Security Analyst

5 days ago

Edmonton AB, Edmonton Census Division, AB; Alberta, Canada MTL Cannabis Corp Full-time €80,000 - €90,000
The CompanyAt Canopy Growth, our mission is clear: improve lives, end cannabis prohibition, and strengthen communities. We believe that cannabis can be a force for good. We’re building a consumer-centric organization that is focused on sharing the transformational potential of cannabis with the world. We will achieve this through an innovative and disruptive portfolio of cannabis and hemp-derived products.
Canopy Growth is the world's leading cannabis and hemp company. We recognize that employees are at the core of our success, and we take pride in a corporate culture that emphasizes inclusiveness, collaboration, and diversity.
If you are interested in building global challenger brands, scaling a business, and working in a values-driven environment, we want to hear from you
The OpportunityCanopy Growth is seeking a highly motivated and technically proficient Security Analyst to join our Cybersecurity team. As a key member of our cybersecurity team, you will serve as the dedicated security operations function — monitoring threats, triaging alerts, investigating incidents, and coordinating response activities. If you’re driven by curiosity, thrive under pressure, and want to make a direct impact on a growing cybersecurity program, this role offers the chance to contribute to Canopy Growth’s security posture at scale.Responsibilities**Vulnerability Management* Own the end-to-end vulnerability management lifecycle using and enterprise vulnerability management platform — scanning, prioritization, tracking, and remediation coordination across servers, endpoints, network assets, and public-facing systems.
* Configure and maintain scan engines, scan templates, asset groups, credentialed scanning, and scan schedules; troubleshoot authentication failures and missing assets to ensure reliable, complete coverage.
* Track remediation against defined SLAs, manage risk exceptions, and report on vulnerability posture and trends to technical and executive stakeholders.
* Deploy and maintain scan sensors/engines across a distributed, multi-site environment.Security Testing* Coordinate independent penetration tests, including scoping, vendor engagement, findings triage, and tracking remediation to closure.
* Perform internal security testing to validate that detection and response controls (e.g., our vulnerability management, endpoint detection, and application security tooling) are performing as expected.
* Apply CVSS scoring to assess and, where warranted, challenge vendor-assigned severity ratings, ensuring risk is measured consistently and accurately.
* Help move the program from theoretical risk discussions toward evidence-based assurance through controlled, repeatable testing.Application Security* Operate and administer our application security (SAST/SCA) scanning program, including onboarding repositories and managing review cadences with development teams.
* Triage SAST and Software Composition Analysis (SCA) findings, distinguish true positives from noise, and work directly with developers to drive remediation of code and open-source library risks.
* Partner with development and cloud teams to embed secure practices into the software development lifecycle.Continuous Improvement & Collaboration* Research and recommend enhancements to vulnerability management, testing, and application security practices.
* Other Responsibilities* Cross-train with cybersecurity team members to provide coverage during vacations, absences, and high-priority incidents.
* Support team-wide initiatives, special projects, and process improvements as assigned.
* Experience
* Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent practical experience).
* 3+ years of hands-on experience in vulnerability management, security testing, or offensive security roles.
* Working knowledge of application security testing concepts and tools (SAST/SCA) and the ability to communicate findings effectively with developers.
* Solid understanding of the Common Vulnerability Scoring System (CVSS) and vulnerability assessment methodologies.
* Familiarity with penetration testing concepts and experience coordinating or supporting third-party testing engagements.
* Strong working knowledge of Linux and Windows operating systems, network protocols, and common security tools.
* Strong problem-solving, documentation, and communication skills, with the ability to engage both technical and non-technical audiences.
* Proven ability to manage multiple security priorities in a fast-paced, evolving environment.
* Previous experience in an IT Operations/Infrastructure role would be an assetOther DetailsThis is a full-time, remote-first position based out of Ontario.
Salary Range: $80,000
- $90,000Benefits
- extended health and dental coverage, paid vacation, and participation in our employer-supported retirement savings programWe appreciate your interest, and promise to review all applications, but we will onl