Senior Application Security Analyst
Job Summary
D2L is a cloud company that is modernizing education and building the Future of Work. The old models of teaching and learning are in the midst of the largest transformation in history and D2L is at the heart of that fundamental shift.
New models of teaching and learning enable a personalized student-centric experience and deliverimproved retention engagement satisfaction and results for learners of all ages in schools campuses and companies.
D2L is disrupting the way the world learns by providing the next generation learning environment and solutions to engage and inspire learners. And most importantly by giving customers a platform that is easy flexible and other company provides a solution as robust and innovative as D2L.
D2L has had a singular mission for 25 years and is dedicated to that same mission in the years ahead: to transform the way the world learns and by doing so we will help improve human potential globally.
Every application we receive is personally reviewed by a member of our Talent Acquisition team - yes a real person looks at your resume! While we use AI tools internally to streamline tasks like meeting notes summaries and administrative work these tools never rank resumes make hiring decisions or influence candidate evaluations.
As Senior Application Security Analyst at D2L you are a key influencer and contributor to the refinement and delivery of D2Ls Application Security Program.
How will I make an Impact
- Assist in refining and delivering D2Ls Application Security Program with particular focus on endpoints applications and the underlying infrastructure.
- Perform regular security scans and coordinate with stakeholders to address open issues
- Collaborate with operational teams on existing and emerging security risks and provide subject matter expertise.
- Triage third-party assessments and follow up with stakeholders to address issues
- Monitor/track security risks and related artifacts throughout their lifecycle
- Support internal D2L teams during security assessments/reviews/audits
- Review independent third-party reports from vendors suppliers and partners for alignment with D2Ls Application Security Program
What youll bring to the role:
Competencies:
- Ability to engage process owners and explain security controls associated with processes
- Ability to break down complex technical concepts to simple terms for various levels of stakeholders
- Ability to work independently
- Ability to learn fast and synthesize information from different domains and sources.
- Acumen with Artificial Intelligence tools
- Ability to work well with a wide cross-section of engineering and operational teams
Suggested Qualifications/Experience:
- You have practical programming experience and are proficient at reviewing code in a variety of languages
- You have previous hands-on experience implementing information security controls across a wide range of domains including Endpoint Security Application Security and Infrastructure Security. (SAST DAST SCA)
- You have hands-on experience with public cloud services like AWS or Azure etc.
- You have hands-on experience performing vulnerability assessments and penetration tests.
- You have demonstrable experience working with teams that have implemented security controls based on ISO 27001/NIST 800-53 PCI-DSS PBMM
- You have experience using enterprise-grade governance risk and compliance (GRC) tools.
- You have experience assessing security control implementations on large enterprises web scale and serverless environments.
- You have experience engaging stakeholders in remediating security-related findings
- You have experience supporting an audit exercise by generating security-related evidence
This position is to fill an existing vacancy
D2L operates in a hybrid work style with expectation of 3 days per week in office.
Required Experience:
Senior IC
About Company
Created by D2L, Brightspace is the best LMS software for online learning and teaching. Discover how our online learning platform for schools and companies can help your organization today.