Talent.com
Canopy Growth
Security AnalystCanopy Growth • Toronto, ON
Security Analyst

Security Analyst

Canopy Growth • Toronto, ON
12 hours ago
Job type
  • Full-time
Job description

The Opportunity

Canopy Growth is seeking a highly motivated and technically proficient Security Analyst to join our Cybersecurity team. This is a unique opportunity for an individual passionate about cyber defense, threat detection, and incident response.

As a key member of our cybersecurity team, you will serve as the dedicated security operations function — monitoring threats, triaging alerts, investigating incidents, and coordinating response activities. You will work alongside our Managed Detection and Response (MDR) provider to complement external escalation with internal investigation, tuning, and cross-tool correlation. You will play a critical role in ensuring our environment remains secure as the organization continues to grow.

If you’re driven by curiosity, thrive under pressure, and want to make a direct impact on a growing cybersecurity program, this role offers the chance to contribute to Canopy Growth’s security posture at scale.

Responsibilities

Vulnerability Management

  • Own the end-to-end vulnerability management lifecycle using and enterprise vulnerability management platform — scanning, prioritization, tracking, and remediation coordination across servers, endpoints, network assets, and public-facing systems.

  • Configure and maintain scan engines, scan templates, asset groups, credentialed scanning, and scan schedules; troubleshoot authentication failures and missing assets to ensure reliable, complete coverage.

  • Take ownership of retesting and validating remediation to confirm findings are genuinely resolved rather than simply closed out.

  • Track remediation against defined SLAs, manage risk exceptions, and report on vulnerability posture and trends to technical and executive stakeholders.

  • Deploy and maintain scan sensors/engines across a distributed, multi-site environment.

Security Testing

  • Coordinate independent penetration tests, including scoping, vendor engagement, findings triage, and tracking remediation to closure.

  • Perform internal security testing to validate that detection and response controls (e.g., our vulnerability management, endpoint detection, and application security tooling) are performing as expected.

  • Apply CVSS scoring to assess and, where warranted, challenge vendor-assigned severity ratings, ensuring risk is measured consistently and accurately.

  • Help move the program from theoretical risk discussions toward evidence-based assurance through controlled, repeatable testing.

Application Security

  • Operate and administer our application security (SAST/SCA) scanning program, including onboarding repositories and managing review cadences with development teams.

  • Triage SAST and Software Composition Analysis (SCA) findings, distinguish true positives from noise, and work directly with developers to drive remediation of code and open-source library risks.

  • Partner with development and cloud teams to embed secure practices into the software development lifecycle.

Continuous Improvement & Collaboration

  • Research and recommend enhancements to vulnerability management, testing, and application security practices.

  • Support incident response readiness, including participation in tabletop exercises.

  • Maintain clear documentation and keep team tracking tools current as work progresses.

  • Stay current with cybersecurity trends, tooling, vulnerabilities, and best practices.

Other Responsibilities

  • Cross-train with cybersecurity team members to provide coverage during vacations, absences, and high-priority incidents.

  • Support team-wide initiatives, special projects, and process improvements as assigned.

  • Perform other duties as assigned to support the evolving needs of the cybersecurity program.

Experience

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent practical experience).

  • 3+ years of hands-on experience in vulnerability management, security testing, or offensive security roles.

  • Hands-on experience with an enterprise vulnerability management platform, including scan engine configuration and credentialed scanning.

  • Working knowledge of application security testing concepts and tools (SAST/SCA) and the ability to communicate findings effectively with developers.

  • Solid understanding of the Common Vulnerability Scoring System (CVSS) and vulnerability assessment methodologies.

  • Familiarity with penetration testing concepts and experience coordinating or supporting third-party testing engagements.

  • Strong working knowledge of Linux and Windows operating systems, network protocols, and common security tools.

  • Familiarity with cybersecurity frameworks such as NIST 800-53, NIST CSF, or ISO 27001.

  • Preferred certifications include OSCP, GIAC GPEN/GWAPT, CEH, CompTIA PenTest+, CySA+.

  • Strong problem-solving, documentation, and communication skills, with the ability to engage both technical and non-technical audiences.

  • Proven ability to manage multiple security priorities in a fast-paced, evolving environment.

