Junior Information Security Analyst

CHR CREATIVE, LLC
Milwaukie, OR, United States
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Compensation
$58,000.0 - $72,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Software as a Service Cyber Security Phishing Runbook Security Information and Event Management

Job description

This is a first-line security role, and a strong entry point into a security career at a firm that takes it seriously. You will be the first set of eyes on security alerts and tickets across our managed client base, triaging them under the direction of our senior analysts and vCSO. You will own the day-to-day SaaS Alerts queue for Microsoft 365, run routine security tasks from documented runbooks, and keep the documentation clean enough that senior staff and auditors can rely on it without re-asking.

This seat is entry level by design, with a real learning curve and senior backstop. We expect you to know what you do not know and escalate early. Interpretation and judgment stay with the senior team. You are measured on triage, execution, and documentation done well.

What You’ll Do

Security triage

  • Acknowledge and triage incoming security alerts and tickets from SaaS Alerts, SOC, and EDR detections, moving them promptly under senior direction.
  • Classify severity for each item against the client’s Alert Response Playbook, and escalate appropriately to the Senior Analyst or vCSO.

SaaS Alerts queue ownership

  • Serve as the named first-line owner of the SaaS Alerts Microsoft 365 queue, worked for every onboarded client tenant so none goes unattended.
  • Flag noisy or benign detection patterns for tuning or automation so the queue stays manageable as volume grows.

Runbook and endpoint tasks

  • Run routine tasks from checklists and runbooks: account compromise first response, MFA and password resets with identity verification, and phishing report review.
  • Monitor endpoint agent health, and follow up on offline or unreporting endpoints until resolved.
  • Identify benign scanner and penetration-test traffic and coordinate allowlisting with the SOC so partners are not paged for expected activity.

Documentation and compliance evidence

  • Keep ticket documentation complete enough for a senior analyst to pick up without re-asking.
  • Gather compliance evidence on request, including screenshots, exports, and asset lists.
  • Help close recurring security findings such as cleartext PII, non-expiring passwords, missing MFA, and Microsoft Secure Score quick wins.

On-call

  • Stand in the on-call and after-hours rotation, responding against the documented escalation SLA.

Requirements

  • A foundational understanding of information security concepts: identity and access, MFA, phishing, endpoint protection, and common alert types.
  • Familiarity with Microsoft 365 and its security and admin surfaces.
  • Precise, reliable documentation habits and clear written communication.
  • The discipline to follow runbooks exactly, and the judgment to escalate early rather than guess.
  • Willingness to participate in an on-call and after-hours rotation.

Preferred

  • Security+ or a comparable entry-level certification, earned or in progress.
  • Exposure to SOC, EDR, SIEM, or alert-triage tooling, and to platforms like SaaS Alerts or Rewst.
  • Awareness of compliance obligations such as HIPAA, PCI, or CJIS.
  • An associate or bachelor degree in cybersecurity or IT, or equivalent hands-on experience.
  • MSP or multi-client environment experience.

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance, * You document as a default, not as an afterthought.
  • You know what you do not know, and you escalate early instead of guessing.
  • You want to build a security career in an environment where standards are enforced, not improvised.
  • You take routine execution seriously, because in security the routine work is what protects clients.

What We Offer

  • Comprehensive health, vision, and dental insurance.
  • 401(k) retirement plan with company match.
  • Paid time off, including vacation and sick days.
  • Professional development and certification support, with a clear path from Tier 1 toward Senior Analyst.
  • A team culture built on accountability, transparency, and continuous learning.
  • Milwaukie, Oregon office, 10 minutes from Portland.

CHR Creative is an equal opportunity employer. We value a diverse team and an inclusive culture.

Job Type: Full-time

Pay: $58,000.00 - $72,000.00 per year, * 401(k)

  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance

About the company

CHR Creative is a security-first managed services and IT risk management firm based in Milwaukie, Oregon. Since 2006, we have partnered with CFOs, senior leadership, and company principals to help them manage technology risk, achieve compliance, and build resilient operations. We serve over 100 clients, with deep experience in the nonprofit and human services sector. We are veteran-owned, locally rooted, and built on long-term client partnerships.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all