Rodeo
Get started

Brookfield Asset Management

Senior Security Analyst

London
Posted about 17 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Location

London - One Canada Square, Level 25

Technology Services

Technology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.

Brookfield Culture

Brookfield has a unique and dynamic culture. We seek team members who have a long-term focus and whose values align with our Attributes of a Brookfield Leader: Entrepreneurial, Collaborative and Disciplined. Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.

Job Description

Additional Requirement

This position participates in a scheduled after-hours on-call rotation and may be required to provide timely support during significant security incidents, critical vulnerabilities, or other urgent security events.

Role Summary

The Senior Security Analyst - Security Operations & Assurance is a senior security generalist responsible for supporting day-to-day security operations and responding flexibly to evolving business and security priorities. The role leads the investigation and resolution of complex security alerts and incidents while providing hands-on administration and support across Zscaler, email security, Microsoft security platforms, identity and access controls, vulnerability management, security awareness, third-party risk, legal hold and eDiscovery, policy implementation, and security technology operations. The Senior Analyst exercises sound judgment, works independently, and moves effectively between operational incidents, control reviews, stakeholder requests, and security improvement initiatives.

Key Responsibilities

  • Investigate and respond to security alerts from Microsoft Sentinel, Microsoft Defender XDR, endpoint security tools, and other monitoring platforms; gather evidence, review logs, coordinate containment, and document findings through resolution.
  • Manage security incidents, approvals, and service requests in ServiceNow; maintain queue health, ensure timely triage, resolve complex escalations, and provide clear stakeholder communication.
  • Manage the security mailbox independently; investigate user-reported security concerns, coordinate required actions, identify recurring issues, and escalate significant matters.
  • Administer Zscaler Internet Access, Zscaler Private Access, and Zscaler Client Connector; investigate connectivity, authentication, policy-enforcement, web-access, and application-access issues.
  • Review Zscaler web, firewall, DNS, and access logs and implement approved changes involving URL filtering, cloud application controls, SSL/TLS inspection, data protection, remote access, and business exceptions.
  • Administer email-security controls across Microsoft Defender for Office 365, Exchange Online, and Abnormal Security; investigate phishing, spoofing, executive impersonation, malicious links, business email compromise, and account compromise.
  • Perform message tracing, quarantine review, tenant allow/block administration, false-positive analysis, phishing-submission review, policy tuning, and investigation of SPF, DKIM, and DMARC failures.
  • Administer assigned Microsoft security platforms, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview, using least-privilege and formal change-management practices.
  • Support the secure adoption and operation of approved artificial intelligence and generative AI services; review AI applications, agents, connectors, integrations, and use cases for security, privacy, identity, data-protection, retention, and third-party risks.
  • Administer and monitor security controls governing access to AI applications, including Zscaler cloud application controls, data loss prevention, identity controls, application restrictions, and approved business exceptions.
  • Identify and investigate unauthorized or shadow AI usage and AI-related security events, including sensitive-data disclosure, malicious uploads, account compromise, prompt injection, insecure integrations, excessive permissions, and unsafe automated actions.
  • Use approved AI-enabled security capabilities to improve investigation, detection, vulnerability analysis, reporting, and workflow automation while validating outputs and protecting sensitive information.
  • Review and maintain Conditional Access, multifactor authentication, privileged access, role-based access control, and access-review configurations; validate changes against least-privilege principles and approved access requirements.
  • Operate the enterprise vulnerability-management lifecycle, including vulnerability identification, validation, risk-based prioritization, remediation coordination, exception management, and reporting across endpoint, server, network, cloud, and application environments.
  • Escalate critical and actively exploited vulnerabilities, coordinate time-sensitive remediation, track vulnerabilities through closure, and maintain dashboards, remediation targets, and documented risk acceptances.
  • Lead phishing simulation and security-awareness activities, including planning, execution, results analysis, targeted follow-up, and user guidance.
  • Execute legal hold and eDiscovery requests using Microsoft Purview under the direction of Legal, Privacy, Human Resources, or Compliance; manage searches, evidence collection, secure data handling, and case documentation.
  • Conduct and coordinate vendor and third-party risk assessments, validate due-diligence responses, identify control gaps, track remediation, and support onboarding and renewals.
  • Provide operational input into security policies and standards, assess security-related change requests, and confirm that approved controls and post-change documentation are complete.
  • Maintain security procedures, investigation playbooks, operational dashboards, metrics, and platform documentation; identify opportunities to automate repetitive activities using PowerShell, Python, APIs, or workflow automation.
  • Participate in a scheduled information security on-call rotation; assess urgent alerts and incidents, initiate containment or escalation procedures, engage appropriate stakeholders, and maintain clear incident handoffs.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Key Deliverables

