Brookfield Renewable
Senior Security Analyst
Job Description
Salary: £59,000 - 59,000 per year
Requirements:- Five or more years of progressive experience in information security, security operations, incident response, or a related discipline.
- Hands-on experience investigating security alerts and managing incidents through ServiceNow or an equivalent workflow platform.
- Experience administering enterprise security technologies and implementing approved security-policy changes.
- Hands-on experience with Zscaler, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Exchange Online security controls, or comparable platforms.
- Experience operating or supporting a vulnerability-management program, including prioritization, remediation coordination, exception handling, and reporting.
- Experience supporting email security, identity controls, security awareness, third-party risk, policy implementation, or access reviews.
- Experience supporting significant incidents and working within formal escalation and on-call procedures.
- Strong understanding of security operations, including alert triage, incident response, containment coordination, queue management, and investigation documentation.
- Working knowledge of Zscaler Internet Access, Zscaler Private Access, Client Connector, SASE, and Zero Trust concepts.
- Hands-on knowledge of Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and Microsoft 365 security controls.
- Understanding of vulnerability risk, exploitability, compensating controls, remediation prioritization, and risk acceptance.
- Working knowledge of email-security controls, SPF, DKIM, DMARC, and common email-based attack techniques.
- Strong documentation, communication, analytical judgment, and cross-functional coordination skills.
- Ability to work independently, adapt to changing priorities, take ownership of unfamiliar issues, and operate effectively during urgent events.
- Working knowledge of AI-security risks, generative AI technologies, data-protection considerations, shadow AI monitoring, and secure use of AI-enabled security capabilities.
- Working knowledge of PowerShell and/or Python and the ability to use APIs or workflow automation is an asset.
- Experience with ServiceNow security modules, workflow management, and operational reporting.
- Experience with vulnerability platforms such as Microsoft Defender Vulnerability Management, Tenable, Qualys, Rapid7, or equivalent technologies.
- Familiarity with SOX compliance requirements, IT general controls, and evidence-based control testing.
- Experience supporting cloud-security monitoring and investigations across Microsoft Azure, Amazon Web Services, or other cloud environments.
- Familiarity with recognized AI-risk guidance such as the NIST AI Risk Management Framework and Generative AI Profile.
- Relevant certifications such as Security+, SC-200, AZ-500, CISSP, GCIH, or equivalent credentials.
- Post-secondary education in cybersecurity, information technology, computer science, or a related discipline, or equivalent practical experience.
- Investigate and respond to security alerts from Microsoft Sentinel, Microsoft Defender XDR, endpoint security tools, and other monitoring platforms; gather evidence, review logs, coordinate containment, and document findings through resolution.
- Manage security incidents, approvals, and service requests in ServiceNow; maintain queue health, ensure timely triage, resolve complex escalations, and provide clear stakeholder communication.
- Manage the security mailbox independently; investigate user-reported security concerns, coordinate required actions, identify recurring issues, and escalate significant matters.
- Administer Zscaler Internet Access, Zscaler Private Access, and Zscaler Client Connector; investigate connectivity, authentication, policy-enforcement, web-access, and application-access issues.
- Review Zscaler web, firewall, DNS, and access logs and implement approved changes involving URL filtering, cloud application controls, SSL/TLS inspection, data protection, remote access, and business exceptions.
- Administer email-security controls across Microsoft Defender for Office 365, Exchange Online, and Abnormal Security; investigate phishing, spoofing, executive impersonation, malicious links, business email compromise, and account compromise.
- Perform message tracing, quarantine review, tenant allow/block administration, false-positive analysis, phishing-submission review, policy tuning, and investigation of SPF, DKIM, and DMARC failures.
- Administer assigned Microsoft security platforms, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview, using least-privilege and formal change-management practices.
- Support the secure adoption and operation of approved artificial intelligence and generative AI services; review AI applications, agents, connectors, integrations, and use cases for security, privacy, identity, data-protection, retention, and third-party risks.
- Administer and monitor security controls governing access to AI applications, including Zscaler cloud application controls, data loss prevention, identity controls, application restrictions, and approved business exceptions.
- Identify and investigate unauthorized or shadow AI usage and AI-related security events, including sensitive-data disclosure, malicious uploads, account compromise, prompt injection, insecure integrations, excessive permissions, and unsafe automated actions.
- Use approved AI-enabled security capabilities to improve investigation, detection, vulnerability analysis, reporting, and workflow automation while validating outputs and protecting sensitive information.
- Review and maintain Conditional Access, multifactor authentication, privileged access, role-based access control, and access-review configurations; validate changes against least-privilege principles and approved access requirements.
- Operate the enterprise vulnerability-management lifecycle, including vulnerability identification, validation, risk-based prioritization, remediation coordination, exception management, and reporting across endpoint, server, network, cloud, and application environments.
- Escalate critical and actively exploited vulnerabilities, coordinate time-sensitive remediation, track vulnerabilities through closure, and maintain dashboards, remediation targets, and documented risk acceptances.
- Lead phishing simulation and security-awareness activities, including planning, execution, results analysis, targeted follow-up, and user guidance.
- Execute legal hold and eDiscovery requests using Microsoft Purview under the direction of Legal, Privacy, Human Resources, or Compliance; manage searches, evidence collection, secure data handling, and case documentation.
- Conduct and coordinate vendor and third-party risk assessments, validate due-diligence responses, identify control gaps, track remediation, and support onboarding and renewals.
- Provide operational input into security policies and standards, assess security-related change requests, and confirm that approved controls and post-change documentation are complete.
- Maintain security procedures, investigation playbooks, operational dashboards, metrics, and platform documentation; identify opportunities to automate repetitive activities using PowerShell, Python, APIs, or workflow automation.
- Participate in a scheduled information security on-call rotation; assess urgent alerts and incidents, initiate containment or escalation procedures, engage appropriate stakeholders, and maintain clear incident handoffs.
- AI
- Azure
- Cloud
- Firewall
- Support
- Microsoft 365
- Network
- Office 365
- PowerShell
- Python
- Security
- ServiceNow
- Web
- RBAC
More:
We are based in London at One Canada Square, Level 25. Our Technology Services team delivers all enterprise infrastructure, applications, and related end-user technology services across our business groups. We have a unique and dynamic culture and seek team members with a long-term focus whose values align with our attributes of being entrepreneurial, collaborative, and disciplined. We are committed to developing our people through challenging work assignments and exposure to diverse businesses. This full-time role participates in a scheduled after-hours on-call rotation and supports timely response to significant security incidents, critical vulnerabilities, and other urgent security events. We also maintain a positive, safe, and respectful work environment and are proud to be an equal opportunity employer.
last updated 39 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Brookfield Renewable
Brookfield Renewable
London
IT
Skills & Technologies
Inferred from job description
Salary Insight
£59,000
This role
£75,000
UK median
This salary is 21% below the UK median for Senior roles (£75,000/yr).
Based on 2024–2025 UK technology sector benchmarks