Ubuntu Security Engineer
Publicado há 20 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Join to apply for the Ubuntu Security Engineer role at Canonical
3 days ago Be among the first 25 applicants
Join to apply for the Ubuntu Security Engineer role at Canonical
Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is very widely used in breakthrough enterprise initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our customers include the world's leading public cloud and silicon providers, and industry leaders in many sectors. The company is a pioneer of global distributed collaboration, with 1200+ colleagues in 75+ countries and very few office-based roles. Teams meet two to four times yearly in person, in interesting locations around the world, to align on strategy and execution.
The company is founder-led, profitable, and growing.
Canonical is building a team dedicated to providing security coverage across a wide range of ecosystems and environments, working to make the world a better, safer place. We are hiring an Ubuntu Security Engineer to join an industry-leading security engineering team and help protect the open source community and Ubuntu users from emerging threats. We are looking for candidates across all levels of experience, from Graduate to Senior.
As part of the Ubuntu Security Team, you will work with some of the best and brightest people in technology to monitor, triage, respond to, and document new and existing vulnerabilities in open source software. You will collaborate with internal teams and external partners to identify issues, prioritize them, and coordinate remediation.
This is an engineering-focused role that may also involve activities such as producing security assessments, building features, conducting code reviews, developing internal tools, engaging with the open source community, and participating in industry initiatives and events.
This role requires international travel at least twice a year, usually for one week. It also requires the ability to be productive in a globally distributed team through self-discipline and self-motivation.
Location: Worldwide, this is a globally remote role
The role entails
- Analyzing, fixing, and testing vulnerabilities in open source packages
- Keeping track of vulnerabilities in the Ubuntu ecosystem as they are discovered, researched, and fixed, leveraging internal tools
- Collaborating with other teams in the Ubuntu community and upstream developers, as needed, to exchange or develop vulnerability patches and ensure that Ubuntu includes the most robust security features
- Auditing source code for vulnerabilities
- Building features and tools to help teams strengthen the security of their products and contribute to the overall security of Ubuntu
- You have a thorough understanding of the common categories of security vulnerabilities and techniques for fixing them
- You are familiar with coordinated disclosure practices
- You are familiar with open source development tools and methodologies
- You are skilled in one or more of C, Python, Go, Rust, Java, Ruby, PHP or JavaScript/TypeScript
- You have excellent logic, problem-solving, troubleshooting, and decision-making skills
- You can clearly and effectively communicate with the team and Ubuntu community members
- Experience with Linux (Debian or Ubuntu preferred)
- Excellent interpersonal skills, curiosity, flexibility, and accountability
- Appreciative of diversity, polite, and effective in a multi-cultural, multi-national organization
- Thoughtfulness and self-motivation
- Result-oriented, with a personal drive to meet commitments
We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognize outstanding performance. In addition to base pay, we offer a performance-driven annual bonus or commission. We provide all team members with additional benefits which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Team Member Assistance Program & Wellness Platform
- Opportunity to travel to new locations to meet colleagues
- Priority Pass and travel upgrades for long-haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open-source projects and the platform for AI, IoT, and the cloud, we are changing the world of software. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence; in order to succeed, we need to be the best at what we do. Most colleagues at Canonical have worked from home since our inception in 2004. Working here is a step into the future and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development
Referrals increase your chances of interviewing at Canonical by 2x
Sign in to set job alerts for “Security Engineer” roles. Linux Cryptography and Security Engineer Site Reliability Engineer ID38563 ($3,000 signing bonus) System Software Engineer - Ubuntu Networking Distributed Systems Software Engineer, Python / Go Senior Software Engineer l Vaga Afirmativa para Mulheres Software Engineer - Solutions Engineering Python and Kubernetes Software Engineer - Data, AI/ML & Analytics Embedded Linux Senior Software Engineer - Optimisation Software Engineer, Ceph & Distributed Storage Python and Kubernetes Software Engineer - Data, Workflows, AI/ML & Analytics Junior Software Development Engineer in Test / R+D - Remote Work | REF# Software Engineer - Cross-platform C++ - Multipass Python Software Engineer - Ubuntu Hardware Certification Team Go (Golang) Software Engineer for Identity Management Software Development Engineer in Test - Remote Work | REF#We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrLinux Cryptography and Security Engineer
Publicado há 20 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Join to apply for the Linux Cryptography and Security Engineer role at Canonical
Linux Cryptography and Security Engineer3 days ago Be among the first 25 applicants
Join to apply for the Linux Cryptography and Security Engineer role at Canonical
This is a unique opportunity to use your software engineering and cryptography skills to build and maintain the security foundation that enables Ubuntu and its users to operate securely and remain compliant to international information security standards such as FIPS 140-3 and Common Criteria. You will use your applied cryptography, Linux Security, and coding skills to enhance the Ubuntu distribution and work with organizations such as DISA and CIS to draft and implement security hardening benchmarks for Ubuntu.
As a member of the Security Hardening team you will work with and develop automation tooling to audit deployed systems for DISA-STIG and CIS benchmark compliance. You will interact with internal and external stakeholders to identify gaps in our frameworks, and develop new solutions to address these challenges. In this role you will have the opportunity to influence team and security culture, facilitate technical delivery, and help drive team direction and execution. You'll collaborate closely with Canonical's kernel team as well as the wider engineering organization to drive features impacting all Ubuntu users.
