# Threat Intelligence Lead

Remote from🌐 AnywhereAnnual salary Undisclosed Salary information is not provided for this position.
Check our [Salary Directory](https://jobicy.com/salaries.md) to estimate the average compensation for similar roles.Department  [Cybersecurity](https://jobicy.com/categories/cybersecurity.md) Employment type Full Time, Job posted21 Jul 2026Apply before21 Aug 2026Experience level  Senior
Views / Applies 66 / 3 [About company](https://jobicy.com/company/canonical-ltd.md)

* Share About [Canonical Ltd.](https://jobicy.com/company/canonical-ltd.md)

Trusted open source for enterprises

[Computer Software](https://jobicy.com/company-category/software.md)
*  2004

Actively Hiring  Verified job posting This job post has been [manually reviewed](https://jobicy.com/tools/help-center/employee/how-does-jobicy-verify-the-legitimacy-of-remote-job-listings.md) for authenticity and compliance.

###  AI Summary

Canonical is seeking a Threat Intelligence Lead to own their threat intelligence strategy, focusing on cyber threat actors targeting the company and the open source ecosystem. The role involves OSINT research, tracking adversary tactics, and collaborating with internal teams and the wider cybersecurity community. The ideal candidate is an experienced threat intelligence leader with strong OSINT skills and the ability to influence security decisions. This is a remote position with twice-yearly travel, reporting to the CISO. The role offers the opportunity to contribute to securing software infrastructure used globally.

### Role DNA

Job Complexity Easy Hard Pace & Pressure Relaxed Fast-paced Autonomy Level Guided Full Ownership Communication Load Independent Highly Collaborative

AI Insight This role requires deep expertise in threat intelligence, OSINT, and strategic leadership, making it challenging but not entry-level. The need to influence product development and communicate with executives adds complexity.

### Salary Analysis

Median  Highly Competitive  $150,000US Market $120k – 180k 0 $198k      AI Insight The salary is not specified in the listing, but based on market data for similar roles in the US, the estimated median is $150,000, which is competitive for a lead threat intelligence position at a tech company.

### Core Skills Required

[Threat Intelligence](https://jobicy.com/jobs?search_keywords=Threat+Intelligence.md) [OSINT](https://jobicy.com/jobs?search_keywords=OSINT.md) [Cyber Threat Analysis](https://jobicy.com/jobs?search_keywords=Cyber+Threat+Analysis.md) [TTP Research](https://jobicy.com/jobs?search_keywords=TTP+Research.md) [Security Strategy](https://jobicy.com/jobs?search_keywords=Security+Strategy.md) [Open Source Security](https://jobicy.com/jobs?search_keywords=Open+Source+Security.md) [Maltego](https://jobicy.com/jobs?search_keywords=Maltego.md) [Shodan](https://jobicy.com/jobs?search_keywords=Shodan.md) [Intel Gathering](https://jobicy.com/jobs?search_keywords=Intel+Gathering.md) [Executive Briefing](https://jobicy.com/jobs?search_keywords=Executive+Briefing.md)

### Cover Letter Sample

Dear Hiring Manager,

I am excited to apply for the Threat Intelligence Lead role at Canonical. With over 8 years of experience in cyber threat intelligence and OSINT, I have a proven track record of building and executing intelligence strategies that protect critical infrastructure. I am particularly drawn to this role because of Canonical's impact on the open source community and the opportunity to serve as a thought leader in this space.

In my previous role, I led a team that tracked advanced persistent threats targeting software supply chains, using tools like Maltego and Shodan to develop actionable intelligence. I also collaborated with engineering teams to integrate threat data into product development, reducing risk for millions of users. I am confident that my expertise in adversary tracking and strategic communication will enable me to drive Canonical's threat intelligence program effectively.

I look forward to discussing how I can contribute to your team.

