Talent.com
Threat Intelligence Lead
Threat Intelligence LeadCanonical • San Francisco, California, United States
[error_messages.no_longer_accepting]
Threat Intelligence Lead

Threat Intelligence Lead

Canonical • San Francisco, California, United States
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Join to apply for the

Threat Intelligence Lead

role at

Canonical

3 months ago Be among the first 25 applicants

Join to apply for the

Threat Intelligence Lead

role at

Canonical

The Threat Intelligence Lead will own Canonical's threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and Procedures (TTP) to better our products and internal cybersecurity controls. You will collaborate with internal stakeholders as well as with the wider cybersecurity community, making sure that Canonical is recognised as a thought leader on open source threat intelligence.

This role will report to the CISO.

You will lead intelligence gathering and development activities on threat actors targeting software supply chains. You'll study attack trends across the wider open source software landscape, report findings to internal security teams, and advise the wider engineering community on the best course of action to detect and mitigate possible threats.

As the publisher of Ubuntu, Canonical products are directly or indirectly present in almost every organisation and household in the world, making them a prime target for threat actors. This team's mission is to help Canonical, and by extension countless community members and companies around the world, secure their software infrastructure.

What you'll do in this role

Build and own Canonical's threat intelligence strategy

Build and maintain OSINT research environments

Develop OSINT tradecraft, principals, and techniques

Identify and track targeted intrusion cyber threats, trends, and new developments by cyber threat actors through analysis of proprietary and open source datasets

Collaborate across teams to inform on activity of interest

Coordinate adversary / campaign tracking

Contribute to the wider threat intelligence community, establishing Canonical as a key contributor and thought leader in the space

Work with product and engineering teams to explain cybersecurity threats and advise on mitigation strategies

Work with the OPSEC and IS team to help implement / update security controls prioritising cyber defence

Identify intelligence gaps and propose new tools and research projects to fill them

Conduct briefings for executives, internal stakeholders and external customers

The successful Threat Intelligence Lead will be

An experienced threat intelligence leader (or similar)

Knowledgeable about the current open source threat landscape and computer networking / infrastructure concepts

Highly competent with OSINT tools (e.g., Buscador, Trace Labs OSINT VM, OSINT Framework, Maltego, Shodan, social media scraping tools, etc.)

Able to identify, organise, catalogue, and track adversary tradecraft trends — often with incomplete data

Experienced using threat intelligence data to influence enterprise architecture or product development decisions

An excellent communicator with the ability to clearly articulate and tailor technical content to a variety of audiences

Able to travel twice a year, for company events up to two weeks long

Desired Characteristics

A professional portfolio of OSINT related scripts, tools, or frameworks

Demonstrated involvement in the larger OSINT community (please share relevant links)

Degree qualified, with a bachelor's degree in computer science, information security, or a related field

Certifications in related areas (e.g. GOSI, SANS SEC487 & SEC587, IntelTechniques OSIP, etc)

Experience in a tech company or government / military signal intelligence departments

What we offer you

We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.

Distributed work environment with twice-yearly team sprints in person

Personal learning and development budget of USD 2,000 per year

Annual compensation review

Recognition rewards

Annual holiday leave

Maternity and paternity leave

Employee Assistance Programme

Opportunity to travel to new locations to meet colleagues

Priority Pass, and travel upgrades for long haul company events

About Canonical

Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.

Canonical is an equal opportunity employer

We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.

Seniority level

Seniority level Mid-Senior level

Employment type

Employment type Full-time

Job function

Job function Information Technology

Industries Software Development

Referrals increase your chances of interviewing at Canonical by 2x

Get notified about new Threat Intelligence Lead jobs in

San Francisco Bay Area .

Principal Security Engineer, Threat Intelligence & Investigations

San Francisco Bay Area $200,000 - $257,500 12 hours ago

Director Product Marketing, Identity Protection & SSPM (Remote)

Sunnyvale, CA $155,000 - $270,000 1 week ago

Senior Technical Recruiter - Engineering Leadership (Contract)

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr

[job_alerts.create_a_job]

Threat Intelligence Lead • San Francisco, California, United States

[internal_linking.similar_jobs]
Security Lead (Vulnerability Management) - SF / NYC / Remote (US)

Security Lead (Vulnerability Management) - SF / NYC / Remote (US)

Cogent Security, Inc. • San Francisco, CA, United States
[filters.remote]
[job_card.full_time]
Cogent Security is on a mission to stop breaches and prevent cybercrime by innovating at the frontier of generative AI systems. We are building the world’s first AI cyber taskforce, composed of AI a...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior PM, Security Research & Threat Intelligence

Senior PM, Security Research & Threat Intelligence

Qualys • Foster City, CA, United States
[job_card.full_time]
A leading cybersecurity company is seeking a Senior Product Manager in Foster City to bridge the gap between the Threat Research Unit and customers. In this role, you will use data analytics to prio...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Lead AI Security Platform Engineering - Hybrid & Equity

Lead AI Security Platform Engineering - Hybrid & Equity

New Amsterdam Technology & Business Ventures • San Francisco, California, United States
[job_card.full_time]
A leading AI security startup in San Francisco is seeking an Engineering Manager to lead a team in developing autonomous alert investigation systems. You will work closely with AI researchers and se...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]
Behavioral Insights Lead - Identity

