At a Glance
- Tasks: Investigate security alerts and manage incidents to protect our digital landscape.
- Company: Join Brookfield, a dynamic tech company with a collaborative culture.
- Benefits: Enjoy competitive salary, health benefits, and opportunities for professional growth.
- Other info: Be part of a team that values entrepreneurial spirit and disciplined collaboration.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: 5+ years in information security and hands-on experience with security technologies.
The predicted salary is between 63000 - 77000 Β£ per year.
- Location
- London - One Canada Square, Level 25
- Technology Services
Technology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.
Brookfield Culture
Brookfield has a unique and dynamic culture.
We seek team members who have a long-term focus and whose values align with our Attributes of a
Brookfield
Leader: Entrepreneurial, Collaborative and Disciplined.
Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.
Job Description
Additional Requirement
This position participates in a scheduled after-hours on-call rotation and may be required to provide timely support during significant security incidents, critical vulnerabilities, or other urgent security events.
Role Summary
The Senior Security Analyst - Security Operations & Assurance is a senior security generalist responsible for supporting day-to-day security operations and responding flexibly to evolving business and security priorities.
The role leads the investigation and resolution of complex security alerts and incidents while providing hands-on administration and support across Zscaler, email security, Microsoft security platforms, identity and access controls, vulnerability management, security awareness, third-party risk, legal hold and e Discovery, policy implementation, and security technology operations.
The Senior Analyst exercises sound judgment, works independently, and moves effectively between operational incidents, control reviews, stakeholder requests, and security improvement initiatives.
Key Responsibilities
- Investigate and respond to security alerts from Microsoft Sentinel, Microsoft Defender XDR, endpoint security tools, and other monitoring platforms; gather evidence, review logs, coordinate containment, and document findings through resolution.
- Manage security incidents, approvals, and service requests in Service Now; maintain queue health, ensure timely triage, resolve complex escalations, and provide clear stakeholder communication.
- Manage the security mailbox independently; investigate user-reported security concerns, coordinate required actions, identify recurring issues, and escalates significant matters.
- Administer Zscaler Internet Access, Zscaler Private Access, and Zscaler Client Connector; investigate connectivity, authentication, policy-enforcement, web-access, and application-access issues.
- Review Zscaler web, firewall, DNS, and access logs and implement approved changes involving URL filtering, cloud application controls, SSL/TLS inspection, data protection, remote access, and business exceptions.
- Administer email-security controls across Microsoft Defender for Office 365, Exchange Online, and Abnormal Security; investigate phishing, spoofing, executive impersonation, malicious links, business email compromise, and account compromise.
- Perform message tracing, quarantine review, tenant allow/block administration, false-positive analysis, phishing-submission review, policy tuning, and investigation of SPF, DKIM, and DMARC failures.
- Administer assigned Microsoft security platforms, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview, using least-privilege and formal change-management practices.
- Support the secure adoption and operation of approved artificial intelligence and generative AI services; review AI applications, agents, connectors, integrations, and use cases for security, privacy, identity, data-protection, retention, and third-party risks.
- Administer and monitor security controls governing access to AI applications, including Zscaler cloud application controls, data loss prevention, identity controls, application restrictions, and approved business exceptions.
- Identify and investigate unauthorized or shadow AI usage and AI-related security events, including sensitive-data disclosure, malicious uploads, account compromise, prompt injection, insecure integrations, excessive permissions, and unsafe automated actions.
- Use approved AI-enabled security capabilities to improve investigation, detection, vulnerability analysis, reporting and workflow automation while validating outputs and protecting sensitive information.
- Review and maintain Conditional Access, multifactor authentication, privileged access, role-based access control, and access-review configurations; validate changes against least-privilege principles and approved access requirements.
- Operate the enterprise vulnerability-management lifecycle, including vulnerability identification, validation, risk-based prioritization, remediation coordination, exception management, and reporting across endpoint, server, network, cloud, and application environments.
- Escalate critical and actively exploited vulnerabilities, coordinate time-sensitive remediation, track vulnerabilities through closure, and maintain dashboards, remediation targets, and documented risk acceptances.
- Lead phishing simulation and security-awareness activities, including planning, execution, results analysis, targeted follow-up, and user guidance.
- Execute legal hold and e Discovery requests using Microsoft Purview under the direction of Legal, Privacy, Human Resources, or Compliance; manage searches, evidence collection, secure data handling, and case documentation.
