
Security Risk Management Specialist
7 days ago
Overview
Join to apply for the Security Risk Management Specialist role at Canonical .
In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do.
To support this we need to use industry best practices paired with emerging threat information to promote risk identification, quantification, impact analysis, and modelling to ultimately drive decision making. In this role, you will help establish and execute a broad strategic vision for the security risk program at Canonical. You will not only work within the team but also cross-functionally with various teams across the organisation. The team contributes ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attacks. Additionally, the team collaborates with our Organisational Learning and Development team to develop playbooks and facilitate security training across Canonical.
The security risk management team\'s mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem. They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.
Responsibilities
- Define Canonical's security risk management standards and playbooks
- Analyse and improve Canonical's security risk practices
- Evaluate, select and implement new security requirements, tools and practices
- Grow the presence and thought leadership of Canonical security risk management practice
- Develop Canonical security risk learning and development materials
- Work with Security leadership to present information and influence change
- Participate in developing key risk indicators, provide inputs to the development of key control indicators, and key performance indicators for various programs
- Apply statistical models to risk frameworks (such as FAIR, sensitivity analysis, and others)
- Participate in risk management, decision-making, and collaborative discussions
- Lead quantified risk assessments and understand the value of qualitative data for improvements to quality and engineering processes
- Interpret internal or external cyber security risk analyses in business terms and recommend a responsible course of action
- Develop templates and materials to help with self-service risk management actions
- Monitor and identify opportunities to improve the effectiveness of risk management processes
- Launch campaigns to perform security assessments and help mitigate security risks across the company
- Build evaluation methods and performance indicators to measure efficiency of security functions and capabilities
Qualifications
- An exceptional academic track record
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- Drive and a track record of going above-and-beyond expectations
- Deep personal motivation to be at the forefront of technology security
- Leadership and management ability
- Excellent business English writing and presentation skills
- Problem-solver with excellent communication skills, a deep technical understanding of security assessments and risk management
- Expertise in threat modelling and risk management frameworks
- Broad knowledge of how to operationalize the management of security risk
- Experience in Secure Development Lifecycle and Security by Design methodology
Benefits
- Distributed work environment with twice-yearly team sprints in person
- Personal learning and development budget of USD 2,000 per year
- Annual compensation review
- Recognition rewards
- Annual holiday leave
- Maternity and paternity leave
- Employee Assistance Programme
- Opportunity to travel to new locations to meet colleagues
- Priority Pass, and travel upgrades for long haul company events
About Canonical
Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.
Canonical is an equal opportunity employer
We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.
#J-18808-Ljbffr-
Ascc Security Manager
2 weeks ago
Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time**ROLES AND RESPONSIBILITIES**: **The main responsibility of the APAC Security Manager is to Support the APAC Security Account Manager with all Security related duties. Oversee the operation, management, training, appraisal, motivation and administration of the APAC Security Control Centre (SCC) and TWDC Security Team. Act as a main point of contact between...
-
Risk Management Security Specialist
1 week ago
Singapore beBeeSecurity Full time $80,000 - $120,000Job Title: Risk Management Security Specialist">We are seeking a highly skilled Risk Management Security Specialist to oversee the Third-Party Security Risk Management domain. The ideal candidate will provide consultation and professional advice on information security and key technology risk matters.">About the RoleThis role aims to foster a strong...
-
IT Security and Risk Management Specialist
2 weeks ago
Singapore beBeeRisk Full time $90,000 - $120,000Job Title:IT Security and Risk SpecialistJob Description:We are seeking a highly skilled IT Security and Risk Specialist to join our team. As an integral part of our organization, you will play a key role in ensuring the security and integrity of our digital assets.Key Responsibilities Include: Conducting risk assessments on global digital projects, systems,...
-
Security Operations Manager
1 week ago
Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time**About SRS** Founded in 2006, Security & Risk Solutions Pte Ltd (SRS) is a global security solutions provider that started in Singapore. Today, we operate in Asia Pacific, China, the Middle East, the Africas, Europe, and Latin America, and work with over 90 clients, with a strong presence in the Finance and Technology sectors. SRS understands there is no...
-
Security Site Lead
2 weeks ago
Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time**Job Summary** The Security Site Lead is responsible for overseeing security operations at a designated site, ensuring compliance with corporate security policies, risk management protocols, and operational efficiency. **Key Responsibilities** - Security Operations Management: Oversee daily security operations, ensuring adherence to corporate security...
-
Regional Security Analyst
2 weeks ago
Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time**Responsibilities** - Manning the 24/7 Regional Security Services Centre (RSCC) in Hong Kong. - Be the focal point for coordinating response to security incidents / crisis events which may expose the Bank's staff, business, reputation and / or facilities to risk. - Monitoring, collation and analyzing security information obtained through specified public...
-
Risk Management Specialist
2 weeks ago
Singapore US Risk Management Agency Full time**Duties**: - Expands and improves the crop insurance program throughout the region using various resources by staying abreast of agricultural developments and conditions. - Assess the need and interest for agricultural risk management tools for producers of specific agricultural commodities. - Research, assemble and release crop insurance actuarial...
-
Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time**Security & Risk Solutions Pte Ltd (SRS) has been providing high quality security services within and beyond Singapore since 2006.** **Over 16 years, SRS has grown from a security company to a complete security solutions provider. We have a global client base of more than 50 individuals and corporations from countries such as Malaysia, Indonesia, Thailand,...
-
Ascc Security Systems Supervisor
2 weeks ago
Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full time**Summary of the Role** **Roles and Responsibilities**: Relationship Management: - Report directly to the ASCC Manager and work in a team of other Supervisors and Specialists. - Collaborate with the APAC Global Security team’s Regional Security Heads and other key business partners. - Serve as a liaison between APAC Security and Security Design and...
-
Apac Security Control Center Supervisor
2 weeks ago
Singapore SECURITY & RISK SOLUTIONS PTE. LTD. Full timeThe APAC Security Control Center (ASCC) is responsible for supporting emergency and non-emergency events, researching regional and global affairs, incoming call mitigation, event dispatching and emergency notification services 24 hours a day, 7 days a week. In an emergency situation, the ASCC directs and coordinates regional security assistance and support...