Day-to-day responsibilities
- Collaborate with other engineers in the Security Hardening team to achieve and retain various Security certifications
- Extend and enhance Linux cryptographic components (OpenSSL, Libgcrypt, GnuTLS, and others) with the features and functionality required for FIPS and CC certification
- Collaborate with external security consultants to test and validate kernel and crypto module components
- Work with external partners to develop security hardening benchmarks and audit + remediation automation for Ubuntu
- Contribute to Ubuntu mainline and upstream projects to land solutions and benefit the community
- Communication and collaboration within and outside Canonical to identify opportunities to improve our security posture, rapidly resolve issues, and deliver high-quality solutions on schedule
- Hands-on experience with low-level Linux cryptography APIs and debugging
- Excellent software engineering fundamentals, including prior experience with C development, and the ability to demonstrate such
- Hands-on experience with Linux system administration and shell scripting
- Demonstrated knowledge of security and cryptography fundamentals + direct experience writing secure code and implementing best practices
- Significant development experience working with open source libraries
- Excellent verbal and written communications to enable efficient collaboration with internal and external partners in a remote-first environment
- Prior experience working on FIPS/Common Criteria certified products and in-depth knowledge of the underlying standards
- Prior experience working directly with DISA-STIG or CIS benchmarks, including related audit + remediation tooling (e.g. Compliance as Code)
- Experience working directly with Linux Kernel
- Prior experience with Python, OVAL (Open Vulnerability Assessment Language), and Ansible
- History of contributions to open source projects
We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.
- Distributed work environment with twice-yearly team sprints in person - we've been working remotely since 2004!
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues from your team and others
- Priority Pass for travel and travel upgrades for long haul company events
Canonical is a pioneering tech firm that is at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do.
Canonical has been a remote-first company since its inception in 2004. Work at Canonical is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game. Canonical provides a unique window into the world of 21st-century digital business.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Seniority level
- Seniority level Entry level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development
Referrals increase your chances of interviewing at Canonical by 2x
Get notified about new Security Engineer jobs in Curitiba, Paraná, Brazil .
Site Reliability Engineer ID38563 ($3,000 signing bonus) System Software Engineer - Ubuntu Networking Distributed Systems Software Engineer, Python / Go Senior Software Engineer l Vaga Afirmativa para Mulheres Software Engineer - Solutions Engineering Python and Kubernetes Software Engineer - Data, AI/ML & Analytics Embedded Linux Senior Software Engineer - Optimisation Software Engineer, Ceph & Distributed Storage Python and Kubernetes Software Engineer - Data, Workflows, AI/ML & Analytics Junior Software Development Engineer in Test / R+D - Remote Work | REF# Software Engineer - Cross-platform C++ - Multipass Python Software Engineer - Ubuntu Hardware Certification Team Go (Golang) Software Engineer for Identity Management Software Development Engineer in Test - Remote Work | REF#We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSecurity Software Engineer
Publicado há 4 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Security Software Engineer at Canonical (Worldwide, remote)
Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is widely used in breakthrough enterprise initiatives such as public cloud, data science, AI, engineering innovation, and IoT. Our customers include the world's leading public cloud and silicon providers, and industry leaders in many sectors. The company is a pioneer of global distributed collaboration, with 1200+ colleagues in 75+ countries and very few office-based roles. Teams meet two to four times yearly in person, in interesting locations around the world, to align on strategy and execution.
The company is founder-led, profitable, and growing.
Canonical is looking for exceptional security-focused software engineers to be integrated across product teams. While they also contribute to the product as engineers, their primary focus is to challenge the entire team to think more deeply about security through state-of-the-art practices such as threat modeling, table-top exercises, architecture and design reviews, static analysis tools, and fuzzing, among others.
These roles encompass all aspects of product security, including feature development, vulnerability response, proactive security, and open source community participation. Engineers in these roles collaborate closely with other Canonical teams, customers, and partners across the open source ecosystem.
Each product engineering team at Canonical reserves one or two openings for security-oriented software engineers. We also develop a number of products driven entirely by security needs, such as our AppArmor kernel investments and the Ubuntu Security Guide (USG). As the publisher of Ubuntu, we also handle long-term security response for the entire operating system and open source ecosystem. Working with tens of thousands of upstreams means that we need to be fluent in every major programming language and design, build, and adopt sophisticated tools that enable us to work at scale and speed with confidence.
Apply here if you are an exceptional security-focused software engineer, passionate about open source, and excited by Canonical's products and mission.
This role requires the ability to be productive in a globally distributed team through strong self-discipline and motivation. It also involves mandatory international travel at least twice a year, typically for one week.