Behavioral Insights Lead - Identity

Cash App • San Francisco, CA, United States
[job_card.full_time]
Behavioral Insights Lead – Identity.Cash App is a dynamic ecosystem building financial products for 50+ million monthly active customers. Our mission is to redefine the world’s relationship with mon...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Cyber Threat Intelligence Team Lead

Cyber Threat Intelligence Team Lead

Control Risks • San Francisco, CA, United States
[job_card.full_time]
Get AI‑powered advice on this job and more exclusive features.This range is provided by Control Risks.Your actual pay will be based on your skills and experience — talk with your recruiter to learn...[show_more]
[last_updated.last_updated_30] • [promoted]
Threat Investigator (Trust & Safety)

Threat Investigator (Trust & Safety)

Cypress HCM • San Francisco, CA, US
[job_card.full_time]
Threat Investigator (Trust & Safety).Our team needs additional support to respond to critical safety incidents and conduct investigations across a range of abuse areas including but not limited...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior Manager - Security Incident Detection and Response

Senior Manager - Security Incident Detection and Response

Lambda Inc. • San Francisco, CA, United States
[job_card.full_time]
Lambda, The Superintelligence Cloud, is a leader in AI cloud infrastructure serving tens of thousands of customers.Our customers range from AI researchers to enterprises and hyperscalers.Lambda's m...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
AI Security Red Team Lead : Assessments & Automation

AI Security Red Team Lead : Assessments & Automation

Lakera Inc • San Francisco, CA, United States
[job_card.full_time]
A technology company specializing in AI security is looking for an AI Security Engineer to lead security assessments and develop methodologies for securing AI systems. The role involves extensive cl...[show_more]
[last_updated.last_updated_30] • [promoted]
Security Engineer Investigator, i3E

Security Engineer Investigator, i3E

Meta • Menlo Park, CA, United States
[job_card.full_time]
Security Engineer Investigator, i3E.This range is provided by Meta.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. The Integrity Investigations,...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Security & Compliance Lead, Global Defense

Security & Compliance Lead, Global Defense

Cerebras • San Francisco, CA, United States
[job_card.full_time]
A space technology company in San Francisco is looking for a Security & Compliance Team Lead to enhance cybersecurity and ensure compliance with government standards. This role requires managing a t...[show_more]
[last_updated.last_updated_30] • [promoted]
Information Security Engineer - Black Lotus Labs Threat Researcher (Crimeware)

Information Security Engineer - Black Lotus Labs Threat Researcher (Crimeware)

Lumen Technologies • San Francisco, CA, United States
[job_card.full_time]
Information Security Engineer - Black Lotus Labs Threat Researcher (Crimeware).We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly.Toge...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Security & Compliance Team Lead

Security & Compliance Team Lead

Mvp VC • San Francisco, CA, United States
[job_card.full_time]
With the company expanding into defense for both the US and EU, Loft Orbital is seeking an experienced.Security & Compliance Team Lead. This role balances hands‑on technical leadership (75%) with st...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior GRC Security Lead — ISO / NIST, Risk & Audits

Senior GRC Security Lead — ISO / NIST, Risk & Audits

Lambda • San Francisco, CA, United States
[job_card.full_time]
A leading AI infrastructure company is seeking a Cybersecurity Risk Manager to enhance their compliance framework.Responsibilities include managing audits, communicating with stakeholders, and ensu...[show_more]
[last_updated.last_updated_30] • [promoted]
Protective Intelligence & Threat Analyst

Protective Intelligence & Threat Analyst

OpenAI • San Francisco, CA, United States
[job_card.full_time]
The Corporate Security team ensures the physical safety and security of the organization's assets, operations, and personnel. We are committed to maintaining a secure environment that enables our te...[show_more]
[last_updated.last_updated_30] • [promoted]
Cyber Threat Exploitation Lead

Cyber Threat Exploitation Lead

Labelbox • San Francisco, CA, United States
[job_card.full_time]
A leading technology firm is seeking an Adversary Exploitation Lead to analyze exploitation chains and evaluate threat actor tactics. This role involves identifying systemic weaknesses and supportin...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
AI Security Architect : Lead Unified AI Security & Trust

AI Security Architect : Lead Unified AI Security & Trust

Salesforce, Inc. • San Francisco, CA, United States
[job_card.full_time]
A leading tech company is seeking an AI Security Architect to enhance the security framework across all products.The role involves defining security standards, collaborating with teams to implement...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior IR & Threat Intel Lead — REACT Consultant (Remote)

Senior IR & Threat Intel Lead — REACT Consultant (Remote)

Ccrps • San Francisco, CA, United States
[filters.remote]
[job_card.full_time]
A tech company is seeking a Cloudforce One REACT Principal Consultant in San Francisco to enhance its cybersecurity efforts. The role involves responding to security incidents, analyzing cyber threa...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Adversary Exploitation Lead

Adversary Exploitation Lead

Alignerr • San Francisco, CA, United States
[job_card.full_time]
This role focuses on analyzing adversary tactics, identifying weaknesses, and producing structured assessments of cyber threat activity. Analyze exploitation chains, privilege-escalation paths, and ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]