D2L is a cloud company that is modernizing education and building the Future of Work. The old models of teaching and learning are in the midst of the largest transformation in history, and D2L is at the heart of that fundamental shift.New models of teaching and learning enable a personalized, student-centric experience – and deliver improved retention, engagement, satisfaction, and results for learners of all ages – in schools, campuses, and companies.D2L is disrupting the way the world learns, by providing the next generation learning setting and solutions to engage and inspire learners. And most importantly, by giving customers a platform that is easy, flexible, and smart. No other company provides a solution as robust and innovative as D2L.D2L has had a singular mission for 25 years and is dedicated to that same mission in the years ahead: to transform the way the world learns – and by doing so, we will help improve human potential globally.Every application we receive is personally reviewed by a member of our Talent Acquisition team - yes, a real person looks at your resume! While we use AI tools internally to streamline tasks like meeting notes, summaries, and administrative work, these tools never rank resumes, make hiring decisions, or influence candidate evaluations.How will I make an Impact?Assist in refining and delivering D2L's Application Security Program with particular focus on endpoints, applications,
and the underlying infrastructure.Perform regular security scans and coordinate with stakeholders to address open issuesCollaborate with operational teams on existing and emerging security risks and provide subject matter expertise.Triage third-party assessments and follow up with stakeholders to address issuesMonitor/track security risks and related artifacts throughout their lifecycleSupport internal D2L teams during security assessments/reviews/auditsReview independent third-party reports from vendors, suppliers and partners for alignment with D2L's Application Security ProgramCompetenciesWhat you'll bring to the role:Ability to engage process owners and explain security controls associated with processesAbility to break down complex technical concepts to simple terms for various levels of stakeholdersAbility to work independentlyAbility to learn fast and synthesize information from different domains and sources.Acumen with Artificial Intelligence toolsAbility to work well with a wide cross-section of engineering and operational teamsSuggested Qualifications/ExperienceYou have practical programming experience and are proficient at reviewing code in a variety of languagesYou have previous hands-on experience implementing information security controls across a wide range of domains including Endpoint Security, Application Security, and Infrastructure Security. (SAST, DAST, SCA)You have hands-on experience with public cloud services like AWS or Azure etc.You have hands-on experience performing vulnerability assessments and penetration tests.You have demonstrable experience working with teams that have implemented security controls based on ISO 27001/NIST 800-53, PCI-DSS,
PBMMYou have experience using enterprise-grade governance risk and compliance (GRC) tools.You have experience assessing security control implementations on large enterprises, web scale and serverless environments.You have experience engaging stakeholders in remediating security-related findingsYou have experience supporting an audit exercise by generating security-related evidenceThis position is to fill an existing vacancyD2L operates in a hybrid work style, with expectation of 3 days per week in office.The expected base salary range for a new hire in this role is listed below. The annualized base salary offered is determined by each candidate's relevant knowledge, skills, education, training and experience. It is aligned to ensure both internal and external competitiveness using market data for the geographic location and industry. As part of the total compensation at D2L the role may be eligible for additional benefits including a Wellness Subsidy, Equity Grants, Variable Incentive, and more.Base Salary Range$100,000—$130,000 CADDon't meet every single requirement?Why We're AwesomeImpactful work transforming the way the world learnsFlexible work arrangementsLearning and Growth opportunitiesTuition reimbursement of up to $4,000 CAD for continuing education through our SkillsWave Program2 Paid Days off for SkillsWave-related activities like exams or final assignmentsEmployee wellbeing (Access to mental health services, EFAP program, financial planning and more)Retirement planning2 Paid Volunteer DaysCompetitive Benefits PackageHome Internet ReimbursementsEmployee Referral ProgramWellness ReimbursementEmployee RecognitionSocial EventsDog Friendly Offices Spaces at our HQ in Kitchener, Winnipeg, Vancouver and Melbourne offices.
📌 Senior Application Security Analyst (Kitchener)
🏢 D2L
📍 Kitchener