Security Risk Management Specialist

1 month ago


Qatar Canonical Full time

In security risk management we’re looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do.

To support this we need to use industry best practices paired with emerging threat information to to promote risk identification, quantification, impact analysis, and modelling to ultimately drive decision making. In this role, you will help establish and execute a broad strategic vision for the security risk program at Canonical. You will not only work within the team but also cross-functionally with various teams across the organisation. The team contributes ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attacks. Additionally, the team collaborates with our Organisational Learning and Development team to develop playbooks and facilitate security training across Canonical.

The security risk management team’s mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem. They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.

What you will do in this role:
  • Define Canonical's security risk management standards and playbooks
  • Analyse and improve Canonical's security risk practices
  • Evaluate, select and implement new security requirements, tools and practices
  • Grow the presence and thought leadership of Canonical security risk management practice
  • Develop Canonical security risk learning and development materials
  • Work with Security leadership to present information and influence change
  • Participate in developing key risk indicators, provide inputs to the development of key control indicators, and key performance indicators for various programs
  • Apply statistical models to risk frameworks (such as FAIR, sensitivity analysis, and others)
  • Participate in risk management, decision-making, and collaborative discussions
  • Lead quantified risk assessments and understand the value of qualitative data for improvements to quality and engineering processes
  • Interpret internal or external cyber security risk analyses in business terms and recommend a responsible course of action
  • Develop templates and materials to help with self-service risk management actions
  • Monitor and identify opportunities to improve the effectiveness of risk management processes
  • Launch campaigns to perform security assessments and help mitigate security risks across the company
  • Build evaluation methods and performance indicators to measure efficiency of security functions and capabilities.
What we are looking for
  • An exceptional academic track record
  • Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
  • Drive and a track record of going above-and-beyond expectations
  • Deep personal motivation to be at the forefront of technology security
  • Leadership and management ability
  • Excellent business English writing and presentation skills
  • Problem-solver with excellent communication skills, a deep technical understanding of security assessments and risk management
  • Expertise in threat modelling and risk management frameworks
  • Broad knowledge of how to operationalize the management of security risk
  • Experience in Secure Development Lifecycle and Security by Design methodology
What we offer you

We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.

  • Distributed work environment with twice-yearly team sprints in person
  • Personal learning and development budget of USD 2,000 per year
  • Annual compensation review
  • Recognition rewards
  • Annual holiday leave
  • Maternity and paternity leave
  • Employee Assistance Programme
  • Opportunity to travel to new locations to meet colleagues
  • Priority Pass, and travel upgrades for long haul company events
About Canonical

Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.

Canonical is an equal opportunity employer

We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.

#LI-remote

#J-18808-Ljbffr
  • Lead Cyber Security

    4 weeks ago


    Qatar Petro Staff International Full time

    **Petro Staff International** - Published- January 23, 2024- Location- Qatar- Category- International- Job Type- Full-time- Field or Industry- IT or Systems DESCRIPTION **Key Job Accountabilities**: *** - Lead and oversee business risk and vulnerability assessments for the company's Information Systems and provide authoritative advice and guidance on...

  • Security Officer

    4 weeks ago


    Qatar U.S. Army Intelligence and Security Command Full time

    **Duties**: - Serves as security specialist responsible for planning, developing, coordinating and implementing an appropriate physical security program. - Provides a reliable and secure means to receive and disseminate Sensitive Compartmented Information (SCI) and Special Access Programs (SAP) to authorized recipients in the organization. - Administers and...


  • Qatar NES Fircroft Full time

    Hiring for Oil & Gas company for PERMANENT role Job Location: Doha, Qatar Candidates from Caspian region will be preferred. Job requirements: • Bachelor's degree in computer science/engineering, Information Technology, Information Systems • 10 years' Information Security experience. • Conversant with relevant Information Security national...


  • Qatar Orion Full time

    **Job description**: **We have an opportunity for a Cyber Security Engineer on a contract basis for a major Oil and Gas client. The position will be based in Doha, Qatar initially before moving to Contractors premises in SE Asia.** The post holder will ensure Engineering Dossier are delivered with a robust cybersecurity engineering definition and fit for...

  • Senior Specialist

    1 month ago


    Qatar NES Fircroft Full time

    Senior Specialist - Category Manager (P4) the following categories are expected across 4 x P4 roles: Repair and Maintenance, Facilities Logistics and Provisions Manpower, Insurance, and General Services Shipyard Services and General Tools Description Lead the efforts to define and implement a Milaha-wide strategy with the aim to guarantee a...


  • Qatar Jacobs Full time

    **Your Impact**: Your Impact**: This position with Jacobs is to support the United States Central Command J2 Directorate through the SSO at CENTCOM Forward Headquarters in Qatar. Your security expertise will be vital to the operations and security of the command. You will witness the impact of your work through the completion of contractual deliverables to...


  • Qatar Azadea Group Full time

    Job Description - Universe Specialist- Decathlon - Qatar (UNI Job Number: Universe Specialist- Decathlon - Qatar ( Job Number: UNI Description The Universe Specialist is responsible for serving customers on the shop floor and assisting the Universe Manager in the effective running of the Universe in order to ensure the highest standards of customer...

