> Markdown version of [/jobs/ext/1914478-junior-information-security-analyst](https://www.wearedevelopers.com/jobs/ext/1914478-junior-information-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior Information Security Analyst - **Company:** CHR CREATIVE, LLC - **Location:** Milwaukie, OR, United States - **Experience:** Starter - **Salary:** $58,000.0 - $72,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software as a Service, Cyber Security, Phishing, Runbook, Security Information and Event Management - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ec2c6b276fccb37e ## About the Role * A foundational understanding of information security concepts: identity and access, MFA, phishing, endpoint protection, and common alert types. * Familiarity with Microsoft 365 and its security and admin surfaces. * Precise, reliable documentation habits and clear written communication. * The discipline to follow runbooks exactly, and the judgment to escalate early rather than guess. * Willingness to participate in an on-call and after-hours rotation. Preferred * Security+ or a comparable entry-level certification, earned or in progress. * Exposure to SOC, EDR, SIEM, or alert-triage tooling, and to platforms like SaaS Alerts or Rewst. * Awareness of compliance obligations such as HIPAA, PCI, or CJIS. * An associate or bachelor degree in cybersecurity or IT, or equivalent hands-on experience. * MSP or multi-client environment experience. ## Description This is a first-line security role, and a strong entry point into a security career at a firm that takes it seriously. You will be the first set of eyes on security alerts and tickets across our managed client base, triaging them under the direction of our senior analysts and vCSO. You will own the day-to-day SaaS Alerts queue for Microsoft 365, run routine security tasks from documented runbooks, and keep the documentation clean enough that senior staff and auditors can rely on it without re-asking. This seat is entry level by design, with a real learning curve and senior backstop. We expect you to know what you do not know and escalate early. Interpretation and judgment stay with the senior team. You are measured on triage, execution, and documentation done well. What You'll Do Security triage * Acknowledge and triage incoming security alerts and tickets from SaaS Alerts, SOC, and EDR detections, moving them promptly under senior direction. * Classify severity for each item against the client's Alert Response Playbook, and escalate appropriately to the Senior Analyst or vCSO. SaaS Alerts queue ownership * Serve as the named first-line owner of the SaaS Alerts Microsoft 365 queue, worked for every onboarded client tenant so none goes unattended. * Flag noisy or benign detection patterns for tuning or automation so the queue stays manageable as volume grows. Runbook and endpoint tasks * Run routine tasks from checklists and runbooks: account compromise first response, MFA and password resets with identity verification, and phishing report review. * Monitor endpoint agent health, and follow up on offline or unreporting endpoints until resolved. * Identify benign scanner and penetration-test traffic and coordinate allowlisting with the SOC so partners are not paged for expected activity. Documentation and compliance evidence * Keep ticket documentation complete enough for a senior analyst to pick up without re-asking. * Gather compliance evidence on request, including screenshots, exports, and asset lists. * Help close recurring security findings such as cleartext PII, non-expiring passwords, missing MFA, and Microsoft Secure Score quick wins. On-call * Stand in the on-call and after-hours rotation, responding against the documented escalation SLA. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)