
1001 - 5000 employees
🏭 Manufacturing
🍽️ Food & Beverage
💊 Pharmaceuticals
Manufacturing • Food & Beverage • Pharmaceuticals
Canopy Growth Corporation is a world leading cannabis company dedicated to harnessing the potential of cannabis to enhance lives. With a focus on personal wellness, economic opportunity, and social justice, Canopy aims to demonstrate cannabis as a positive influence in society.
🔥 0 minutes ago
🇨🇦 Canada – Remote
💵 $80k - $90k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
🔐 Security Analyst
👻 Ghost score 0%
Improve your chances of getting an interview by checking your resume score before you apply.

1001 - 5000 employees
🏭 Manufacturing
🍽️ Food & Beverage
💊 Pharmaceuticals
Manufacturing • Food & Beverage • Pharmaceuticals
Canopy Growth Corporation is a world leading cannabis company dedicated to harnessing the potential of cannabis to enhance lives. With a focus on personal wellness, economic opportunity, and social justice, Canopy aims to demonstrate cannabis as a positive influence in society.
• Own the end-to-end vulnerability management lifecycle across servers, endpoints, network assets, and public-facing systems • Configure and maintain scan engines, templates, asset groups, credentialed scanning, and scan schedules • Troubleshoot authentication failures and missing assets to ensure complete scanning coverage • Retest and validate remediation to confirm vulnerabilities are genuinely resolved • Track remediation against SLAs, manage risk exceptions, and report vulnerability posture and trends to stakeholders • Deploy and maintain scan sensors/engines across a distributed, multi-site environment • Coordinate independent penetration tests, including scoping, vendor engagement, findings triage, and remediation tracking • Perform internal security testing to validate detection and response controls • Apply CVSS scoring and challenge vendor-assigned severity ratings where warranted • Administer application security SAST/SCA scanning, onboard repositories, and manage review cadences with development teams • Triage SAST/SCA findings, identify true positives, and drive remediation with developers • Partner with development and cloud teams to embed secure practices into the software development lifecycle • Research and recommend enhancements to vulnerability management, testing, and application security practices • Support incident response readiness and participate in tabletop exercises • Maintain documentation and keep team tracking tools current • Stay current with cybersecurity trends, tooling, vulnerabilities, and best practices • Cross-train with cybersecurity team members and support team initiatives, special projects, and process improvements
• Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent practical experience) • 3+ years of hands-on experience in vulnerability management, security testing, or offensive security roles • Hands-on experience with an enterprise vulnerability management platform, including scan engine configuration and credentialed scanning • Working knowledge of application security testing concepts and tools (SAST/SCA) and ability to communicate findings effectively with developers • Solid understanding of the Common Vulnerability Scoring System (CVSS) and vulnerability assessment methodologies • Familiarity with penetration testing concepts and experience coordinating or supporting third-party testing engagements • Strong working knowledge of Linux and Windows operating systems, network protocols, and common security tools • Familiarity with cybersecurity frameworks such as NIST 800-53, NIST CSF, or ISO 27001 • Preferred certifications include OSCP, GIAC GPEN/GWAPT, CEH, CompTIA PenTest+, CySA+ • Strong problem-solving, documentation, and communication skills, with ability to engage technical and non-technical audiences • Proven ability to manage multiple security priorities in a fast-paced, evolving environment • Previous experience in an IT Operations/Infrastructure role would be an asset • Chosen applicant must successfully complete background and reference checks
• Extended health and dental coverage • Paid vacation • Participation in employer-supported retirement savings program
Apply Now🕒 July 28
Security Analyst I responsible for security event monitoring and incident response at VC3. Collaborating with clients and utilizing security tools to diagnose and remediate threats.
🕒 July 22
Cybersecurity SOC Analyst monitoring and responding to security alerts for Canadian clients. Working entirely remote within the client's IT/security team and project manager oversight.
🗣️🇫🇷 French Required
🕒 February 14
Senior Analyst performing SOC 1 and SOC 2 examinations at Kraken. Leading compliance initiatives and enhancing IT controls in a remote environment.