Junior Information Security Analyst

CHR Creative

Milwaukie (OR)

Hybrid

USD 60,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive pay
Health, vision & dental coverage
401(k) with company match
Paid time off
Professional development support

Job summary

CHR Creative, a security-first managed services and IT risk firm in Milwaukie, OR, is hiring a Security Analyst I. You will triage security alerts from SaaS Alerts and SOC/EDR tools, escalate as needed, and maintain thorough ticket notes for seamless handoffs to senior staff.

The role requires strong documentation habits, familiarity with Microsoft 365 security features, and willingness to participate in on-call rotations. Hybrid remote work is offered.

Qualifications

  • Foundational knowledge of information security topics such as IAM, MFA, phishing, endpoint protection, and alert patterns.
  • Experience with documenting processes accurately and clearly.
  • Familiarity with Microsoft 365 security/admin features.

Responsibilities

  • Acknowledge and triage incoming security alerts and tickets from SaaS Alerts, SOC, and EDR under guidance.
  • Assess severity against client playbooks and escalate to seniors when needed.
  • Serve as the frontline owner of the SaaS Alerts Microsoft 365 queue across clients.
  • Identify noisy or benign detections for tuning or automation.
  • Carry out routine tasks from checklists and runbooks, including MFA/password resets with identity verification.
  • Monitor endpoint agent health and follow up on offline or unreported endpoints.
  • Coordinate allowlisting with SOC to minimize false alerts.
  • Maintain clear ticket notes for seamless handover to seniors.
  • Gather compliance evidence when requested (screenshots, exports, asset lists).
  • Help resolve recurring findings like cleartext PII, non-expiring passwords, and MFA gaps.
  • Participate in on-call and after-hours rotation per escalation SLA.

Skills

Core information security concepts
Identity and access
MFA
Phishing awareness
Endpoint protection
Alert patterns
Written communication
Runbooks adherence
On-call readiness
Security certifications (Security+)

Education

Associate/Bachelor's in cybersecurity or IT
Security+ or equivalent certification

Tools

Microsoft 365 security/admin interfaces
SaaS Alerts
SOC/EDR/SIEM tools

Job description

Requirements

Must have:
  • We need a foundational grasp of core information security topics, including identity and access, MFA, phishing, endpoint protection, and common alert patterns.
  • We expect familiarity with Microsoft 365 and its security and admin interfaces.
  • We value accurate, dependable documentation habits and strong written communication.
  • You should be disciplined about following runbooks precisely and escalating early instead of making assumptions.
  • You must be willing to take part in an on‑call and after‑hours rotation.
  • Security+ or a similar entry‑level certification is preferred, whether completed or in progress.
  • Exposure to SOC, EDR, SIEM, or alert‑triage tools, as well as platforms such as SaaS Alerts or Rewst, is preferred.
  • Awareness of compliance requirements such as HIPAA, PCI, or CJIS is preferred.
  • An associate or bachelors degree in cybersecurity or IT, or equivalent practical experience, is preferred.
  • MSP or multi‑client environment experience is preferred.

Responsibilities:

  • We want you to acknowledge and triage incoming security alerts and tickets from SaaS Alerts, SOC, and EDR detections, moving them forward under senior guidance.
  • You will assess severity against each clients Alert Response Playbook and elevate appropriately to the Senior Analyst or vCSO.
  • You will serve as the primary first‑line owner of the SaaS Alerts Microsoft 365 queue across onboarded client tenants.
  • You will identify noisy or benign detection patterns for tuning or automation so the queue remains manageable.
  • You will carry out routine tasks from checklists and runbooks, including account compromise first response, MFA and password resets with identity verification, and phishing report review.
  • You will monitor endpoint agent health and follow up on offline or unreporting endpoints until resolved.
  • You will recognize benign scanner and penetration‑test traffic and coordinate allowlisting with the SOC so partners are not alerted unnecessarily.
  • You will keep ticket notes complete enough for a senior analyst to continue work without needing clarification.
  • You will gather compliance evidence when requested, including screenshots, exports, and asset lists.
  • You will help resolve recurring security findings such as cleartext PII, non‑expiring passwords, missing MFA, and Microsoft Secure Score quick wins.
  • You will participate in the on‑call and after‑hours rotation, responding according to the documented escalation SLA.

Company:

We are CHR Creative, a security‑first managed services and IT risk management firm based in Milwaukie, Oregon, just 10 minutes from Portland. Since 2006, we have partnered with CFOs, senior leadership, and company principals to reduce technology risk, support compliance, and build resilient operations. We support more than 100 clients, with especially deep experience in the nonprofit and human services sector. We are veteran‑owned, locally rooted, and committed to long‑term client relationships. This is a full‑time, hybrid remote role

  • competitive pay
  • comprehensive health, vision, and dental coverage
  • a 401(k) plan with company match
  • paid time off
  • professional development support, including a clear path from Tier 1 toward Senior Analyst

We foster a team culture centered on accountability, transparency, continuous learning, and inclusion.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior InfoSec Analyst – SOC Triage & First Response
Junior InfoSec Analyst – SOC Triage & First Response

CHR Creative • Milwaukie (OR)

Hybrid
USD 60,000 - 80,000
Competitive pay
Health, vision & dental coverage
401(k) with company match
+2
Cybersecurity Analyst
Cybersecurity Analyst

TurnPoint Services • Louisville (KY)

On-site
USD 70,000 - 100,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Information Security Analyst
Information Security Analyst

Clearcapital • Reno (NV)

On-site
USD 113,800 - 139,000
Comprehensive medical, dental, and vision insurance
401(k) retirement plan with employer match
Paid time off (PTO) and paid holidays
Senior Security Analyst
Senior Security Analyst

Katalyst • North Carolina

On-site
USD 120,000 - 180,000
401(k) matching
Paid time off
Health insurance
+1
SOC Tier 1 Analyst
SOC Tier 1 Analyst

ECS • Portland (OR)

On-site
USD 65,000 - 90,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Security Analyst II(NW Arkansas)
Security Analyst II(NW Arkansas)

Cyderes • Fayetteville (AR)

Hybrid
USD 70,000 - 100,000
Medical Insurance
Life Insurance
Retirement Match
+6
Security Operations Engineer
Security Operations Engineer

Reserv • Atlanta (GA)

Hybrid
USD 80,000 - 100,000
Generous health-insurance package
401(k) retirement plan with employer matching
Competitive PTO policy
+1
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper LLP (US) • Baltimore (MD)

On-site
USD 90,000 - 120,000