# Head of Security Operations

Remote from🌐 AnywhereAnnual salary Undisclosed Salary information is not provided for this position.
Check our [Salary Directory](https://jobicy.com/salaries.md) to estimate the average compensation for similar roles.Department  [Cybersecurity](https://jobicy.com/categories/cybersecurity.md) Employment type Full Time, Job posted21 Jul 2026Apply before21 Aug 2026Experience level  Director
Views / Applies 83 / 4 [About company](https://jobicy.com/company/canonical-ltd.md)

* Share About [Canonical Ltd.](https://jobicy.com/company/canonical-ltd.md)

Trusted open source for enterprises

[Computer Software](https://jobicy.com/company-category/software.md)
*  2004

Actively Hiring  Verified job posting This job post has been [manually reviewed](https://jobicy.com/tools/help-center/employee/how-does-jobicy-verify-the-legitimacy-of-remote-job-listings.md) for authenticity and compliance.

###  AI Summary

This is a global leadership role at Canonical to manage the Security Operations (SecOps) team. The role involves designing and implementing security practices, tools, and policies to protect Canonical's data, infrastructure, and build processes. The manager will lead a high-performing team, collaborate with other departments, and contribute to the wider open-source security ecosystem. The ideal candidate has deep hands-on expertise in security tooling, SOC architecture, and incident response. This position reports to the CISO and requires a strategic mindset combined with technical proficiency.

### Role DNA

Job Complexity Easy Hard Pace & Pressure Relaxed Fast-paced Autonomy Level Guided Full Ownership Communication Load Independent Highly Collaborative

AI Insight This role demands expert-level technical knowledge, strategic leadership, and the ability to handle sophisticated threats, making it one of the most challenging positions in cybersecurity.

### Salary Analysis

Median  Market Rate  $225,000US Market $150k – 350k 0 $385k      AI Insight The offered salary is not specified, but for a senior leadership role like Head of Security Operations, the market range in the US is typically $150,000 to $350,000. The estimated median of $225,000 is competitive for a global company like Canonical, especially considering the high level of responsibility and expertise required.

### Core Skills Required

[Security Operations](https://jobicy.com/jobs?search_keywords=Security+Operations.md) [SOC Architecture](https://jobicy.com/jobs?search_keywords=SOC+Architecture.md) [Linux Security](https://jobicy.com/jobs?search_keywords=Linux+Security.md) [Threat Intelligence](https://jobicy.com/jobs?search_keywords=Threat+Intelligence.md) [Incident Response](https://jobicy.com/jobs?search_keywords=Incident+Response.md) [Team Leadership](https://jobicy.com/jobs?search_keywords=Team+Leadership.md) [Cyber Security Strategy](https://jobicy.com/jobs?search_keywords=Cyber+Security+Strategy.md) [NIST CSF](https://jobicy.com/jobs?search_keywords=NIST+CSF.md) [Open Source Security](https://jobicy.com/jobs?search_keywords=Open+Source+Security.md)

### Cover Letter Sample

Dear Hiring Team,

I am writing to express my enthusiasm for the Head of Security Operations position at Canonical. With over 15 years of experience in cybersecurity, including leading SOC teams and developing enterprise-wide security strategies, I am confident in my ability to drive Canonical's security posture to the next level. My expertise in Linux security, threat intelligence, and incident response aligns perfectly with the requirements outlined in the job description. I am particularly drawn to Canonical's commitment to open source and its impact on the broader ecosystem. I look forward to the opportunity to contribute to your team and help safeguard Canonical's infrastructure and products.

Sincerely,
Jane Doe

Copy

### Sample Interview Questions

Can you describe your experience with designing and implementing a Security Operations Center (SOC) from the ground up?In my previous role at a global tech firm, I led the design and deployment of a SOC that handled over 10,000 alerts daily. We implemented a tiered system with SIEM, SOAR, and threat intelligence integration. I focused on creating efficient workflows for detection, triage, and response, which reduced mean time to detect (MTTD) by 40%.How do you stay current with advanced threat actors and nation-state threats?I actively participate in threat intelligence sharing groups like FS-ISAC and attend industry conferences. I also follow security researchers and contribute to open-source threat intel platforms. My team regularly conducts tabletop exercises based on real-world attack scenarios to ensure preparedness.How would you approach hiring and mentoring a team of security professionals?I look for candidates with a blend of technical skills and curiosity. For mentoring, I establish clear career paths, provide hands-on training, and encourage participation in external training and certifications. I also foster a culture of knowledge sharing through weekly tech talks and post-incident reviews.Can you give an example of a complex incident you managed and how you coordinated the response?We detected a sophisticated APT campaign targeting our network. I activated the incident response plan, assembled a cross-functional team, and used our SOAR platform to automate containment. We worked with external intelligence partners to identify the threat actor's infrastructure. The response minimized data exfiltration and led to improved detection rules.How do you integrate security into an agile development process?I advocate for 'security as code' by embedding security checks into CI/CD pipelines. We use automated scanning for vulnerabilities and misconfigurations. I also ensure security representatives are part of sprint planning and review sessions to provide timely feedback. Regular security training for developers is key to shifting left.  This global leadership role in cyber security is to manage the Security Operations (SecOps) team responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies. The team is the primary owner of strategy and practices that determine how Canonical secures its data, internal infrastructure and build processes. They are responsible for assuring the security and integrity of our own infrastructure and product deployments. They design and implement technical security controls that ensure security threats are automatically identified, contained and remediated. The team will also contribute ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attack.

