detection
Senior Cybersecurity Analyst: Lead Security Ops & Detection

Oregon Metro • Portland (OR)

Hybrid
USD 94,000 - 126,000
Safety and Training Program Analyst
Safety and Training Program Analyst

Oregon Metro • Oregon (WI)

Hybrid
USD 99,000 - 132,000
Hybrid telework
On-site four days per week
Sr. Solutions Architect III (5787)
Sr. Solutions Architect III (5787)

MetroStar • Great Falls Crossing (VA)

On-site
USD 170,000 - 230,000
Generous benefits package
Professional growth opportunities
Time to recharge
Sr. DevSecOps Engineer III (6735)
Sr. DevSecOps Engineer III (6735)

metrostarsystems • Reston (VA)

On-site
USD 200,000 - 220,000
Sr. Cyber Operations Engineer III (NOC/SOC) (6797)
Sr. Cyber Operations Engineer III (NOC/SOC) (6797)

metrostarsystems • Washington

On-site
USD 140,000 - 210,000