Senior Application Security Analyst

Socket.dev

Kitchener

Hybrid

CAD 100,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Tuition reimbursement
SkillsWave program
2 Paid Days off for SkillsWave-related
Mental health services
Retirement planning
2 Paid Volunteer Days
Home Internet Reimbursements
Employee Referral Program
Wellness Reimbursement
Employee Recognition
Social Events
Dog Friendly Offices

Job summary

D2L is a cloud company modernizing education and transforming the way the world learns. As a Senior Application Security Analyst, you will influence and deliver D2L's Application Security Program across endpoints, applications, and infrastructure, coordinating with engineering and operations teams.

You will perform security scans, engage stakeholders for remediation, and review third-party reports to ensure alignment with security standards. Hybrid work with 3 days in-office per week.

Qualifications

  • Practical programming experience and proficiency at reviewing code in multiple languages.
  • Hands-on experience implementing information security controls across Endpoint, Application, and Infrastructure Security (SAST/DAST/SCA).
  • Hands-on experience with public cloud services like AWS or Azure.
  • Experience performing vulnerability assessments and penetration tests.
  • Demonstrated experience with ISO 27001/NIST 800-53, PCI-DSS, PBMM.
  • Experience using enterprise-grade GRC tools.
  • Experience assessing security control implementations on large enterprises, web-scale and serverless environments.
  • Experience engaging stakeholders in remediating security-related findings.
  • Experience supporting an audit exercise by generating security-related evidence.

Responsibilities

  • Assist in refining and delivering D2L's Application Security Program with focus on endpoints, applications, and underlying infrastructure.
  • Perform regular security scans and coordinate with stakeholders to address open issues.
  • Collaborate with operational teams on existing and emerging security risks and provide subject matter expertise.
  • Triage third-party assessments and follow up with stakeholders to address issues.
  • Monitor/track security risks and related artifacts throughout their lifecycle.
  • Support internal D2L teams during security assessments/reviews/audits.
  • Review independent third-party reports from vendors, suppliers and partners for alignment with D2L’s Application Security Program.

Skills

Programming experience
Code review proficiency
Security controls implementation
Cloud services (AWS/Azure)
Vulnerability assessments
GRC tools
Stakeholder engagement
ISO 27001/NIST 800-53/PCI-DSS
Serverless security

Tools

AWS
Azure

Job description

D2L is a cloud company that is modernizing education and building the Future of Work. The old models of teaching and learning are in the midst of the largest transformation in history, and D2L is at the heart of that fundamental shift.

New models of teaching and learning enable a personalized, student-centric experience – and deliver improved retention, engagement, satisfaction, and results for learners of all ages – in schools, campuses, and companies.

D2L is disrupting the way the world learns, by providing the next generation learning environment and solutions to engage and inspire learners. And most importantly, by giving customers a platform that is easy, flexible, and smart. No other company provides a solution as robust and innovative as D2L.

D2L has had a singular mission for 25 years and is dedicated to that same mission in the years ahead: to transform the way the world learns – and by doing so, we will help improve human potential globally.

Every application we receive is personally reviewed by a member of our Talent Acquisition team - yes, a real person looks at your resume! While we use AI tools internally to streamline tasks like meeting notes, summaries, and administrative work, these tools never rank resumes, make hiring decisions, or influence candidate evaluations.

As Senior Application Security Analyst at D2L, you are a key influencer and contributor to the refinement and delivery of D2L's Application Security Program.

How will I make an Impact?
  • Assist in refining and delivering D2L's Application Security Program with particular focus on endpoints, applications, and the underlying infrastructure.
  • Perform regular security scans and coordinate with stakeholders to address open issues
  • Collaborate with operational teams on existing and emerging security risks and provide subject matter expertise.
  • Triage third-party assessments and follow up with stakeholders to address issues
  • Monitor/track security risks and related artifacts throughout their lifecycle
  • Support internal D2L teams during security assessments/reviews/audits
  • Review independent third-party reports from vendors, suppliers and partners for alignment with D2L’s Application Security Program
What you’ll bring to the role:
Competencies:
  • Ability to engage process owners and explain security controls associated with processes
  • Ability to break down complex technical concepts to simple terms for various levels of stakeholders
  • Ability to work independently
  • Ability to learn fast and synthesize information from different domains and sources.
  • Acumen with Artificial Intelligence tools
  • Ability to work well with a wide cross-section of engineering and operational teams
Suggested Qualifications/Experience:
  • You have practical programming experience and are proficient at reviewing code in a variety of languages
  • You have previous hands‑on experience implementing information security controls across a wide range of domains including Endpoint Security, Application Security, and Infrastructure Security. (SAST, DAST, SCA)
  • You have hands‑on experience with public cloud services like AWS or Azure etc.
  • You have hands‑on experience performing vulnerability assessments and penetration tests.
  • You have demonstrable experience working with teams that have implemented security controls based on ISO 27001/NIST 800-53, PCI-DSS, PBMM
  • You have experience using enterprise‑grade governance risk and compliance (GRC) tools.
  • You have experience assessing security control implementations on large enterprises, web scale and serverless environments.
  • You have experience engaging stakeholders in remediating security‑related findings
  • You have experience supporting an audit exercise by generating security‑related evidence

