Threat Intelligence Lead

Remote from
🌐 Anywhere
Annual salary
Undisclosed
Salary information is not provided for this position. Check our Salary Directory to estimate the average compensation for similar roles.
Department
Cybersecurity
Employment type
Full Time,
Job posted
Apply before
21 Aug 2026
Experience level
Senior
Views / Applies
62 / 2

About Canonical Ltd.

Trusted open source for enterprises

Actively Hiring
Verified job posting
This job post has been manually reviewed for authenticity and compliance.

AI Summary

Canonical is seeking a Threat Intelligence Lead to own their threat intelligence strategy, focusing on cyber threat actors targeting the company and the open source ecosystem. The role involves OSINT research, tracking adversary tactics, and collaborating with internal teams and the wider cybersecurity community. The ideal candidate is an experienced threat intelligence leader with strong OSINT skills and the ability to influence security decisions. This is a remote position with twice-yearly travel, reporting to the CISO. The role offers the opportunity to contribute to securing software infrastructure used globally.

Role DNA

Job Complexity
Easy Hard
Pace & Pressure
Relaxed Fast-paced
Autonomy Level
Guided Full Ownership
Communication Load
Independent Highly Collaborative
AI Insight This role requires deep expertise in threat intelligence, OSINT, and strategic leadership, making it challenging but not entry-level. The need to influence product development and communicate with executives adds complexity.

Salary Analysis

Median Highly Competitive
$150,000
US Market
$120k – 180k
0 $198k
AI Insight The salary is not specified in the listing, but based on market data for similar roles in the US, the estimated median is $150,000, which is competitive for a lead threat intelligence position at a tech company.

Dear Hiring Manager,

I am excited to apply for the Threat Intelligence Lead role at Canonical. With over 8 years of experience in cyber threat intelligence and OSINT, I have a proven track record of building and executing intelligence strategies that protect critical infrastructure. I am particularly drawn to this role because of Canonical's impact on the open source community and the opportunity to serve as a thought leader in this space.

In my previous role, I led a team that tracked advanced persistent threats targeting software supply chains, using tools like Maltego and Shodan to develop actionable intelligence. I also collaborated with engineering teams to integrate threat data into product development, reducing risk for millions of users. I am confident that my expertise in adversary tracking and strategic communication will enable me to drive Canonical's threat intelligence program effectively.

I look forward to discussing how I can contribute to your team.

Sincerely,
[Your Name]

Describe your experience building a threat intelligence program from scratch. What were the key challenges and how did you overcome them?
In my previous role, I built a threat intelligence program for a mid-size tech company. Key challenges included defining intelligence requirements with no existing framework and gaining buy-in from engineering teams. I started by conducting stakeholder interviews and focusing on high-impact threats to the software supply chain. I implemented OSINT tools like Maltego and automated data collection, which improved detection of targeted intrusions. I also established regular briefings to demonstrate value, which helped secure resources for expansion.
How do you prioritize which threat actors or campaigns to track given limited resources?
I prioritize based on a combination of factors: relevance to our industry, likelihood of targeting our organization or customers, and potential impact. I use a threat modeling framework to assess actor capabilities and intentions. I also stay updated on community reports and intelligence sharing platforms. For example, if a state-sponsored group is known to target open source package managers, I would allocate more resources to tracking that activity. Regular reviews ensure the priorities align with evolving threats.
Can you walk me through your process for conducting OSINT research on a specific threat actor?
I start by defining the actor's known identifiers (e.g., infrastructure, tools, TTPs) based on existing reports. Then I use tools like Shodan to discover associated servers, Maltego for relationship mapping, and social media scraping for persona tracking. I document findings in a structured format, cross-referencing with open source intelligence to validate. I also maintain a sandbox environment for testing indicators. The output is a tactical report with actionable indicators for defensive teams.
How do you communicate threat intelligence findings to non-technical executives?
I tailor communications by focusing on business impact and risk, avoiding technical jargon. For executives, I use visual aids like heat maps or timelines to show the threat landscape and current mitigation status. I highlight concrete recommendations and resource needs. For example, I might say 'We have observed increased targeting of our deployment pipelines by a sophisticated actor; I recommend accelerating our software supply chain security enhancements.' This ensures clear decision-making.
How do you stay current with evolving TTPs and the threat landscape?
I actively participate in threat intelligence sharing communities like FS-ISAC and attend industry conferences. I follow OSINT and threat research blogs, and use automated feeds to track indicators. I also allocate time for hands-on research, such as setting up honeypots or analyzing new malware strains. Additionally, I contribute to open source threat intelligence projects, which helps me learn from peers and share insights.