Sincerely,
[Your Name]

Copy

### Sample Interview Questions

Describe your experience building a threat intelligence program from scratch. What were the key challenges and how did you overcome them?In my previous role, I built a threat intelligence program for a mid-size tech company. Key challenges included defining intelligence requirements with no existing framework and gaining buy-in from engineering teams. I started by conducting stakeholder interviews and focusing on high-impact threats to the software supply chain. I implemented OSINT tools like Maltego and automated data collection, which improved detection of targeted intrusions. I also established regular briefings to demonstrate value, which helped secure resources for expansion.How do you prioritize which threat actors or campaigns to track given limited resources?I prioritize based on a combination of factors: relevance to our industry, likelihood of targeting our organization or customers, and potential impact. I use a threat modeling framework to assess actor capabilities and intentions. I also stay updated on community reports and intelligence sharing platforms. For example, if a state-sponsored group is known to target open source package managers, I would allocate more resources to tracking that activity. Regular reviews ensure the priorities align with evolving threats.Can you walk me through your process for conducting OSINT research on a specific threat actor?I start by defining the actor's known identifiers (e.g., infrastructure, tools, TTPs) based on existing reports. Then I use tools like Shodan to discover associated servers, Maltego for relationship mapping, and social media scraping for persona tracking. I document findings in a structured format, cross-referencing with open source intelligence to validate. I also maintain a sandbox environment for testing indicators. The output is a tactical report with actionable indicators for defensive teams.How do you communicate threat intelligence findings to non-technical executives?I tailor communications by focusing on business impact and risk, avoiding technical jargon. For executives, I use visual aids like heat maps or timelines to show the threat landscape and current mitigation status. I highlight concrete recommendations and resource needs. For example, I might say 'We have observed increased targeting of our deployment pipelines by a sophisticated actor; I recommend accelerating our software supply chain security enhancements.' This ensures clear decision-making.How do you stay current with evolving TTPs and the threat landscape?I actively participate in threat intelligence sharing communities like FS-ISAC and attend industry conferences. I follow OSINT and threat research blogs, and use automated feeds to track indicators. I also allocate time for hands-on research, such as setting up honeypots or analyzing new malware strains. Additionally, I contribute to open source threat intelligence projects, which helps me learn from peers and share insights.  The Threat Intelligence Lead will own Canonical’s threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and Procedures (TTP) to better our products and internal cybersecurity controls. You will collaborate with internal stakeholders as well as with the wider cybersecurity community, making sure that Canonical is recognised as a thought leader on open source threat intelligence.

This role will report to the CISO.

You will lead intelligence gathering and development activities on threat actors targeting software supply chains. You’ll study attack trends across the wider open source software landscape, report findings to internal security teams, and advise the wider engineering community on the best course of action to detect and mitigate possible threats.

As the publisher of Ubuntu, Canonical products are directly or indirectly present in almost every organisation and household in the world, making them a prime target for threat actors. This team’s mission is to help Canonical, and by extension countless community members and companies around the world, secure their software infrastructure.

## What you’ll do in this role

* Build and own Canonical’s threat intelligence strategy
* Build and maintain OSINT research environments
* Develop OSINT tradecraft, principals, and techniques
* Identify and track targeted intrusion cyber threats, trends, and new developments by cyber threat actors through analysis of proprietary and open source datasets
* Collaborate across teams to inform on activity of interest
* Coordinate adversary/campaign tracking
* Contribute to the wider threat intelligence community, establishing Canonical as a key contributor and thought leader in the space
* Work with product and engineering teams to explain cybersecurity threats and advise on mitigation strategies
* Work with the OPSEC and IS team to help implement/update security controls prioritising cyber defence
* Identify intelligence gaps and propose new tools and research projects to fill them
* Conduct briefings for executives, internal stakeholders and external customers

## The successful Threat Intelligence Lead will be

* An experienced threat intelligence leader (or similar)
* Knowledgeable about the current open source threat landscape and computer networking/infrastructure concepts
* Highly competent with OSINT tools (e.g., Buscador, Trace Labs OSINT VM, OSINT Framework, Maltego, Shodan, social media scraping tools, etc.)
* Able to identify, organise, catalogue, and track adversary tradecraft trends — often with incomplete data
* Experienced using threat intelligence data to influence enterprise architecture or product development decisions
* An excellent communicator with the ability to clearly articulate and tailor technical content to a variety of audiences
* Able to travel twice a year, for company events up to two weeks long

