Brookfield Asset Management Inc. Logo

Brookfield Asset Management Inc.

Senior Analyst – Cyber Threat Intelligence

Posted 11 Days Ago
Be an Early Applicant
In-Office
Toronto, ON, CAN
Senior level
In-Office
Toronto, ON, CAN
Senior level
Monitors open, deep, and dark web sources to identify cyber threats, threat actors, credential exposures, data leaks, ransomware, fraud, and AI-enabled attacks. Conducts OSINT and cybercrime investigations, validates intelligence, develops threat actor profiles, maps activity to analytical frameworks, and produces actionable reports and executive briefings. Supports Security Operations and Incident Response during investigations and incidents, maintains intelligence records and monitoring processes, and participates in an after-hours on-call rotation.
The summary above was generated by AI

Location

Brookfield Place - 181 Bay Street

Technology Services

Technology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.

Brookfield Culture

Brookfield has a unique and dynamic culture.  We seek team members who have a long-term focus and whose values align with our Attributes of a Brookfield Leader:  Entrepreneurial, Collaborative and Disciplined.  Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.

Job Description

The Senior Security Analyst - Cyber Threat Intelligence is responsible for monitoring, investigating, and assessing emerging cyber threats across the open, deep, and dark web to identify risks that may affect Brookfield, its employees, executives, clients, portfolio companies, technology environment, brand, or critical business operations. This role combines threat intelligence analysis, cybercrime research, dark web monitoring, investigative research, and intelligence reporting to deliver proactive, Brookfield-specific threat visibility. The Senior Analyst works closely with Security Operations, Incident Response, Vulnerability Management, Legal, Privacy, and Fraud teams to translate external threat activity into actionable security and business outcomes.


Key Responsibilities

  • Monitor cybercriminal ecosystems across the dark web, underground forums, marketplaces, messaging platforms, paste sites, and leak sites for activity targeting Brookfield, its executives, employees, portfolio companies, brands, domains, and technology environment.
  • Identify and track threat actors, ransomware groups, initial access brokers, malware operators, fraud networks, and criminal collectives relevant to Brookfield's industry, profile, and operations.
  • Research and investigate stolen credentials, compromised accounts, data leaks, ransomware activity, initial access sales, vulnerability exploitation, malware campaigns, phishing operations, business email compromise, and fraud schemes.
  • Collect, validate, enrich, and analyze intelligence from OSINT, commercial intelligence sources, internal security data, and specialized cybercrime sources; assess source credibility and distinguish credible threats from speculation and criminal posturing.
  • Develop and maintain threat actor profiles covering motivations, capabilities, tactics, techniques, and procedures (TTPs), infrastructure, targeting patterns, and historical activity.
  • Correlate dark web intelligence with internal telemetry, security events, threat intelligence feeds, vulnerability information, and publicly available intelligence.
  • Map adversary activity to MITRE ATT&CK and other analytical frameworks; identify indicators of compromise (IOCs), adversary infrastructure, domains, IP addresses, cryptocurrency addresses, and other intelligence artifacts.
  • Produce concise, actionable intelligence reports, threat assessments, executive briefings, and tactical alerts for technical and non-technical audiences.
  • Support Security Operations and Incident Response teams with external threat context during active investigations, ransomware events, data breaches, fraud cases, and third-party compromises.
  • Investigate potential exposure of corporate credentials, sensitive data, intellectual property, customer information, and employee information across underground sources.
  • Validate claims made by threat actors regarding alleged data theft or compromise through appropriate intelligence sources.
  • Monitor and assess the use of artificial intelligence by threat actors, including AI-enabled phishing, business email compromise, executive impersonation, deepfakes, synthetic identities, disinformation, malware development, and automated reconnaissance.
  • Investigate suspected synthetic media and AI-generated content using appropriate technical, contextual, and intelligence-validation methods; communicate confidence levels and analytical limitations clearly.
  • Use approved AI tools to support intelligence collection, translation, analysis, summarization, and reporting while protecting sensitive information and independently validating material conclusions.
  • Develop and maintain repeatable processes for dark web monitoring, threat actor tracking, intelligence collection, source validation, investigative research, and escalation.
  • Maintain intelligence records, threat actor dossiers, watchlists, case notes, and documented evidence in accordance with legal, privacy, and operational-security requirements.
  • Participate in a scheduled information security on-call rotation and provide time-sensitive intelligence support during significant incidents, including ransomware claims, credential exposure, data leaks, executive threats, active exploitation, and third-party compromise.

Key Deliverables

  • Continuous dark web and underground monitoring, with credible threats identified and escalated within defined timelines.
  • Current threat actor profiles for groups relevant to Brookfield's industry and risk profile.
  • Intelligence reports and executive briefings produced on a regular cadence and delivered to security leadership and relevant stakeholders.
  • Credential exposure and data leak investigations completed, with findings documented and remediation actions tracked.
  • IOCs and threat intelligence artifacts delivered to Security Operations and Incident Response teams in support of active investigations.
  • Repeatable intelligence collection and monitoring processes documented and continuously improved.
  • Threat intelligence integrated with internal telemetry to improve detection and response capabilities.
  • Material AI-enabled threats assessed and communicated through timely tactical alerts or executive intelligence reporting.
  • Critical intelligence identified outside regular business hours validated, documented, and escalated within established response targets.