  • Previous experience in an IT Operations/Infrastructure role would be an asset

Create a job alert for this search

Security Analyst • Toronto, ON

Similar jobs

Security Analyst

Obsidiantoronto, on, Canada
Full-time

Mercor is partnering with leading AI labs to engage experienced cybersecurity professionals — security analysts, penetration testers, incident responders, threat intelligence specialists, and secur... Show more

 • Promoted

Experienced Info Security Analyst Position

Haventree Banktoronto, on, Canada
Full-time

Elevate your career as a Senior Information Security Analyst at Haventree Bank, where your skills will directly enhance our security practices.This role combines technical execution with strategic ... Show more

 • Promoted

IT Security Analyst

ERCO WorldwideToronto, ON, CA
Permanent

Satellite Drive, Mississauga (Hybrid).ERCO Worldwide’s century‑long tradition of excellence has firmly established its reputation for providing reliable, intelligent, and environmentally responsibl... Show more

 • Promoted

Security Analyst, Lawful Acces

Rogers CommunicationsToronto, ON, CA
Full-time

We are committed to connecting Canadians through unique partnerships, our world-class network and content Canadians love—and our innovative team is growing.We are looking for dedicated team members... Show more

 • Promoted

Cloud Security and Compliance Analyst

ScotiabankToronto, ON, CA
Full-time

Enhance Cloud security measures as a Senior Information Security Analyst.Leverage strong technical expertise to ensure compliance with security protocols and optimize user experiences.This pivotal ... Show more

 • Promoted

Cyber Security Analyst

Lorex TechnologyMarkham, ON, CA
Full-time

For 34 years, Lorex has been creating security systems designed to protect your home and business.Founded and headquartered in Canada, we’ve grown to become leaders in DIY (Do It Yourself) security... Show more

 • Promoted

Security Analyst

York UniversityToronto
Full-time +1

The Security Analyst contributes to the mission of the University by supporting the delivery of information security program.This includes security investigations, assessments, monitoring and incid... Show more

 • Promoted

Governance Risk and Compliance Security Analyst

Scarborough Health NetworkToronto, ON, CA
Full-time +1

Governance Risk and Compliance Security AnalystApplylocations: Centenary Hospitaltime type: Full timeposted on: Posted Todayjob requisition id: JR106133Job Number: JR106133Job Title: Govern... Show more

 • Promoted

Senior Fund Data Analyst, Security Master and Pricing

CI FinancialToronto, ON, CA
Full-time

We are currently seeking a Senior Fund Data Analyst to join our Portfolio Operations team.In this role, the successful candidate is expected to support Data for CI’s order management and investment... Show more

 • Promoted

Senior Security Analyst

MindlanceToronto
Full-time

Global Cyber Security team, providing deep technical expertise and advisory support across endpoint and threat surface security platforms.This role focuses on maintaining and strengthening enterpri... Show more

 • Promoted

Equitable Bank Senior Analyst in Cyber Security

EQ BankToronto, ON, CA
Full-time

Advance your career as a Senior Analyst in Cyber Security at Equitable Bank, where innovation meets security in a hybrid work environment.You'll manage and assess cyber threats to enhance resilient... Show more

 • Promoted

Information Security Analyst

BDO CanadaToronto, ON, CA
Full-time

BDO is a firm built on a foundation of positive relationships with our people and clients.Reporting to the Manager, Information Security, the Information Security Analyst supports security operatio... Show more

 • Promoted

Senior AI Security & Governance Analyst

Compunnel, Inc.Toronto
Full-time

A leading technology firm in Toronto is seeking a seasoned Security Analyst III to join their Information Risk team.This role focuses on conducting comprehensive risk assessments and designing gove... Show more

 • Promoted

Security Analyst - Part Time

Equifax, Inc.Toronto, ON, CA
Part-time

As our IT Security Analyst, this role requires a motivated self-starter.Someone who has strong analytical and problem-solving skills, a deep understanding of risk and compliance management principl... Show more

 • Promoted

Akamai API Security or NoName API Security Analyst

Net2Source Inc.Toronto
Full-time

Akamai API Security or NoName API Security Analyst.This position is offered by Net2Source Inc.Your actual pay will depend on your skills and experience — please consult with your recruiter for more... Show more

 • Promoted

Senior Analyst, Security Compliance

P2PToronto, ON, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Security Analyst - Security & Governance Compliance

TVET CollegeRichmond Hill, York Region, CA
Full-time

Security Analyst - Security & Governance Compliance.The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance progra... Show more

 • Promoted

Workday Security Analyst

neteffectsToronto, ON, CA
Full-time

Remote from the UK - to work for an International US-based company.Workday security area – focusing on Workday HR user, domain, business process, and integrations security, privacy, audit, controls... Show more

 • Promoted

Security Analyst - Security & Governance Compliance

Staples CanadaRichmond Hill
Full-time

Some of what you will do: The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance program and broader cybersecurit... Show more

 • Promoted

Remote Information Risk & Security Analyst

DexianToronto, ON, CA
Remote
Full-time

A leading IT services firm is seeking an Information Control Testing Specialist to manage information risk and ensure compliance with security policies.You will work on global initiatives, conduct ... Show more