Information Security Analyst

ZGF Architects
Seattle, WA, United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$95,310.0 - $111,195.0
Working hours
Regular working hours
Job source

Tech stack

Active Directory Cloud Computing CompTIA Security+ Cyber Security Information Systems Identity and Access Management Intrusion Detection and Prevention Public Key Infrastructure Azure Active Directory Phishing Zero Trust Network Access Security Information and Event Management
+8 more
Software Vulnerability Management EndPointSecurity Scripting Firewalls (Computer Science) Microsoft InTune Information Technology Cybercrime Fortinet

Job description

ZGF is seeking a motivated and collaborative Information Security Analyst to join our Technology team. We are open for this role to be based in one of ZGF ‘ s offices (Portland, Seattle, Vancouver BC, Los Angeles, Denver, New York, or Washington DC), but with a preference for Portland, OR . This role will help support and enhance firmwide cybersecurity protections.

The Information Security Analyst reports to the Senior Manager, Information Security and works closely with the broader IT team across seven North American offices to implement firm-wide security initiatives and strengthen the firm’s overall security posture.

ZGF maintains a strong security program leveraging Microsoft’s security platform (e.g., Defender, Intune, Entra ID, Active Directory, Purview), a SOC and MDR managed by Arctic Wolf, and Fortinet network technologies. This role provides the opportunity to contribute across and expand expertise in multiple areas of cybersecurity operations, including identity security, threat detection, vulnerability management, incident response, and security architecture., + Support daily security operations, including monitoring and analyzing alerts, investigating suspicious activity, threat prevention, and responding to security events.

  • Participate in incident response activities and security investigations.

  • Collaborate with the firm’s Managed Security Service Provider (MSSP) to enhance detection and response capabilities.

  • Administer identity and access lifecycle processes, including provisioning, access reviews, and privilege management.

  • Support the secure configuration and administration of identity systems, including Active Directory and Microsoft Entra ID.

  • Conduct vulnerability management activities and coordinate remediation efforts.

  • Identify and evaluate security risks and work with IT teams to implement mitigation strategies.

  • Identify opportunities to strengthen the firm’s security posture and support the implementation of improvements.

  • Assist with the deployment and maintenance of security technologies across the environment.

  • Contribute to the development and maintenance of security standards, documentation, and operational procedures.

  • Partner with IT and business teams to ensure security controls balance productivity with security best practices.

  • Support security awareness initiatives and assist with educating employees on cybersecurity best practices.

Requirements

We are looking for a mid-level cybersecurity professional who enjoys hands-on security operations, problem-solving, improving systems, and collaborating with others to build practical and effective security solutions., Required:

  • Strong professional integrity and commitment to confidentiality.

  • Strong problem-solving skills and the ability to manage multiple priorities.

  • Experience supporting security operations in Microsoft environments, including Active Directory and M365 E5 technologies such as:

  • Defender for Endpoint, Identity, Cloud Apps, + Experience evaluating vulnerabilities and implementing remediation actions.

  • Understanding of modern cyber threats, including phishing, credential attacks, and lateral movement techniques.

  • Approximately 3+ years of cybersecurity or related IT experience.

  • Bachelor’s degree in Computer Science, Information Systems, or related field, or equivalent professional experience.

Preferred:

  • Professional cybersecurity certification (Security+, CISSP, SSCP, GIAC, or similar).

  • Experience working with managed SOC services or MSSPs.

  • Familiarity with security frameworks and compliance standards such as NIST CSF, CMMC, and NIST 800-171.

  • Familiarity with Microsoft GCC environments.

  • Experience with automation tools or scripting languages used for security or system administration tasks.

  • Experience administering cybersecurity technologies such as firewalls, endpoint protection, zero trust network access, RADIUS, PKI, and encryption.

  • Familiarity with SIEM platforms and security alert management.

  • Understanding of technology environments supporting architectural or design workflows.

Additional Requirements:

  • Occasional travel to other ZGF offices may be required.

  • Ability to lift and transport technology equipment when needed.

  • Availability for occasional after-hours support related to security incidents or initiatives.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:17 min

Fortinet firewall administrative passwords leaked on the dark net

Chris Heilmann +1 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all