At a Glance
- Tasks: Join us to tackle complex security challenges and protect our digital landscape.
- Company: Brookfield, a dynamic tech-driven company with a collaborative culture.
- Benefits: Competitive salary, flexible working hours, and opportunities for professional growth.
- Other info: Be part of a team that values innovation and continuous learning.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: 5+ years in information security and hands-on experience with security technologies.
The predicted salary is between 63000 - 77000 £ per year.
- Location
- London - One Canada Square, Level 25
- Technology Services
Technology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.
Brookfield Culture
Brookfield has a unique and dynamic culture.
We seek team members who have a long-term focus and whose values align with our Attributes of a
Brookfield
Leader: Entrepreneurial, Collaborative and Disciplined.
Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.
Job Description
Additional Requirement
This position participates in a scheduled after-hours on-call rotation and may be required to provide timely support during significant security incidents, critical vulnerabilities, or other urgent security events.
Role Summary
The Senior Security Analyst - Security Operations & Assurance is a senior security generalist responsible for supporting day-to-day security operations and responding flexibly to evolving business and security priorities.
The role leads the investigation and resolution of complex security alerts and incidents while providing hands-on administration and support across Zscaler, email security, Microsoft security platforms, identity and access controls, vulnerability management, security awareness, third-party risk, legal hold and e Discovery, policy implementation, and security technology operations.
The Senior Analyst exercises sound judgment, works independently, and moves effectively between operational incidents, control reviews, stakeholder requests, and security improvement initiatives.
Key Responsibilities
- Investigate and respond to security alerts from Microsoft Sentinel, Microsoft Defender XDR, endpoint security tools, and other monitoring platforms; gather evidence, review logs, coordinate containment, and document findings through resolution.
- Manage security incidents, approvals, and service requests in Service Now; maintain queue health, ensure timely triage, resolve complex escalations, and provide clear stakeholder communication.
- Manage the security mailbox independently; investigate user-reported security concerns, coordinate required actions, identify recurring issues, and escalates significant matters.
- Administer Zscaler Internet Access, Zscaler Private Access, and Zscaler Client Connector; investigate connectivity, authentication, policy-enforcement, web-access, and application-access issues.
- Review Zscaler web, firewall, DNS, and access logs and implement approved changes involving URL filtering, cloud application controls, SSL/TLS inspection, data protection, remote access, and business exceptions.
- Administer email-security controls across Microsoft Defender for Office 365, Exchange Online, and Abnormal Security; investigate phishing, spoofing, executive impersonation, malicious links, business email compromise, and account compromise.
- Perform message tracing, quarantine review, tenant allow/block administration, false-positive analysis, phishing-submission review, policy tuning, and investigation of SPF, DKIM, and DMARC failures.
- Administer assigned Microsoft security platforms, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview, using least-privilege and formal change-management practices.
- Support the secure adoption and operation of approved artificial intelligence and generative AI services; review AI applications, agents, connectors, integrations, and use cases for security, privacy, identity, data-protection, retention, and third-party risks.
- Administer and monitor security controls governing access to AI applications, including Zscaler cloud application controls, data loss prevention, identity controls, application restrictions, and approved business exceptions.
- Identify and investigate unauthorized or shadow AI usage and AI-related security events, including sensitive-data disclosure, malicious uploads, account compromise, prompt injection, insecure integrations, excessive permissions, and unsafe automated actions.
- Use approved AI-enabled security capabilities to improve investigation, detection, vulnerability analysis, reporting and workflow automation while validating outputs and protecting sensitive information.
- Review and maintain Conditional Access, multifactor authentication, privileged access, role-based access control, and access-review configurations; validate changes against least-privilege principles and approved access requirements.
- Operate the enterprise vulnerability-management lifecycle, including vulnerability identification, validation, risk-based prioritization, remediation coordination, exception management, and reporting across endpoint, server, network, cloud, and application environments.
- Escalate critical and actively exploited vulnerabilities, coordinate time-sensitive remediation, track vulnerabilities through closure, and maintain dashboards, remediation targets, and documented risk acceptances.
- Lead phishing simulation and security-awareness activities, including planning, execution, results analysis, targeted follow-up, and user guidance.
- Execute legal hold and e Discovery requests using Microsoft Purview under the direction of Legal, Privacy, Human Resources, or Compliance; manage searches, evidence collection, secure data handling, and case documentation.
- Conduct and coordinate vendor and third-party risk assessments, validate due-diligence responses, identify control gaps, track remediation, and support onboarding and renewals.
- Provide operational input into security policies and standards, assess security-related change requests, and confirm that approved controls and post-change documentation are complete.
