Threat Intelligence Lead

6 months ago


London, United Kingdom Canonical Full time

The Threat Intelligence Lead will own Canonical’s threat intelligence strategy and execution, including understanding of which cyber threat actors are targeting Canonical, and the use of intelligence on Tactics, Techniques and Procedures (TTP) to better our products and internal cybersecurity controls. You will collaborate with internal stakeholders as well as with the wider cybersecurity community, making sure that Canonical is recognised as a thought leader on open source threat intelligence.

This role will report to the CISO.

You will lead intelligence gathering and development activities on threat actors targeting software supply chains. You'll study attack trends across the wider open source software landscape, report findings to internal security teams, and advise the wider engineering community on the best course of action to detect and mitigate possible threats.

As the publisher of Ubuntu, Canonical products are directly or indirectly present in almost every organisation and household in the world, making them a prime target for threat actors. This team's mission is to help Canonical, and by extension countless community members and companies around the world, secure their software infrastructure.

What you’ll do in this role

Build and own Canonical’s threat intelligence strategy Build and maintain OSINT research environments Develop OSINT tradecraft, principals, and techniques Identify and track targeted intrusion cyber threats, trends, and new developments by cyber threat actors through analysis of proprietary and open source datasets  Collaborate across teams to inform on activity of interest Coordinate adversary/campaign tracking Contribute to the wider threat intelligence community, establishing Canonical as a key contributor and thought leader in the space Work with product and engineering teams to explain cybersecurity threats and advise on mitigation strategies Work with the OPSEC and IS team to help implement/update security controls prioritising cyber defence Identify intelligence gaps and propose new tools and research projects to fill them Conduct briefings for executives, internal stakeholders and external customers

The successful Threat Intelligence Lead will be

An experienced threat intelligence leader (or similar) Knowledgeable about the current open source threat landscape and computer networking/infrastructure concepts Highly competent with OSINT tools (e.g., Buscador, Trace Labs OSINT VM, OSINT Framework, Maltego, Shodan, social media scraping tools, etc.) Able to identify, organise, catalogue, and track adversary tradecraft trends — often with incomplete data Experienced using threat intelligence data to influence enterprise architecture or product development decisions An excellent communicator with the ability to clearly articulate and tailor technical content to a variety of audiences Able to travel twice a year, for company events up to two weeks long

Desired Characteristics

A professional portfolio of OSINT related scripts, tools, or frameworks Demonstrated involvement in the larger OSINT community (please share relevant links) Degree qualified, with a bachelor's degree in computer science, information security, or a related field Certifications in related areas (e.g. GOSI, SANS SEC & SEC, IntelTechniques OSIP, etc) Experience in a tech company or government/military signal intelligence departments

What we offer you

We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.

Distributed work environment with twice-yearly team sprints in person Personal learning and development budget of USD 2, per year Annual compensation review Recognition rewards Annual holiday leave Maternity and paternity leave Employee Assistance Programme Opportunity to travel to new locations to meet colleagues Priority Pass, and travel upgrades for long haul company events

  • London, Greater London, United Kingdom Palo Alto Networks Full time

    About the Role:As a key member of our Unit 42 National Security Team (NATSEC), you will be part of a globally distributed team of vulnerability researchers, reverse engineers, and threat intelligence analysts. You will be embedded in a customer environment to track advanced persistent threats in support of sensitive customer intelligence requirements. We are...


  • London, Greater London, United Kingdom Bupa Full time

    About the RoleThis is a unique opportunity to join Bupa's Global Functions team as a Threat Intelligence Analyst Lead. We are looking for a highly skilled individual to lead our threat intelligence capabilities, developing processes where automation has the potential to improve efficiency.As a seasoned threat intelligence expert, you will have extensive...


  • London, Greater London, United Kingdom Canonical Full time

    The Threat Intelligence Lead will be responsible for developing and executing Canonical's threat intelligence strategy, including identifying and tracking targeted intrusion cyber threats, trends, and new developments by cyber threat actors through analysis of proprietary and open source datasets.This role will involve collaborating with internal...


  • London, United Kingdom Foundations Executive Search Full time

    **Lead in Cyber Threat Intelligence** Remote / London - **1 day in the office per month, only **(London area) - up to Circa 80K + Excellent Benefits. **Please note that due to new CTC vetting requirements, this role is only available to individuals who have resided in the UK for at least the last three years.** Foundations Executive Search has the...


  • London, Greater London, United Kingdom Hunter Bond Full time

    Threat Intelligence LeadHunter Bond is seeking a highly skilled Threat Intelligence Lead to join its newly created team. As part of the enterprise and risk teams, you will report directly to the Chief Security Officer and contribute to threat and risk management across the organization.This role is critical in mitigating risks, reducing losses, and...


  • London, Greater London, United Kingdom Hunter Bond Full time

    A leading global bank are now seeking a Threat Intelligence Response Lead to join its newly created team on contract. As part of their enterprise and risk teams, you will be part of the critical business unit reporting up to the Chief Security Officer.This team are new to London and contribute to threat and risk management that spans the organisation to...


