高级应用安全分析师
查看雇主原标题
Senior Application Security AnalystD2L · Kitchener · base salary range for a new hire in this role is listed below. The annualized base salary offered is determined by each candidate’s relevant knowledge, skills,
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 52/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 稀有职位匹配
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 稀有职位+11
- 公司来源健康度+8
该职位未包含:已披露薪资、远程职位、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译D2L 是一家云公司,正在推动教育现代化并构建未来工作方式。旧有的教学与学习模式正处于历史上最大规模的转型之中,而 D2L 正处于这一根本性转变的核心。
新的教学与学习模式能够实现个性化、以学生为中心的体验——并为各年龄段的学习者——无论是在学校、校园还是企业——带来更高的留存率、参与度、满意度和成果。
D2L 正在颠覆全球学习方式,通过提供下一代学习环境和解决方案来吸引和激励学习者。最重要的是,为客户提供一个简单、灵活且智能的平台。没有其他公司能提供像 D2L 这样强大且创新的解决方案。
25 年来,D2L 始终肩负着一个独特的使命,并在未来岁月中继续致力于这一使命:改变全球学习方式——通过这样做,我们将帮助提升全球人类潜能。
我们收到的每一份申请都会由我们人才招聘团队的成员亲自审阅——是的,真人会查看你的简历!虽然我们在内部使用 AI 工具来简化会议记录、摘要和行政工作等任务,但这些工具绝不会对简历进行排名、做出招聘决定或影响候选人评估。
作为 D2L 的高级应用安全分析师,你是 D2L 应用安全计划完善与交付的关键影响者和贡献者。
我将如何产生影响?
• 协助完善和交付 D2L 的应用安全计划,特别关注端点、应用程序和底层基础设施。
• 执行定期安全扫描,并与利益相关方协调解决未决问题
• 与运营团队就现有和新兴安全风险开展协作,并提供主题专业知识。
• 对第三方评估进行分诊,并跟进利益相关方以解决问题
• 在整个生命周期中监控/跟踪安全风险及相关工件
• 在安全评估/审查/审计期间为 D2L 内部团队提供支持
• 审查来自供应商、供货商和合作伙伴的独立第三方报告,以确保其与 D2L 的应用安全计划保持一致
你将为本职位带来:
能力:
• 能够与流程负责人沟通,并解释与流程相关的安全控制措施
• 能够将复杂的技术概念拆解为简单术语,以便向不同层级的利益相关方说明
• 能够独立工作
• 能够快速学习并综合来自不同领域和来源的信息。
• 具备人工智能工具的敏锐度
• 能够与各类工程和运营团队良好合作
建议的资格/经验:
• 你具备实际编程经验,并熟练审查多种语言的代码
• 你拥有在广泛领域实施信息安全控制的先前实操经验,包括端点安全、应用安全和基础设施安全。(SAST、DAST、SCA)
• 你拥有使用 AWS 或 Azure 等公共云服务的实操经验。
• 你拥有执行漏洞评估和渗透测试的实操经验。
• 你拥有与基于 ISO 27001/NIST 800-53、PCI-DSS、PBMM 实施安全控制的团队合作的明确经验
• 你拥有使用企业级治理、风险与合规(GRC)工具的经验。
• 你拥有评估大型企业、Web 规模和无服务器环境中安全控制实施情况的经验。
• 你拥有推动利益相关方修复安全相关发现的经验
• 你拥有通过生成安全相关证据来支持审计工作的经验
该职位用于填补现有空缺
D2L 采用混合工作模式,期望每周到办公室工作 3 天。
该职位新员工预期基本薪资范围如下。所提供的年度基本薪资由每位候选人的相关知识、技能、教育、培训和经验决定。它会结合该地理位置和行业的市场数据进行校准,以确保内部和外部竞争力。作为 D2L 总薪酬的一部分,该职位可能有资格获得额外福利,包括健康补贴、股权授予、浮动激励等。
基本薪资范围 $100,000 — $130,000 CAD
没有满足每一项要求?我们强烈鼓励你仍然申请!在 D2L,我们致力于创造一个多元且包容的环境。即使你认为自己并不符合列出的每一项资格,我们也鼓励你申请,因为我们乐于帮助我们的员工成长和发展!
为什么我们很棒:
在 D2L,我们致力于为你提供工具,让你完成人生中最出色的工作。虽然我们的一些福利和待遇可能因地点或雇佣类型而异,但我们很自豪通过 #LifeAtD2L 为员工提供以下内容:
• 改变全球学习方式的有影响力的工作
• 灵活的工作安排
• 学习和成长机会
• 通过我们的 SkillsWave Program,为继续教育提供最高 $4,000 CAD 的学费报销
• 因 SkillsWave 相关活动(如考试或期末作业)可享受 2 天带薪休假
• 员工福祉(获得心理健康服务、EFAP 计划、财务规划等)
• 退休规划
• 2 天带薪志愿者假
• 有竞争力的福利套餐
• 家庭互联网报销
• 员工推荐计划
• 健康报销
• 员工表彰
• 社交活动
• 我们在 Kitchener、Winnipeg、Vancouver 和 Melbourne 办公室的办公空间允许携带宠物狗。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
D2L is a cloud company that is modernizing education and building the Future of Work. The old models of teaching and learning are in the midst of the largest transformation in history, and D2L is at the heart of that fundamental shift.
