Security Risk Management Lead

5 days ago


London, Greater London, United Kingdom Canonical Full time

At Canonical, we're seeking a talented Security Risk Management Specialist to join our team. The successful candidate will be responsible for defining our security risk management standards and playbooks, analyzing and improving our security risk practices, and evaluating and implementing new security requirements, tools, and practices.

As a Security Risk Management Specialist, you will contribute to the development of our security risk management practice, including the creation of risk assessments, identification of security threats, and implementation of countermeasures. You will also work closely with our security leadership team to present information and influence change.

In this role, you will have the opportunity to work on a wide range of projects, from developing key risk indicators to applying statistical models to risk frameworks. You will also participate in risk management, decision-making, and collaborative discussions.

To succeed in this role, you will need to have a strong academic track record, an undergraduate degree in Computer Science or a related field, and a deep personal motivation to be at the forefront of technology security. You will also need to have excellent business English writing and presentation skills, as well as a deep technical understanding of security assessments and risk management.

We offer a competitive salary and benefits package, including a personal learning and development budget of $2,000 per year, annual compensation review, and recognition rewards. We also provide a distributed work environment with twice-yearly team sprints in person, and opportunities to travel to new locations to meet colleagues.

Apply now to join our team and contribute to the security of the wider open source ecosystem.

Responsibilities:

  • Define Canonical's security risk management standards and playbooks
  • Analyze and improve Canonical's security risk practices
  • Evaluate, select and implement new security requirements, tools, and practices
  • Grow the presence and thought leadership of Canonical security risk management practice
  • Develop Canonical security risk learning and development materials
  • Work with Security leadership to present information and influence change
  • Participate in developing key risk indicators, provide inputs to the development of key control indicators, and key performance indicators for various programs
  • Apply statistical models to risk frameworks (such as FAIR, sensitivity analysis, and others)
  • Participate in risk management, decision-making, and collaborative discussions
  • Lead quantified risk assessments and understand the value of qualitative data for improvements to quality and engineering processes
  • Interpret internal or external cyber security risk analyses in business terms and recommend a responsible course of action
  • Develop templates and materials to help with self-service risk management actions
  • Monitor and identify opportunities to improve the effectiveness of risk management processes
  • Launch campaigns to perform security assessments and help mitigate security risks across the company
  • Build evaluation methods and performance indicators to measure efficiency of security functions and capabilities

Requirements:

  • Exceptional academic track record
  • Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
  • Drive and a track record of going above-and-beyond expectations
  • Deep personal motivation to be at the forefront of technology security
  • Leadership and management ability
  • Excellent business English writing and presentation skills
  • Problem-solver with excellent communication skills, a deep technical understanding of security assessments and risk management
  • Expertise in threat modelling and risk management frameworks
  • Broad knowledge of how to operationalize the management of security risk
  • Experience in Secure Development Lifecycle and Security by Design methodology


  • London, Greater London, United Kingdom Risk Management Security Services Full time

    Job Summary:We are seeking a reliable and skilled Perimeter Security Officer to join our team at Risk Management Security Services in Chessington. As a key member of our security team, you will be responsible for ensuring the safety and security of our site.About the Role:This is a full-time permanent position, working an average of 42 hours per week on a 4...


  • London, Greater London, United Kingdom Validus Risk Management Full time

    At Validus Risk Management, we are seeking a highly skilled Financial Risk Management Specialist to join our team. This is an exciting opportunity for both personal development and professional growth in the field of risk management.About UsValidus Risk Management is an independent technology-enabled advisory firm specialising in the management of financial...


  • London, Greater London, United Kingdom Validus Risk Management Full time

    **About Validus Risk Management**We are a specialist provider of financial market risk services, working with institutional investors, fund managers, and portfolio companies to design and implement strategies to measure, manage and monitor financial market risk.**Job Summary**This is an exciting opportunity for a full-time Risk Control Analyst to join our...


  • London, Greater London, United Kingdom Alma Risk Full time

    Role OverviewThe Operations Manager will oversee the delivery of security services in the UK and abroad, ensuring consistent service delivery.This role involves managing daily security operations, including domestic and international assignments.Main ResponsibilitiesDay-to-Day Operations: Manage daily security operations, ensuring teams are well-prepared for...


  • London, Greater London, United Kingdom Alma Risk Full time

    Job Title: Security Operations ManagerJob Summary:We are seeking a highly skilled Security Operations Manager to join our team at Alma Risks. The successful candidate will be responsible for overseeing the day-to-day delivery of security services in the UK and abroad.Main Responsibilities:Manage daily security operations, including domestic and international...


  • London, Greater London, United Kingdom Currys plc Full time

    Currys plc is looking for a seasoned Security Risk Management Lead to join our team. In this role, you will be responsible for administering the policy and standards exceptions process, working with SMEs in InfoSec and technology risk functions to link exceptions to risk.About the CompanyCurrys plc is the UK's best-known retailer of tech, proud of the...


