Hiring.Camp

Senior Analyst – Cyber Threat Intelligence

Brookfield

·

Today

Location
Brookfield Place, Canada
Type
Full-time
Department
Human Resources
Seniority
Senior
Source
Workday

Description

Location

Brookfield Place - 181 Bay Street

Technology Services

Technology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.

Brookfield Culture

Brookfield has a unique and dynamic culture.  We seek team members who have a long-term focus and whose values align with our Attributes of a Brookfield Leader:  Entrepreneurial, Collaborative and Disciplined.  Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.


Job Description

The Senior Security Analyst - Cyber Threat Intelligence is responsible for monitoring, investigating, and assessing emerging cyber threats across the open, deep, and dark web to identify risks that may affect Brookfield, its employees, executives, clients, portfolio companies, technology environment, brand, or critical business operations. This role combines threat intelligence analysis, cybercrime research, dark web monitoring, investigative research, and intelligence reporting to deliver proactive, Brookfield-specific threat visibility. The Senior Analyst works closely with Security Operations, Incident Response, Vulnerability Management, Legal, Privacy, and Fraud teams to translate external threat activity into actionable security and business outcomes.


Key Responsibilities

  • Monitor cybercriminal ecosystems across the dark web, underground forums, marketplaces, messaging platforms, paste sites, and leak sites for activity targeting Brookfield, its executives, employees, portfolio companies, brands, domains, and technology environment.
  • Identify and track threat actors, ransomware groups, initial access brokers, malware operators, fraud networks, and criminal collectives relevant to Brookfield's industry, profile, and operations.
  • Research and investigate stolen credentials, compromised accounts, data leaks, ransomware activity, initial access sales, vulnerability exploitation, malware campaigns, phishing operations, business email compromise, and fraud schemes.
  • Collect, validate, enrich, and analyze intelligence from OSINT, commercial intelligence sources, internal security data, and specialized cybercrime sources; assess source credibility and distinguish credible threats from speculation and criminal posturing.
  • Develop and maintain threat actor profiles covering motivations, capabilities, tactics, techniques, and procedures (TTPs), infrastructure, targeting patterns, and historical activity.
  • Correlate dark web intelligence with internal telemetry, security events, threat intelligence feeds, vulnerability information, and publicly available intelligence.
  • Map adversary activity to MITRE ATT&CK and other analytical frameworks; identify indicators of compromise (IOCs), adversary infrastructure, domains, IP addresses, cryptocurrency addresses, and other intelligence artifacts.
  • Produce concise, actionable intelligence reports, threat assessments, executive briefings, and tactical alerts for technical and non-technical audiences.
  • Support Security Operations and Incident Response teams with external threat context during active investigations, ransomware events, data breaches, fraud cases, and third-party compromises.
  • Investigate potential exposure of corporate credentials, sensitive data, intellectual property, customer information, and employee information across underground sources.
  • Validate claims made by threat actors regarding alleged data theft or compromise through appropriate intelligence sources.
  • Monitor and assess the use of artificial intelligence by threat actors, including AI-enabled phishing, business email compromise, executive impersonation, deepfakes, synthetic identities, disinformation, malware development, and automated reconnaissance.
  • Investigate suspected synthetic media and AI-generated content using appropriate technical, contextual, and intelligence-validation methods; communicate confidence levels and analytical limitations clearly.
  • Use approved AI tools to support intelligence collection, translation, analysis, summarization, and reporting while protecting sensitive information and independently validating material conclusions.
  • Develop and maintain repeatable processes for dark web monitoring, threat actor tracking, intelligence collection, source validation, investigative research, and escalation.
  • Maintain intelligence records, threat actor dossiers, watchlists, case notes, and documented evidence in accordance with legal, privacy, and operational-security requirements.
  • Participate in a scheduled information security on-call rotation and provide time-sensitive intelligence support during significant incidents, including ransomware claims, credential exposure, data leaks, executive threats, active exploitation, and third-party compromise.

Key Deliverables

  • Continuous dark web and underground monitoring, with credible threats identified and escalated within defined timelines.
  • Current threat actor profiles for groups relevant to Brookfield's industry and risk profile.
  • Intelligence reports and executive briefings produced on a regular cadence and delivered to security leadership and relevant stakeholders.
  • Credential exposure and data leak investigations completed, with findings documented and remediation actions tracked.
  • IOCs and threat intelligence artifacts delivered to Security Operations and Incident Response teams in support of active investigations.
  • Repeatable intelligence collection and monitoring processes documented and continuously improved.
  • Threat intelligence integrated with internal telemetry to improve detection and response capabilities.
  • Material AI-enabled threats assessed and communicated through timely tactical alerts or executive intelligence reporting.
  • Critical intelligence identified outside regular business hours validated, documented, and escalated within established response targets.

Required Experience

  • Three to seven years of experience in cyber threat intelligence, cyber investigations, SOC operations, incident response, digital forensics, or security research.
  • Demonstrated experience researching cybercrime activity and dark web or underground ecosystems.
  • Experience conducting OSINT and investigative research using multiple sources and analytical techniques.
  • Strong understanding of threat actor behavior, cybercrime business models, common attack methodologies, and the broader threat landscape.
  • Experience producing intelligence reports and briefings for technical and executive audiences.
  • Experience supporting time-sensitive investigations or incidents and working within defined escalation procedures.

