Skip to main content
Canonical
Canonical

Threat Intelligence Lead

RemoteWorldwide
Published
Role
Security
Experience
Lead
Salary not disclosed
Check eligibility

Open to Worldwide. Set where you work from to check your eligibility.

No BS summary

Threat intelligence lead for Canonical, focused on OSINT, threat actors targeting software supply chains, and open source threat landscape. Must be experienced in threat intelligence, OSINT tools, and using intelligence to influence enterprise architecture or product decisions. Home based worldwide, with travel twice a year for company events.

Core skills

OSINTThreat Intelligence

Required skills

BuscadorTrace Labs OSINT VMOSINT FrameworkMaltegoShodansocial media scraping toolsComputer networking

What you'll do

  • Build and own Canonical’s threat intelligence strategy
  • Build and maintain OSINT research environments
  • Develop OSINT tradecraft, principals, and techniques
  • Identify and track targeted intrusion cyber threats, trends, and new developments by cyber threat actors through analysis of proprietary and open source datasets
  • Collaborate across teams to inform on activity of interest
  • Coordinate adversary/campaign tracking
  • Contribute to the wider threat intelligence community, establishing Canonical as a key contributor and thought leader in the space
  • Work with product and engineering teams to explain cybersecurity threats and advise on mitigation strategies
  • Work with the OPSEC and IS team to help implement/update security controls prioritising cyber defence
  • Identify intelligence gaps and propose new tools and research projects to fill them
  • Conduct briefings for executives, internal stakeholders and external customers

What they require

  • An experienced threat intelligence leader (or similar)
  • Knowledgeable about the current open source threat landscape and computer networking/infrastructure concepts
  • Highly competent with OSINT tools (e.g., Buscador, Trace Labs OSINT VM, OSINT Framework, Maltego, Shodan, social media scraping tools, etc.)
  • Able to identify, organise, catalogue, and track adversary tradecraft trends — often with incomplete data
  • Experienced using threat intelligence data to influence enterprise architecture or product development decisions
  • An excellent communicator with the ability to clearly articulate and tailor technical content to a variety of audiences
  • Able to travel twice a year, for company events up to two weeks long
  • Preferred: A professional portfolio of OSINT related scripts, tools, or frameworks
  • Preferred: Demonstrated involvement in the larger OSINT community (please share relevant links)
  • Preferred: Degree qualified, with a bachelor's degree in computer science, information security, or a related field
  • Preferred: Certifications in related areas (e.g. GOSI, SANS SEC487 & SEC587, IntelTechniques OSIP, etc)
  • Preferred: Experience in a tech company or government/military signal intelligence departments

Benefits

  • Distributed work environment with twice-yearly team sprints in person
  • Personal learning and development budget of USD 2,000 per year
  • Annual compensation review
  • Recognition rewards
  • Annual holiday leave
  • Maternity and paternity leave
  • Employee Assistance Programme
  • Opportunity to travel to new locations to meet colleagues
  • Priority Pass, and travel upgrades for long haul company events
  • Performance-driven annual bonus

London-based software company, developer of Ubuntu

Open Source SoftwareEnterprisecanonical.com/

What people say about this company

3.6/ 5

  • Employees appreciate the company's commitment to open-source software and its impact on the tech community.
  • Many enjoy the flexibility of remote work and the work-life balance offered.
  • Some reviews mention a lack of clear career progression and development opportunities.
Salary not disclosed