Loading jobs…
Loading jobs…
D2L — Kitchener, Ontario
D2L is a cloud company that is modernizing education and building the Future of Work. The old models of teaching and learning are in the midst of the largest transformation in history, and D2L is at the heart of that fundamental shift. New models of teaching and learning enable a personalized, student-centric experience – and deliver improved retention, engagement, satisfaction, and results for learners of all ages – in schools, campuses, and companies.
D2L is disrupting the way the world learns, by providing the next generation learning environment and solutions to engage and inspire learners. And most importantly, by giving customers a platform that is easy, flexible, and smart. No other company provides a solution as robust and innovative as D2L.
D2L has had a singular mission for 25 years and is dedicated to that same mission in the years ahead: to transform the way the world learns – and by doing so, we will help improve human potential globally. Every application we receive is personally reviewed by a member of our Talent Acquisition team - yes, a real person looks at your resume! While we use AI tools internally to streamline tasks like meeting notes, summaries, and administrative work, these tools never rank resumes, make hiring decisions, or influence candidate evaluations.
As Senior Information Security Analyst at D2L, you are a key influencer and contributor to the refinement and delivery of D2L's Information Security P rogram. How will I make an Impact? Assist in refining and delivering D2L's Information Security Program with particular focus on endpoints, applications, and the underlying infrastructure.
Perform regular application/infrastructure security scans, generate reports, and liaise with related stakeholders to work towards closing open issues. Liaise with operational teams on existing and emerging information security risks and provide subject matter expertise. Monitor/track information security risks and related artifacts throughout their lifecycle.
Support the Information Security Continuous Monitoring Program(s) aligned with specific security compliance programs. Support the product sales cycle by completing security questionnaires from prospective clients. Collaborate with internal subject matter experts to collate, review, and submit periodic security questionnaires from D2L’s client.
Support internal D2L teams during security assessments/reviews/audits. Review independent third-party reports from vendors, suppliers and partners for adequacy and alignment with D2L’s Information Security Program. Track identified gaps from third party assessments and follow up with stakeholders to close outstanding issues.
What you’ll bring to the role: Competencies: Ability to think critically Ability to engage process owners and explain security controls associated with processes Ability to breakdown complex technical concepts to simple terms for various levels of stakeholders Ability to achieve outcomes with minimal supervision. Ability to learn fast and synthesize information from different domains and sources. Ability to work well with teams within a matrix structure and operational setting Skills Sound knowledge of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA).
Sound knowledge of public cloud infrastructure Practical knowledge of implementing security controls in public cloud deployments/workloads Practical knowledge of Governance Risk and Compliance (GRC) tools Practical knowledge of infrastructure and application security scanning tools Deep understanding of vulnerability management and penetration testing Acumen with Artificial Intelligence tools Sound knowledge of risk management framework and standards Sound knowledge of Information Security frameworks and standards including ISO 27001, NIST 800-53 etc.
Qualifications
/Experience: You have previous hands-on experience implementing information security controls across a