Skills & Qualifications

  • Strong analytical and investigative mindset, with the ability to evaluate source credibility and distinguish fact from speculation.
  • Ability to translate complex technical findings into concise, actionable intelligence for technical and non-technical stakeholders.
  • Working knowledge of MITRE ATT&CK, Cyber Kill Chain, Diamond Model, or similar analytical frameworks.
  • Understanding of IOCs, adversary infrastructure, and intelligence artifact analysis.
  • Strong written and verbal communication skills, with experience producing structured intelligence products.
  • Ability to work independently, manage competing priorities, and conduct investigations with appropriate discretion and operational security.
  • Working knowledge of generative AI technologies, AI-enabled threat activity, synthetic media risks, and responsible use of AI-assisted analytical tools.
  • Working knowledge of PowerShell and/or Python is an asset.

Preferred Qualifications

  • Experience tracking ransomware groups, initial access brokers, credential theft operations, data extortion groups, malware-as-a-service, or underground marketplaces.
  • Experience with cyber threat intelligence platforms, dark web monitoring tools, SIEM technologies, EDR/XDR platforms, and OSINT tooling.
  • Understanding of cryptocurrency and blockchain activity relevant to cybercrime investigations.
  • Familiarity with threat intelligence standards and formats such as STIX/TAXII.
  • Experience conducting investigations involving credential exposure, ransomware, data extortion, fraud, phishing, business email compromise, or third-party compromise.
  • Familiarity with AI-security risks and recognized guidance such as the NIST AI Risk Management Framework and Generative AI Profile.
  • Relevant certifications such as CTIA, GCTI, GCFA, GCIH, GCIA, CISSP, or Security+.
  • Post-secondary education in cybersecurity, computer science, information security, intelligence studies, criminal justice, or a related discipline, or equivalent practical experience.

Additional Requirement

  • This position participates in a scheduled after-hours on-call rotation and may be required to provide timely support during significant security incidents, critical vulnerabilities, or other urgent security events.



Salary Range: C$105K - $115K

#LI-MW1

Position Opening Reason:

New Position

Brookfield is committed to maintaining a Positive Work Environment that is safe, respectful; our shared success depends on it. We do not tolerate workplace discrimination, violence or harassment. We are proud to be an Equal Opportunity Employer and make employment decisions based on qualifications, merit, and business needs, without regard to any characteristic protected by applicable law. Applicant information is collected and handled in accordance with our Applicant Privacy Notice. As part of this commitment, we provide barrier-free and accessible employment practices in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and applicable human rights legislation. If you require a Human Rights Code-protected accommodation at any stage of the recruitment process, please let us know when contacted, and we will work with you to meet your needs.

Skills

PythonCybersecuritySIEMSOCRisk ManagementCISSP

Similar Jobs

30

Senior Data Analyst

Crunchyroll·Hyderabad, Telangana

Today

Senior Data Analyst

Wellcome isn·Gibbs Building, UK

Today

Senior Business Analyst

Air New Zealand·Auckland, New Zealand

Today

Senior Analyst

Nab·DLF Downtown, IND·Hybrid

1d ago

Senior Analyst

Spgi·US - TN - NASHVILLE 818 18TH AVENUE SOUTH, US

1d ago

Senior Business Analyst

COACTION CAREERS·Morristown, NJ·Hybrid

2d ago

Senior Business Analyst

Higginbotham·Nationwide

3d ago

Senior Data Analyst

EXL Talent Acquisition Team·Haryana, India·Hybrid

3d ago

Senior Data Analyst

EXL·Haryana, India·Hybrid

3d ago

Senior Data Analyst

Delivery Hero·Singapore·Hybrid

3d ago

Senior Business Analyst

ASRC Federal·Remote

3d ago

Senior Data Analyst

Morgan 6·Tampa, FL

3d ago

SR Analyst

Hrone·GO-STEPHENS ROAD, US

3d ago

Senior Analyst

Alsglobal·GBR - Coventry, UK·Onsite

3d ago

Senior Business Analyst

Springernature·Lisbon, Portugal +1

3d ago

Senior Analyst

Leidos·0045 Joint Systems Integration Ctr Suffolk VA, US·Onsite

3d ago

Senior Analyst

Peopletec·Colorado Springs, CO

3d ago

Senior Business Analyst

Fult·East Petersburg, PA +1·Hybrid

3d ago

Senior Data Analyst

Cai·PA-CLIENT-STATE, US·Remote

3d ago

Senior Business Analyst

Ascend Learning·Remote, Hybrid

3d ago

Senior Data Analyst

TeleSolv Consulting·Hybrid·Hybrid

3d ago

Senior Analyst

Kenvue·JP311 DCL Ebisu Prime Square, Japan·Hybrid

3d ago

Senior Data Analyst

Westpac Group·Sydney, NSW

3d ago

Senior Analyst

Flatiron Energy·Boston, TBD +3

3d ago

Senior Data Analyst

Gifthealth Inc·Columbus, OH

4d ago

Senior Data Analyst

Alpha Omega Integration·Vienna, VA

4d ago

Senior Business Analyst

Version 1·Dublin, County Dublin·Hybrid

4d ago

Senior Business Analyst

Netcompany·Leeds, England·Hybrid

4d ago

Senior Analyst

Careers @ MUFG Pension & Market Services·India

4d ago

Senior Business Analyst

LGC·London, England·Hybrid

4d ago