Job Overview
The Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, focusing on cyber threat actors targeting Canonical. You will use TTP intelligence to improve products and internal cybersecurity controls, collaborate with internal stakeholders, and help position Canonical as a thought leader on open‑source threat intelligence.
Responsibilities
- Build and own Canonical's threat intelligence strategy.
- Build and maintain OSINT research environments.
- Develop OSINT tradecraft, principles, and techniques.
- Identify and track targeted intrusion cyber threats, trends, and new developments through analysis of proprietary and open‑source datasets.
- Collaborate across teams to inform on activities of interest.
- Coordinate adversary and campaign tracking.
- Contribute to the wider threat intelligence community, establishing Canonical as a key contributor and thought leader.
- Work with product and engineering teams to explain cybersecurity threats and advise on mitigation strategies.
- Work with the OPSEC and IS team to implement or update security controls prioritizing cyber defence.
- Identify intelligence gaps and propose new tools and research projects.
- Conduct briefings for executives, internal stakeholders, and external customers.
Qualifications
Experienced threat intelligence leader (or equivalent).Knowledgeable about the current open‑source threat landscape and computer networking / infrastructure concepts.Highly competent with OSINT tools (e.g., Buscador, Trace Labs OSINT VM, OSINT Framework, Maltego, Shodan, social media scraping tools).Able to identify, organise, catalogue, and track adversary tradecraft trends—often with incomplete data.Experienced using threat intelligence data to influence enterprise architecture or product development decisions.Excellent communicator with the ability to tailor technical content to a variety of audiences.Able to travel twice a year for company events up to two weeks long.Desired Characteristics
Professional portfolio of OSINT related scripts, tools, or frameworks.Demonstrated involvement in the larger OSINT community (please share relevant links).Bachelor's degree in computer science, information security, or a related field.Certifications in related areas (e.g., GOSI, SANS SEC487 & SEC587, IntelTechniques OSIP).Experience in a tech company or government / military signal intelligence department.What we offer you
Distributed work environment with twice‑yearly team sprints in person.Personal learning and development budget of USD 2,000 per year.Annual compensation review.Recognition rewards.Annual holiday leave.Maternity and paternity leave.Employee Assistance Programme.Opportunity to travel to new locations to meet colleagues.Priority Pass and travel upgrades for long‑haul company events.About Canonical
Canonical is a pioneering tech firm at the forefront of the open‑source movement. As the publisher of Ubuntu—the platform for AI, IoT, and the cloud—Canonical changes the world every day. We recruit on an integral basis, set high standards for people joining the company, and aim for excellence. Canonical is a remote‑first company and values forward‑thinking, smart work, and continuous learning.
Canonical is an equal‑opportunity employer. We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background creates a better work environment and better products. Whatever your identity, we will give your application fair consideration.
#J-18808-Ljbffr