Senior Security Operations Engineer
Job Description
<p>The Canonical Security Operations team is hiring for a Senior or Staff engineer. The Security Operations team is responsible for designing, building, and operating a world-class Security Operations Center, and the successful candidate will provide leadership, mentorship, expertise, and outstanding individual contributions towards those ends.</p> <p>This role involves aspects of:</p> <ul> <li>Traditional SOC duties - security monitoring, threat hunting, and response.</li> <li>Security engineering - assessing and protecting Canonical platforms and products.</li> <li>Software engineering - building custom tools and platforms.</li> <li>Site reliability engineering - deploying, maintaining, and automating security tools.</li> </ul> <p>We are looking for individuals with engineering and security experience, as well as a history of remarkable achievement. Senior security operations personnel with engineering experience and senior developers with security experience are equally well-suited to this role.</p> <p>Beyond securing Canonical’s digital estate, this position represents a unique opportunity to contribute to the open source ecosystem. Team members may present at industry conferences, share threat intelligence with the wider community, or publish open source security software.</p> <p><em>Junior positions are also available for less-experienced individuals with a compelling academic or professional background.</em></p> <h2><strong>In this role, you will:</strong></h2> <ul> <li>Provide operational and engineering leadership.</li> <li>Implement and evolve Canonical’s Security Operations Center.</li> <li>Design and develop security software and platforms.</li> <li>Monitor for, identify, respond to, and remediate security incidents.</li> <li>Assess and improve Canonical’s security controls.</li> <li>Mentor early-career Security Operations engineers.</li> <li>Plan and deliver work within Canonical's agile engineering framework.</li> <li>Contribute to open source security.</li> <li>Publish blog posts, whitepapers and conference presentations.</li> </ul> <h2><strong>We are looking for:</strong></h2> <ul> <li>An exceptional academic track record.</li> <li>Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path.</li> <li>10+ years of relevant professional experience</li> <li>Professional cybersecurity experience, preferably working or leading a Security Operations Center.</li> <li>Professional engineering experience.</li> <li>An eagerness to contribute to open source security.</li> <li>Proficiency in common scripting languages, such as Python and Bash.</li> <li>Knowledge of Git, GitOps, Infrastructure-as-Code, and common orchestration platforms (e.g., Kubernetes)</li> </ul> <h2><strong>Though optional, we value:</strong></h2> <ul> <li>Familiarity with security frameworks such as the NIST CSF, CIS CSC, and ISO 27001</li> <li>Knowledge of security architecture and market-leading security tools.</li> <li>Experience in a security operations team or a security operations center.</li> <li>Experience in offensive or defensive security teams with hands-on ability.</li> <li>Experience with advanced persistent threats.</li> <li>Proficiency in additional programming languages, such as Golang.</li> </ul> <h2><strong>What we offer you:</strong></h2> <p>We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compen