D2L, founded in 1999 and headquartered in Kitchener, Ontario, builds and operates Brightspace, a learning management system deployed across K-12, higher ed, government, and enterprise environments. The attack surface is non-trivial: Brightspace serves over 1,400 customers globally, handling sensitive student data, research IP, and compliance-bound records for institutions and corporations alike. The threat model spans credential stuffing, API exploitation, data exfiltration, and supply-chain risk across a cloud-delivered platform at scale.
The security team operates across application security, infrastructure hardening, and identity management, with AI integration adding both capability and new risk vectors - D2L is actively investing in AI-driven features while maintaining that the technology should empower rather than replace human decision-making. With more than 1,000 employees worldwide and 25+ years of continuous operation, the company has matured past startup-stage chaos but still contends with the operational complexity of a platform serving diverse regulatory environments, from FERPA-compliant U.S. school districts to global government deployments.
Roles here involve defending a system where a breach doesn't just mean financial exposure - it means compromising the educational pathways of millions of learners. The work is platform security at the intersection of edtech and AI, with the added weight of public trust baked into every architectural decision.






