Information Security Analyst
ZGF ArchitectsAbout the role
ZGF is seeking a motivated and collaborative Information Security Analyst to join our Technology team. We are open for this role to be based in one of ZGF’s offices (Portland, Seattle, Vancouver BC, Los Angeles, Denver, New York, or Washington DC), but with a preference for Portland, OR. This role will help support and enhance firmwide cybersecurity protections.
The Information Security Analyst reports to the Senior Manager, Information Security and works closely with the broader IT team across seven North American offices to implement firm-wide security initiatives and strengthen the firm’s overall security posture.
ZGF maintains a strong security program leveraging Microsoft’s security platform (e.g., Defender, Intune, Entra ID, Active Directory, Purview), a SOC and MDR managed by Arctic Wolf, and Fortinet network technologies. This role provides the opportunity to contribute across and expand expertise in multiple areas of cybersecurity operations, including identity security, threat detection, vulnerability management, incident response, and security architecture.
We are looking for a mid-level cybersecurity professional who enjoys hands-on security operations, problem-solving, improving systems, and collaborating with others to build practical and effective security solutions.
As an Information Security Analyst, you will….
- Support daily security operations, including monitoring and analyzing alerts, investigating suspicious activity, threat prevention, and responding to security events.
- Participate in incident response activities and security investigations.
- Collaborate with the firm’s Managed Security Service Provider (MSSP) to enhance detection and response capabilities.
- Administer identity and access lifecycle processes, including provisioning, access reviews, and privilege management.
- Support the secure configuration and administration of identity systems, including Active Directory and Microsoft Entra ID.
- Conduct vulnerability management activities and coordinate remediation efforts.
- Identify and evaluate security risks and work with IT teams to implement mitigation strategies.
- Identify opportunities to strengthen the firm’s security posture and support the implementation of improvements.
- Assist with the deployment and maintenance of security technologies across the environment.
- Contribute to the development and maintenance of security standards, documentation, and operational procedures.
- Partner with IT and business teams to ensure security controls balance productivity with security best practices.
- Support security awareness initiatives and assist with educating employees on cybersecurity best practices.
Qualifications
Required:
- Strong professional integrity and commitment to confidentiality.
- Strong problem-solving skills and the ability to manage multiple priorities.
- Experience supporting security operations in Microsoft environments, including Active Directory and M365 E5 technologies such as:
- Defender for Endpoint, Identity, Cloud Apps
- Group Policy
- Intune
- Purview
- Conditional Access
- Certificate Services
- Experience evaluating vulnerabilities and implementing remediation actions.
- Understanding of modern cyber threats, including phishing, credential attacks, and lateral movement techniques.
- Approximately 3+ years of cybersecurity or related IT experi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s