Canonical
Threat Intelligence Lead
Employer explicitly allows international or location-independent remote work.
Worldwide
Employer listed it 7 weeks ago · Added 5 days ago
Been open since 7 weeks ago. Long-running listings are sometimes left up after the role is filled.
Salary
Not stated
Location
Worldwide
Timezone
Not stated
Contract
Full-time
Experience
Lead
Category
Operations
This employer didn't state pay. Jobs like this usually pay around $160k–$250k a year, a typical range taken from 145 lead-level operations roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from anywhere
The employer explicitly allows candidates to work from anywhere in the world, with no stated country restriction.
What the employer says
- Source listing states candidate location: "Home based - Worldwide"
What Nomaders makes of it
- Listing location explicitly says anywhere/worldwide, with no country requirement
- Check timezone expectations before applying
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
The Threat Intelligence Lead will own Canonical’s threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and Procedures (TTP) to better our products and internal cybersecurity controls. You will collaborate with internal stakeholders as well as with the wider cybersecurity community, making sure that Canonical is recognised as a thought leader on open source threat intelligence.
This role will report to the CISO.
You will lead intelligence gathering and development activities on threat actors targeting software supply chains. You'll study attack trends across the wider open source software landscape, report findings to internal security teams, and advise the wider engineering community on the best course of action to detect and mitigate possible threats.
As the publisher of Ubuntu, Canonical products are directly or indirectly present in almost every organisation and household in the world, making them a prime target for threat actors. This team's mission is to help Canonical, and by extension countless community members and companies around the world, secure their software infrastructure.
What you’ll do in this role
Build and own Canonical’s threat intelligence strategy
Build and maintain OSINT research environments
Develop OSINT tradecraft, principals, and techniques
Identify and track targeted intrusion cyber threats, trends, and new developments by cyber threat actors through analysis of proprietary and open source datasets
Collaborate across teams to inform on activity of interest
Coordinate adversary/campaign tracking
Contribute to the wider threat intelligence community, establishing Canonical as a key contributor and thought leader in the space
Work with product and engineering teams to explain cybersecurity threats and advise on mitigation strategies
Work with the OPSEC and IS team to help implement/update security controls prioritising cyber defence
Identify intelligence gaps and propose new tools and research projects to fill them
Conduct briefings for executives, internal stakeholders and external customers
The successful Threat Intelligence Lead will be
An experienced threat intelligence leader (or similar)
Knowledgeable about the current open source threat landscape and computer networking/infrastructure concepts
Highly competent with OSINT tools (e.g., Buscador, Trace Labs OSINT VM, OSINT Framework, Maltego, Shodan, social media scraping tools, etc.)
Able to identify, organise, catalogue, and track adversary tradecraft trends — often with incomplete data
Experienced using threat intelligence data to influence enterprise architecture or product development decisions
An excellent communicator with the ability to clearly articulate and tailor technical content to a variety of audiences
Able to travel twice a year, for company events up to two weeks long
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- ·Distributed work environment with twice-yearly team sprints in person
- ·Personal learning and development budget of USD 2,000 per year
- ·Annual compensation review
- ·Recognition rewards
- ·Annual holiday leave
How to apply
- 1Check the flexibility label above, work from anywhere, matches where you plan to live and work.
- 2Tailor your CV to the role at Canonical, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open operations roles with comparable remote rules.
Free to apply, no account needed.
Typically $160k to $250k per year · You'll be taken to the employer's careers page.