Senior Analyst – Cyber Threat Intelligence

Brookfield Asset Management Inc

Toronto

On-site

CAD 105,000 - 115,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Brookfield Asset Management Inc. is seeking a Senior Security Analyst - Cyber Threat Intelligence to monitor, investigate, and assess emerging cyber threats across open, deep, and dark web.

You will translate external threat activity into actionable security outcomes and collaborate with Security Operations, Incident Response, and Compliance teams. The role requires 3–7 years in cyber threat intelligence or related fields, strong OSINT capabilities, and experience producing reports for technical

Qualifications

  • Three to seven years of experience in cyber threat intelligence, cyber investigations, SOC operations, incident response, digital forensics, or security research.
  • Experience researching cybercrime activity and dark web or underground ecosystems.
  • Experience OSINT and investigative research using multiple sources and analytical techniques.
  • Post-secondary education in cybersecurity or related discipline.

Responsibilities

  • Monitor cyber threat activity across open, deep, and dark web for Brookfield-specific risk.
  • Identify threat actors, ransomware groups, initial access brokers, and fraud networks relevant to Brookfield.
  • Investigate stolen credentials, data leaks, ransomware activity, and phishing campaigns.
  • Collect, validate, and analyze intelligence from OSINT and internal sources; assess credibility.
  • Develop threat actor profiles with motivations, TTPs, and infrastructure.
  • Correlate dark web intelligence with internal telemetry and threat feeds.
  • Map activity to MITRE ATT&CK and identify IOCs and infrastructure.
  • Produce concise intelligence reports, briefings, and alerts for technical and non-technical audiences.
  • Support Security Operations and Incident Response during investigations and incidents.
  • Validate claims of data theft or compromise using credible sources.
  • Monitor AI-enabled threat activity and investigate synthetic media risks.
  • Use approved AI tools for collection, translation, analysis, and reporting.
  • Maintain repeatable dark web monitoring and intelligence collection processes.
  • Maintain threat actor dossiers and watchlists with evidence.

Skills

Analytical mindset
Clear communication
MITRE ATT&CK
IOC analysis
Independent work
AI threat awareness
PowerShell
Threat intel platforms
Dark web monitoring tools
SIEM technologies
EDR/XDR
OSINT tools

Education

Post-secondary education in cybersecurity

Tools

Dark web monitoring tools
SIEM technologies
EDR/XDR
OSINT tools
Threat intelligence platforms

Job description

Location

Brookfield Place - 181 Bay Street

Technology Services

Technology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.

Brookfield Culture

Brookfield has a unique and dynamic culture. We seek team members who have a long-term focus and whose values align with our Attributes of a Brookfield Leader: Entrepreneurial, Collaborative and Disciplined. Brookfield is committed to the development of our people through challenging work assignments and exposure to diverse businesses.

Job Description

The Senior Security Analyst - Cyber Threat Intelligence is responsible for monitoring, investigating, and assessing emerging cyber threats across the open, deep, and dark web to identify risks that may affect Brookfield, its employees, executives, clients, portfolio companies, technology environment, brand, or critical business operations. This role combines threat intelligence analysis, cybercrime research, dark web monitoring, investigative research, and intelligence reporting to deliver proactive, Brookfield-specific threat visibility. The Senior Analyst works closely with Security Operations, Incident Response, Vulnerability Management, Legal, Privacy, and Fraud teams to translate external threat activity into actionable security and business outcomes.