Location: Worldwide, this is a globally remote role
Responsibilities- Define, implement, and document new security features
- Lead security-focused initiatives within a product engineering team
- Analyze, fix, and test vulnerabilities in open source software
- Contribute to Ubuntu and upstream open source projects to benefit the community
- Audit and analyze source code for vulnerabilities
- Integrate new tools into our security infrastructure, pipelines, and processes
- Achieve and retain various security certifications
- Extend and enhance Linux cryptographic components to meet country-specific compliance requirements, such as FIPS and Common Criteria (CC) certifications
- Work with external partners to develop Center for Internet Security (CIS) benchmarks
- Design and develop hardening automation for Ubuntu
- Stay up to date with trends and developments in the security industry
- Develop, test, and maintain new software capabilities
- Provide guidance and support to other engineering teams on security best practices
- An exceptional academic track record from both high school and university
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- A track record of going above and beyond expectations
- Thorough understanding of the common categories of security vulnerabilities and how to fix them
- Knowledge of modern software engineering techniques
- Familiarity with open source development tools and methodologies
- Skill in one or more of C, C++, Python, Go, Rust, Java, Ruby, PHP, or JavaScript/Typescript
- Experience as a security champion
- Experience driving security within a wider SSDLC process
- Professional written and spoken English
- Experience with Linux (Debian or Ubuntu preferred)
- Excellent interpersonal skills, curiosity, flexibility, and accountability
- Passion, thoughtfulness, and self-motivation
- Excellent communication and presentation skills
- Results-oriented, with a personal drive to meet commitments
- Clear and effective communication with both the team and Ubuntu community members
- Experience working with the Linux kernel
- Experience with security certifications and knowledge of FIPS and/or Common Criteria (CC)
- Experience with OVAL (Open Vulnerability Assessment Language)
- Knowledge of cryptographic modules such as OpenSSL and Libgcrypt
- Knowledge of low-level Linux cryptography APIs
- Demonstrated ability to learn quickly
- Performance engineering experience
We offer a competitive, globally remote-friendly package with compensation reviewed annually. In addition to base pay, we provide a performance-driven annual bonus and a range of benefits that reflect Canonical's values and commitments.
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues
- Priority Pass, and travel upgrades for long haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Details- Seniority level: Entry level
- Employment type: Full-time
- Job function: Engineering and Information Technology
- Industries: Software Development
Staff Security Operations Engineer
Publicado há 25 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Join to apply for the Staff Security Operations Engineer role at Canonical
3 months ago Be among the first 25 applicants
Join to apply for the Staff Security Operations Engineer role at Canonical
We have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range of experience in these positions - at the high end we are looking for deep experience defending highly contested critical assets and high-value cyber targets against advanced persistent threats and state-level actors. We have more junior roles for exceptional individuals with a proven personal interest an engagement in cyber attack and defence, and outstanding academic and career performance even if experience is limited.
Our goal is to build an entirely new level of assurance and observable rigour into the open source supply chain. We have our own estate to monitor, but more broadly our goal is to raise the robustness of the entire global Ubuntu estate through the work of this team.
The Security Operations (SecOps) team is responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies. The team is the primary owner of strategy and practices that determine how Canonical secures its data, internal infrastructure and build processes. They are responsible for assuring the security and integrity of our own infrastructure and product deployments. They design and implement technical security controls that ensure security threats are automatically identified, contained and remediated. The team will also contribute ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attack.
The SecOps team's mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem. They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.
What you will do in this role:
- Implement and evolve Canonical's SecOps security standards and playbooks
- Analyse and improve Canonical's security architecture
- Evaluate, select and implement new security tools and practices
- Identify, contain and guide the remediation of security threats and cyber attacks
- Grow the presence and thought leadership of Canonical SecOps practice
- Contribute to open source threat intelligence initiatives
- Drive threat modelling, table top exercises and other SecOps practices across Engineering, IS and Canonical
- Develop Canonical SecOps learning and development materials
- Publish blog posts, whitepapers and conference presentations
- Identify, implement and track SecOps KPIs
- Plan and deliver SecOps work in the framework of Canonical's agile engineering practice
- Work with Security leadership to present information and influence change
- An exceptional academic track record
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- Drive and a track record of going above-and-beyond expectations
- Deep personal motivation to be at the forefront of technology security
- Expertise in threat modelling and risk management frameworks
- Knowledge of security architecture and market-leading security tools
- Experience contributing to, and consuming, threat intelligence feeds
- Experience in security risk management frameworks such as NIST CSF
- Experience with security standards such as ISO 27001
- Experience in a security operations team or a security operations centre (SOC)
- Experience in offensive or defensive security teams with hands-on ability
- Experience with state-actor and other advanced persistent threats
We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues
- Priority Pass, and travel upgrades for long haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Seniority level
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development
Referrals increase your chances of interviewing at Canonical by 2x
Get notified about new Security Engineer jobs in Curitiba, Paraná, Brazil .
Linux Cryptography and Security Engineer Senior Software Engineer l Vaga Afirmativa para Mulheres Distributed Systems Software Engineer, Python / Go Software Engineer (Python/Linux/Packaging) Graduate Software Engineer, Open Source and Linux, Canonical Ubuntu Software Engineer - Solutions Engineering Python and Kubernetes Software Engineer - Data, AI/ML & Analytics Embedded Linux Senior Software Engineer - Optimisation Python and Kubernetes Software Engineer - Data, Workflows, AI/ML & Analytics Software Engineer - Cross-platform C++ - Multipass Junior Software Development Engineer in Test / R+D - Remote Work | REF# Golang System Software Engineer - Containers / Virtualisation Python Software Engineer - Ubuntu Hardware Certification Team Software Engineer III, Full Stack, Web App (Remote) System Software Engineer - GCC/LLVM compiler, tooling, and ecosystemWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSenior Security Operations Engineer
Publicado há 25 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Join to apply for the Senior Security Operations Engineer role at Canonical
Continue with Google Continue with Google
Join to apply for the Senior Security Operations Engineer role at Canonical
Get AI-powered advice on this job and more exclusive features.