- Conduct and coordinate vendor and third-party risk assessments, validate due-diligence responses, identify control gaps, track remediation, and support onboarding and renewals.
- Provide operational input into security policies and standards, assess security-related change requests, and confirm that approved controls and post-change documentation are complete.
- Maintain security procedures, investigation playbooks, operational dashboards, metrics, and platform documentation; identify opportunities to automate repetitive activities using Power Shell, Python, APIs, or workflow automation.
- Participate in a scheduled information security on-call rotation; assess urgent alerts and incidents, initiate containment or escalation procedures, engage appropriate stakeholders, and maintain clear incident handoffs.
- Key Deliverables
- Security alerts, incidents, and Service Now requests resolved and documented within defined service-level targets.
- Zscaler, email-security, identity-security, and Microsoft security-platform configurations maintained in accordance with approved standards and change-management requirements.
- Phishing and business email compromise investigations completed promptly, with containment and remediation actions tracked.
- Critical vulnerabilities escalated promptly, with remediation plans established and tracked through closure.
- Vulnerability dashboards and metrics maintained, with overdue findings, exceptions, and accepted risks clearly reported.
- Phishing simulation and security-awareness activities delivered on schedule, with results analyzed and follow-up actions completed.
- Legal hold and e Discovery requests completed accurately, securely, and within required deadlines.
- Vendor assessments completed, control gaps documented, and remediation actions tracked through closure.
- Conditional Access, privileged access, RBAC, and access reviews completed on schedule, with findings documented.
- Operational runbooks, dashboards, and platform documentation maintained and continuously improved.
- AI applications and use cases reviewed for security risk, with identified control gaps, exceptions, and remediation actions documented and tracked.
- On-call security events triaged, documented, and escalated within established response targets.
- Required Experience
- Five or more years of progressive experience in information security, security operations, incident response, or a related discipline.
- Hands-on experience investigating security alerts and managing incidents through Service Now or an equivalent workflow platform.
- Experience administering enterprise security technologies and implementing approved security-policy changes.
- Hands-on experience with Zscaler, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Exchange Online security controls, or comparable platforms.
- Experience operating or supporting a vulnerability-management program, including prioritization, remediation coordination, exception handling, and reporting.
- Experience supporting email security, identity controls, security awareness, third-party risk, policy implementation, or access reviews.
- Experience supporting significant incidents and working within formal escalation and on-call procedures.
Skills & Qualifications
- Strong understanding of security operations, including alert triage, incident response, containment coordination, queue management, and investigation documentation.
- Working knowledge of Zscaler Internet Access, Zscaler Private Access, Client Connector, SASE, and Zero Trust concepts.
- Hands-on knowledge of Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and Microsoft 365 security controls.
- Understanding of vulnerability risk, exploitability, compensating controls, remediation prioritization, and risk acceptance.
- Working knowledge of email-security controls, SPF, DKIM, DMARC, and common email-based attack techniques.
- Strong documentation, communication, analytical judgment, and cross-functional coordination skills.
- Ability to work independently, adapt to changing priorities, take ownership of unfamiliar issues, and operate effectively during urgent events.
- Working knowledge of AI-security risks, generative AI technologies, data-protection considerations, shadow AI monitoring, and secure use of AI-enabled security capabilities.
- Working knowledge of Power Shell and/or Python and the ability to use APIs or workflow automation is an asset.
- Preferred Qualifications
- Experience with Service Now security modules, workflow management, and operational reporting.
- Experience with vulnerability platforms such as Microsoft Defender Vulnerability Management, Tenable, Qualys, Rapid7, or equivalent technologies.
- Familiarity with SOX compliance requirements, IT general controls, and evidence-based control testing.
- Experience supporting cloud-security monitoring and investigations across Microsoft Azure, Amazon Web Services, or other cloud environments.
- Familiarity with recognized AI-risk guidance such as the NIST AI Risk Management Framework and Generative AI Profile.
- Relevant certifications such as Security+, SC-200, AZ-500, CISSP, GCI
- #J-18808-Ljbffr
Senior Security Analyst employer: Brookfield Asset Management
Brookfield Asset Management is an exceptional employer, offering a dynamic work culture in the heart of London that fosters collaboration and innovation. Employees benefit from comprehensive growth opportunities, competitive compensation, and a commitment to work-life balance, making it an ideal place for those seeking meaningful and rewarding careers in a global environment.
Contact Details:
Brookfield Asset Management Recruitment Team