Senior Security Analyst
Brookfield Asset Manager (UK) Holdco Limited · Remote, England, United Kingdom
About The Role
London - One Canada Square, Level 25
Technology Services
Technology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.
Brookfield Culture
Brookfield has a unique and dynamic culture. We seek team members who have a long-term focus and whose values align with our Attributes of a Brookfield Leader: Entrepreneurial, Collaborative and Disciplined. Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.
Job Description
Additional Requirement
This position participates in a scheduled after-hours on-call rotation and may be required to provide timely support during significant security incidents, critical vulnerabilities, or other urgent security events.
Role Summary
The Senior Security Analyst - Security Operations & Assurance is a senior security generalist responsible for supporting day-to-day security operations and responding flexibly to evolving business and security priorities. The role leads the investigation and resolution of complex security alerts and incidents while providing hands-on administration and support across Zscaler, email security, Microsoft security platforms, identity and access controls, vulnerability management, security awareness, third-party risk, legal hold and eDiscovery, policy implementation, and security technology operations. The Senior Analyst exercises sound judgment, works independently, and moves effectively between operational incidents, control reviews, stakeholder requests, and security improvement initiatives.
Key Responsibilities
Investigate and respond to security alerts from Microsoft Sentinel, Microsoft Defender XDR, endpoint security tools, and other monitoring platforms; gather evidence, review logs, coordinate containment, and document findings through resolution.
Manage security incidents, approvals, and service requests in ServiceNow; maintain queue health, ensure timely triage, resolve complex escalations, and provide clear stakeholder communication.
Manage the security mailbox independently; investigate user-reported security concerns, coordinate required actions, identify recurring issues, and escalate significant matters.
Administer Zscaler Internet Access, Zscaler Private Access, and Zscaler Client Connector; investigate connectivity, authentication, policy-enforcement, web-access, and application-access issues.
Review Zscaler web, firewall, DNS, and access logs and implement approved changes involving URL filtering, cloud application controls, SSL/TLS inspection, data protection, remote access, and business exceptions.
Administer email-security controls across Microsoft Defender for Office 365, Exchange Online, and Abnormal Security; investigate phishing, spoofing, executive impersonation, malicious links, business email compromise, and account compromise.
Perform message tracing, quarantine review, tenant allow/block administration, false-positive analysis, phishing-submission review, policy tuning, and investigation of SPF, DKIM, and DMARC failures.
Administer assigned Microsoft security platforms, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview, using least-privilege and formal change-management practices.
Support the secure adoption and operation of approved artificial intelligence and generative AI services; review AI applications, agents, connectors, integrations, and use cases for security, privacy, identity, data-protection, retention, and third-party risks.
Administer and monitor security controls governing access to AI applications, including Zscaler cloud application controls, data loss prevention, identity controls, application restrictions, and approved business exceptions.
Identify and investigate unauthorized or shadow AI usage and AI-related security events, including sensitive-data disclosure, malicious uploads, account compromise, prompt injection, insecure integrations, excessive permissions, and unsafe automated actions.
Use approved AI-enabled security capabilities to improve investigation, detection, vulnerability analysis, reporting, and workflow automation while validating outputs and protecting sensitive information.
Review and maintain Conditional Access, multifactor authentication, privileged access, role-based access control, and access-review configurations; validate changes against least-privilege principles and approved access requirements.
Operate the enterprise vulnerability-management lifecycle, including vulnerability identification, validation, risk-based prioritization, remediation coordination, exception management, and reporting across endpoint, server, network, cloud, and application environments.
Escalate critical and actively exploited vulnerabilities, coordinate time-sensitive remediation, track vulnerabilities through closure, and maintain dashboards, remediation targets, and documented risk acceptances.
Lead phishing simulation and security-awareness activities, including planning, execution, results analysis, targeted follow-up, and user guidance.
Execute legal hold and eDiscovery requests using Microsoft Purview under the direction of Legal, Privacy, Human Resources, or Compliance; manage searches, evidence collection, secure data handling, and case documentation.
Conduct and coordinate vendor and third-party risk assessments, validate due-diligence responses, identify control gaps, track remediation, and support onboarding and renewals.
Provide operational input into security policies and standards, assess security-related change requests, and confirm that approved controls and post-change documentation are complete.
