See more Collapse

Head of Security Operations

2 months ago


San Diego, California, United States Canonical Full time


This global leadership role in cyber security is to manage the Security Operations (SecOps) team responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies.

The team is the primary owner of strategy and practices that determine how Canonical secures its data, internal infrastructure and build processes.

They are responsible for assuring the security and integrity of our own infrastructure and product deployments. They design and implement technical security controls that ensure security threats are automatically identified, contained and remediated.

The team will also contribute ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attack.

As a leader on cyber security in the company, the SecOps team manager will collaborate with our Organisational Learning and Development team to develop playbooks and facilitate SecOps training across Canonical.

They will operate in a wider security organisation, run a high performing security team and improve Canonical's security posture. They will lead initiatives to integrate the team's insights into Canonical's broader software development process.

While this is a management position, we expect managers to be expert practitioners, able to lead by example, contribute at the highest level, and assess work based on their own professional experience and skill.

Candidates should have deep, hands-on expertise with a range of open source and proprietary security tooling and practices, which they can integrate into a holistic next generation security solution across the breadth of Canonical's interests.

The SecOps team's mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem.

They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.

This role reports to the CISO.
What you will do in this role:

Hire and mentor a team of outstanding technical security professionals
Define Canonical's SecOps security standards and playbooks
Own and drive the architecture and design of the SOC
Analyse and improve Canonical's security architecture
Evaluate, select and implement new security tools and practices
Identify, contain and guide the remediation of security threats and cyber attacks
Grow the presence and thought leadership of Canonical SecOps practice
Contribute to open source threat intelligence initiatives
Drive threat modelling, table top exercises and other SecOps practices across Engineering, IS and Canonical
Develop Canonical SecOps learning and development materials
Publish blog posts, whitepapers and conference presentations
Identify, implement and track SecOps KPIs
Plan and deliver SecOps work in the framework of Canonical's agile engineering practice
Work with Security leadership to present information and influence change
What we are looking for

Proven track record of mitigating with advanced threat actors and nation state threats
Expert technical understanding of SOCs from the ground up
In depth knowledge of SOC architecture and design including strategies for logging, firewalls, network segmentation, honeypots etc
Someone who understands how the SOC works not just how to use it
Ability to define, implement, automate and measure effective incident response playbooks
Knowledge of security architecture and market-leading security tools
Experience contributing to, and consuming, threat intelligence feeds
Experience in security risk management frameworks such as NIST CSF
An exceptional academic track record from both high school and university
Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
Drive and a track record of going above-and-beyond expectations
Deep personal motivation to be at the forefront of technology security
Leadership and management ability
Excellent business English writing and presentation skills
Confidence to report security performance metrics with accountability for accuracy and completeness
Optional things we value

Experience in offensive or defensive security teams with hands-on ability
Experience with open source security tools
Experience with security standards such as ISO 27001
Experience with security posture management of corporate endpoitns
During this application process I agree to use only my own words. I understand that plagiarism, the use of AI or other generated content will disqualify my application.


Please describe your most intensive cyber-security operational experience, where you felt the threat actors were most sophisticated or the stakes particularly high.

Please describe your role and contribution to that security work.


Please list of SecOps tools or technologies that you are familiar with, along with any comments to indicate the tools in which you have very significant experience or interest.

Do you have experience against nation state level adversaries?

Describe your experience building or designing a SOC?

How did you perform in mathematics at high school?

Please select
How did you perform in your native language at high school?

Please select
Please share your rationale or evidence for the high school performance selections above.

Make reference to provincial, state or nation-wide scoring systems, rankings, or recognition awards, or to competitive or selective college entrance results such as SAT or ACT scores, JAMB, matriculation results, IB results etc.

We recognise every system is different but we will ask you to justify your selections above.


What was your bachelor's university degree result, or expected result if you have not yet graduated? Please include the grading system to help us understand your result e.g.

'85 out of 100', '2:1 (Grading system:
first class, 2:1, 2:2, third class)' or 'GPA score of 3.8/4.0 (predicted)'. We have hired outstanding individuals who did not attend or complete university. If this describes you, please continue with your application and enter 'no degree'.

Universities around the world score degrees in different ways.

Please indicate your result, or expected result if you are close to graduation, along with information about the grading system.


We expect all colleagues to meet in person 2-4 times a year, at internal company events lasting between 1-2 weeks.

We try to pick new and interesting locations that will likely require international travel and entry requirement visas and vaccinations.

Are you willing and able to commit to this?


Please note that if you require any accommodation for travel that relates to a physical disability please do let us know during your hiring process and we will be happy to discuss your requirements further.


