Location
Mumbai - 10th Floor, Ventura, Hiranandani Gardens, Powai
Technology Services
Technology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.
Brookfield Culture
Brookfield has a unique and dynamic culture. We seek team members who have a long-term focus and whose values align with our Attributes of a Brookfield Leader: Entrepreneurial, Collaborative and Disciplined. Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.
Job Description
IT Job Description
Job Title
Senior Security Analyst
Department: Technology Services – Information Security
Reports To: Manager, Information Security
Role Summary
The Senior Security Analyst is responsible for day-to-day security operations, governance support, and user-facing security controls across the organization. This role focuses on responding to SOC alerts, managing security queues and incidents in ServiceNow, handling the security mailbox, supporting user security awareness and phishing simulations, vendor risk assessment, identity and access controls, email security, legal hold and eDiscovery support using Microsoft Purview, and providing operational input into enterprise security policies. The role also maintains operational documentation for internal security tools and platforms and retains a working knowledge of vulnerability assessment and penetration testing to support coordination and follow-up.
Key Responsibilities
Security Operations
- Respond to and investigate security alerts generated by the SOC, SIEM, and Microsoft security tooling.
- Manage and monitor security-related queues in ServiceNow, including security approvals, incidents, and requests.
- Review, triage, and progress incidents allocated to the team through ServiceNow to ensure timely resolution.
- Handle and respond to inquiries received through the security mailbox, ensuring appropriate triage and follow-up.
- Support incident response activities by gathering evidence, reviewing logs, and documenting findings.
- Prioritize vulnerabilities based on real-world exploitation likelihood using Microsoft threat intelligence.
User Security Awareness & Phishing Simulation
- Coordinate and support user security awareness training programs, including tracking participation and completion.
- Manage phishing simulation campaigns, including execution, result analysis, and follow-up actions.
- Respond to user-reported phishing emails and provide guidance on secure practices.
Email Security
- Support email security controls within Exchange Online and Abnormal Security.
- Review and investigate email-based threats including phishing, spoofing, and business email compromise.
- Assist with tuning and validation of email security policies and detections.
Identity, Access & Cloud Security Controls
- Support the design, review, and maintenance of Conditional Access policies.
- Assist with defining and reviewing RBAC roles across M365 and Azure environments.
- Review access-related changes to ensure alignment with least-privilege principles.
Microsoft Purview, Legal Hold & eDiscovery
- Execute and support Legal Hold and eDiscovery requests using Microsoft Purview.
- Perform and document Purview searches, evidence collection, and data handling activities.
- Collaborate with Legal, HR, and Compliance teams to support requests.
Vendor Risk Assessment & Business Security Support
- Support vendor and third-party risk assessments, including validation of due diligence questionnaires.
- Respond to security questions from business teams and support vendor onboarding and renewal activities.
- Track remediation actions and follow-ups related to vendor risk findings.
Enterprise Security Policy & Governance Support
- Provide operational input into the development, review, and maintenance of enterprise security policies and standards.
- Ensure security policies reflect current operational practices, tooling, and threat landscape.
- Support policy awareness and adoption across technical and business teams.
Infrastructure & Cloud Security Awareness
- Maintain a working understanding of network security, firewall controls, secure connectivity, and cloud security fundamentals.
- Develop familiarity with SASE and Zero Trust concepts to support access-related investigations and user issues.
- Assist with reviewing security implications of infrastructure and cloud-related changes from an operational perspective.
- Support documentation and follow-ups related to infrastructure or cloud security findings assigned to the operations team.
Change Management & Security Review
- Review security-related change requests to assess risk and required controls.
- Participate in change management processes to ensure security requirements are considered.
- Review post-change and post-incident documentation to ensure corrective actions are completed.
Vulnerability Assessment & Penetration Testing
- Maintain a working understanding of vulnerability assessment and penetration testing
- Leverage Armis to maintain visibility into managed, unmanaged, IoT, and ephemeral assets.
- Validate remediation efforts and identify recurring or systemic vulnerability patterns.
- Execute and maintain end-to-end vulnerability assessment processes across cloud, SaaS, identity, and enterprise assets.
Key Deliverables
- Resolve and document SOC alerts, ServiceNow tickets, and incidents
- Timely responses to security mailbox inquiries and approvals
- Security awareness training metrics and phishing simulation reports
- Complete Purview searches and legal hold.
- Reviewed and validated vendor due diligence questionnaires
- Operational security policy inputs and updates
- Maintained operational manuals and runbooks for security tools
- Approved security change reviews and documented outcomes
- Track VMS remediation status.
Required Experience
- 5+ years of experience in information security or security operations.
- Hands-on experience responding to security alerts and managing incidents or requests through ServiceNow or similar platforms.
- Experience supporting governance-related security functions such as awareness training, vendor risk, policy support, or access reviews.
- Working exposure to vulnerability assessment and penetration testing activities.
- Industry certifications such as CISSP, CEH, Security+, SC-900 or equivalent.
Skills & Qualifications
- Strong understanding of security operations, alert triage, incident response, and ticket management workflows.
- Hands-on experience with Microsoft security platforms including Defender, Sentinel, Entra ID, and Purview.
- Experience with ServiceNow for incident, request, and approval queue management.
- Experience with email security solutions including Abnormal Security.
- Understanding of identity and access management, Conditional Access, and RBAC.
- Working knowledge of network security, cloud security fundamentals, and secure access concepts such as SASE and Zero Trust.
- Strong documentation, communication, and coordination skills.
- Working knowledge of PowerShell and/or Python is an asset.
Education & Training
- Bachelor’s degree, diploma, or equivalent training in Cybersecurity, Information Technology, or a related field.
- Ongoing professional development in security operations and Microsoft security tooling.
Brookfield is committed to maintaining a Positive Work Environment that is safe and respectful; our shared success depends on it. Accordingly, we do not tolerate workplace discrimination, violence or harassment.
We are proud to create a diverse environment and are proud to be an equal opportunity employer. We are grateful for your interest in this position, however, only candidates selected for pre-screening will be contacted.