Posted today · be early
Security Software Engineer
Canonical
WorldwideremotePosted today
Skill Required
Software-EngineerSecurity-EngineeringApplication-SecurityLinux-SecurityDevSecOpsOpen-Source-SecurityVulnerability-ResearchSecurity-Software-EngineerSoftware-Security-EngineerCybersecurity-Software-EngineerSecurity-Software-EngineeringSoftware-Security-DeveloperPrincipal-Security-Software-EngineerProduct-Security-EngineerSoftware-Security-ArchitectSoftware-Security-EngineeringSecurity EngineerSoftware EngineerSoftware Developersecuritysoftware engineeringCryptographyEngineeringR ProgrammingJavaScriptTypeScriptautomationwrittenPythondesignLinuxC++CloudJavaRustRubyAPIsPHPandGoAIFulltime
Key highlights
- Compensation: Annual bonus and reviews based on location/performance
- Work Environment: Globally remote / Remote-first since 2004
- Travel: Mandatory international travel at least twice a year
- Education: Undergraduate degree in Computer Science or STEM required
- Budget: USD 2,000 annual personal learning and development budget
- Key Perk: Priority Pass and travel upgrades for long haul events
Role overview
Canonical is looking for exceptional security-focused software engineers to be integrated across product teams to challenge the entire team to think more deeply about security through state-of-the-art practices. While contributing to products as engineers, these roles encompass all aspects of product security, including feature development, vulnerability response, proactive security, and open source community participation.
Responsibilities
- Define, implement, and document new security features
- Lead security-focused initiatives within a product engineering team
- Analyze, fix, and test vulnerabilities in open source software
- Contribute to Ubuntu and upstream open source projects to benefit the community
- Audit and analyze source code for vulnerabilities
- Integrate new tools into our security infrastructure, pipelines, and processes
- Achieve and retain various security certifications
- Extend and enhance Linux cryptographic components to meet country-specific compliance requirements, such as FIPS and Common Criteria (CC) certifications
- Work with external partners to develop Center for Internet Security (CIS) benchmarks
- Design and develop hardening automation for Ubuntu
- Stay up to date with trends and developments in the security industry
- Develop, test, and maintain new software capabilities
- Provide guidance and support to other engineering teams on security practices
- Contribute to the product as engineers
- Challenge the team to think deeply about security through threat modeling, table-top exercises, architecture and design reviews, static analysis tools, and fuzzing
- Collaborate closely with other Canonical teams, customers, and partners across the open source ecosystem
- Handle long-term security response for the entire operating system and open source ecosystem
- Design, build, and adopt sophisticated tools that enable working at scale and speed with confidence
Requirements
- An exceptional academic track record from both high school and university
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- A track record of going above and beyond expectations
- Thorough understanding of the common categories of security vulnerabilities and how to fix them
- Knowledge of modern software engineering techniques
- Familiarity with open source development tools and methodologies
- Skill in one or more of C, C++, Python, Go, Rust, Java, Ruby, PHP, or JavaScript/Typescript
- Experience as a security champion
- Experience driving security within a wider SSDLC process
- Professional written and spoken English
- Experience with Linux (Debian or Ubuntu preferred)
- Excellent interpersonal skills, curiosity, flexibility, and accountability
- Passion, thoughtfulness, and self-motivation
- Excellent communication and presentation skills
- Results-oriented, with a personal drive to meet commitments
- Ability to be productive in a globally distributed team through strong self-discipline and motivation
- Mandatory international travel at least twice a year, typically for one week
- Fluency in major programming languages to work with tens of thousands of upstreams
Nice to have
- Clear and effective communication with both the team and Ubuntu community members
- Experience working with the Linux kernel
- Experience with security certifications and knowledge of FIPS and/or Common Criteria (CC)
- Experience with OVAL (Open Vulnerability Assessment Language)
- Knowledge of cryptographic modules such as OpenSSL and Libgcrypt
- Knowledge of low-level Linux cryptography APIs
- Demonstrated ability to learn quickly
- Performance engineering experience
Benefits
- Performance-driven annual bonus
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review (and more often for graduates and associates)
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues
- Priority Pass, and travel upgrades for long haul company events
Additional details
- Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets
- Platform Ubuntu is used in public cloud, data science, AI, engineering innovation, and IoT
- Customers include the world's leading public cloud and silicon providers, and industry leaders in many sectors
- The company is a pioneer of global distributed collaboration, with 1200+ colleagues in 75+ countries and very few office-based roles
- Teams meet two to four times yearly in person, in interesting locations around the world, to align on strategy and execution
- The company is founder-led, profitable, and growing
- Each product engineering team at Canonical reserves one or two openings for security-oriented software engineers
- Canonical develops products driven entirely by security needs, such as AppArmor kernel investments and the Ubuntu Security Guide (USG)
- Location: Worldwide, this is a globally remote role
- Compensation factors in geographical location, experience, and performance
- Canonical is an equal opportunity employer and proud to foster a workplace free from discrimination
- Canonical has been a remote-first company since its inception in 2004
- Originally posted on Himalayas