  • London, Greater London, United Kingdom Deutsche Bank Full time

    Data Protection and Threat Intelligence LeadDeutsche Bank is seeking a highly skilled Data Protection and Threat Intelligence Lead to join our team. The successful candidate will be responsible for leading the company's cyber threat intelligence and vulnerability management capability.The role involves tailoring threat intelligence to meet the needs of a...


  • London, United Kingdom Control Risks Full time

    To conduct open-source intelligence research to support a complex and fast-paced threat intelligence programme. **Role tasks and responsibilities** Intelligence Collection and Analysis - Gather information on individuals and groups posing a threat to our client and their assets through open-source intelligence (OSINT) and social media intelligence...


  • London, Greater London, United Kingdom Palo Alto Networks Full time

    About the Role: As a Cybersecurity Threat Intelligence Lead, you will play a key part in our National Security Team's efforts to understand and counter advanced persistent threats. Your expertise will be invaluable in tracking malicious cyber actors, their infrastructure, and campaigns.


  • London, Greater London, United Kingdom Canonical Full time

    Job Title: Threat Intelligence StrategistJob Summary: Canonical is seeking a Threat Intelligence Strategist to own the company's threat intelligence strategy and execution. The ideal candidate will have experience in threat intelligence leadership and be knowledgeable about the current open source threat landscape.Develop and maintain Canonical's threat...


  • London, United Kingdom M&S Full time

    **All the details** **Summary** Marks & Spencer is actively searching for a skilled Threat Intelligence Specialist to fortify our cybersecurity efforts. This crucial role involves identifying and analysing cyber threats, utilizing advanced threat intelligence tools and methodologies to safeguard our digital infrastructure. Collaborating with our dedicated...


  • London, Greater London, United Kingdom Control Risks Full time

    Job SummaryWe are seeking a highly motivated Cyber Threat Intelligence Lead Analyst to join our team at Control Risks in London. The ideal candidate will have a strong background in cyber security and intelligence analysis, with experience in threat assessment, client engagement, and project management.About the RoleThis is a senior-level position that...


  • London, Greater London, United Kingdom Control Risks Full time

    We are seeking a Senior Analyst to join our Cyber Threat Intelligence team in London. As Senior Analyst, your role involves managing, producing and reviewing analysis of current and future cyber threats to all business sectors and to public sector organisations. You will support business development, sales and marketing activities of the team as relevant to...


  • London, Greater London, United Kingdom undisclosed Full time

    The Cyber Threat Intelligence Analyst will play a key role in better understanding and assessing cyber threats that are likely to impact the organisation. They will demonstrate an ability to apply technical insights and knowledge of global events and threat actors to produce practical actionable security intelligence.The Analyst will understand strategic...


  • London, Greater London, United Kingdom PDS Cyber Services Full time

    About the RolePDS Cyber Services are seeking a highly skilled Cyber Threat Intelligence Specialist to join their team. As a key member of the Threat Intelligence team, you will play a crucial role in developing awareness for the policing community of cyber risks and informing stakeholders.Key ResponsibilitiesDevelop and deliver cybercrime and risk reduction...


  • London, Greater London, United Kingdom undisclosed Full time

    A leading global bank seeks a Threat Intelligence Response Lead to join its newly created team on contract. In this role, you will be part of the critical business unit reporting up to the Chief Security Officer.About the RoleThis team is new to London and contributes to threat and risk management that spans the organisation to mitigate risks, reduce losses,...


  • London, Greater London, United Kingdom Bupa Full time

    Role RequirementsWe are seeking an experienced Cyber Threat Intelligence Professional to join our team in London or Staines. The successful candidate will be responsible for assessing and analysing strategic threat intelligence to support Bupa's business operations worldwide.The role requires strong technical skills, including experience with collection,...


  • London, Greater London, United Kingdom M-KOPA-SOLAR Full time

    About M-KOPA-SOLARM-KOPA-SOLAR is a leading company in the solar industry, recognized for its innovative approach to providing energy solutions to underserved communities. As a Junior Threat Intelligence Analyst, you will be part of our Threat Intelligence team, responsible for identifying and assessing threats against our products, business, and...


  • London, Greater London, United Kingdom Hunter Bond Full time

    Job Title: Financial Security SpecialistHunter Bond is a global bank seeking a highly skilled individual to lead its Threat Intelligence Response team. As a key member of the enterprise and risk teams, you will contribute to the development and implementation of strategies to mitigate risks, reduce losses, and protect against financial crimes.The ideal...


  • London, Greater London, United Kingdom Hunter Bond Full time

    We are seeking a Threat Intelligence Manager to join our newly created team at Hunter Bond in London.As part of the enterprise and risk teams, you will be responsible for managing threat and risk across the organisation and contributing to event management to resolve issues quickly.Key responsibilities include:Providing specialised advice and analysis on...