Security Analyst

Job not on LinkedIn

🔥 0 minutes ago

🇨🇦 Canada – Remote

💵 $80k - $90k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔐 Security Analyst

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Canopy Growth Corporation

Canopy Growth Corporation

1001 - 5000 employees

🏭 Manufacturing

🍽️ Food & Beverage

💊 Pharmaceuticals

Manufacturing • Food & Beverage • Pharmaceuticals

Canopy Growth Corporation is a world leading cannabis company dedicated to harnessing the potential of cannabis to enhance lives. With a focus on personal wellness, economic opportunity, and social justice, Canopy aims to demonstrate cannabis as a positive influence in society.

📋 Description

• Own the end-to-end vulnerability management lifecycle across servers, endpoints, network assets, and public-facing systems • Configure and maintain scan engines, templates, asset groups, credentialed scanning, and scan schedules • Troubleshoot authentication failures and missing assets to ensure complete scanning coverage • Retest and validate remediation to confirm vulnerabilities are genuinely resolved • Track remediation against SLAs, manage risk exceptions, and report vulnerability posture and trends to stakeholders • Deploy and maintain scan sensors/engines across a distributed, multi-site environment • Coordinate independent penetration tests, including scoping, vendor engagement, findings triage, and remediation tracking • Perform internal security testing to validate detection and response controls • Apply CVSS scoring and challenge vendor-assigned severity ratings where warranted • Administer application security SAST/SCA scanning, onboard repositories, and manage review cadences with development teams • Triage SAST/SCA findings, identify true positives, and drive remediation with developers • Partner with development and cloud teams to embed secure practices into the software development lifecycle • Research and recommend enhancements to vulnerability management, testing, and application security practices • Support incident response readiness and participate in tabletop exercises • Maintain documentation and keep team tracking tools current • Stay current with cybersecurity trends, tooling, vulnerabilities, and best practices • Cross-train with cybersecurity team members and support team initiatives, special projects, and process improvements

🎯 Requirements

• Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent practical experience) • 3+ years of hands-on experience in vulnerability management, security testing, or offensive security roles • Hands-on experience with an enterprise vulnerability management platform, including scan engine configuration and credentialed scanning • Working knowledge of application security testing concepts and tools (SAST/SCA) and ability to communicate findings effectively with developers • Solid understanding of the Common Vulnerability Scoring System (CVSS) and vulnerability assessment methodologies • Familiarity with penetration testing concepts and experience coordinating or supporting third-party testing engagements • Strong working knowledge of Linux and Windows operating systems, network protocols, and common security tools • Familiarity with cybersecurity frameworks such as NIST 800-53, NIST CSF, or ISO 27001 • Preferred certifications include OSCP, GIAC GPEN/GWAPT, CEH, CompTIA PenTest+, CySA+ • Strong problem-solving, documentation, and communication skills, with ability to engage technical and non-technical audiences • Proven ability to manage multiple security priorities in a fast-paced, evolving environment • Previous experience in an IT Operations/Infrastructure role would be an asset • Chosen applicant must successfully complete background and reference checks

🏖️ Benefits

• Extended health and dental coverage • Paid vacation • Participation in employer-supported retirement savings program

Apply Now

Similar Jobs

🕒 July 28

VC3

501 - 1000

🔒 Cybersecurity

🏥 Healthcare

Security Analyst I responsible for security event monitoring and incident response at VC3. Collaborating with clients and utilizing security tools to diagnose and remediate threats.

🇨🇦 Canada – Remote

💰 Venture Round on 2016-02

⏰ Full Time

🟢 Junior

🟡 Mid-level

🔐 Security Analyst

🕒 July 22

Workin Group

11 - 50

🏨 Hospitality

🏗️ Construction

🏥 Healthcare

Cybersecurity SOC Analyst monitoring and responding to security alerts for Canadian clients. Working entirely remote within the client's IT/security team and project manager oversight.

🇨🇦 Canada – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔐 Security Analyst

🗣️🇫🇷 French Required

🕒 February 14

Kraken Digital Asset Exchange

1001 - 5000

₿ Crypto

💸 Finance

💳 Fintech

Senior Analyst performing SOC 1 and SOC 2 examinations at Kraken. Leading compliance initiatives and enhancing IT controls in a remote environment.

🇨🇦 Canada – Remote

⏰ Full Time

🟠 Senior

🔐 Security Analyst