This position is to fill an existing vacancy

D2L operates in a hybrid work style, with expectation of 3 days per week in office.

Base Salary Range

$100,000$130,000 CAD

Why we're awesome:

At D2L, we are dedicated to providing you with the tools to do the best work of your life. While some of our perks and benefits may vary depending on location or employment type, we are proud to provide employees with the following through #LifeAtD2L:

  • Impactful work transforming the way the world learns
  • Flexible work arrangements
  • Learning and Growth opportunities
  • Tuition reimbursement of up to $4,000 CAD for continuing education through our SkillsWave Program
  • 2 Paid Days off for SkillsWave-related activities like exams or final assignments
  • Employee wellbeing (Access to mental health services, EFAP program, financial planning and more)
  • Retirement planning
  • 2 Paid Volunteer Days
  • Competitive Benefits Package
  • Home Internet Reimbursements
  • Employee Referral Program
  • Wellness Reimbursement
  • Employee Recognition
  • Social Events
  • Dog Friendly Offices Spaces at our HQ in Kitchener, Winnipeg, Vancouver and Melbourne offices.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Test Developer - New Graduate
Software Test Developer - New Graduate

D2L • Kitchener

Hybrid
CAD 70,000 - 85,000
Flexible work arrangements
Tuition reimbursement
Wellness program
+5
Software Test Developer
Software Test Developer

D2L • Kitchener

On-site
CAD 70,000 - 85,000
Flexible work arrangements
Learning and Growth opportunities
Tuition reimbursement up to CAD 4,000
+11
Manager, Social Media
Manager, Social Media

D2L • Kitchener, Toronto

On-site
CAD 98,000 - 105,000
Wellness Subsidy
Equity Grants
Tuition reimbursement (CAD 4,000)
+4
Senior Product Manager - Createspace, Canada Based
Senior Product Manager - Createspace, Canada Based

Talanto • Toronto

Hybrid
CAD 110,000 - 150,000
Flexible work arrangements
Wellness Subsidy
Equity Grants
+5
Product Support Analyst - Winter 2027 Co-op
Product Support Analyst - Winter 2027 Co-op

Socket.dev • Kitchener

On-site
CAD 35,000 - 44,000
Tuition reimbursement
Flexible work arrangements
Paid days off
+2
Senior Proposal Manager
Senior Proposal Manager

D2L • Kitchener, Toronto

On-site
CAD 103,000 - 120,000
Flexible work arrangements
Tuition reimbursement up to CAD 4,000
Wellness reimbursement
+2
Solutions Architect
Solutions Architect

D2L • Kitchener

On-site
CAD 85,000 - 105,000
Tuition reimbursement of up to CAD 4,
Wellness benefits
2 paid days off for SkillsWave
+3
Senior Product Manager - Createspace, Canada Based
Senior Product Manager - Createspace, Canada Based

Socket.dev • Winnipeg, Kitchener

Hybrid
CAD 110,000 - 150,000
Tuition reimbursement up to CAD 4,000
2 Paid Days off for SkillsWave
Flexible work arrangements
+2
Software Developer - Winter 2027 Co-op
Software Developer - Winter 2027 Co-op

Socket.dev • Kitchener

On-site
CAD 44,000 - 66,000
Flexible work arrangements
Learning and Growth opportunities
Tuition reimbursement of up to CAD 4,0
+10
Business Development Representative
Business Development Representative

D2L • Kitchener

On-site
CAD 40,000 - 56,000
Tuition reimbursement up to $4,000 CAD
Flexible work arrangements
Wellness Subsidy