Senior Information Security Analyst
About this job
<div class="content-intro"><p>D2L is a cloud company that is modernizing education and building the Future of Work. The old models of teaching and learning are in the midst of the largest transformation in history, and D2L is at the heart of that fundamental shift. </p> <p>New models of teaching and learning enable a personalized, student-centric experience – and deliver improved retention, engagement, satisfaction, and results for learners of all ages – in schools, campuses, and companies.</p> <p>D2L is disrupting the way the world learns, by providing the next generation learning environment and solutions to engage and inspire learners. And most importantly, by giving customers a platform that is easy, flexible, and smart. No other company provides a solution as robust and innovative as D2L.</p> <p>D2L has had a singular mission for 25 years and is dedicated to that same mission in the years ahead: to transform the way the world learns – and by doing so, we will help improve human potential globally.</p> <hr> <p>Every application we receive is personally reviewed by a member of our Talent Acquisition team - yes, a real person looks at your resume! While we use AI tools internally to streamline tasks like meeting notes, summaries, and administrative work, these tools never rank resumes, make hiring decisions, or influence candidate evaluations.</p></div><div id="description"> <p><span class="TextRun SCXW36748930 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW36748930 BCX0" data-ccp-parastyle="Normal (Web)">As </span><span class="NormalTextRun SCXW36748930 BCX0" data-ccp-parastyle="Normal (Web)">Senior Information Security </span><span class="NormalTextRun SCXW36748930 BCX0" data-ccp-parastyle="Normal (Web)">Analyst </span><span class="NormalTextRun SCXW36748930 BCX0" data-ccp-parastyle="Normal (Web)">at D2L, you are a key influencer and contributor to the refinement and delivery of D2L's </span><span class="NormalTextRun SCXW36748930 BCX0" data-ccp-parastyle="Normal (Web)">Information Security</span><span class="NormalTextRun SCXW36748930 BCX0" data-ccp-parastyle="Normal (Web)"> </span><span class="NormalTextRun SCXW36748930 BCX0" data-ccp-parastyle="Normal (Web)">P</span><span class="NormalTextRun SCXW36748930 BCX0" data-ccp-parastyle="Normal (Web)">rogram.</span><span class="NormalTextRun SCXW36748930 BCX0" data-ccp-parastyle="Normal (Web)"> </span></span><span class="EOP Selected SCXW36748930 BCX0" data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p> <p><strong>How will I make an Impact? </strong></p> <ul> <li><span data-contrast="auto">Assist in refining and delivering D2L's Information Security Program with particular focus on endpoints, applications, and the underlying infrastructure. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Perform regular application/infrastructure security scans, generate reports, and liaise with related stakeholders to work towards closing open issues. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Liaise with operational teams on existing and emerging information security risks and provide subject matter expertise. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Monitor/track information security risks and related artifacts throughout their lifecycle. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Support the Information Security Continuous Monitoring Program(s) aligned with specific security compliance programs. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Support the product sales cycle by completing security questionnaires from prospective clients. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Collaborate with internal subject matter experts to collate, review, and submit periodic security questionnaires from D2L’s client. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Support internal D2L teams during security assessments/reviews/audits. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Review independent third-party reports from vendors, suppliers and partners for adequacy and alignment with D2L’s Information Security Program. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Track identified gaps from third party assessments and follow up with stakeholders to close outstanding issues. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> </ul> <p><strong>What you’ll bring to the role:</strong></p> <p><strong><span data-contrast="auto">Competencies:</span></strong><span data-ccp-props="{}"> </span></p> <ul> <li><span data-contrast="auto">Ability to think critically </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Ability to engage process owners and explain security controls associated with processes</span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Ability to breakdown complex technical concepts to simple terms for various levels of stakeholders</span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Ability to achieve outcomes with minimal supervision.</span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Ability to learn fast and synthesize information from different domains and sources.</span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Ability to work well with teams within a matrix structure and operational setting</span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> </ul> <p><strong><span data-contrast="auto">Skills</span></strong><span data-ccp-props="{"469777462":[720],"469777927":[0],"469777928":[1]}"> </span></p> <ul> <li><span data-contrast="auto">Sound knowledge of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA). </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Sound knowledge of public cloud infrastructure </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Practical knowledge of implementing security controls in public cloud deployments/workloads </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Practical knowledge of Governance Risk and Compliance (GRC) tools </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Practical knowledge of infrastructure and application security scanning tools </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Deep understanding of vulnerability management and penetration testing </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}">Acumen with Artificial Intelligence tools</span></li> <li><span data-contrast="auto">Sound knowledge of risk management framework and standards</span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">Sound knowledge of Information Security frameworks and standards including ISO 27001, NIST 800-53 etc.</span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> </ul> <p><strong><span data-contrast="auto">Suggested Qualifications/Experience:</span></strong><span data-ccp-props="{"201341983":0,"335559740":276}"> </span></p> <ul> <li><span data-contrast="auto">You have previous hands-on experience implementing information security controls across a wide range of domains including Endpoint Security, Application Security, and Infrastructure Security. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">You have hands-on experience with public cloud services like Amazon Web Services (AWS), Azure etc. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">You have hands-on experience performing vulnerability assessments and penetration tests. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">You have demonstrable experience working with teams that have implemented security controls based on ISO 27001/NIST 800-53, CSAE 3416/SSAE18, SOC1/2/3. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">You have experience using enterprise-grade governance risk and compliance (GRC) tools. </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">You have experience assessing security control implementations on large enterprise, web scale and serverless environments.</span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">You have experience engaging stakeholder in remediating security-related findings </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> <li><span data-contrast="auto">You have experience supporting an audit exercise by generating security-related evidence </span><span data-ccp-props="{"134233118":true,"201341983":0,"335559740":240}"> </span></li> </ul> <hr> <p> </p> <p>This position is to fill an existing vacancy</p> <hr> <p>D2L operates in a hybrid work style, with expectation of 3 days per week in office. </p> <p> </p> </div><div class="content-pay-transparency"><div class="pay-input"><div class="description"><p>The expected base salary range for a new hire in this role is listed below. The annualized base salary offered is determined by each candidate’s relevant knowledge, skills, education, training and experience. It is aligned to ensure both internal and external competitiveness using market data for the geographic location and industry. As part of the total compensation at D2L the role may be eligible for additional benefits including a Wellness Subsidy, Equity Grants, Variable Incentive, and more.</p></div><div class="title">Base Salary Range</div><div class="pay-range"><span>$100,000</span><span class="divider">—</span><span>$130,000 CAD</span></div></div></div><div class="content-conclusion"><p><strong>Don’t meet every single requirement?</strong> We strongly encourage you to still apply! At D2L, we are committed to creating a diverse and inclusive environment. We encourage your application even if you don't believe you meet every single qualification outlined, because we love to help our people grow and develop!</p> <p><strong>Why we're awesome:</strong></p> <div style="padding: 56.25% 0 0 0; position: relative;"><iframe style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border: 0;" src="https://player.vimeo.com/video/906835244?badge=0&autopause=0&player_id=0&app_id=58479"></iframe></div> <hr> <p> </p> <p>At D2L, we are dedicated to providing you with the tools to do the best work of your life. While some of our perks and benefits may vary depending on location or employment type, we are proud to provide employees with the following through <a href="https://www.d2l.com/careers/blog/" target="_blank">#LifeAtD2L</a>:</p> <ul class="p-rich_text_list p-rich_text_list__bullet" data-stringify-type="unordered-list" data-indent="0" data-border="0"> <li data-stringify-indent="0" data-stringify-border="0">Impactful work transforming the way the world learns</li> <li data-stringify-indent="0" data-stringify-border="0">Flexible work arrangements</li> <li data-stringify-indent="0" data-stringify-border="0">Learning and Growth opportunities</li> <li data-stringify-indent="0" data-stringify-border="0">Tuition reimbursement of up to $4,000 CAD for continuing education through our SkillsWave Program</li> <li data-stringify-indent="0" data-stringify-border="0">2 Paid Days off for SkillsWave-related activities like exams or final assignments</li> <li data-stringify-indent="0" data-stringify-border="0">Employee wellbeing (Access to mental health services, EFAP program, financial planning and more)</li> <li data-stringify-indent="0" data-stringify-border="0">Retirement planning</li> <li data-stringify-indent="0" data-stringify-border="0">2 Paid Volunteer Days</li> <li data-stringify-indent="0" data-stringify-border="0">Competitive Benefits Package</li> <li data-stringify-indent="0" data-stringify-border="0">Home Internet Reimbursements</li> <li data-stringify-indent="0" data-stringify-border="0">Employee Referral Program</li> <li data-stringify-indent="0" data-stringify-border="0">Wellness Reimbursement</li> <li data-stringify-indent="0" data-stringify-border="0">Employee Recognition</li> <li data-stringify-indent="0" data-stringify-border="0">Social Events</li> <li data-stringify-indent="0" data-stringify-border="0">Dog Friendly Offices Spaces at our HQ in Kitchener, Winnipeg, Vancouver and Melbourne offices.</li> </ul></div>