We have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range of experience in these positions - at the high end we are looking for deep experience defending highly contested critical assets and high-value cyber targets against advanced persistent threats and state-level actors. We have more junior roles for exceptional individuals with a proven personal interest an engagement in cyber attack and defence, and outstanding academic and career performance even if experience is limited.
Our goal is to build an entirely new level of assurance and observable rigour into the open source supply chain. We have our own estate to monitor, but more broadly our goal is to raise the robustness of the entire global Ubuntu estate through the work of this team.
The Security Operations (SecOps) team is responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies. The team is the primary owner of strategy and practices that determine how Canonical secures its data, internal infrastructure and build processes. They are responsible for assuring the security and integrity of our own infrastructure and product deployments. They design and implement technical security controls that ensure security threats are automatically identified, contained and remediated. The team will also contribute ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attack.
The SecOps team's mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem. They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.
What you will do in this role:
- Implement and evolve Canonical's Security Operation Center
- Analyse and improve Canonical's security architecture
- Evaluate, select and implement new security tools and practices
- Identify, contain and guide the remediation of security threats and cyber attacks
- Grow the presence and thought leadership of Canonical SecOps practice
- Contribute to open source threat intelligence initiatives
- Drive threat modelling, table top exercises and other SecOps practices across Engineering, IS and Canonical
- Develop Canonical SecOps learning and development materials
- Publish blog posts, whitepapers and conference presentations
- Identify, implement and track SecOps KPIs
- Plan and deliver SecOps work in the framework of Canonical's agile engineering practice
- Work with Security leadership to present information and influence change
- An exceptional academic track record
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- Previous professional experience working or leading a Security Operation Center
- Deep personal motivation to be at the forefront of technology security
- Expertise in threat modelling and risk management frameworks
- Knowledge of security architecture and market-leading security tools
- Experience contributing to, and consuming, threat intelligence feeds
- Experience in security risk management frameworks such as NIST CSF and ISO27001
- Experience in a security operations team or a security operations centre (SOC)
- Experience in offensive or defensive security teams with hands-on ability
- Experience with state-actor and other advanced persistent threats
We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues
- Priority Pass, and travel upgrades for long haul company events
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
Seniority level
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Information Technology
- Industries Software Development
Referrals increase your chances of interviewing at Canonical by 2x
Sign in to set job alerts for “Senior Security Engineer” roles. Linux Cryptography and Security EngineerWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrInformation Security Manager
Publicado há 25 dias atrás
Trabalho visualizado
Descrição Do Trabalho
O EBANX é uma fintech global fundada em 2012 com a missão de ser o principal parceiro de pagamentos em mercados em ascensão. Com tecnologia e infraestrutura própria, aliadas a um profundo conhecimento sobre o mercado da América Latina, o EBANX permite que essas empresas se conectem a centenas de métodos de pagamento em diferentes países da região. E vai além, criando resultados para as empresas e experiências de compra simples para os consumidores.
Desde o início da nossa jornada, temos uma importante missão: dar acesso. E isso não diz respeito apenas aos nossos produtos e serviços, mas atravessa tudo aquilo que somos e fazemos. Acreditamos que só é possível inovar com a diversidade, por isso valorizamos diferenças de gênero, raça, nacionalidade, deficiência, orientação sexual, religião e idade. A pluralidade é o que torna o nosso Sonho Grande possível.
Nós somos os ebankers e nós estamos mudando a maneira como as pessoas compram, se conectam e vivem globalmente. Topa fazer história com a gente?
Como Gerente de Segurança da Informação sua missão será de desenvolver e implementar políticas, metodologias e controles de Segurança da Informação .
Você também será responsável por:
- Liderar o time de Infosec, buscando o desenvolvimento dos ebankers;
- Conduzir e aprimorar nosso Sistema de Gestão de Segurança da Informação;
- Manter e garantir nossas certificações incluindo PCI-DSS e ISO 27001;
- Conduzir o gerenciamento de privacidade dentro da área de Segurança da Informação e em sinergia com as demais áreas da empresa;
- Garantir a correta conscientização dos ebankers em Segurança e Privacidade com melhoria continua do processo estabelecido;
- Gerenciar KPIs e métricas de Segurança da Informação;
- Prover através dos corretos frameworks a medição de maturidade de segurança, bem como acompanhar os planos para evolução destes indicadores;
- Atuar em conjunto com todas as áreas da empresa entendendo suas necessidades e endereçando pontos de segurança.
Principais requisitos da posição:
- Experiência em gestão de projetos, com habilidade de planejar, gerenciar e manter projetos complexos que atinjam diversas áreas da companhia;
- Conhecimento da família de padrões ISO / IEC 27000, PCI-DSS e BACEN;
- Conhecimento em COBIT e NIST SP 800;
- Conhecimento em riscos de Segurança da Informação;
- Experiencia anterior em liderança e formação de times;
- Inglês avançado (leitura, escrita e fala).
- Orientação a resultados;
- Certificações em Segurança;
- Espanhol.
O que o EBANX oferece:
- Um ambiente super desafiador e com muitas oportunidades de crescimento;
- Escritório casual, e um dress code flexível;
- Aulas de Espanhol, Inglês e Português (para não nativos);
- WAVES: Programa de metas e resultados;
- EBANX Play – Programas de Saúde (Gympass, e-Sports, SESC);
- Jornada semi flexível (8 horas por dia, de segunda a sexta-feira);
- Vale-refeição/Vale-alimentação;
- Vale transporte se necessário;
- EBANX Education: Possibilidade de auxílio financeiro na graduação e pós graduação;
- EBANX Skills: Possibilidade de fazer cursos e treinamentos ligados com a área de atuação;
- EBANX Flexible: Day Off dos meses de fevereiro a novembro, Birthday Day Off e Rest up month, um mês de licença remunerada a cada três anos de EBANX.
- EBANX Family: Auxílio creche, licença estendida aos cuidadores e programa de apoio a gestantes e crianças;
- EBANX Health: Plano de Saúde e Plano Dental (SulAmérica), com subsídio para dependentes, e subsídio de medicamentos para ebankers;
- Seguro de Vida: Seguro de Vida 100% custeado pelo EBANX
- Hello ebanker: Orientações psicológicas, legais ou financeiras;
- Blue Club: Descontos exclusivos para ebankers em panificadoras, restaurantes, cursos, lojas e mais!
Information Security Team Leader
Publicado há 5 dias atrás
Trabalho visualizado
Descrição Do Trabalho
At EBANX, you’ll help expand access to payments and technology in some of the world’s most dynamic markets. We’re a unicorn-status fintech , AI-powered , and scaling fast across 29 countries and counting .
Our platform connects leading global companies to more than 1 billion consumers , enabling seamless cross-border payments where it matters most. We build with purpose, move with speed, and create solutions that are both innovative and inclusive.
If you’re looking to be part of a company that’s transforming the future of payments with clarity , ambition , and real-world impact — we’d love to meet you.
In the IT Ops team, we take care of the infrastructure that keeps EBANX running every day. We ensure that employees have the best experience with devices, networks, and systems, providing fast, secure, and efficient support so nothing gets in the way.
- Lead and develop a high-performing InfoSec team focused on Governance and Awareness;
- Oversee the implementation, maintenance, and continuous improvement of ISO/IEC 27001, 27701, 27018, and PCI DSS compliance frameworks;
- Coordinate internal and external security assessments, audits, and the execution of remediation plans;
- Define, monitor, and report on key security metrics and service-level agreements (SLAs);
- Drive the creation and delivery of company-wide security awareness programs, phishing simulations, and training initiatives;
- Ensure alignment between InfoSec policies and EBANX’s business processes, internal controls, and legal/regulatory obligations;
- Collaborate with cross-functional teams (Legal, Risk, HR, Engineering, etc.) to embed security practices into business operations;
- Manage operational routines, handle incidents, support change requests, and ensure governance of ongoing activities;
- Track and report on the team’s progress, resource planning, KPIs, and strategic initiatives;
- Support the onboarding of new services and contracts, ensuring security requirements are embedded from day one;
- Foster a security-first mindset through influence, engagement, and continuous improvement culture;
- Solid experience in leading teams , with proven ability to motivate, coach, and develop people.
- Deep knowledge in Information Security Governance and Compliance , including risk management, internal controls, and security frameworks.
- Hands-on experience with global standards and certifications such as ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, and PCI DSS.
- Strong communication skills , capable of engaging both technical and non-technical stakeholders.
- Proven track record managing audits, assessments, and external regulatory demands.
- Analytical mindset with a business-oriented approach , connecting security decisions with strategic goals.
- Experience designing and running awareness programs that go beyond checklists and truly shift culture.
- Advanced English — you’ll often interact with international stakeholders.
- Information Security certifications such as ISO/IEC 27001 Lead Implementer/Auditor .
- Experience working in global or multicultural environments , with distributed teams and international operations.
- Familiarity with SOX controls , data privacy frameworks, and third-party risk management.
- Knowledge of cloud security standards (e.g., AWS, GCP, Azure) and secure development practices.
- Hands-on experience with awareness platforms (e.g., KnowBe4, Wombat, MetaCompliance) and phishing simulation tools.
- Experience implementing metrics dashboards and KPIs for InfoSec programs.
- Previous involvement in security incident response , including coordination and post-incident reviews.
- Passion for building a security culture , storytelling, and engaging people in non-technical areas.
- Experience using Artificial Intelligence (AI) or Machine Learning to automate governance processes , enhance risk analysis, streamline controls management, or improve compliance monitoring.
EBANX offers:
- WAVES Program: Annual bonuses based on the company’s performance.
- Meal/Food Allowance: Credit provided on a flexible benefits card.
- EBANX Education: Financial support for undergraduate, graduate, and MBA programs to support your professional growth.
- EBANX Skills: Budget dedicated to workshops, courses, and certifications to encourage your continuous development.
- Language Classes: Spanish, English, and Portuguese lessons for your personal and professional development.
- EBANX Health: Comprehensive medical and dental plans fully covered for the employee, plus subsidies for dependents to take care of your and your family’s well-being.
- EBANX Family: Childcare assistance, extended parental leave for caregivers, and support programs for pregnant employees and children.
- Life Insurance: Fully paid by EBANX.
- Transportation: Parking assistance or transportation vouchers, depending on your needs.
- EBANX Flexible: A special day off on your birthday, semi-flexible working hours (8 hours/day, Monday to Friday), and year-end recess between Christmas and New Year’s without affecting your vacation days.
- EBANX Play: Well-being program including access to Wellhub, e-Sports, and partnerships with SESC.
- Blue Club: Exclusive discounts at bakeries, restaurants, stores, courses, and more.
Follow us on LinkedIn and check out our Instagram to learn more about the #ebanxlife.
#LI-ONSITE
#LI-TC1
Create a Job Alert
Interested in building your career at EBANX? Get future opportunities sent straight to your email.
Apply for this jobFirst Name *
Last Name *
Preferred First Name
Email *
Phone
Resume/CV
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
LinkedIn Profile
Privacy Notice * Select.
By applying for jobs at EBANX, you declare that you have read our Privacy Notice and agree to the use of your data by EBANX. *
Your agreement with our Notice is fundamental for EBANX to take all the necessary steps to start the application process, such as contacting you, scheduling and conducting interviews, and registering you as a candidate in our systems.
EBANX will store your data for the duration of the application process and, after it has ended, for a further 5 years. If you wish to have your data deleted before then, please contact EBANX via our Privacy Portal.
Level of English * Select.
Level of Spanish * Select.
Work Location Availability * Select.
Demographic Information * Select.
We believe it is possible to create a diverse, equal and inclusive environment. That is why we have prepared a questionnaire that addresses demographic issues by collecting sensitive personal data. The information collected is part of our efforts to monitor our evolution, so filling it out is optional , but we invite you to do so. Filling in or refusing to provide these details will in no way affect your hiring process, but it will help us to get to know the people who apply to EBANX better. Check out this link for more information to support your decision on whether or not to provide consent for the processing of this data.
By selecting the "Agree" option in this section, you register your free, express, informed, and unequivocal expression of awareness about the processing of sensitive data and consent to the processing of this data. This means that you agree to the legal entity EBANX Ltda., CNPJ / , headquartered at Rua Marechal Deodoro, 630, Praça San Marco, CEP , Centro, Curitiba, PR, processing your personal data under the terms listed.
You declare yourself a person (select the option that best defines your race/skin color): * Select.
Select which gender identity you identify with: * Select.
Select which sexual orientation you identify with: * Select.
Are you a person with a disability? * Select.
If you are a person with a disability and you answered yes in the previous question, please indicate what disability you have: * Select.
Are you eligible to work in the country of the job position you are applying to? * Select.
#J-18808-LjbffrSeja o primeiro a saber
Sobre o mais recente Cissp Empregos em Curitiba !
Information Security Team Leader Curitiba | On-site
Publicado há 5 dias atrás
Trabalho visualizado
Descrição Do Trabalho
At EBANX, you’ll help expand access to payments and technology in some of the world’s most dynamic markets. We’re a unicorn-status fintech , AI-powered , and scaling fast across 29 countries and counting .
Our platform connects leading global companies to more than 1 billion consumers , enabling seamless cross-border payments where it matters most. We build with purpose, move with speed, and create solutions that are both innovative and inclusive.
If you’re looking to be part of a company that’s transforming the future of payments with clarity , ambition , and real-world impact — we’d love to meet you.
In the IT Ops team, we take care of the infrastructure that keeps EBANX running every day. We ensure that employees have the best experience with devices, networks, and systems, providing fast, secure, and efficient support so nothing gets in the way.
Responsibilities- Lead and develop a high-performing InfoSec team focused on Governance and Awareness;
- Oversee the implementation, maintenance, and continuous improvement of ISO/IEC 27001, 27701, 27018, and PCI DSS compliance frameworks;
- Coordinate internal and external security assessments, audits, and the execution of remediation plans;
- Define, monitor, and report on key security metrics and service-level agreements (SLAs);
- Drive the creation and delivery of company-wide security awareness programs, phishing simulations, and training initiatives;
- Ensure alignment between InfoSec policies and EBANX’s business processes, internal controls, and legal/regulatory obligations;
- Collaborate with cross-functional teams (Legal, Risk, HR, Engineering, etc.) to embed security practices into business operations;
- Manage operational routines, handle incidents, support change requests, and ensure governance of ongoing activities;
- Track and report on the team’s progress, resource planning, KPIs, and strategic initiatives;
- Support the onboarding of new services and contracts, ensuring security requirements are embedded from day one;
- Foster a security-first mindset through influence, engagement, and continuous improvement culture;
- Solid experience in leading teams , with proven ability to motivate, coach, and develop people.
- Deep knowledge in Information Security Governance and Compliance , including risk management, internal controls, and security frameworks.
- Hands-on experience with global standards and certifications such as ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 27018, and PCI DSS.
- Strong communication skills , capable of engaging both technical and non-technical stakeholders.
- Proven track record managing audits, assessments, and external regulatory demands.
- Analytical mindset with a business-oriented approach , connecting security decisions with strategic goals.
- Experience designing and running awareness programs that go beyond checklists and truly shift culture.
- Advanced English — you’ll often interact with international stakeholders.
