Security Analyst

atCanopy Growth CorporationRemoteCA flagCanadaFull-timeUncategorizedMid-levelSeniorC$80k – C$90k/year

Posted Aug 22

This is a fully remote position, open to applicants in Canada.

📋 Description

• Take charge of the comprehensive vulnerability management lifecycle for servers, endpoints, network assets, and public-facing systems.

• Set up and maintain scanning engines, templates, asset groups, credentialed scanning, and scan schedules.

• Diagnose authentication issues and missing assets to guarantee thorough scanning coverage.

• Reassess and verify remediation efforts to ensure vulnerabilities are fully resolved.

• Monitor remediation efforts against SLAs, manage risk exceptions, and report on vulnerability posture and trends to stakeholders.

• Implement and oversee scan sensors/engines in a distributed, multi-site environment.

• Organize independent penetration tests, which include scoping, vendor engagement, findings triage, and tracking of remediation efforts.

• Conduct internal security assessments to validate detection and response mechanisms.

• Utilize CVSS scoring and contest vendor-assigned severity ratings when appropriate.

• Manage application security SAST/SCA scanning, onboard repositories, and oversee review cycles with development teams.

• Evaluate SAST/SCA findings, identify genuine positives, and drive remediation efforts alongside developers.

• Collaborate with development and cloud teams to integrate secure practices into the software development lifecycle.

• Investigate and suggest improvements to vulnerability management, testing, and application security practices.

• Assist in incident response preparedness and take part in tabletop exercises.

• Keep documentation up to date and maintain current tracking tools for the team.

• Remain informed about cybersecurity trends, tools, vulnerabilities, and best practices.

• Cross-train with cybersecurity colleagues and support team initiatives, special projects, and process enhancements.


⛳️ Requirements

• Bachelor’s degree in Computer Science, Information Security, Engineering, or a related discipline (or equivalent practical experience).

• Over 3 years of direct experience in vulnerability management, security testing, or roles focused on offensive security.

• Practical experience with an enterprise vulnerability management platform, including configuration of scan engines and credentialed scanning.

• Familiarity with application security testing concepts and tools (SAST/SCA) and the ability to effectively communicate findings to developers.

• Strong grasp of the Common Vulnerability Scoring System (CVSS) and methodologies for vulnerability assessment.

• Knowledge of penetration testing concepts and experience in coordinating or supporting third-party testing engagements.

• Proficient understanding of Linux and Windows operating systems, network protocols, and prevalent security tools.

• Awareness of cybersecurity frameworks such as NIST 800-53, NIST CSF, or ISO 27001.

• Desired certifications include OSCP, GIAC GPEN/GWAPT, CEH, CompTIA PenTest+, CySA+.

• Excellent problem-solving, documentation, and communication abilities, with the capacity to engage both technical and non-technical audiences.

• Demonstrated ability to juggle multiple security priorities in a dynamic and fast-paced environment.

• Previous experience in an IT Operations/Infrastructure position would be advantageous.

• The selected candidate must successfully pass background and reference checks.


🏝️ Benefits

• Comprehensive health and dental coverage.

• Paid vacation time.

• Participation in an employer-supported retirement savings plan.

People also viewed

Parallel Design Studio5 hours ago

Web Development Lead

IN flagIndia OnlyFull-timeUncategorized
ApplyView job
Mercor5 hours ago

Special Education, IEP Evaluator

US flagUnited States OnlyFreelanceUncategorized$80 – $120/hour
ApplyView job
Phigenics5 hours ago

Part-Time Water Management Equipment Technician

US flagLouisiana OnlyPart-timeUncategorized
ApplyView job
RWS Group5 hours ago

Generative Audio Evaluation – Spanish

ES flagSpain OnlyPart-timeUncategorized$12/hour
ApplyView job
Longbridge Financial, LLC (NMLS# 957935)5 hours ago

Quality Control Coordinator

US flagNew Jersey OnlyFull-timeUncategorized$52k – $57k/year
ApplyView job
Boston Medical Center (BMC)5 hours ago

Team Lead – Epic Willow Ambulatory

US flagMassachusetts OnlyFull-timeUncategorized$89.5k – $130k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers