Senior Information Security Analyst

Kitchener or Canada Remote

Applications have closed

D2L is a cloud company that is modernizing education and building the Future of Work. The old models of teaching and learning are in the midst of the largest transformation in history, and D2L is at the heart of that fundamental shift. 

New models of teaching and learning enable a personalized, student-centric experience – and deliver improved retention, engagement, satisfaction, and results for learners of all ages – in schools, campuses, and companies.

D2L is disrupting the way the world learns, by providing the next generation learning environment and solutions to engage and inspire learners. And most importantly, by giving customers a platform that is easy, flexible, and smart. No other company provides a solution as robust and innovative as D2L.

D2L has had a singular mission for 20 years and is dedicated to that same mission in the years ahead: to transform the way the world learns – and by doing so, we will help improve human potential globally.

A member of our Talent Acquisition team reviews ALL of our applications - yes a real person reviews resumes! They are excited to read more about what amazing things you could add to D2L. 

Job Summary:

Join our team as a Senior Information Security Analyst, where you will play a pivotal role in refining and delivering our Information Security Program, focusing on endpoints, applications, and infrastructure. You'll conduct regular security scans, generate comprehensive reports, and engage stakeholders to address identified issues efficiently. Additionally, you will collaborate closely with operational teams, provide expert advice on emerging security risks, and support various security compliance programs, ensuring a robust Information Security Continuous Monitoring Program is in place. As a Senior Information Security Analyst at D2L, you are a key influencer and contributor to the refinement and delivery of D2L's Information Security Program!

How Will I Make an Impact?

  • Assist in refining and delivering D2L's Information Security Program with particular focus on endpoints, applications, and the underlying infrastructure.
  • Perform regular application/infrastructure security scans, generate reports, and liaise with related stakeholders to work towards closing open issues.
  • Liaise with operational teams on existing and emerging information security risks and provide subject matter expertise.
  • Monitor/track information security risks and related artifacts throughout their lifecycle.
  • Support the Information Security Continuous Monitoring Program(s) aligned with specific security compliance programs.
  • Support the product sales cycle by completing security questionnaires from prospective clients.
  • Collaborate with internal subject matter experts to collate, review, and submit periodic security questionnaires from D2L’s client.
  • Support internal D2L teams during security assessments/reviews/audits.
  • Review independent third-party reports from vendors, suppliers and partners for adequacy and alignment with D2L’s Information Security Program.
  • Track identified gaps from third party assessments and follow up with stakeholders to close outstanding issues.

Competencies (What you’ll bring to the role):

  • Ability to think critically  
  • Ability to engage process owners and explain security controls associated with processes 
  • Ability to breakdown complex technical concepts to simple terms for various levels of stakeholders 
  • Ability to achieve outcomes with minimal supervision. 
  • Ability to learn fast and synthesize information from different domains and sources. 
  • Ability to work well with teams within a matrix structure and operational setting 

Skills

  • Sound knowledge of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA).  
  • Sound knowledge of public cloud infrastructure  
  • Practical knowledge of implementing security controls in public cloud deployments/workloads  
  • Practical knowledge of Governance Risk and Compliance (GRC) tools  
  • Practical knowledge of infrastructure and application security scanning tools  
  • Deep understanding of vulnerability management and penetration testing  
  • Sound knowledge of risk management framework and standards 
  • Sound knowledge of Information Security frameworks and standards including ISO 27001, NIST 800-53 etc. 

D2L Leadership Competencies  

  • Leads by Example with personal and professional integrity, high accountability and say/do ratio   
  • Boundaryless collaboration and influence skills both within team, peer group and broader organization. Effective communicator with a proven track record of success.  
  • Delivers Awesome Outcomes: Strategic mindset and business acumen, with strong prioritization skills and a focus on organizational outcomes vs. team tasks. Effective problem solver, able to achieve results individually and through others, in fast paced, deadline-driven  
  • environments.   
  • Talent Magnet: Talent-focused leader, with demonstrated ability to coach, build and lead a high performing, diverse team.   
  • Better, Smarter, Faster: An agile learner, with a growth mindset, attention to detail and organizational skills. An operationally minded leader, with a focus on continuous improvement and innovation.  
  • Wins Hearts and Minds: An effective communicator, with the ability to connect the why and the what. A change agent, with proven delegation, motivation, and team building skills.