As a leader on cyber security in the company, the SecOps team manager will collaborate with our Organisational Learning and Development team to develop playbooks and facilitate SecOps training across Canonical. They will operate in a wider security organisation, run a high performing security team and improve Canonical’s security posture. They will lead initiatives to integrate the team’s insights into Canonical’s broader software development process.

While this is a management position, we expect managers to be expert practitioners, able to lead by example, contribute at the highest level, and assess work based on their own professional experience and skill. Candidates should have deep, hands-on expertise with a range of open source and proprietary security tooling and practices, which they can integrate into a holistic next generation security solution across the breadth of Canonical’s interests.

The SecOps team’s mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem. They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.

This role reports to the CISO.

## What you will do in this role:

* Hire and mentor a team of outstanding technical security professionals
* Define Canonical’s SecOps security standards and playbooks
* Own and drive the architecture and design of the SOC
* Analyse and improve Canonical’s security architecture
* Evaluate, select and implement new security tools and practices
* Identify, contain and guide the remediation of security threats and cyber attacks
* Grow the presence and thought leadership of Canonical SecOps practice
* Contribute to open source threat intelligence initiatives
* Drive threat modelling, table top exercises and other SecOps practices across Engineering, IS and Canonical
* Develop Canonical SecOps learning and development materials
* Publish blog posts, whitepapers and conference presentations
* Identify, implement and track SecOps KPIs
* Plan and deliver SecOps work in the framework of Canonical’s agile engineering practice
* Work with Security leadership to present information and influence change

## What we are looking for

* Proven track record of mitigating with advanced threat actors and nation state threats
* Expert technical understanding of SOCs from the ground up
* In depth knowledge of SOC architecture and design including strategies for logging, firewalls, network segmentation, honeypots etc
* Someone who understands how the SOC works not just how to use it
* Expert in Linux security
* Ability to define, implement, automate and measure effective incident response playbooks
* Knowledge of security architecture and market-leading security tools
* Experience contributing to, and consuming, threat intelligence feeds
* Experience in security risk management frameworks such as NIST CSF
* An exceptional academic track record from both high school and university
* Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
* Drive and a track record of going above-and-beyond expectations
* Deep personal motivation to be at the forefront of technology security
* Leadership and management ability
* Excellent business English writing and presentation skills
* Confidence to report security performance metrics with accountability for accuracy and completeness

## Optional things we value

* Experience in offensive or defensive security teams with hands-on ability
* Experience with open source security tools
* Experience with security standards such as ISO 27001
* Experience with security posture management of corporate endpoitns

Show more

[Apply now >](https://jobicy.com/jobs/149541-head-of-security-operations.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

## How to apply

## See a few more

Similar Cybersecurity remote jobs

*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Senior Security Operations Engineer](https://jobicy.com/jobs/149578-senior-security-operations-engineer.md)

The Canonical Security Operations team is hiring for a Senior or Staff engineer. The Security Operations team is responsible for designing, building, and operating a world-class Security Operations Center, and…

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Ubuntu Security Engineer](https://jobicy.com/jobs/149565-ubuntu-security-engineer.md)

Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is very widely used in breakthrough enterprise initiatives…

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Security Risk Management Specialist](https://jobicy.com/jobs/149564-security-risk-management-specialist.md)

In security risk management we’re looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security…

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Security Software Engineer](https://jobicy.com/jobs/149550-security-software-engineer.md)

Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is widely used in breakthrough enterprise initiatives such…

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Threat Intelligence Lead](https://jobicy.com/jobs/149542-threat-intelligence-lead.md)

The Threat Intelligence Lead will own Canonical’s threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques…

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Staff Security Operations Engineer](https://jobicy.com/jobs/149540-staff-security-operations-engineer.md)

We have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range of experience in these positions –…

🌐 Anywhere•Full TimeNEW*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)

Synthesia

### [Application Security Engineering Manager](https://jobicy.com/jobs/146803-application-security-engineering-manager.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…

![UK flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/gb.svg)

![Europe flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/eu.svg)
GB, EU•Full TimeJul 18*
![Experian logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/dcc5b29a570bb19b9f5c3e150db2fdfe.jpg)

Experian

### [Cyber Defense Senior Analyst](https://jobicy.com/jobs/146651-cyber-defense-senior-analyst.md)

Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,…

![USA flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/us.svg)
US•Full TimeJul 17*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)

Nebius

### [Application Security Engineer](https://jobicy.com/jobs/146769-application-security-engineer-2.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

![UK flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/gb.svg)

![Europe flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/eu.svg)
GB, EU +3 more, DE, NL, CZ•Full TimeEUR 75k-240k/year*
![Experian logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/dcc5b29a570bb19b9f5c3e150db2fdfe.jpg)

Experian

### [Cyber Defense Senior Analyst](https://jobicy.com/jobs/149401-cyber-defense-senior-analyst-2.md)

Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,…

![USA flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/us.svg)
US•Full TimeJul 17
[More Jobs](https://jobicy.com/jobs.md)