New models of teaching and learning enable a personalized, student-centric experience – and deliver improved retention, engagement, satisfaction, and results for learners of all ages – in schools, campuses, and companies.
D2L is disrupting the way the world learns, by providing the next generation learning environment and solutions to engage and inspire learners. And most importantly, by giving customers a platform that is easy, flexible, and smart. No other company provides a solution as robust and innovative as D2L.
D2L has had a singular mission for 25 years and is dedicated to that same mission in the years ahead: to transform the way the world learns – and by doing so, we will help improve human potential globally.
Every application we receive is personally reviewed by a member of our Talent Acquisition team - yes, a real person looks at your resume! While we use AI tools internally to streamline tasks like meeting notes, summaries, and administrative work, these tools never rank resumes, make hiring decisions, or influence candidate evaluations.
As Senior Application Security Analyst at D2L, you are a key influencer and contributor to the refinement and delivery of D2L's Application Security Program.
How will I make an Impact?
• Assist in refining and delivering D2L's Application Security Program with particular focus on endpoints, applications, and the underlying infrastructure.
• Perform regular security scans and coordinate with stakeholders to address open issues
• Collaborate with operational teams on existing and emerging security risks and provide subject matter expertise.
• Triage third-party assessments and follow up with stakeholders to address issues
• Monitor/track security risks and related artifacts throughout their lifecycle
• Support internal D2L teams during security assessments/reviews/audits
• Review independent third-party reports from vendors, suppliers and partners for alignment with D2L’s Application Security Program
What you’ll bring to the role:
Competencies:
• Ability to engage process owners and explain security controls associated with processes
• Ability to break down complex technical concepts to simple terms for various levels of stakeholders
• Ability to work independently
• Ability to learn fast and synthesize information from different domains and sources.
• Acumen with Artificial Intelligence tools
• Ability to work well with a wide cross-section of engineering and operational teams
Suggested Qualifications/Experience:
• You have practical programming experience and are proficient at reviewing code in a variety of languages
• You have previous hands-on experience implementing information security controls across a wide range of domains including Endpoint Security, Application Security, and Infrastructure Security. (SAST, DAST, SCA)
• You have hands-on experience with public cloud services like AWS or Azure etc.
• You have hands-on experience performing vulnerability assessments and penetration tests.
• You have demonstrable experience working with teams that have implemented security controls based on ISO 27001/NIST 800-53, PCI-DSS, PBMM
• You have experience using enterprise-grade governance risk and compliance (GRC) tools.
• You have experience assessing security control implementations on large enterprises, web scale and serverless environments.
• You have experience engaging stakeholders in remediating security-related findings
• You have experience supporting an audit exercise by generating security-related evidence
This position is to fill an existing vacancy
D2L operates in a hybrid work style, with expectation of 3 days per week in office.
The expected base salary range for a new hire in this role is listed below. The annualized base salary offered is determined by each candidate’s relevant knowledge, skills, education, training and experience. It is aligned to ensure both internal and external competitiveness using market data for the geographic location and industry. As part of the total compensation at D2L the role may be eligible for additional benefits including a Wellness Subsidy, Equity Grants, Variable Incentive, and more.
Base Salary Range $100,000 — $130,000 CAD
Don’t meet every single requirement? We strongly encourage you to still apply! At D2L, we are committed to creating a diverse and inclusive environment. We encourage your application even if you don't believe you meet every single qualification outlined, because we love to help our people grow and develop!
Why we're awesome:
At D2L, we are dedicated to providing you with the tools to do the best work of your life. While some of our perks and benefits may vary depending on location or employment type, we are proud to provide employees with the following through #LifeAtD2L :
• Impactful work transforming the way the world learns
• Flexible work arrangements
• Learning and Growth opportunities
• Tuition reimbursement of up to $4,000 CAD for continuing education through our SkillsWave Program
• 2 Paid Days off for SkillsWave-related activities like exams or final assignments
• Employee wellbeing (Access to mental health services, EFAP program, financial planning and more)
• Retirement planning
• 2 Paid Volunteer Days
• Competitive Benefits Package
• Home Internet Reimbursements
• Employee Referral Program
• Wellness Reimbursement
• Employee Recognition
• Social Events
• Dog Friendly Offices Spaces at our HQ in Kitchener, Winnipeg, Vancouver and Melbourne offices.