  • Manager Market Risk

    4 weeks ago


    Qatar Talent Pal Full time

    To conduct the analysis monitoring and assessment on a wide array of market risk aspects and asset & liability management (ALM) including valuation stress testing and financial modelling of banks assets and liabilities.Key AccountabilitiesDevelop implement and maintain market risk models to facilitate effective assessment and monitoring of an array of risks...


  • Qatar Paramount Computer Systems FZ LLC Full time

    Track and monitor operating risk issues for business units.Report operational risk issues and decisions to senior management on regular basis.Assist in identifying and evaluating risk areas across the operational activities.Investigate root causes of operational risks and provide support to mitigate risk.

  • Safety Specialist

    5 days ago


    Qatar Kin-Tec Full time

    An exciting opportunity to join a new project with a Oil & Gas Operator based in Qatar. They are looking for Safety Specialist to join ASAP. The role is a 1 year renewable contract working 5 days per week 8 - 10 hours per day based in Ras Laffan. Hourly rate, accommodation & transportation allowance and economy class flights provided for mobilisation &...


  • Qatar AlRayyan Marketing and Project Management Full time

    Marketing specialist tasks includes but not limited to: - Create marketing plans. - Brainstorm and develop ideas for creative marketing campaigns. - Create marketing content. - Manage social media accounts in various platforms like Insatgram, facebook, twitter, and linkedin, (this includes: design posts, upload posts, answer peoples inquiries through...


  • Qatar NES Fircroft Full time

    Position: Cyber Security EngineerLocation: Doha/India/Vietnam/Malaysia/Oman/China/Korea/ SingaporeMob date: 01-DEC-2023Demob date: 30-NOV-2025Qualification: Engineering degree in Electrical and Electronic / Instrument and control engineering or similar. Experience: 10-15 years' experience as ICSS and Packages cybersecurity engineer in Offshore Oil and Gas...


  • Qatar NES Fircroft Full time

    Position: Cyber Security Engineer Location: Doha/India/Vietnam/Malaysia/Oman/China/Korea/ Singapore Mob date: 01-DEC-2023 Demob date: 30-NOV-2025 Qualification: Engineering degree in Electrical and Electronic / Instrument and control engineering or similar. Experience: 10-15 years' experience as ICSS and Packages cybersecurity engineer in Offshore...


  • Qatar QatarEnergy Full time

    Department INFORMATION & COMMUNICATION TECHNOLOGY Title SR. ENTERPRISE SECURITY ARCHITECT Primary Purpose of Job Define and develop information security architecture, solutions blueprint and practices to effectively translate business objectives and risk management strategies into specific information security solutions and processes enabled by security...


  • Qatar QatarEnergy Full time

    DepartmentINFORMATION & COMMUNICATION TECHNOLOGYTitleSENIOR ENTERPRISE SECURITY ARCHITECTMain Focus of the RoleThe main focus of this position is to define and create information security architecture, solutions blueprint, and practices that effectively align with business objectives and risk management strategies. This involves developing specific...

  • Senior Specialist

    4 weeks ago


    Qatar NES Fircroft Full time

    Senior Specialist - Category Manager (P4)the following categories are expected across 4 x P4 roles:Repair and Maintenance, Facilities Logistics and Provisions Manpower, Insurance, and General Services Shipyard Services and General ToolsDescription Lead the efforts to define and implement a Milaha-wide strategy with the aim to guarantee a structured approach...

  • Corporate Tax

    3 weeks ago


    Qatar MBC Management Consultancies Full time

    Chartered Financial Analyst, Chartered Accountant Nationality Indian Any Vacancy 1 Vacancy Job Description · Tax Compliance and Reporting: Manage and ensure timely and accurate preparation, review, and filing of all corporate tax returns, including federal, state, and local tax filings. Ensure compliance with tax laws and regulations. · Tax...

  • Safety Specialist

    4 weeks ago


    Qatar Gadget Express Full time

    Job SummarySafety Specialist is responsible for monitoring and providing technical support to an assigned area of the program. Specialist will evaluate work sites to ensure operations are in compliance with Federal and local requirements, provide technical support to area supervisors/managers in corrective actions for compliance deficiencies, conduct...

  • Reporting Specialist

    1 month ago


    Qatar Mekdam Holding Group Full time

    About the job Reporting Specialist (O-1124) Qualifications BA or BSc , professional qualification however any qualification, technical or knowledge requirements may be waived through relevant work experience. Knowledge and/or Experience Minimum of 8 (8) years broad experience in all project phases i.e. engineering, procurement and construction. Worldwide...


  • Qatar NES FIRCROFT Full time

    BH-260380 Posted: 21/02/2024 - competitive- Qatar Qatar- Permanent- Oil & Gas- Senior Loss Prevention & Risk Engineer - JOB DETAILS - **Job Context & Major Challenge(s)** - Role involves implementation of policies and procedures in compliance with emerging regulations and changing requirements, coping with extended scope over all onshore and offshore assets...