- Information Security certifications such as ISO/IEC 27001 Lead Implementer/Auditor
- Experience working in global or multicultural environments , with distributed teams and international operations.
- Familiarity with SOX controls , data privacy frameworks, and third-party risk management.
- Knowledge of cloud security standards (eg AWS, GCP, Azure) and secure development practices.
- Hands-on experience with awareness platforms (eg KnowBe4, Wombat, MetaCompliance) and phishing simulation tools.
- Experience implementing metrics dashboards and KPIs for InfoSec programs.
- Previous involvement in security incident response , including coordination and post-incident reviews.
- Passion for building a security culture , storytelling, and engaging people in non-technical areas.
- Experience using Artificial Intelligence (AI) or Machine Learning to automate governance processes, enhance risk analysis, streamline controls management, or improve compliance monitoring.
- WAVES Program: Annual bonuses based on the company’s performance.
- Meal/Food Allowance: Credit provided on a flexible benefits card.
- EBANX Education: Financial support for undergraduate, graduate, and MBA programs to support your professional growth.
- EBANX Skills: Budget dedicated to workshops, courses, and certifications to encourage your continuous development.
- Language Classes: Spanish, English, and Portuguese lessons for your personal and professional development.
- EBANX Health: Comprehensive medical and dental plans fully covered for the employee, plus subsidies for dependents to take care of your and your family’s well-being.
- EBANX Family: Childcare assistance, extended parental leave for caregivers, and support programs for pregnant employees and children.
- Life Insurance: Fully paid by EBANX.
- Transportation: Parking assistance or transportation vouchers, depending on your needs.
- EBANX Flexible: A special day off on your birthday, semi-flexible working hours (8 hours/day, Monday to Friday), and year-end recess between Christmas and New Year’s without affecting your vacation days.
- EBANX Play: Well-being program including access to Wellhub, e-Sports, and partnerships with SESC.
- Blue Club: Exclusive discounts at bakeries, restaurants, stores, courses, and more.
Specialist II, Business Information Security Officer (BISO)
Publicado há 25 dias atrás
Trabalho visualizado
Descrição Do Trabalho
Join to apply for the Specialist II, Business Information Security Officer (BISO) role at Concentrix
Specialist II, Business Information Security Officer (BISO)2 days ago Be among the first 25 applicants
Join to apply for the Specialist II, Business Information Security Officer (BISO) role at Concentrix
Direct message the job poster from Concentrix
Professional Talent Acquisition @ Concentrix | IT & Digital Recruiter LATAMConcentrix Corporation is seeking a Country Business Information Security Officer to join the Global Security team reporting to the CNX GEO Business Information Security Officer – Insider Risk and Compliance team.
Qualifications:
- 3 to 5 years of experience working in risk and compliance management, internal security controls, internal/external security assessment or audit, internal or cyber incident investigations.
- Bachelor's degree preferred in Security or Information Technology.
- Experience in the BPO industry working in quality, security compliance or delivery strongly preferred.
- Deep understanding of BPO Business Operation and CRM services delivery processes.
- Ability to identify performance and opportunity gaps.
- Process driven and an eye for detail
- Demonstrable experience of driving operational implementation of risk reduction initiatives, across business units, using influencing and security skills
- Solid background of key network and technical security controls
BISO Responsibilities:
- Drive the highest Integrity and Ethical standards across the staff and the accounts in scope.
- Provide governance to operations management team and Quality Assurance team for effective and efficient surveillance and monitoring towards pro-active security and business process non-compliance issue identification.
- Collaborate with respective supporting functions/departments (IT, HR, Facility, Legal, DPO, etc.) to address relevant security issues/risks.
- Perform internal audit/assessment on regular basis based on different business process compliance management and risk control mechanisms in different accounts to ensure the full compliance as per relevant standard and identify potential issues/risks.
- Work closely with the operation team to get all identified non-compliance items fixed in a timely manner to drive for closure and proactively propose and deploy extra preventive controls where appropriate.
- Establish and execute a robust methodology for periodic reviews aiming to highlight the gaps that exist in the operational processes.
- Analyze operational data to identify trends, root causes of business issues, and/or opportunities.
- Provide recommendations for corrective and preventive actions and suggest improvements to the processes.
- Review and report the results and present them to management team.
- Ensure partnership with accounts management team for Proactive Compliance Risk Management – identification, assessment, risk action planning, and closures.
- Coordinate and support Global Security Assessments (GSAs) - a holistic assessment (technology, HR, operations, finance, etc.) of risks being faced by delivery operations and No Notice Inspections (NNIs) conducted against the specific accounts in scope.
- Conduct employee awareness and assist in developing training materials and where necessary assist in specific training.
Accountability:
- Primary contact for security matters in country/region as appropriate
- Accountable for local implementation of country specific global security strategies and initiatives
- Delivery of established Global Security metrics as well as all visibility enabling initiatives, country-wide
- Study the contracts signed with Clients, and validate continuous contractual compliance for all controls, both physical and logical.
- Must have strong project leadership experience and ability to work with global, multi-cultural teams and drive to meet stringent deliverable timelines
- Accountable to drive identified account (client) and internal (corporate) risks, in partnership with key stakeholders, through to remediation or risk sign-off
- Plan, participate and execute Global Security Assessments (GSAs) in specific country per GSA Schedule / Calendar identifying both internal & external vulnerabilities
- Lead & Execute in the action planning activity as necessary to close identified vulnerabilities the security and business process compliance in various accounts to meet business and client expectation.
- Seniority level Mid-Senior level
- Employment type Full-time
- Job function Consulting and Analyst
- Industries IT Services and IT Consulting
Referrals increase your chances of interviewing at Concentrix by 2x
Get notified about new Information Security Officer jobs in Curitiba, Paraná, Brazil .
Specialist II, Business Information Security Officer (BISO) (TCF) Bilingual Specialist II, Business Information Security Officer (BISO) (TCF) Bilingual Scientific System Administrator - Remote - Latin AmericaWe’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-LjbffrSpecialist II, Business Information Security Officer (BISO) (TCF) Bilingual
Hoje
Trabalho visualizado
Descrição Do Trabalho
Overview
Job Title: Specialist II, Business Information Security Officer (BISO) (TCF) Bilingual
The Country Business Information Security Officer (BISO) focuses on proactively identifying security and compliance issues/risks to business operation processes in various accounts, drives in executing the controls to deter, detect and mitigate security and insider risks - including establishing capability and mechanisms to monitor and audit information and data protection of both Concentrix and clients as well as compliance level of each process and relevant control item as deployed in the operational environment. The country BISO drives proactively to enhance the fraud and compliance prevention culture and risk-free environment in Concentrix as well as identifies issues that would include but not limited to physical and logical security, data privacy, KPI, CSAT, inbound/outbound calls manipulation, information leakage, etc. impacting business. Typical activities include but are not limited to Risk Management – risk identification, risk assessments, support in development of risk action plans, risk closures, supporting investigations - case documentation, written first-hand reports, involve in-person or remote interview of persons of interest and working outside normal business hours, etc., Governance and metrics, Executive presentations, Collaboration with all teams/departments. Achieves results through direct interaction as well as influencing other internal groups or persons to achieve results.
Concentrix Corporation is seeking a Country Business Information Security Officer to join the Global Security team reporting to the CNX GEO Business Information Security Officer – Insider Risk and Compliance team.
Qualifications- 3 to 5 years of experience working in risk and compliance management, internal security controls, internal/external security assessment or audit, internal or cyber incident investigations.
- Bachelor's degree preferred in Security or Information Technology.
- Experience in the BPO industry working in quality, security compliance or delivery strongly preferred.
- Deep understanding of BPO Business Operation and CRM services delivery processes.
- Ability to identify performance and opportunity gaps.
- Process driven and an eye for detail
- Demonstrable experience of driving operational implementation of risk reduction initiatives, across business units, using influencing and security skills
- Solid background of key network and technical security controls
- Drive the highest Integrity and Ethical standards across the staff and the accounts in scope.
- Provide governance to operations management team and Quality Assurance team for effective and efficient surveillance and monitoring towards pro-active security and business process non-compliance issue identification.
- Collaborate with respective supporting functions/departments (IT, HR, Facility, Legal, DPO, etc.) to address relevant security issues/risks.
- Perform internal audit/assessment on regular basis based on different business process compliance management and risk control mechanisms in different accounts to ensure the full compliance as per relevant standard and identify potential issues/risks.
- Work closely with the operation team to get all identified non-compliance items fixed in a timely manner to drive for closure and proactively propose and deploy extra preventive controls where appropriate.
- Establish and execute a robust methodology for periodic reviews aiming to highlight the gaps that exist in the operational processes.
- Analyze operational data to identify trends, root causes of business issues, and/or opportunities.
- Provide recommendations for corrective and preventive actions and suggest improvements to the processes.
- Review and report the results and present them to management team.
- Ensure partnership with accounts management team for Proactive Compliance Risk Management – identification, assessment, risk action planning, and closures.
- Coordinate and support Global Security Assessments (GSAs) - a holistic assessment (technology, HR, operations, finance, etc.) of risks being faced by delivery operations and No Notice Inspections (NNIs) conducted against the specific accounts in scope.
- Conduct employee awareness and assist in developing training materials and where necessary assist in specific training.
- Primary contact for security matters in country/region as appropriate
- Accountable for local implementation of country specific global security strategies and initiatives
- Delivery of established Global Security metrics as well as all visibility enabling initiatives, country-wide
- Study the contracts signed with Clients, and validate continuous contractual compliance for all controls, both physical and logical.
- Must have strong project leadership experience and ability to work with global, multi-cultural teams and drive to meet stringent deliverable timelines
- Accountable to drive identified account (client) and internal (corporate) risks, in partnership with key stakeholders, through to remediation or risk sign-off
- Plan, participate and execute Global Security Assessments (GSAs) in specific country per GSA Schedule / Calendar identifying both internal & external vulnerabilities
- Lead & Execute in the action planning activity as necessary to close identified vulnerabilities the security and business process compliance in various accounts to meet business and client expectation.
Location: BRA Curitiba - MAL DEODORO, 314 Ed. Tibagi
Time Type: Full time
Posting Date:
Privacy Notice: If you are a California resident, by submitting your information you acknowledge that you have read and have access to the Job Applicant Privacy Notice for California Residents.
#J-18808-Ljbffr