About this role
Job title: Senior Information Security Analyst
About the Role As Senior Information Security Analyst at D2L, you will be a key influencer and contributor to the refinement and delivery of D2L's Information Security Program, with a focus on endpoints, applications, and underlying infrastructure. You will perform regular security assessments, collaborate with operational teams, and support audits and client security questionnaires to protect D2L's systems and data.
What You'll Do
- Assist in refining and delivering D2L's Information Security Program with particular focus on endpoints, applications, and the underlying infrastructure.
- Perform regular application/infrastructure security scans, generate reports, and liaise with related stakeholders to close open issues.
- Liaise with operational teams on existing and emerging information security risks and provide subject matter expertise.
- Monitor/track information security risks and related artifacts throughout their lifecycle.
- Support the Information Security Continuous Monitoring Program(s) aligned with specific security compliance programs.
- Support the product sales cycle by completing security questionnaires from prospective clients; collaborate with internal subject matter experts to collate, review, and submit periodic security questionnaires from D2L’s client.
- Support internal D2L teams during security assessments/reviews/audits.
- Review independent third-party reports from vendors, suppliers and partners for adequacy and alignment with D2L’s Information Security Program; track identified gaps and follow up with stakeholders to close outstanding issues.
What We're Looking For
- Critical thinking and ability to engage process owners and explain security controls.
- Ability to breakdown complex technical concepts to simple terms for various levels of stakeholders.
- Ability to achieve outcomes with minimal supervision.
- Ability to learn fast and synthesize information from different domains.
- Ability to work well with teams within a matrix structure and operational setting.
- SAST, DAST and SCA proficiency.
- Public cloud infrastructure knowledge (AWS, Azure).
- Experience implementing security controls in public cloud deployments.
- GRC tools experience.
- Infrastructure and application security scanning tools experience.
- Vulnerability management and penetration testing expertise.
- Acumen with Artificial Intelligence tools.
- Knowledge of risk management framework and standards (RMF).
- Knowledge of information security frameworks and standards (ISO 27001, NIST 800-53).
Nice to Have
- Experience implementing security controls across Endpoint, Application, and Infrastructure Security.
- Hands-on experience with AWS, Azure.
- Hands-on vulnerability assessments and penetration tests.
- Experience with ISO 27001 / NIST 800-53, CSAE 3416/SSAE18, SOC1/2/3.
- Experience using enterprise-grade GRC tools.
- Experience assessing security control implementations on large enterprise, web-scale and serverless environments.
- Experience engaging stakeholders in remediating security-related findings.
- Experience supporting an audit by generating security-related evidence.
Compensation & Benefits
- Base Salary Range: CAD 100,000 – 130,000.
- Hybrid work style: 3 days per week in office.
- Wellness Subsidy, Equity Grants, Variable Incentive, and more.