The Threat Intelligence Lead will own Canonical’s threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and Procedures (TTP) to better our products and internal cybersecurity controls. You will collaborate with internal stakeholders as well as with the wider cybersecurity community, making sure that Canonical is recognised as a thought leader on open source threat intelligence.

This role will report to the CISO.

You will lead intelligence gathering and development activities on threat actors targeting software supply chains. You’ll study attack trends across the wider open source software landscape, report findings to internal security teams, and advise the wider engineering community on the best course of action to detect and mitigate possible threats.

As the publisher of Ubuntu, Canonical products are directly or indirectly present in almost every organisation and household in the world, making them a prime target for threat actors. This team’s mission is to help Canonical, and by extension countless community members and companies around the world, secure their software infrastructure.

What you’ll do in this role

  • Build and own Canonical’s threat intelligence strategy
  • Build and maintain OSINT research environments
  • Develop OSINT tradecraft, principals, and techniques
  • Identify and track targeted intrusion cyber threats, trends, and new developments by cyber threat actors through analysis of proprietary and open source datasets 
  • Collaborate across teams to inform on activity of interest
  • Coordinate adversary/campaign tracking
  • Contribute to the wider threat intelligence community, establishing Canonical as a key contributor and thought leader in the space
  • Work with product and engineering teams to explain cybersecurity threats and advise on mitigation strategies
  • Work with the OPSEC and IS team to help implement/update security controls prioritising cyber defence
  • Identify intelligence gaps and propose new tools and research projects to fill them
  • Conduct briefings for executives, internal stakeholders and external customers

The successful Threat Intelligence Lead will be

  • An experienced threat intelligence leader (or similar)
  • Knowledgeable about the current open source threat landscape and computer networking/infrastructure concepts
  • Highly competent with OSINT tools (e.g., Buscador, Trace Labs OSINT VM, OSINT Framework, Maltego, Shodan, social media scraping tools, etc.)
  • Able to identify, organise, catalogue, and track adversary tradecraft trends — often with incomplete data
  • Experienced using threat intelligence data to influence enterprise architecture or product development decisions
  • An excellent communicator with the ability to clearly articulate and tailor technical content to a variety of audiences
  • Able to travel twice a year, for company events up to two weeks long

Desired Characteristics

  • A professional portfolio of OSINT related scripts, tools, or frameworks
  • Demonstrated involvement in the larger OSINT community (please share relevant links)
  • Degree qualified, with a bachelor’s degree in computer science, information security, or a related field
  • Certifications in related areas (e.g. GOSI, SANS SEC487 & SEC587, IntelTechniques OSIP, etc)
  • Experience in a tech company or government/military signal intelligence departments

What we offer you

We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.

  • Distributed work environment with twice-yearly team sprints in person
  • Personal learning and development budget of USD 2,000 per year
  • Annual compensation review
  • Recognition rewards
  • Annual holiday leave
  • Maternity and paternity leave
  • Employee Assistance Programme
  • Opportunity to travel to new locations to meet colleagues
  • Priority Pass, and travel upgrades for long haul company events

About Canonical

Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence – in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004.​ Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.

Canonical is an equal opportunity employer

We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.

#LI-remote

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

How to apply

Did you apply? Let us know, and we’ll help you track your application.

See a few more

Similar Cybersecurity remote jobs

Jobs Talent Salaries
Menu