  • Security alerts, incidents, and ServiceNow requests resolved and documented within defined service-level targets.
  • Zscaler, email-security, identity-security, and Microsoft security-platform configurations maintained in accordance with approved standards and change-management requirements.
  • Phishing and business email compromise investigations completed promptly, with containment and remediation actions tracked.
  • Critical vulnerabilities escalated promptly, with remediation plans established and tracked through closure.
  • Vulnerability dashboards and metrics maintained, with overdue findings, exceptions, and accepted risks clearly reported.
  • Phishing simulation and security-awareness activities delivered on schedule, with results analyzed and follow-up actions completed.
  • Legal hold and eDiscovery requests completed accurately, securely, and within required deadlines.
  • Vendor assessments completed, control gaps documented, and remediation actions tracked through closure.
  • Conditional Access, privileged access, RBAC, and access reviews completed on schedule, with findings documented.
  • Operational runbooks, dashboards, and platform documentation maintained and continuously improved.
  • AI applications and use cases reviewed for security risk, with identified control gaps, exceptions, and remediation actions documented and tracked.
  • On-call security events triaged, documented, and escalated within established response targets.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Required Experience

  • Five or more years of progressive experience in information security, security operations, incident response, or a related discipline.
  • Hands-on experience investigating security alerts and managing incidents through ServiceNow or an equivalent workflow platform.
  • Experience administering enterprise security technologies and implementing approved security-policy changes.
  • Hands-on experience with Zscaler, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Exchange Online security controls, or comparable platforms.
  • Experience operating or supporting a vulnerability-management program, including prioritization, remediation coordination, exception handling, and reporting.
  • Experience supporting email security, identity controls, security awareness, third-party risk, policy implementation, or access reviews.
  • Experience supporting significant incidents and working within formal escalation and on-call procedures.

Skills & Qualifications

  • Strong understanding of security operations, including alert triage, incident response, containment coordination, queue management, and investigation documentation.
  • Working knowledge of Zscaler Internet Access, Zscaler Private Access, Client Connector, SASE, and Zero Trust concepts.
  • Hands-on knowledge of Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and Microsoft 365 security controls.
  • Understanding of vulnerability risk, exploitability, compensating controls, remediation prioritization, and risk acceptance.
  • Working knowledge of email-security controls, SPF, DKIM, DMARC, and common email-based attack techniques.
  • Strong documentation, communication, analytical judgment, and cross-functional coordination skills.
  • Ability to work independently, adapt to changing priorities, take ownership of unfamiliar issues, and operate effectively during urgent events.
  • Working knowledge of AI-security risks, generative AI technologies, data-protection considerations, shadow AI monitoring, and secure use of AI-enabled security capabilities.
  • Working knowledge of PowerShell and/or Python and the ability to use APIs or workflow automation is an asset.

Preferred Qualifications

  • Experience with ServiceNow security modules, workflow management, and operational reporting.
  • Experience with vulnerability platforms such as Microsoft Defender Vulnerability Management, Tenable, Qualys, Rapid7, or equivalent technologies.
  • Familiarity with SOX compliance requirements, IT general controls, and evidence-based control testing.
  • Experience supporting cloud-security monitoring and investigations across Microsoft Azure, Amazon Web Services, or other cloud environments.
  • Familiarity with recognized AI-risk guidance such as the NIST AI Risk Management Framework and Generative AI Profile.
  • Relevant certifications such as Security+, SC-200, AZ-500, CISSP, GCIH, or equivalent credentials.
  • Post-secondary education in cybersecurity, information technology, computer science, or a related discipline, or equivalent practical experience.

Brookfield is committed to maintaining a Positive Work Environment that is safe and respectful; our shared success depends on it. We do not tolerate workplace discrimination, violence or harassment. We are proud to be an Equal Opportunity Employer and make employment decisions based on qualifications, merit and business needs, without regard to any characteristic protected by applicable law. Applicant information is collected and handled in accordance with our Applicant Privacy Notice.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Security Operations
Incident Response
Zscaler
Microsoft Sentinel
Microsoft Defender XDR
Vulnerability Management
Identity and Access Management
Email Security
ServiceNow
Threat Intelligence
Risk Assessment
Data Protection
PowerShell
Python
Cloud Security
Security Awareness

Location

London, England, United Kingdom

Sign up to applySee more jobs like this