Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is widely used in breakthrough enterprise initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our customers include the world's leading public cloud and silicon providers, and industry leaders in many sectors. The company is a pioneer of global distributed collaboration, with 1200+ colleagues in 75+ countries and very few office-based roles. Teams meet two to four times yearly in person, in interesting locations around the world, to align on strategy and execution.
Canonical is looking for exceptional security-focused software engineers to be integrated across product teams. While they also contribute to the product as engineers, their primary focus is to challenge the entire team to think more deeply about security through state-of-the-art practices such as threat modeling, table-top exercises, architecture and design reviews, static analysis tools, and fuzzing, among others.
These roles encompass all aspects of product security, including feature development, vulnerability response, proactive security, and open source community participation. Engineers in these roles collaborate closely with other Canonical teams, customers, and partners across the open source ecosystem.
Location : Worldwide, this is a globally remote role
What you'll do
- Define, implement, and document new security features
- Lead security-focused initiatives within a product engineering team
- Analyze, fix, and test vulnerabilities in open source software
- Contribute to Ubuntu and upstream open source projects to benefit the community
- Audit and analyze source code for vulnerabilities
- Integrate new tools into our security infrastructure, pipelines, and processes
- Achieve and retain various security certifications
- Extend and enhance Linux cryptographic components to meet country-specific compliance requirements, such as FIPS and Common Criteria (CC) certifications
- Work with external partners to develop Center for Internet Security (CIS) benchmarks
- Design and develop hardening automation for Ubuntu
- Stay up to date with trends and developments in the security industry
- Develop, test, and maintain new software capabilities
- Provide guidance and support to other engineering teams on security best practices
What we are looking for in you
An exceptional academic track record from both high school and universityUndergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative pathA track record of going above and beyond expectationsThorough understanding of the common categories of security vulnerabilities and how to fix themKnowledge of modern software engineering techniquesFamiliarity with open source development tools and methodologiesSkill in one or more of C, C++, Python, Go, Rust, Java, Ruby, PHP, or JavaScript / TypescriptExperience as a security championExperience driving security within a wider SSDLC processProfessional written and spoken EnglishExperience with Linux (Debian or Ubuntu preferred)Excellent interpersonal skills, curiosity, flexibility, and accountabilityPassion, thoughtfulness, and self-motivationExcellent communication and presentation skillsResults-oriented, with a personal drive to meet commitmentsOptional skills we also value
Clear and effective communication with both the team and Ubuntu community membersExperience working with the Linux kernelExperience with security certifications and knowledge of FIPS and / or Common Criteria (CC)Experience with OVAL (Open Vulnerability Assessment Language)Knowledge of cryptographic modules such as OpenSSL and LibgcryptKnowledge of low-level Linux cryptography APIsDemonstrated ability to learn quicklyPerformance engineering experienceWhat we offer you
Distributed work environment with twice-yearly team sprints in personPersonal learning and development budget of USD 2,000 per yearAnnual compensation reviewRecognition rewardsAnnual holiday leaveMaternity and paternity leaveEmployee Assistance ProgrammeOpportunity to travel to new locations to meet colleaguesPriority Pass, and travel upgrades for long haul company eventsCanonical is an equal opportunity employer. We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
#J-18808-Ljbffr