Key Responsibilities
  • Monitor cybercriminal ecosystems across the dark web, underground forums, marketplaces, messaging platforms, paste sites, and leak sites for activity targeting Brookfield, its executives, employees, portfolio companies, brands, domains, and technology environment.
  • Identify and track threat actors, ransomware groups, initial access brokers, malware operators, fraud networks, and criminal collectives relevant to Brookfield's industry, profile, and operations.
  • Research and investigate stolen credentials, compromised accounts, data leaks, ransomware activity, initial access sales, vulnerability exploitation, malware campaigns, phishing operations, business email compromise, and fraud schemes.
  • Collect, validate, enrich, and analyze intelligence from OSINT, commercial intelligence sources, internal security data, and specialized cybercrime sources; assess source credibility and distinguish credible threats from speculation and criminal posturing.
  • Develop and maintain threat actor profiles covering motivations, capabilities, tactics, techniques, and procedures (TTPs), infrastructure, targeting patterns, and historical activity.
  • Correlate dark web intelligence with internal telemetry, security events, threat intelligence feeds, vulnerability information, and publicly available intelligence.
  • Map adversary activity to MITRE ATT&CK and other analytical frameworks; identify indicators of compromise (IOCs), adversary infrastructure, domains, IP addresses, cryptocurrency addresses, and other intelligence artifacts.
  • Produce concise, actionable intelligence reports, threat assessments, executive briefings, and tactical alerts for technical and non-technical audiences.
  • Support Security Operations and Incident Response teams with external threat context during active investigations, ransomware events, data breaches, fraud cases, and third-party compromises.
  • Investigate potential exposure of corporate credentials, sensitive data, intellectual property, customer information, and employee information across underground sources.
  • Validate claims made by threat actors regarding alleged data theft or compromise through appropriate intelligence sources.
  • Monitor and assess the use of artificial intelligence by threat actors, including AI-enabled phishing, business email compromise, executive impersonation, deepfakes, synthetic identities, disinformation, malware development, and automated reconnaissance.
  • Investigate suspected synthetic media and AI-generated content using appropriate technical, contextual, and intelligence-validation methods; communicate confidence levels and analytical limitations clearly.
  • Use approved AI tools to support intelligence collection, translation, analysis, summarization, and reporting while protecting sensitive information and independently validating material conclusions.
  • Develop and maintain repeatable processes for dark web monitoring, threat actor tracking, intelligence collection, source validation, investigative research, and escalation.
  • Maintain intelligence records, threat actor dossiers, watchlists, case notes, and documented evidence in accordance with legal, privacy, and operational-security requirements.
  • Participate in a scheduled information security on-call rotation and provide time-sensitive intelligence support during significant incidents, including ransomware claims, credential exposure, data leaks, executive threats, active exploitation, and third-party compromise.
Key Deliverables
  • Continuous dark web and underground monitoring, with credible threats identified and escalated within defined timelines.
  • Current threat actor profiles for groups relevant to Brookfield's industry and risk profile.
  • Intelligence reports and executive briefings produced on a regular cadence and delivered to security leadership and relevant stakeholders.
  • Credential exposure and data leak investigations completed, with findings documented and remediation actions tracked.
  • IOCs and threat intelligence artifacts delivered to Security Operations and Incident Response teams in support of active investigations.
  • Repeatable intelligence collection and monitoring processes documented and continuously improved.
  • Threat intelligence integrated with internal telemetry to improve detection and response capabilities.
  • Material AI-enabled threats assessed and communicated through timely tactical alerts or executive intelligence reporting.
  • Critical intelligence identified outside regular business hours validated, documented, and escalated within established response targets.
Required Experience
  • Three to seven years of experience in cyber threat intelligence, cyber investigations, SOC operations, incident response, digital forensics, or security research.
  • Demonstrated experience researching cybercrime activity and dark web or underground ecosystems.
  • Experience conducting OSINT and investigative research using multiple sources and analytical techniques.
  • Strong understanding of threat actor behavior, cybercrime business models, common attack methodologies, and the broader threat landscape.
  • Experience producing intelligence reports and briefings for technical and executive audiences.
  • Experience supporting time-sensitive investigations or incidents and working within defined escalation procedures.
Skills & Qualifications
  • Strong analytical and investigative mindset, with the ability to evaluate source credibility and distinguish fact from speculation.
  • Ability to translate complex technical findings into concise, actionable intelligence for technical and non-technical stakeholders.
  • Working knowledge of MITRE ATT&CK, Cyber Kill Chain, Diamond Model, or similar analytical frameworks.
  • Understanding of IOCs, adversary infrastructure, and intelligence artifact analysis.
  • Strong written and verbal communication skills, with experience producing structured intelligence products.
  • Ability to work independently, manage competing priorities, and conduct investigations with appropriate discretion and operational security.
  • Working knowledge of generative AI technologies, AI-enabled threat activity, synthetic media risks, and responsible use of AI-assisted analytical tools.
  • Working knowledge of PowerShell and/or Python is an asset.
Preferred Qualifications
  • Experience tracking ransomware groups, initial access brokers, credential theft operations, data extortion groups, malware-as-a-service, or underground marketplaces.
  • Experience with cyber threat intelligence platforms, dark web monitoring tools, SIEM technologies, EDR/XDR platforms, and OSINT tooling.
  • Understanding of cryptocurrency and blockchain activity relevant to cybercrime investigations.
  • Familiarity with threat intelligence standards and formats such as STIX/TAXII.
  • Experience conducting investigations involving credential exposure, ransomware, data extortion, fraud, phishing, business email compromise, or third-party compromise.
  • Familiarity with AI-security risks and recognized guidance such as the NIST AI Risk Management Framework and Generative AI Profile.
  • Relevant certifications such as CTIA, GCTI, GCFA, GCIH, GCIA, CISSP, or Security+.
  • Post-secondary education in cybersecurity, computer science, information security, intelligence studies, criminal justice, or a related discipline, or equivalent practical experience.
Additional Requirement
  • This position participates in a scheduled after-hours on-call rotation and may be required to provide timely support during significant security incidents, critical vulnerabilities, or other urgent security events.
Salary Range: C$105K - $115K
#LI-MW1
Position Opening Reason:

New Position

Brookfield is committed to maintaining a Positive Work Environment that is safe, respectful; our shared success depends on it. We do not tolerate workplace discrimination, violence or harassment. We are proud to be an Equal Opportunity Employer and make employment decisions based on qualifications, merit, and business needs, without regard to any characteristic protected by applicable law. Applicant information is collected and handled in accordance with our Applicant Privacy Notice. As part of this commitment, we provide barrier-free and accessible employment practices in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and applicable human rights legislation. If you require a Human Rights Code-protected accommodation at any stage of the recruitment process, please let us know when contacted, and we will work with you to meet your needs.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Analyst – Cyber Threat Intelligence
Senior Analyst – Cyber Threat Intelligence

Brookfield • Toronto

On-site
CAD 105,000 - 115,000
Senior Analyst – Cyber Threat Intelligence
Senior Analyst – Cyber Threat Intelligence

Brookfield Asset Management • Toronto

On-site
CAD 105,000 - 115,000
Senior Analyst - Security Operations and Assurance
Senior Analyst - Security Operations and Assurance

Brookfield • Toronto

On-site
CAD 105,000 - 115,000
Sr. Analyst, Business Systems Analysis
Sr. Analyst, Business Systems Analysis

Brookfield • Toronto

On-site
CAD 95,000 - 115,000
Sr Analyst, DevOps
Sr Analyst, DevOps

Brookfield • Toronto

On-site
CAD 105,000 - 120,000
Sr. Analyst, Audit, Attestations & Governance
Sr. Analyst, Audit, Attestations & Governance

Brookfield • Toronto

On-site
CAD 80,000 - 100,000
Sr Analyst, DevOps
Sr Analyst, DevOps

Brookfield Asset Management • Toronto

On-site
CAD 105,000 - 120,000
Manager, Business Systems Analysis
Manager, Business Systems Analysis

Brookfield Asset Management Inc • Toronto

On-site
CAD 115,000 - 130,000
Senior Analyst – Operations and Assurance
Senior Analyst – Operations and Assurance

Brookfield HRS TS LP • Toronto

On-site
CAD 105,000 - 115,000
Manager, Application Integration
Manager, Application Integration

Brookfield Asset Management Inc • Toronto

On-site
CAD 120,000 - 160,000