Senior Security Operations Engineer

Remote from
🌐 Anywhere
Annual salary
Undisclosed
Salary information is not provided for this position. Check our Salary Directory to estimate the average compensation for similar roles.
Department
Cybersecurity
Employment type
Full Time,
Job posted
Apply before
21 Aug 2026
Experience level
Senior
Views / Applies
58 / 4

About Canonical Ltd.

Trusted open source for enterprises

Actively Hiring
Verified job posting
This job post has been manually reviewed for authenticity and compliance.

AI Summary

Canonical is seeking a Senior Security Operations Engineer to lead and build a world-class SOC. The role combines traditional SOC duties with software engineering, SRE, and security engineering. The ideal candidate has 10+ years of experience, a STEM degree, and proficiency in Python, Bash, Git, and Kubernetes. This is a unique opportunity to contribute to open source security and work in a distributed team with global impact. The position offers a competitive compensation package including a performance bonus and professional development budget.

Role DNA

Job Complexity
Easy Hard
Pace & Pressure
Relaxed Fast-paced
Autonomy Level
Guided Full Ownership
Communication Load
Independent Highly Collaborative
AI Insight The role requires deep expertise across security operations, software engineering, and leadership, with 10+ years of experience and the ability to mentor and drive SOC strategy.

Salary Analysis

Median Highly Competitive
$160,000
US Market
$120k – 200k
0 $220k
AI Insight The offered salary is not specified, but based on the senior level and required experience, the market median for similar roles is approximately $160,000. Canonical's compensation is globally competitive and includes performance bonuses and annual reviews.
Dear Hiring Team,

I am excited to apply for the Senior Security Operations Engineer position at Canonical. With over 10 years of experience in cybersecurity and software engineering, I have built and led SOC teams, developed custom security tools, and contributed to open source projects. My background in Python, Bash, and Kubernetes aligns perfectly with your requirements for this role.

I am passionate about securing digital estates and thrive in fast-paced, collaborative environments. At my previous company, I implemented security monitoring and incident response processes that reduced response times by 40%. I also mentored junior engineers and published threat intelligence reports.

Canonical's commitment to open source and global impact is inspiring. I am eager to bring my technical expertise and leadership to your team, further strengthening your SOC and contributing to the open source security community.

Thank you for considering my application. I look forward to the possibility of discussing how my skills can benefit Canonical.

Sincerely, [Your Name]
Describe a complex security incident you managed from detection to remediation. What steps did you take and what tools did you use?
In a previous role, I detected a sophisticated APT leveraging a zero-day vulnerability. I immediately isolated affected systems, initiated forensic imaging, and analyzed logs with Elasticsearch and Kibana. I coordinated with the threat intelligence team to identify IOCs, then deployed custom YARA rules for detection. Post-incident, I led a tabletop exercise to improve response procedures.
How would you design a scalable SOC for a global company like Canonical?
I would implement a cloud-native SOC using a SIEM like Splunk or Elastic, integrated with SOAR for automation. Key components: log aggregation from all endpoints and cloud services, threat intelligence feeds, and automated playbooks for common alerts. I'd also establish 24/7 monitoring with tiered response and use machine learning for anomaly detection.
Explain a time you had to mentor a junior engineer. How did you approach it and what was the outcome?
I paired a junior engineer with me during a major threat hunt. I explained our methodology, reviewed their analysis, and provided constructive feedback. Over three months, they independently identified a critical misconfiguration. I also encouraged them to attend security conferences, which boosted their confidence and skills.
How do you stay current with evolving security threats and technologies?
I follow industry blogs (e.g., Krebs, SANS), participate in Bug Bounty programs, and contribute to open source security projects. I also attend conferences like RSA and Black Hat. For hands-on practice, I maintain a homelab with various tools and simulate attacks using Kali Linux.
Can you walk us through your experience with Kubernetes security?
I have deployed and secured Kubernetes clusters using pod security policies, network policies (Calico), and runtime security with Falco. I've also implemented Image scanning via Trivy, secret management with Vault, and CIS benchmarks. In one case, I discovered a privilege escalation vulnerability and patched it by enforcing RBAC.

The Canonical Security Operations team is hiring for a Senior or Staff engineer. The Security Operations team is responsible for designing, building, and operating a world-class Security Operations Center, and the successful candidate will provide leadership, mentorship, expertise, and outstanding individual contributions towards those ends.

This role involves aspects of:

  • Traditional SOC duties – security monitoring, threat hunting, and response.
  • Security engineering – assessing and protecting Canonical platforms and products.
  • Software engineering – building custom tools and platforms.
  • Site reliability engineering – deploying, maintaining, and automating security tools.

We are looking for individuals with engineering and security experience, as well as a history of remarkable achievement. Senior security operations personnel with engineering experience and senior developers with security experience are equally well-suited to this role.

Beyond securing Canonical’s digital estate, this position represents a unique opportunity to contribute to the open source ecosystem. Team members may present at industry conferences, share threat intelligence with the wider community, or publish open source security software.

Junior positions are also available for less-experienced individuals with a compelling academic or professional background.

In this role, you will:

  • Provide operational and engineering leadership.
  • Implement and evolve Canonical’s Security Operations Center.
  • Design and develop security software and platforms.
  • Monitor for, identify, respond to, and remediate security incidents.
  • Assess and improve Canonical’s security controls.
  • Mentor early-career Security Operations engineers.
  • Plan and deliver work within Canonical’s agile engineering framework.
  • Contribute to open source security.
  • Publish blog posts, whitepapers and conference presentations.

We are looking for:

  • An exceptional academic track record.
  • Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path.
  • 10+ years of relevant professional experience
  • Professional cybersecurity experience, preferably working or leading a Security Operations Center.
  • Professional engineering experience.
  • An eagerness to contribute to open source security.
  • Proficiency in common scripting languages, such as Python and Bash.
  • Knowledge of Git, GitOps, Infrastructure-as-Code, and common orchestration platforms (e.g., Kubernetes)

Though optional, we value:

  • Familiarity with security frameworks such as the NIST CSF, CIS CSC, and ISO 27001
  • Knowledge of security architecture and market-leading security tools.
  • Experience in a security operations team or a security operations center.
  • Experience in offensive or defensive security teams with hands-on ability.
  • Experience with advanced persistent threats.
  • Proficiency in additional programming languages, such as Golang.

What we offer you:

We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.

  • Distributed work environment with twice-yearly team sprints in person
  • Personal learning and development budget of USD 2,000 per year
  • Annual compensation review
  • Recognition rewards
  • Annual holiday leave
  • Maternity and paternity leave
  • Employee Assistance Programme
  • Opportunity to travel to new locations to meet colleagues
  • Priority Pass, and travel upgrades for long haul company events

About Canonical

Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence – in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004.​ Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.

Canonical is an equal opportunity employer

We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.

#LI-remote

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

How to apply

Did you apply? Let us know, and we’ll help you track your application.

See a few more

Similar Cybersecurity remote jobs

Jobs Talent Salaries
Menu