Anyone, anywhere in the world can apply.
Canonical recruits globally for this fully remote role with compensation adjusted worldwide and no regional or timezone restrictions.
Applies on the original listing · via Jobicy
Who can apply
Read straight from the listing, so you know before you spend time on it.
Anyone, anywhere in the world can apply.
Canonical recruits globally for this fully remote role with compensation adjusted worldwide and no regional or timezone restrictions.
Globally distributed team working remotely across worldwide locations.
- Async-first
- The listing doesn't promise async-first working.
- Contractor / B2B
- No mention of hiring international contractors or invoicing.
- Global stipend
- USD 2,000 annual personal learning and development budget.
- Annual retreat
- Twice-yearly in-person team sprints with travel upgrades for long-haul events.
Read from the listing automatically. Always confirm the details with the company before you accept an offer.
About the role
As a Security Risk Management Specialist, you will help establish and execute a broad strategic vision for Canonical's security risk program. You will combine industry best practices with emerging threat intelligence to lead risk identification, quantification (using frameworks like FAIR), impact analysis, and modeling. In addition to securing Canonical's internal and product environments, you will collaborate across teams to develop playbooks, facilitate training, and contribute to the broader open-source security ecosystem.
What you'll do
- Define Canonical's security risk management standards, playbooks, and templates for self-service risk actions
- Evaluate, select, and implement new security requirements, tools, and practices across the organization
- Apply statistical models to risk frameworks (such as FAIR and sensitivity analysis) and lead quantified risk assessments
- Interpret internal and external cyber security risk analyses into business terms and recommend responsible mitigation paths
- Develop security risk learning and development materials in collaboration with organizational training teams
- Establish key risk indicators (KRIs) and performance metrics to evaluate the efficiency of security capabilities
What you bring
- Undergraduate degree in Computer Science, STEM, or a compelling narrative about your alternative path
- Demonstrated expertise in threat modelling and risk management frameworks
- Broad operational knowledge of security risk management and Secure Development Lifecycle (SDLC) / Security by Design methodologies
- Deep technical understanding of security assessments and risk quantification
- Exceptional problem-solving, communication, and business English writing/presentation skills
- Strong leadership, management ability, and track record of exceeding expectations
About Canonical
Canonical is the pioneering tech firm behind Ubuntu, one of the world's most significant open source platforms powering cloud, IoT, and AI. A remote-first company since 2004, Canonical recruits globally to drive innovation across open source technology.
View Canonical profile & open roles →