  • In which country do you currently work?
Please select your current location from the dropdown.
Please select
Please confirm that you have read and agree to Canonical's Recruitment Privacy Notice and Privacy Policy.

Recruitment Privacy Notice
Privacy Policy
Please select
For government reporting purposes, we ask candidates to respond to the below self-identification survey.
Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Canonical - Jobs's Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.

As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA.


Classification of protected categoriesis as follows:
A "disabled veteran" is one of the following: a veteran of the U.S.

military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S.

military, ground, naval, or air service.
An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S.

military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S.

military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number
Expires 04/30/2026
Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.
Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Canonical - Jobs's Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

Gender

Please select

Gender

Are you Hispanic/Latino?

Please select

Are you Hispanic/Latino?

Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.

As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA.


Classification of protected categoriesis as follows:
A "disabled veteran" is one of the following: a veteran of the U.S.

military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S.

military, ground, naval, or air service.
An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S.

military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S.

military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Veteran Status

Please select

Veteran Status

Voluntary Self-Identification of Disability

Form CC-305

Page 1 of 1

OMB Control Number

Expires 04/30/2026
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.
Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor's Office of Federal Contract Compliance Programs (OFCCP) website at .
How do you know if you have a disability?


A disability is a condition that substantially limits one or more of your "major life activities." If you have or have ever had such a condition, you are a person with a disability.


Disabilities include, but are not limited to:
Alcohol or other substance use disorder (not currently using drugs illegally)
Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
Blind or low vision
Cancer (past or present)
Cardiovascular or heart disease
Celiac disease
Cerebral palsy
Deaf or serious difficulty hearing
Diabetes
Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
Epilepsy or other seizure disorder
Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
Intellectual or developmental disability
Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
Missing limbs or partially missing limbs
Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
Nervous system condition, for example, migraine headaches, Parkinson's disease, multiple sclerosis (MS)
Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
Partial or complete paralysis (any cause)
Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
Short stature (dwarfism)
Traumatic brain injury
Disability Status

Please select

Disability Status

PUBLIC BURDEN STATEMENT:

According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number.

This survey should take about 5 minutes to complete.

#J-18808-Ljbffr

We have other current jobs related to this field that you can find below

  • Head of Operations

    3 days ago


    San Francisco, California, United States Robust Intelligence Full time

    Robust Intelligence's mission is to eliminate AI Risk. As the world increasingly adopts AI into automated decision processes, we inherit great risk. Our flagship product is built to be integrated with existing AI systems to enumerate and eliminate risks caused by unintentional and intentional (adversarial) failure modes. With Generative AI becoming...


  • San Rafael, California, United States BioMarin Pharmaceutical Inc. Full time

    Title: Head of Global Cyber Security Location: San Rafael, CA Work style: Hybrid local onsite three days + per week Who We Are For more than two decades, going our own way has led to countless breakthroughs, bettering the lives of those suffering from rare genetic disease. In 1997 we were founded to make a big difference in small patient populations. Now we...


  • San Francisco, California, United States Department Of Homeland Security Full time

    Summary Securing Travel, Protecting People - At the Transportation Security Administration, you will serve in a high-stakes environment to safeguard the American way of life. In cities across the country, you would secure airports, seaports, railroads, highways, and/or public transit systems, thus protecting America's transportation infrastructure and...


  • San Francisco, California, United States Hex Full time

    About the role:Hex is hiring an experienced leader to build out the next evolution of our security program. The Security team's responsibility is to safeguard Hex, our staff, and our customers while enabling us to continue building the best-in-class product that customers love.In this role, you will:Define what a world-class security program looks like at...


  • San Francisco, California, United States Hex Full time

    About the roleHex is hiring an experienced leader to build out the next evolution of our security program. The Security team's responsibility is to safeguard Hex, our staff, and our customers while enabling us to continue building the best-in-class product that customers love.On any given day you might find yourself:Define what a world-class security program...

  • Security Leader

    1 month ago


    San Diego, California, United States Philips Full time

    Job TitleSecurity Leader - Ambulatory Monitoring & DiagnosticsJob DescriptionSecurity Leader- AM&D (Malvern, PA or San Diego, CA)The Security Leader is responsible for leading the strategic direction of the security operations function within the Ambulatory Monitoring & Diagnostics (AM&D) business; ranging from planning and budgeting, to motivational and...

  • Head of Projects

    4 weeks ago


    San Jose, California, United States Antora Energy Full time

    At Antora, we're on a mission to stop climate change. And we can't do that unless we tackle the 30% of global emissions that come from industry.Antora is unlocking zero-emissions industrial energy, cheaper than fossil fuels. Antora's thermal batteries store energy from renewables as heat for days on end, delivering that stored energy as heat and power at the...


