Security Analyst

Posted 15 Days Ago
Be an Early Applicant
2 Locations
Remote
73K-103K Annually
Mid level
Edtech • Software
The Role
As a Security Analyst at Xello, you will develop and implement policies for Governance, Risk, and Compliance (GRC) according to industry standards, perform risk assessments, support incident response efforts, and educate staff on security best practices. Your focus will be on maintaining compliance and managing security risks while fostering a strong security culture.
Summary Generated by Built In

Xello is looking for a Security Analyst
Who are you?

You are a dedicated security professional who thrives in environments where Governance, Risk, and Compliance (GRC) intersect with hands-on security operations. You excel at developing and implementing robust policies and procedures aligned with industry standards such as SOC2, ISO27001, and GDPR. Your proactive approach to risk assessment, incident response, and collaboration ensures that your organization remains compliant, resilient, and ahead of emerging threats.
You possess a strong understanding of regulatory requirements and privacy frameworks, and you stay current with industry best practices. You’re not just knowledgeable about compliance and security tools (SIEMs, IDS/IPS, vulnerability management platforms); you’re adept at using them to identify, assess, and mitigate risks. You’re skilled in creating actionable strategies for security awareness, educating your peers, and ensuring that everyone in the organization has the knowledge to uphold strong security practices.
With a proven track record in incident response, you are calm under pressure, methodical in analyzing threats, and decisive in implementing remediation plans. Your ability to work cross-functionally with IT, legal, and business units, coupled with your excellent communication skills, ensures that stakeholders are aligned on security and GRC goals.
Above all, you are committed to fostering a culture of security and compliance, viewing them not as checkboxes but as opportunities to strengthen the organization. Your work contributes to building trust with clients, external auditors, and regulators, ensuring the organization’s long-term success in a rapidly evolving digital landscape.
What you'll do ...
  • Governance, Risk, and Compliance (GRC)
    • Develop, implement, and maintain GRC policies, procedures, and controls aligned with regulatory requirements (SOC2, ISO27001, GDPR, CCPA, etc.).
    • Lead or assist with security and privacy audits, ensuring compliance with industry standards.
    • Perform risk assessments to identify, evaluate, and mitigate risks across the organization.
    • Work closely with various departments to ensure proper implementation of controls and to manage security risks.
    • Maintain and update the GRC management system to track compliance efforts, manage risks, and report progress to senior leadership.
    • Prepare and assist in security and privacy-related questionnaires and vendor risk assessments.
    • Stay up-to-date with regulatory changes and industry best practices to ensure the organization remains compliant.
  • Incident Response and Security Operations:
    • Support the security team in responding to security incidents, including investigation, containment, and remediation of incidents.
    • Monitor and analyze security events from various systems and tools (SIEM, IDS/IPS, firewalls) to detect suspicious activity.
    • Conduct post-incident analysis to determine root cause and implement preventive measures.
    • Develop and improve incident response playbooks and processes to ensure efficient and timely handling of security incidents.
    • Assist with vulnerability assessments and penetration testing efforts, working with internal and external teams to prioritize remediation.
  • Security Awareness and Education:
    • Develop and deliver training programs to educate staff on security and privacy best practices, including data protection and incident handling.
    • Conduct regular phishing simulations and social engineering tests to ensure employee readiness.
  • Documentation and Reporting:
    • Create and maintain accurate documentation for all GRC initiatives, incident response procedures, and remediation efforts.
    • Prepare detailed reports for senior management on the state of security, including compliance gaps, risk profiles, and incidents.
    • Provide clear and concise updates on ongoing risk assessments, audits, and security metrics.
  • Collaboration:
    • Work cross-functionally with IT, legal, and business units to ensure proper alignment on GRC and security measures.
    • Collaborate with external auditors, regulators, and clients to demonstrate compliance and resolve any findings.

What we're looking for ... 

  • Bachelor's degree in Information Security, Computer Science, or a related field (or equivalent experience).
  • 2-5 years of experience in a similar role, focusing on GRC, privacy, or security operations.
  • Experience with compliance frameworks such as SOC2, ISO27001, NIST, GDPR & CyberEssentials.
  • Familiarity with incident response processes, security controls, and risk management.
  • Hands-on experience with security tools and platforms, such as SIEM, vulnerability management tools, and compliance management software.
  • Certifications such as CISSP, CISA, CISM, or equivalent would be an asset.
  • Knowledge of data privacy regulations, including GDPR, CCPA, etc.
  • Strong analytical and problem-solving skills, with the ability to manage multiple tasks simultaneously.
  • Excellent communication skills, both written and verbal.

The compensation for this role offers a range from $72,805 - $103,305 CAD. The final offer will be determined based on the candidate's experience and expertise, as assessed during the interview process.

Top Skills

Ccpa
Compliance
Gdpr
Governance
Ids
Ips
Iso27001
Risk
SIEM
Soc2
Vulnerability Management
The Company
HQ: Toronto, Ontario
250 Employees
On-site Workplace
Year Founded: 1997

What We Do

Xello is the only online college and career readiness program that’s inclusive, engaging, and empowering for your entire district community.

Established in 1997, Xello is currently used by over 20,000 institutions across North America, including schools, employment agencies, libraries, colleges, and universities.

Xello’s mission is to help anyone, anywhere in the world create a successful future through self-knowledge, exploration, and planning. Started by three friends who sought a way to answer the “what’s the right path for me” question, our online software programs are used globally by millions of students, educators, and adults.

Xello is committed to continually updating and improving our products to better serve clients now and in the future. To this end, we invest heavily in research and development, we listen carefully to our clients'​ needs and expectations, and we seek out complementary partnerships and alliances to ensure Xello remains at the forefront of future readiness.

Similar Jobs

Coinbase Logo Coinbase

Security Analyst Lead Americas

Cloud • Fintech • Cryptocurrency • NFT • Web3
Remote
Canada
3700 Employees
212K-212K Annually

Affirm Logo Affirm

Analyst II, Full Stack

Big Data • Fintech • Mobile • Payments • Financial Services
Easy Apply
Remote
Canada
2200 Employees

Cash App Logo Cash App

Senior Data Scientist, Ad Sales

Blockchain • Fintech • Mobile • Payments • Software • Financial Services
Remote
Hybrid
8 Locations
3500 Employees
146K-258K Annually

Block Logo Block

Senior Machine Learning Engineer (Modeling), Personalization

Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
Remote
Hybrid
8 Locations
12000 Employees
139K-245K Annually

Similar Companies Hiring

Jobba Trade Technologies, Inc. Thumbnail
Software • Professional Services • Productivity • Information Technology • Cloud
Chicago, IL
45 Employees
RunPod Thumbnail
Software • Infrastructure as a Service (IaaS) • Cloud • Artificial Intelligence
Charlotte, North Carolina
53 Employees
Hedra Thumbnail
Software • News + Entertainment • Marketing Tech • Generative AI • Enterprise Web • Digital Media • Consumer Web
San Francisco, CA
14 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account