Required Experience

  • Three to seven years of experience in cyber threat intelligence, cyber investigations, SOC operations, incident response, digital forensics, or security research.
  • Demonstrated experience researching cybercrime activity and dark web or underground ecosystems.
  • Experience conducting OSINT and investigative research using multiple sources and analytical techniques.
  • Strong understanding of threat actor behavior, cybercrime business models, common attack methodologies, and the broader threat landscape.
  • Experience producing intelligence reports and briefings for technical and executive audiences.
  • Experience supporting time-sensitive investigations or incidents and working within defined escalation procedures.

Skills & Qualifications

  • Strong analytical and investigative mindset, with the ability to evaluate source credibility and distinguish fact from speculation.
  • Ability to translate complex technical findings into concise, actionable intelligence for technical and non-technical stakeholders.
  • Working knowledge of MITRE ATT&CK, Cyber Kill Chain, Diamond Model, or similar analytical frameworks.
  • Understanding of IOCs, adversary infrastructure, and intelligence artifact analysis.
  • Strong written and verbal communication skills, with experience producing structured intelligence products.
  • Ability to work independently, manage competing priorities, and conduct investigations with appropriate discretion and operational security.
  • Working knowledge of generative AI technologies, AI-enabled threat activity, synthetic media risks, and responsible use of AI-assisted analytical tools.
  • Working knowledge of PowerShell and/or Python is an asset.

Preferred Qualifications

  • Experience tracking ransomware groups, initial access brokers, credential theft operations, data extortion groups, malware-as-a-service, or underground marketplaces.
  • Experience with cyber threat intelligence platforms, dark web monitoring tools, SIEM technologies, EDR/XDR platforms, and OSINT tooling.
  • Understanding of cryptocurrency and blockchain activity relevant to cybercrime investigations.
  • Familiarity with threat intelligence standards and formats such as STIX/TAXII.
  • Experience conducting investigations involving credential exposure, ransomware, data extortion, fraud, phishing, business email compromise, or third-party compromise.
  • Familiarity with AI-security risks and recognized guidance such as the NIST AI Risk Management Framework and Generative AI Profile.
  • Relevant certifications such as CTIA, GCTI, GCFA, GCIH, GCIA, CISSP, or Security+.
  • Post-secondary education in cybersecurity, computer science, information security, intelligence studies, criminal justice, or a related discipline, or equivalent practical experience.

Additional Requirement

  • This position participates in a scheduled after-hours on-call rotation and may be required to provide timely support during significant security incidents, critical vulnerabilities, or other urgent security events.

Salary Range: C$105K - $115K

#LI-MW1

Position Opening Reason:

New Position

Brookfield is committed to maintaining a Positive Work Environment that is safe, respectful; our shared success depends on it. We do not tolerate workplace discrimination, violence or harassment. We are proud to be an Equal Opportunity Employer and make employment decisions based on qualifications, merit, and business needs, without regard to any characteristic protected by applicable law. Applicant information is collected and handled in accordance with our Applicant Privacy Notice. As part of this commitment, we provide barrier-free and accessible employment practices in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and applicable human rights legislation. If you require a Human Rights Code-protected accommodation at any stage of the recruitment process, please let us know when contacted, and we will work with you to meet your needs.

Brookfield Asset Management Inc. Toronto, Ontario, CAN Office

Brookfield Place, 181 Bay Street, Suite 100, Toronto, Ontario, Canada, M5J 2T3

Similar Jobs

An Hour Ago
Remote or Hybrid
Ontario, ON, CAN
Senior level
Senior level
Artificial Intelligence • Cloud • Information Technology • Consulting
Leads complex, cross-functional client management projects from planning through implementation. Manages scope, budgets, financial forecasts, stakeholders, risks, dependencies, vendors, and teams exceeding 20 members across multiple countries. Consolidates workstream information for executive reporting, governance, escalation, and mitigation planning. Provides project management expertise, process improvements, mentoring, and guidance while ensuring delivery meets time, quality, and budget expectations.
2 Hours Ago
Hybrid
Senior level
Senior level
Automotive
Develops and launches high-volume machining processes for engine cylinder blocks and heads. Responsibilities include manufacturability evaluation, process and equipment specifications, tooling and supplier coordination, equipment commissioning, production readiness, capability studies, quality improvements, and corrective actions. The role manages launch schedules, costs, risks, and cross-functional collaboration with product development, purchasing, suppliers, logistics, and plant teams. Regular travel to the Windsor Engine Plant and occasional extended assignments are required.
Top Skills: AimAutomationAvbomCatiaCmmsCparsCutting ToolsE2KsError-ProofingFixturesGaugingGd&TGspas/AptLeak TestingLean ManufacturingMachining ProcessesExcelMicrosoft PowerpointPfmeaSix SigmaStatistical Process ControlTeamcenterVismockupWers
3 Hours Ago
In-Office or Remote
CA
Mid level
Mid level
Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Own third-party risk management and business continuity programs while building production data pipelines, integrations, policy-as-code controls, continuous monitoring, and agentic AI workflows. The role requires defining technical direction, integrating imperfect data sources, automating evidence collection, and partnering across Security, Procurement, Resilience, and Engineering teams to improve governance and operational resilience.
Top Skills: AWSBuildkiteCi/CdClaudeGCPGoGrpcHTTPJavaJSONKotlinKubernetesLlm ApisModel Context ProtocolProtocol BuffersPythonRest ApisSnowflakeSQLTerraform

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account