{"id":1140613,"url":"https://alion.io/job/apollocannabis-security-analyst","title":"Security Analyst","company":{"id":1068421,"name":"ApolloCannabis","domain":"apollocannabis.ca","url":"https://alion.io/company/apollocannabis","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Ottawa, Canada","Toronto, Canada"],"countries":["CA"],"hiring_countries":["CA"],"hiring_countries_total":1,"salary":{"min":80000,"max":90000,"currency":"USD","period":"year","gross":null,"usd_annual":90000},"salary_estimate":null,"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CVSS","optional":false},{"name":"ISO 27001","optional":false},{"name":"NIST 800-53","optional":false},{"name":"NIST CSF","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-08-21T00:00:00Z","employer_posted_date":"2026-08-21","last_verified_at":"2026-10-01T07:32:52Z","board_verified":true,"closed_at":null,"days_open":42,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":42},"description":"The Company\nAt Canopy Growth, our mission is clear: improve lives, end cannabis prohibition, and strengthen communities. We believe that cannabis can be a force for good. We’re building a consumer-centric organization that is focused on sharing the transformational potential of cannabis with the world. We will achieve this through an innovative and disruptive portfolio of cannabis and hemp-derived products.\nCanopy Growth is the world's leading cannabis and hemp company. We recognize that employees are at the core of our success, and we take pride in a corporate culture that emphasizes inclusiveness, collaboration, and diversity.\nOur employees come from a wide range of backgrounds, each bringing their own unique skills and talents to the table, working together to continue our incredible momentum of growth. If you are interested in building global challenger brands, scaling a business, and working in a values-driven environment, we want to hear from you!\nThe Opportunity\nCanopy Growth is seeking a highly motivated and technically proficient Security Analyst to join our Cybersecurity team. This is a unique opportunity for an individual passionate about cyber defense, threat detection, and incident response.\nAs a key member of our cybersecurity team, you will serve as the dedicated security operations function - monitoring threats, triaging alerts, investigating incidents, and coordinating response activities. You will work alongside our Managed Detection and Response (MDR) provider to complement external escalation with internal investigation, tuning, and cross-tool correlation. You will play a critical role in ensuring our environment remains secure as the organization continues to grow.\nIf you’re driven by curiosity, thrive under pressure, and want to make a direct impact on a growing cybersecurity program, this role offers the chance to contribute to Canopy Growth’s security posture at scale.\nResponsibilities\nVulnerability Management\nOwn the end-to-end vulnerability management lifecycle using and enterprise vulnerability management platform - scanning, prioritization, tracking, and remediation coordination across servers, endpoints, network assets, and public-facing systems.\n\nConfigure and maintain scan engines, scan templates, asset groups, credentialed scanning, and scan schedules; troubleshoot authentication failures and missing assets to ensure reliable, complete coverage.\n\nTake ownership of retesting and validating remediation to confirm findings are genuinely resolved rather than simply closed out.\n\nTrack remediation against defined SLAs, manage risk exceptions, and report on vulnerability posture and trends to technical and executive stakeholders.\n\nDeploy and maintain scan sensors/engines across a distributed, multi-site environment.\n\nSecurity Testing\nCoordinate independent penetration tests, including scoping, vendor engagement, findings triage, and tracking remediation to closure.\n\nPerform internal security testing to validate that detection and response controls (e.g., our vulnerability management, endpoint detection, and application security tooling) are performing as expected.\n\nApply CVSS scoring to assess and, where warranted, challenge vendor-assigned severity ratings, ensuring risk is measured consistently and accurately.\n\nHelp move the program from theoretical risk discussions toward evidence-based assurance through controlled, repeatable testing.\n\nApplication Security\nOperate and administer our application security (SAST/SCA) scanning program, including onboarding repositories and managing review cadences with development teams.\n\nTriage SAST and Software Composition Analysis (SCA) findings, distinguish true positives from noise, and work directly with developers to drive remediation of code and open-source library risks.\n\nPartner with development and cloud teams to embed secure practices into the software development lifecycle.\n\nContinuous Improvement & Collaboration\nResearch and recommend enhancements to vulnerability management, testing, and application security practices.\n\nSupport incident response readiness, including participation in tabletop exercises.\n\nMaintain clear documentation and keep team tracking tools current as work progresses.\n\nStay current with cybersecurity trends, tooling, vulnerabilities, and best practices.\n\nOther Responsibilities\nCross-train with cybersecurity team members to provide coverage during vacations, absences, and high-priority incidents.\n\nSupport team-wide initiatives, special projects, and process improvements as assigned.\n\nPerform other duties as assigned to support the evolving needs of the cybersecurity program.\n\nExperience\nBachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent practical experience).\n\n3+ years of hands-on experience in vulnerability management, security testing, or offensive security roles.\n\nHands-on experience with an enterprise vulnerability management platform, including scan engine configuration and credentialed scanning.\n\nWorking knowledge of application security testing concepts and tools (SAST/SCA) and the ability to communicate findings effectively with developers.\n\nSolid understanding of the Common Vulnerability Scoring System (CVSS) and vulnerability assessment methodologies.\n\nFamiliarity with penetration testing concepts and experience coordinating or supporting third-party testing engagements.\n\nStrong working knowledge of Linux and Windows operating systems, network protocols, and common security tools.\n\nFamiliarity with cybersecurity frameworks such as NIST 800-53, NIST CSF, or ISO 27001.\n\nPreferred certifications include OSCP, GIAC GPEN/GWAPT, CEH, CompTIA PenTest+, CySA+.\n\nStrong problem-solving, documentation, and communication skills, with the ability to engage both technical and non-technical audiences.\n\nProven ability to manage multiple security priorities in a fast-paced, evolving environment.\n\nPrevious experience in an IT Operations/Infrastructure role would be an asset\n\nOther Details\nThis is a full-time, remote-first position based out of Ontario.\nSalary Range: $80,000 - $90,000\nBenefits - extended health and dental coverage, paid vacation, and participation in our employer-supported retirement savings program\nWe appreciate your interest, and promise to review all applications, but we will only be contacting those who best fit the requirements.\nWe welcome and encourage applications from people with disabilities. Accommodations are available upon request for candidates taking part in all aspects of the selection process. If you require accommodation, please notify your Talent Acquisition Partner. Please note, the chosen applicant will be required to successfully complete background and reference checks.\nRecruitment Process: All applications for this role are reviewed manually; no AI-based screening or ranking tools are used.\nThis post is for an existing vacancy.","description_format":"text","description_chars":6936,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Canada","iso":"CA","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Telemedicine & Virtual Care","Cannabis & CBD","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-23T10:58:22Z"}],"liveness":{"score":43,"band":"fade","label":"Fading","p_open":1,"p_active":0.788,"p_room":0.55,"age_days":41,"expected_fill_days":34,"reasons":["conf:18","win:tail"],"computed_at":"2026-10-01T05:45:00Z"},"pay":{"stated_usd_annual":90000,"is_top_pay":false},"html_url":"https://alion.io/job/apollocannabis-security-analyst","json_url":"https://alion.io/job/apollocannabis-security-analyst.json","meta":{"generated_at":"2026-10-02T00:15:08Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":80,"day_limit":5000,"remaining_today":4920,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}