Overview
Canonical is seeking a Security Risk Management Specialist to establish and execute Canonical's security risk program, using industry best practices and emerging threat intelligence to promote risk identification, quantification, impact analysis, and modelling to drive decision making and policy development. This role is remote worldwide and will involve collaboration with Engineering, Operations, and Compliance to implement risk controls and maintain governance across the organization.
Responsibilities
- Develop, implement, and continuously improve Canonical's security risk management program.
- Identify, assess, and quantify security risks to Canonical's systems, data, and operations.
- Conduct threat modelling, risk analysis, and impact assessment; translate findings into actionable policy and controls.
- Collaborate with engineering and product teams to design and implement risk controls, monitoring, and incident response measures.
- Establish risk reporting to leadership; track risk trends and metrics; support audits and regulatory inquiries.
- Stay current with industry threats, standards (NIST, ISO 27001, FAIR) and best practices.
Qualifications
- Experience in information security risk management, governance, risk and compliance.
- Knowledge of threat modelling methodologies and risk assessment frameworks.
- Strong analytical and communication skills; ability to explain risk to non-technical stakeholders.
- Bachelor's degree in a relevant field or equivalent experience; security certifications (e.g., CISSP, CISM) are a plus.
- Ability to work in a remote, globally distributed team.
Benefits
- Competitive salary and benefits
- Flexible, remote-friendly work environment
- Opportunities for professional growth and development.