  • San Francisco, California, United States Oomnitza Full time

    Oomnitza offers the industry's most versatile Enterprise Technology Management platform that orchestrates and automates key business processes for IT. Our SaaS solution, with agentless integrations, best practices and low-code workflows, enables enterprises to leverage their existing infrastructure systems and automate processes such as offboarding,...


  • San Diego, California, United States STR Full time

    STR has a great opportunity for multidisciplinary security professional to join our mission as a dual-hatted Facility Security Officer (FSO) and Contractor Program Security Officer (CPSO) responsible for managing multiple programs executed out of our Carlsbad/San Diego office. The candidate will work closely with security management, program management,...

  • Security Guard

    1 week ago


    San Diego, California, United States Davidson Hospitality Group Full time

    Property DescriptionHilton San Diego Gaslamp Quarter is a prestigious hotel located in the heart of downtown San Diego, offering exciting job opportunities for hospitality professionals looking to be part of a dynamic team. Joining our team means becoming part of a renowned hospitality brand known for its commitment to exceptional guest service and luxurious...


  • San Francisco, California, United States Huntress Full time

    Reports to: SOC Support ManagerLocation: Remote USCompensation Range: $60,000 Base plus bonus and equityWhat We Do:Founded in 2015 as a fully remote company by former NSA cyber operators, Huntress was built on a simple premise: to force hackers to earn every inch of their access. Today's cyber-attacks aren't limited to large organizations with the security...

  • Security

    2 weeks ago


    San Bernardino, California, United States House of Blues Full time

    Job Summary:WHO ARE WE?Live Nation Entertainment is the world's leading live entertainment company, comprised of global market leaders: Ticketmaster, Live Nation Concerts, and Live Nation Media & Sponsorship. Ticketmaster is the global leader in event ticketing with over 500 million tickets sold annually and more than 12,000 clients worldwide. Live Nation...


  • San Diego, California, United States ServiceNow Full time

    Company DescriptionAt ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can't wait, and we innovate in ways no one else can for our customers and communities. By joining ServiceNow, you are part of an ambitious team of change makers who have a restless curiosity and a drive for...

  • Head of Compliance

    1 month ago


    San Francisco, California, United States Cardless Full time

    At Cardless, we're building a credit card and loyalty platform that consumer businesses use to engage their customers. We've launched 9 credit cards, including for the largest mall operator in the U.S. and the largest airline in South America. We help businesses bring imaginative card programs to life, and have pioneered technology to embed credit card...


  • San Francisco, California, United States Fastly Full time

    Fastly helps people stay better connected with the things they love. Fastly's edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers' applications as close to their end-users as possible — at the edge of the Internet. The platform is designed to take...


  • San Francisco, California, United States Cash App Full time

    Job DescriptionWe're looking for an exceptional product leader to take the helm of our Operating Systems abstraction which owns everything from our core Peer to Peer product, Shared Surfaces & Primitives, Messaging & Recommendations, Design Systems, Social vision and more. The Operating Systems team owns the information architecture for the entire Cash App...


  • San Francisco, California, United States Redwood Materials Full time

    About Redwood MaterialsRedwood Materials was founded in 2017 to create a circular supply chain for electric vehicles and clean energy products, making them more sustainable and driving down the cost for batteries. We're doing this by developing and deploying new technologies to increase the scope and scale of recycled and sustainable materials in the global...

  • CSOC Operator

    5 days ago


    San Diego, California, United States Constellis Full time

    Triple Canopy: PPO #120047, A Constellis CompanyCA Main Office: 915 Highland Pointe Drive Ste 250 | Roseville, CA 95678POSITION SUMMARY:Monitor security alarm systems in from various buildings across the San Diego area. Coordinate the appropriate response, to include sending and receiving audible and distinguishing voice communications via radio and...


  • San Diego, California, United States teamworkonline Full time

    WE'D LOVE FOR YOU TO JOIN USSan Diego Wave Fútbol Club is on a mission to build a world class home for players and fans. We are seeking a dynamic, forward-thinking individual to join our mission to share our story, win championships, increase, and delight our fans. We're making memories and engaging our community through this beautiful game. We are hiring...


  • San Diego, California, United States Constellis Full time

    POSITION SUMMARYThe Services will consist of experienced, trained and uniformed concierge personnel providing highly visible, reliable and professional concierge servicePAY TRANSPARENCY/COMPENSATIONRate of Pay: $24/hrPaid training for 1.5 weeks at full hourly rate RESPONSIBILITIESWelcome and greet tenants, guests, visitors, vendors, contractors and all other...