- Maintain security procedures, investigation playbooks, operational dashboards, metrics, and platform documentation; identify opportunities to automate repetitive activities using Power Shell, Python, APIs, or workflow automation.
- Participate in a scheduled information security on-call rotation; assess urgent alerts and incidents, initiate containment or escalation procedures, engage appropriate stakeholders, and maintain clear incident handoffs.
- Key Deliverables
- Security alerts, incidents, and Service Now requests resolved and documented within defined service-level targets.
- Zscaler, email-security, identity-security, and Microsoft security-platform configurations maintained in accordance with approved standards and change-management requirements.
- Phishing and business email compromise investigations completed promptly, with containment and remediation actions tracked.
- Critical vulnerabilities escalated promptly, with remediation plans established and tracked through closure.
- Vulnerability dashboards and metrics maintained, with overdue findings, exceptions, and accepted risks clearly reported.
- Phishing simulation and security-awareness activities delivered on schedule, with results analyzed and follow-up actions completed.
- Legal hold and e Discovery requests completed accurately, securely, and within required deadlines.
- Vendor assessments completed, control gaps documented, and remediation actions tracked through closure.
- Conditional Access, privileged access, RBAC, and access reviews completed on schedule, with findings documented.
- Operational runbooks, dashboards, and platform documentation maintained and continuously improved.
- AI applications and use cases reviewed for security risk, with identified control gaps, exceptions, and remediation actions documented and tracked.
- On-call security events triaged, documented, and escalated within established response targets.
- Required Experience
- Five or more years of progressive experience in information security, security operations, incident response, or a related discipline.
- Hands-on experience investigating security alerts and managing incidents through Service Now or an equivalent workflow platform.
- Experience administering enterprise security technologies and implementing approved security-policy changes.
- Hands-on experience with Zscaler, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Exchange Online security controls, or comparable platforms.
- Experience operating or supporting a vulnerability-management program, including prioritization, remediation coordination, exception handling, and reporting.
- Experience supporting email security, identity controls, security awareness, third-party risk, policy implementation, or access reviews.
- Experience supporting significant incidents and working within formal escalation and on-call procedures.
Skills & Qualifications
- Strong understanding of security operations, including alert triage, incident response, containment coordination, queue management, and investigation documentation.
- Working knowledge of Zscaler Internet Access, Zscaler Private Access, Client Connector, SASE, and Zero Trust concepts.
- Hands-on knowledge of Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and Microsoft 365 security controls.
- Understanding of vulnerability risk, exploitability, compensating controls, remediation prioritization, and risk acceptance.
- Working knowledge of email-security controls, SPF, DKIM, DMARC, and common email-based attack techniques.
- Strong documentation, communication, analytical judgment, and cross-functional coordination skills.
- Ability to work independently, adapt to changing priorities, take ownership of unfamiliar issues, and operate effectively during urgent events.
- Working knowledge of AI-security risks, generative AI technologies, data-protection considerations, shadow AI monitoring, and secure use of AI-enabled security capabilities.
- Working knowledge of Power Shell and/or Python and the ability to use APIs or workflow automation is an asset.
- Preferred Qualifications
- Experience with Service Now security modules, workflow management, and operational reporting.
- Experience with vulnerability platforms such as Microsoft Defender Vulnerability Management, Tenable, Qualys, Rapid7, or equivalent technologies.
- Familiarity with SOX compliance requirements, IT general controls, and evidence-based control testing.
- Experience supporting cloud-security monitoring and investigations across Microsoft Azure, Amazon Web Services, or other cloud environments.
- Familiarity with recognized AI-risk guidance such as the NIST AI Risk Management Framework and Generative AI Profile.
- Relevant certifications such as Security+, SC-200, AZ-500, CISSP, GCI
- #J-18808-Ljbffr
Senior Security Analyst in London employer: Brookfield Asset Management
Brookfield Asset Management is an exceptional employer, offering a dynamic work culture in the heart of London that fosters collaboration and innovation. Employees benefit from comprehensive growth opportunities, competitive compensation, and a commitment to work-life balance, making it an ideal place for those seeking meaningful and rewarding careers in a global environment.
Contact Details:
Brookfield Asset Management Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Senior Security Analyst in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Brookfield Asset Management, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Brookfield Asset Management
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Brookfield Asset Management. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior Security Analyst in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Brookfield Asset Management insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Brookfield Asset Management that you’re committed to staying ahead in the game.
How to prepare for a job interview at Brookfield Asset Management
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Brookfield Asset Management to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Brookfield Asset Management.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.