  • London, Greater London, United Kingdom Tbwa ChiatDay Inc Full time

    We are seeking a highly skilled Information Security and Risk Lead to join our team at Flo Health. As a key member of our security team, you will be responsible for designing and implementing friction-free security solutions and controls that enable us to build, grow, and deliver a trusted, secure platform for our millions of users.The ideal candidate will...


  • London, Greater London, United Kingdom Flo Health Full time

    Job DescriptionFlo Health is seeking a highly skilled Information Security and Risk Lead to join our team. As a key member of our security team, you will be responsible for designing and implementing friction-free security solutions and controls that enable us to build, grow, and deliver a trusted, secure platform for our millions of users.The ideal...


  • London, Greater London, United Kingdom LexisNexis Risk Solutions Full time

    About the CompanyLexisNexis Risk Solutions is the essential partner in the assessment of risk. We offer a multitude of solutions focused on helping businesses drive higher revenue growth, maximize operational efficiencies, and improve customer experience.As a Risk Management Technical Lead, you will be responsible for leading the delivery of projects related...


  • London, Greater London, United Kingdom Flo Full time

    About the RoleFlo is seeking a highly skilled Security Architect and Risk Management Lead to join our team. As a key member of our security team, you will be responsible for designing and implementing secure systems environments, embedding security controls, and mitigating risks within engineering and wider business processes.You will lead the security risk...

  • Cyber Security Lead

    1 month ago


    London, Greater London, United Kingdom Carrington Recruitment Solutions Full time

    Cyber Security Lead - Business Risk ManagerWe are seeking a highly skilled Cyber Security Lead to join our team at Carrington Recruitment Solutions. As a Cyber Security Lead, you will be responsible for managing business risk and ensuring the security of our clients' technology infrastructure.Key Responsibilities:Develop and implement effective security...


  • London, Greater London, United Kingdom Securitas Security Services Full time

    About the RoleJoin Securitas Security Services as a dynamic Site Security Manager in Brimsdown. We seek an exceptional leader with strong security operational management experience, capable of inspiring and motivating a team to deliver excellence.This role offers a unique opportunity to lead and manage a committed team, ensuring the highest standards of...

  • Cyber Security Lead

    4 weeks ago


    London, Greater London, United Kingdom E1 EDF Trading Ltd Full time

    Job Title: Cyber Security LeadDescription:The Cyber Security Lead role at E1 EDF Trading Ltd is a critical position that plays a key part in the company's IT Risk Management strategy. The successful candidate will be responsible for managing cyber risks and issuing globally, collaborating with the Global Head of IT Security to drive the implementation of the...

  • Security Risk Manager

    4 weeks ago


    London, Greater London, United Kingdom Compass Group UK Full time

    About the Role:We are seeking a highly skilled and dedicated Security Risk Manager to join our team in Whitehall London.The successful candidate will be responsible for implementing and monitoring safety and security protocols to protect the organization's staff, facilities, and resources.The Security Risk Manager will conduct regular patrols of the...


  • London, Greater London, United Kingdom Vertus Partners Full time

    Job SummaryWe are seeking an experienced Security Governance, Risk, and Compliance (GRC) Manager to join our team at Vertus Partners. The successful candidate will be responsible for overseeing the security compliance and governance activities of our organisation, ensuring that regulatory requirements are met and robust security practices are...


  • London, Greater London, United Kingdom City Facilities Management Full time

    About City Facilities ManagementCity Refrigeration Holdings was founded in 1985 by Willie and Susan Haughey, who aimed to revolutionize the facilities management industry. By focusing on collaboration and transparency, they created a unique business model that replaced traditional client-contractor relationships with long-term, mutually beneficial...


  • London, Greater London, United Kingdom Genius Sports Full time

    About Genius SportsGenius Sports is a leading sports technology company that captures, processes, and activates sports data across performance analysis, fan engagement, advertising, and sports betting.We are at the forefront of the global network connecting sports, brands, and fans through official live data. Our mission is to build a more sustainable sports...

  • Risk Management Lead

    4 weeks ago


    London, Greater London, United Kingdom TalentHawk Full time

    Cloud Security Posture Management SME RoleOur client is seeking a highly experienced Cloud Security Posture Management (CSPM) Subject Matter Expert (SME) to lead the development and execution of a comprehensive cloud security posture strategy.The CSPM SME will define and implement a CSPM managed security service (MSS), provide best practice guidance for...


  • London, Greater London, United Kingdom TEKsystems Full time

    This is a proactive role that requires a security and risk manager to ensure the organisation's assets are protected and compliant with relevant standards and regulations.Key ResponsibilitiesAssist regional Information Security and IT Risk managers with routine review and approval activities.Provide expert assistance for resolving technical security...


  • London, Greater London, United Kingdom Arup Full time

    Arup's Security Advisory stream provides services across the region and worldwide as part of Arup's global Resilience, Security & Risk offering. Our services include threat and risk analysis, threat, vulnerability and risk assessment, security intelligence, travel risk assessment, strategic security design, regulatory and policy affairs, and advice on...