Security Software Engineer
Canonical
Posted on 2 Sep
Send me Jobs like this
Experience
2 - 4 Years
Job Location
Education
Bachelor of Technology/Engineering(Agriculture)
Nationality
Any Nationality
Gender
Not Mentioned
Vacancy
1 Vacancy
Job Description
Roles & Responsibilities
Canonical is looking for exceptional security-focused software engineers to be integrated across product teams. While they also contribute to the product as engineers, their primary focus is to challenge the entire team to think more deeply about security through state-of-the-art practices such as threat modeling, table-top exercises, architecture and design reviews, static analysis tools, and fuzzing, among others.
These roles encompass all aspects of product security, including feature development, vulnerability response, proactive security, and open source community participation. Engineers in these roles collaborate closely with other Canonical teams, customers, and partners across the open source ecosystem.
Each product engineering team at Canonical reserves one or two openings for security-oriented software engineers. We also develop a number of products driven entirely by security needs, such as our AppArmor kernel investments and the Ubuntu Security Guide (USG). As the publisher of Ubuntu, we also handle long-term security response for the entire operating system and open source ecosystem. Working with tens of thousands of upstreams means that we need to be fluent in every major programming language and design, build, and adopt sophisticated tools that enable us to work at scale and speed with confidence.
This role requires the ability to be productive in a globally distributed team through strong self-discipline and motivation. It also involves mandatory international travel at least twice a year, typically for one week.
What youll do
Security roles might tackle any of the following:
- Define, implement, and document new security features
- Lead security-focused initiatives within a product engineering team
- Analyze, fix, and test vulnerabilities in open source software
- Contribute to Ubuntu and upstream open source projects to benefit the community
- Audit and analyze source code for vulnerabilities
- Integrate new tools into our security infrastructure, pipelines, and processes
- Achieve and retain various security certifications
- Extend and enhance Linux cryptographic components to meet country-specific compliance requirements, such as FIPS and Common Criteria (CC) certifications
- Work with external partners to develop Center for Internet Security (CIS) benchmarks
- Design and develop hardening automation for Ubuntu
- Stay up to date with trends and developments in the security industry
- Develop, test, and maintain new software capabilities
- Provide guidance and support to other engineering teams on security best practices
- An exceptional academic track record from both high school and university
- Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
- A track record of going above and beyond expectations
- Thorough understanding of the common categories of security vulnerabilities and how to fix them
- Knowledge of modern software engineering techniques
- Familiarity with open source development tools and methodologies
- Skill in one or more of C, C++, Python, Go, Rust, Java, Ruby, PHP, or JavaScript/Typescript
- Experience as a security champion
- Experience driving security within a wider SSDLC process
- Professional written and spoken English
- Experience with Linux (Debian or Ubuntu preferred)
- Excellent interpersonal skills, curiosity, flexibility, and accountability
- Passion, thoughtfulness, and self-motivation
- Excellent communication and presentation skills
- Results-oriented, with a personal drive to meet commitments
- Clear and effective communication with both the team and Ubuntu community members
- Experience working with the Linux kernel
- Experience with security certifications and knowledge of FIPS and/or Common Criteria (CC)
- Experience with OVAL (Open Vulnerability Assessment Language)
- Knowledge of cryptographic modules such as OpenSSL and Libgcrypt
- Knowledge of low-level Linux cryptography APIs
- Demonstrated ability to learn quickly
- Performance engineering experience
Company Industry
Department / Functional Area
Keywords
Disclaimer: Naukrigulf.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@naukrigulf.com
Similar Jobs
API Support & Integration Specialist - IT Support
NAMISHER TECHNOLOGIES L.L.C
- 1 - 4 Years
- Sharjah - United Arab Emirates (UAE)
IT Support Executive
Life Pharmacy LLC
- 2 - 7 Years
- Dubai - United Arab Emirates (UAE)
Data Entry Operator
Confidential Company
- 0 - 1 Year
- Dubai - United Arab Emirates (UAE)