
Role Overview
The Threat Intelligence Lead will own Canonical’s threat intelligence strategy and execution. You will identify which cyber threat actors are targeting Canonical and leverage intelligence on Tactics, Techniques, and Procedures (TTP) to improve our products and internal cybersecurity controls. Reporting to the CISO, you will collaborate with internal stakeholders and the wider cybersecurity community to establish Canonical as a thought leader in open source threat intelligence.
What You’ll Do
- Strategy: Build and own the global threat intelligence strategy.
- Research: Build and maintain OSINT research environments and develop tradecraft, principles, and techniques.
- Analysis: Identify and track targeted intrusion threats, trends, and developments using proprietary and open source datasets.
- Collaboration: Coordinate adversary/campaign tracking and work with product/engineering teams to advise on mitigation strategies.
- Security Operations: Partner with OPSEC and IS teams to implement and update security controls.
- Communication: Conduct briefings for executives, internal stakeholders, and external customers.
- Community: Contribute to the wider threat intelligence community and represent Canonical as a key contributor.
Requirements
- Experienced threat intelligence leader or similar professional.
- Strong knowledge of the open source threat landscape and computer networking/infrastructure concepts.
- Highly competent with OSINT tools (e.g., Buscador, Trace Labs OSINT VM, OSINT Framework, Maltego, Shodan, social media scraping).
- Ability to track adversary tradecraft trends, often with incomplete data.
- Experience using threat intelligence to influence enterprise architecture or product development.
- Excellent communication skills with the ability to tailor technical content to diverse audiences.
- Ability to travel twice a year for company events (up to two weeks per trip).
Desired Characteristics
- Professional portfolio of OSINT scripts, tools, or frameworks.
- Demonstrated involvement in the larger OSINT community.
- Degree in Computer Science, Information Security, or a related field.
- Relevant certifications (e.g., GOSI, SANS SEC487/587, IntelTechniques OSIP).
- Experience in a tech company or government/military signal intelligence departments.
Benefits
- Distributed work environment with twice-yearly in-person team sprints.
- Personal learning and development budget of USD 2,000 per year.
- Annual compensation review and performance-driven bonus.
- Comprehensive leave policies (holiday, maternity, paternity).
- Employee Assistance Programme and travel perks for company events.
Benefits
Open to
Worldwide
Sign in to track applications and earn points.