Ubuntu Security Engineer
Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is widely used in breakthrough initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our customers include the world's leading public cloud and silicon providers, as well as industry leaders across many sectors. The company is a pioneer of global distributed collaboration, with 1200+ colleagues in 75+ countries.
About the role
Canonical is building a team dedicated to providing security coverage across a wide range of ecosystems and environments, working to make the world a better, safer place. As an Ubuntu Security Engineer, you will join an industry-leading security engineering team to help protect the open source community and Ubuntu users from emerging threats. We are hiring across all levels of experience, from Graduate to Senior.
As part of the Ubuntu Security Team, you will work with some of the best and brightest in technology to monitor, triage, respond to, and document new and existing vulnerabilities in open source software. You will collaborate with internal teams and external partners to identify issues, prioritize them, and coordinate remediation. This engineering-focused role may also involve producing security assessments, building features, conducting code reviews, developing internal tools, engaging with the open source community, and participating in industry initiatives and events.
This role requires international travel at least twice a year, usually for one week, and the ability to be productive in a globally distributed team through self-discipline and self-motivation.
Location: Worldwide (globally remote role).
Responsibilities
- Analyze, fix, and test vulnerabilities in open source packages
- Track vulnerabilities in the Ubuntu ecosystem as they are discovered, researched, and fixed, leveraging internal tools
- Collaborate with other teams in the Ubuntu community and upstream developers to exchange or develop vulnerability patches and ensure Ubuntu includes robust security features
- Audit source code for vulnerabilities
- Build features and tools to help teams strengthen the security of their products and contribute to the overall security of Ubuntu
Requirements
- Thorough understanding of common categories of security vulnerabilities and techniques for fixing them
- Familiarity with coordinated disclosure practices
- Familiarity with open source development tools and methodologies
- Proficiency in one or more of C, Python, Go, Rust, Java, Ruby, PHP, or JavaScript/TypeScript
- Excellent logic, problem-solving, troubleshooting, and decision-making skills
- Ability to clearly and effectively communicate with the team and Ubuntu community members
- Experience with Linux (Debian or Ubuntu preferred)
- Excellent interpersonal skills, curiosity, flexibility, and accountability
- Appreciation of diversity, politeness, and effectiveness in a multi-cultural, multi-national organization
- Thoughtfulness, self-motivation, and a result-oriented mindset with a personal drive to meet commitments
Benefits
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Performance-driven annual bonus or commission
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Team Member Assistance Program & Wellness Platform
- Opportunity to travel to new locations to meet colleagues
- Priority Pass and travel upgrades for long-haul company events
About Canonical
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company behind Ubuntu, one of the most important open-source projects and the platform for AI, IoT, and the cloud, we are changing the world of software. We recruit globally and set a very high standard for people joining the company. We expect excellence; to succeed, we need to be the best at what we do. Most colleagues at Canonical have worked remotely since our inception in 2004. Working here is a step into the future and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer. We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.