Suggested Qualifications/Experience: 

  • You have previous hands-on experience implementing information security controls across a wide range of domains including Endpoint Security, Application Security, and Infrastructure Security.  
  • You have hands-on experience with public cloud services like Amazon Web Services (AWS), Azure etc.  
  • You have hands-on experience performing vulnerability assessments and penetration tests.  
  • You have demonstrable experience working with teams that have implemented security controls based on ISO 27001/NIST 800-53, CSAE 3416/SSAE18, SOC1/2/3.  
  • You have experience using enterprise-grade governance risk and compliance (GRC) tools.  
  • You have experience assessing security control implementations on large enterprise, web scale and serverless environments. 
  • You have experience engaging stakeholder in remediating security-related findings  
  • You have experience supporting an audit exercise by generating security-related evidence  

About the team

  • We work daily to enhance our defenses and actively anticipate potential threats to ensure we are protecting the availability, integrity and confidentiality of D2L services and data.
  • Our solutions are heavily focused on the native AWS technology stack while also making use of a variety of supporting technologies such as Terraform, Cloud Formation, and Jenkins.
  • Our current compliance coverage includes ISO27001, ISO 27701, ISO 27017, ISO 27018; CSAE 3416/SSAE18; SOC1/2/3; TX-RAMP; Cyber Essentials
  • Our team is physically located at D2L’s HQ in Kitchener, Ontario Canada but we maintain a strong virtual presence to enable us to collaborate from wherever we may be.

The expected base salary range for a new hire in this role is listed below. The annualized base salary offered is determined by each candidate’s relevant knowledge, skills, education, training and experience. It is aligned to ensure both internal and external competitiveness using market data for the geographic location and industry. As part of the total compensation at D2L the role may be eligible for additional benefits including a Wellness Subsidy, Equity Grants, Variable Incentive, and more.

Base Salary Range$95,000—$115,000 CAD

 

Don’t meet every single requirement? We strongly encourage you to still apply! At D2L, we are committed to creating a diverse and inclusive environment. We encourage your application even if you don't believe you meet every single qualification outlined, because we love to help our people grow and develop!

Why we're awesome:

At D2L, we are dedicated to providing you with the tools to do the best work of your life. While some of our perks and benefits may vary depending on location or employment type, we are proud to provide employees with the following through #LifeAtD2L;

  • Impactful work transforming the way the world learns
  • Flexible work arrangements
  • Learning and Growth opportunities
  • Tuition reimbursement of up to $4,000 CAD for continuing education through our Catch the Wave Program
  • 2 Paid Days off for Catch the Wave related activities like exams or final assignments
  • Employee wellbeing (Access to mental health services, EFAP program, financial planning and more)
  • Retirement planning
  • 2 Paid Volunteer Days
  • Competitive Benefits Package
  • Home Internet Reimbursements
  • Employee Referral Program
  • Wellness Reimbursement
  • Employee Recognition
  • Social Events
  • Dog Friendly Offices at our HQ in Kitchener, Winnipeg, Vancouver and Melbourne.

Tags: Agile Application security Audits AWS Azure Cloud Compliance DAST Endpoint security Governance ISO 27001 Monitoring NIST NIST 800-53 Pentesting Risk management RMF SAST Security assessment SOC 1 Teaching Terraform Vulnerability management

Perks/benefits: Career development Competitive pay Equity Flex hours Health care Startup environment Team events Wellness

Regions: Remote/Anywhere North America
Country: Canada
Job stats:  32  6  0
Category: Analyst Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.