Maintain security procedures, investigation playbooks, operational dashboards, metrics, and platform documentation; identify opportunities to automate repetitive activities using PowerShell, Python, APIs, or workflow automation.
Participate in a scheduled information security on-call rotation; assess urgent alerts and incidents, initiate containment or escalation procedures, engage appropriate stakeholders, and maintain clear incident handoffs.
Key Deliverables
- Security alerts, incidents, and ServiceNow requests resolved and documented within defined service-level targets.
- Zscaler, email-security, identity-security, and Microsoft security-platform configurations maintained in accordance with approved standards and change-management requirements.
- Phishing and business email compromise investigations completed promptly, with containment and remediation actions tracked.
- Critical vulnerabilities escalated promptly, with remediation plans established and tracked through closure.
- Vulnerability dashboards and metrics maintained, with overdue findings, exceptions, and accepted risks clearly reported.
- Phishing simulation and security-awareness activities delivered on schedule, with results analyzed and follow-up actions completed.
- Legal hold and eDiscovery requests completed accurately, securely, and within required deadlines.
- Vendor assessments completed, control gaps documented, and remediation actions tracked through closure.
- Conditional Access, privileged access, RBAC, and access reviews completed on schedule, with findings documented.
- Operational runbooks, dashboards, and platform documentation maintained and continuously improved.
- AI applications and use cases reviewed for security risk, with identified control gaps, exceptions, and remediation actions documented and tracked.
- On-call security events triaged, documented, and escalated within established response targets.
Required Experience
- Five or more years of progressive experience in information security, security operations, incident response, or a related discipline.
- Hands-on experience investigating security alerts and managing incidents through ServiceNow or an equivalent workflow platform.
- Experience administering enterprise security technologies and implementing approved security-policy changes.
- Hands-on experience with Zscaler, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Exchange Online security controls, or comparable platforms.
- Experience operating or supporting a vulnerability-management program, including prioritization, remediation coordination, exception handling, and reporting.
- Experience supporting email security, identity controls, security awareness, third-party risk, policy implementation, or access reviews.
- Experience supporting significant incidents and working within formal escalation and on-call procedures.
Skills & Qualifications
- Strong understanding of security operations, including alert triage, incident response, containment coordination, queue management, and investigation documentation.
- Working knowledge of Zscaler Internet Access, Zscaler Private Access, Client Connector, SASE, and Zero Trust concepts.
- Hands-on knowledge of Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and Microsoft 365 security controls.
- Understanding of vulnerability risk, exploitability, compensating controls, remediation prioritization, and risk acceptance.
- Working knowledge of email-security controls, SPF, DKIM, DMARC, and common email-based attack techniques.
- Strong documentation, communication, analytical judgment, and cross-functional coordination skills.
- Ability to work independently, adapt to changing priorities, take ownership of unfamiliar issues, and operate effectively during urgent events.
- Working knowledge of AI-security risks, generative AI technologies, data-protection considerations, shadow AI monitoring, and secure use of AI-enabled security capabilities.
- Working knowledge of PowerShell and/or Python and the ability to use APIs or workflow automation is an asset.
Preferred Qualifications
Experience with ServiceNow security modules, workflow management, and operational reporting.
Experience with vulnerability platforms such as Microsoft Defender Vulnerability Management, Tenable, Qualys, Rapid7, or equivalent technologies.
Familiarity with SOX compliance requirements, IT general controls, and evidence-based control testing.
Experience supporting cloud-security monitoring and investigations across Microsoft Azure, Amazon Web Services, or other cloud environments.
Familiarity with recognized AI-risk guidance such as the NIST AI Risk Management Framework and Generative AI Profile.
Relevant certifications such as Security+, SC-200, AZ-500, CISSP, GCIH, or equivalent credentials.
Post-secondary education in cybersecurity, information technology, computer science, or a related discipline, or equivalent practical experience.
Brookfield is committed to maintaining a Positive Work Environment that is safe and respectful; our shared success depends on it. We do not tolerate workplace discrimination, violence or harassment. We are proud to be an Equal Opportunity Employer and make employment decisions based on qualifications, merit and business needs, without regard to any characteristic protected by applicable law.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
