Security Analyst at Canopy Growth Corporation | CA | Rezi

Security Analyst at Canopy Growth Corporation

Security Analyst

Canopy Growth Corporation · CA

1 weeks ago

Security Analyst

Canopy Growth Corporation · CA

8 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Canopy Growth is seeking a highly motivated and technically proficient Security Analyst to join our Cybersecurity team. This role serves as the dedicated security operations function, monitoring threats, triaging alerts, investigating incidents, and coordinating response activities. You will play a critical role in ensuring our environment remains secure as the organization continues to grow.

Responsibilities

  • Own the end-to-end vulnerability management lifecycle using an enterprise vulnerability management platform — scanning, prioritization, tracking, and remediation coordination.
  • Configure and maintain scan engines, scan templates, asset groups, credentialed scanning, and scan schedules; troubleshoot authentication failures and missing assets.
  • Take ownership of retesting and validating remediation to confirm findings are genuinely resolved.
  • Track remediation against defined SLAs, manage risk exceptions, and report on vulnerability posture and trends.
  • Deploy and maintain scan sensors/engines across a distributed, multi-site environment.
  • Coordinate independent penetration tests, including scoping, vendor engagement, findings triage, and tracking remediation.
  • Perform internal security testing to validate that detection and response controls are performing as expected.
  • Apply CVSS scoring to assess and challenge vendor-assigned severity ratings.
  • Operate and administer our application security (SAST/SCA) scanning program, including onboarding repositories and managing review cadences.
  • Triage SAST and Software Composition Analysis (SCA) findings and work directly with developers to drive remediation.
  • Partner with development and cloud teams to embed secure practices into the software development lifecycle.
  • Research and recommend enhancements to vulnerability management, testing, and application security practices.
  • Support incident response readiness, including participation in tabletop exercises.
  • Maintain clear documentation and keep team tracking tools current.
  • Stay current with cybersecurity trends, tooling, vulnerabilities, and best practices.
  • Cross-train with cybersecurity team members to provide coverage during vacations, absences, and high-priority incidents.
  • Support team-wide initiatives, special projects, and process improvements.
  • Perform other duties as assigned to support the evolving needs of the cybersecurity program.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent practical experience).
  • 3+ years of hands-on experience in vulnerability management, security testing, or offensive security roles.
  • Hands-on experience with an enterprise vulnerability management platform, including scan engine configuration and credentialed scanning.
  • Working knowledge of application security testing concepts and tools (SAST/SCA) and the ability to communicate findings effectively with developers.
  • Solid understanding of the Common Vulnerability Scoring System (CVSS) and vulnerability assessment methodologies.
  • Familiarity with penetration testing concepts and experience coordinating or supporting third-party testing engagements.
  • Strong working knowledge of Linux and Windows operating systems, network protocols, and common security tools.
  • Familiarity with cybersecurity frameworks such as NIST 800-53, NIST CSF, or ISO 27001.
  • Strong problem-solving, documentation, and communication skills, with the ability to engage both technical and non-technical audiences.
  • Proven ability to manage multiple security priorities in a fast-paced, evolving environment.
  • Previous experience in an IT Operations/Infrastructure role would be an asset.
  • The chosen applicant will be required to successfully complete background and reference checks.

Skills

  • Vulnerability Management
  • Security Testing
  • Application Security
  • SAST
  • SCA
  • CVSS
  • Penetration Testing
  • Linux
  • Windows
  • Network Protocols
  • Security Tools
  • NIST 800-53
  • NIST CSF
  • ISO 27001
  • Problem-solving
  • Documentation
  • Communication

Location

  • Ontario

Work Type

  • Full-time
  • Remote-first

Experience Level

  • 3+ years of hands-on experience

Education Level

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent practical experience)

Salary/Compensations

  • $80,000 - $90,000

Benefits

  • Extended health and dental coverage
  • Paid vacation
  • Participation in our employer-supported retirement savings program

About the Company

  • At Canopy Growth, our mission is clear: improve lives, end cannabis prohibition, and strengthen communities. We believe that cannabis can be a force for good. We’re building a consumer-centric organization that is focused on sharing the transformational potential of cannabis with the world. We will achieve this through an innovative and disruptive portfolio of cannabis and hemp-derived products.
  • Canopy Growth is the world's leading cannabis and hemp company.
  • We recognize that employees are at the core of our success, and we take pride in a corporate culture that emphasizes inclusiveness, collaboration, and diversity.
  • Our employees come from a wide range of backgrounds, each bringing their own unique skills and talents to the table, working together to continue our incredible momentum of growth.
  • If you are interested in building global challenger brands, scaling a business, and working in a values-driven environment, we want to hear from you!

Equal Opportunity

  • We welcome and encourage applications from people with disabilities. Accommodations are available upon request for candidates taking part in all aspects of the selection process. If you require accommodation, please notify your Talent Acquisition Partner.