## Desired Characteristics

* A professional portfolio of OSINT related scripts, tools, or frameworks
* Demonstrated involvement in the larger OSINT community (please share relevant links)
* Degree qualified, with a bachelor’s degree in computer science, information security, or a related field
* Certifications in related areas (e.g. GOSI, SANS SEC487 & SEC587, IntelTechniques OSIP, etc)
* Experience in a tech company or government/military signal intelligence departments

## What we offer you

We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.

* Distributed work environment with twice-yearly team sprints in person
* Personal learning and development budget of USD 2,000 per year
* Annual compensation review
* Recognition rewards
* Annual holiday leave
* Maternity and paternity leave
* Employee Assistance Programme
* Opportunity to travel to new locations to meet colleagues
* Priority Pass, and travel upgrades for long haul company events

## About Canonical

Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence – in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004.​ Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.

## Canonical is an equal opportunity employer

We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. [Whatever your identity, we will give your application fair consideration.](https://canonical.com/careers/diversity/identity)

#LI-remote

Show more

[Apply now >](https://jobicy.com/jobs/149542-threat-intelligence-lead.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

## How to apply

## See a few more

Similar Cybersecurity remote jobs

*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Senior Security Operations Engineer](https://jobicy.com/jobs/149578-senior-security-operations-engineer.md)

The Canonical Security Operations team is hiring for a Senior or Staff engineer. The Security Operations team is responsible for designing, building, and operating a world-class Security Operations Center, and…

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Ubuntu Security Engineer](https://jobicy.com/jobs/149565-ubuntu-security-engineer.md)

Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is very widely used in breakthrough enterprise initiatives…

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Security Risk Management Specialist](https://jobicy.com/jobs/149564-security-risk-management-specialist.md)

In security risk management we’re looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security…

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Security Software Engineer](https://jobicy.com/jobs/149550-security-software-engineer.md)

Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is widely used in breakthrough enterprise initiatives such…

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Head of Security Operations](https://jobicy.com/jobs/149541-head-of-security-operations.md)

This global leadership role in cyber security is to manage the Security Operations (SecOps) team responsible for design, implementation and evolution of Canonical security practices, techniques, tools, systems and policies….

🌐 Anywhere•Full TimeNEW*
![Canonical Ltd. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)

Canonical Ltd.

### [Staff Security Operations Engineer](https://jobicy.com/jobs/149540-staff-security-operations-engineer.md)

We have opened several senior/staff Security Operations Engineer (SOC) positions, creating a new team reporting to the CISO. We are looking for a range of experience in these positions –…

🌐 Anywhere•Full TimeNEW*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)

Synthesia

### [Application Security Engineering Manager](https://jobicy.com/jobs/146803-application-security-engineering-manager.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…

![UK flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/gb.svg)

![Europe flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/eu.svg)
GB, EU•Full TimeJul 18*
![Experian logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/dcc5b29a570bb19b9f5c3e150db2fdfe.jpg)

Experian

### [Cyber Defense Senior Analyst](https://jobicy.com/jobs/146651-cyber-defense-senior-analyst.md)

Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,…

![USA flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/us.svg)
US•Full TimeJul 17*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)

Nebius

### [Application Security Engineer](https://jobicy.com/jobs/146769-application-security-engineer-2.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

![UK flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/gb.svg)

![Europe flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/eu.svg)
GB, EU +3 more, DE, NL, CZ•Full TimeEUR 75k-240k/year*
![Experian logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/dcc5b29a570bb19b9f5c3e150db2fdfe.jpg)

Experian

### [Cyber Defense Senior Analyst](https://jobicy.com/jobs/149401-cyber-defense-senior-analyst-2.md)

Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,…

![USA flag](https://cloud.jobicy.com/nyc4-cold/img/round-flags/us.svg)
US•Full TimeJul 17
[More Jobs](https://jobicy.com/jobs.md)