Overview
In this role you will lead day-to-day security operations and handle evolving priorities to protect Brookfield’s digital assets. You will own investigation and resolution of complex alerts, work closely with cross-functional teams, and influence security improvements at scale. You’ll operate across Zscaler, Microsoft security platforms, identity and access controls, and vulnerability management to reduce risk. This is an opportunity to shape security practices in a fast-moving, on-call environment and contribute to a mature security program.
Responsibilities
- Investigate and respond to alerts from Microsoft Sentinel, Defender XDR, endpoint tools, and other monitoring platforms; document findings through resolution
- Manage security incidents and service requests in ServiceNow; maintain queue health and stakeholder communication
- Administer Zscaler services and investigate connectivity and policy issues
- Review logs and implement changes for URL filtering, cloud controls, SSL/TLS inspection, and data protection
- Administer email-security controls (Microsoft Defender for Office 365, Exchange Online, Abnormal Security); investigate phishing and account compromise
- Perform message tracing, quarantine review, and policy tuning for SPF/DKIM/DMARC
- Manage Microsoft security platforms (Defender XDR, Sentinel, Entra ID, Purview) with least-privilege change management
- Support secure adoption of AI services, reviewing AI use cases for security, privacy, and data protection
- Oversee access controls (Conditional Access, MFA, RBAC) and least-privilege configurations
- Run enterprise vulnerability-management lifecycle; coordinate remediation and reporting
- Lead phishing simulations and security-awareness activities
- Execute legal hold and eDiscovery with Microsoft Purview; coordinate data handling and case documentation
- Conduct vendor and third-party risk assessments and follow-up remediation
- Provide input to security policies and maintain runbooks, dashboards, and automation
- Participate in on-call rotation and ensure timely containment or escalation
Key requirements
- Five+ years in information security, operations, or incident response
- Hands-on experience with investigating alerts and incidents via ServiceNow or equivalent
- Experience administering enterprise security technologies and policy changes
- Experience with Zscaler, Microsoft Defender XDR, Defender Sentinel, Entra ID, Purview, Exchange Online security controls, or similar platforms
- Experience in vulnerability-management programs and reporting
- Experience supporting email security, identity controls, and access reviews
- Experience handling significant incidents and on-call procedures
- Clear documentation and communication
- Analytical judgment and cross-functional coordination
- Ability to work independently and manage changing priorities
- Zscaler Internet Access, Zscaler Private Access, Zscaler Client Connector
- Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview
- Exchange Online security controls; Abnormal Security
…
