Security Risk Management Specialist

hace 2 meses


Madrid, España Canonical A tiempo completo
In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do.

To support this we need to use industry best practices paired with emerging threat information to to promote risk identification, quantification, impact analysis, and modelling to ultimately drive decision making. In this role, you will help establish and execute a broad strategic vision for the security risk program at Canonical. You will not only work within the team but also cross-functionally with various teams across the organisation. The team contributes ideas and requirements for Canonical product security, improving the resilience and robustness of all Ubuntu customers and users subject to cyber attacks. Additionally, the team collaborates with our Organisational Learning and Development team to develop playbooks and facilitate security training across Canonical.

The security risk management team's mission is not only to secure Canonical, but also to contribute to the security of the wider open source ecosystem. They might share knowledge through public presentations and industry events, and share threat intelligence with the wider community or represent Canonical in sector-specific governance bodies.

What you will do in this role:

  • Define Canonical's security risk management standards and playbooks
  • Analyse and improve Canonical's security risk practices
  • Evaluate, select and implement new security requirements, tools and practices
  • Grow the presence and thought leadership of Canonical security risk management practice
  • Develop Canonical security risk learning and development materials
  • Work with Security leadership to present information and influence change
  • Participate in developing key risk indicators, provide inputs to the development of key control indicators, and key performance indicators for various programs
  • Apply statistical models to risk frameworks (such as FAIR, sensitivity analysis, and others)
  • Participate in risk management, decision-making, and collaborative discussions
  • Lead quantified risk assessments and understand the value of qualitative data for improvements to quality and engineering processes
  • Interpret internal or external cyber security risk analyses in business terms and recommend a responsible course of action
  • Develop templates and materials to help with self-service risk management actions
  • Monitor and identify opportunities to improve the effectiveness of risk management processes
  • Launch campaigns to perform security assessments and help mitigate security risks across the company
  • Build evaluation methods and performance indicators to measure efficiency of security functions and capabilities.

    What we are looking for

    • An exceptional academic track record
    • Undergraduate degree in Computer Science or STEM, or a compelling narrative about your alternative path
    • Drive and a track record of going above-and-beyond expectations
    • Deep personal motivation to be at the forefront of technology security
    • Leadership and management ability
    • Excellent business English writing and presentation skills
    • Problem-solver with excellent communication skills, a deep technical understanding of security assessments and risk management
    • Expertise in threat modelling and risk management frameworks
    • Broad knowledge of how to operationalize the management of security risk
    • Experience in Secure Development Lifecycle and Security by Design methodology

      What we offer you

      We consider geographical location, experience, and performance in shaping compensation worldwide. We revisit compensation annually (and more often for graduates and associates) to ensure we recognise outstanding performance. In addition to base pay, we offer a performance-driven annual bonus. We provide all team members with additional benefits, which reflect our values and ideals. We balance our programs to meet local needs and ensure fairness globally.

      • Distributed work environment with twice-yearly team sprints in person
      • Personal learning and development budget of USD 2,000 per year
      • Annual compensation review
      • Recognition rewards
      • Annual holiday leave
      • Maternity and paternity leave
      • Employee Assistance Programme
      • Opportunity to travel to new locations to meet colleagues
      • Priority Pass, and travel upgrades for long haul company events

        About Canonical

        Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis. We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do. Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.

        Canonical is an equal opportunity employer

        We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products. Whatever your identity, we will give your application fair consideration.



  • Madrid, España Sdi Digital Group A tiempo completo

    Description As IT Risk & Compliance Specialist, your mission is to keep key IT risks away from Hitachi Energy. You are responsible for IT risk monitoring and reporting and IT risk & compliance assurance for the whole organization. You facilitate effective IT risk & compliance decisions by defining, maintaining, communicating and promoting IT risks &...


  • Madrid, España Apollo Solutions A tiempo completo

    **Cloud Security Risk Lead** Location: Madrid, Spain Salary €60K - €65K plus benefits & bonus A great opportunity for a **Cloud Security Risk Lead** to join a leading Banking organisation based in the **Madrid, Spain**. This position will have a strong focus on Business Continuity and Technology Resilience. **As a Cloud Security Risk Lead, you will be...


  • Madrid, España Apollo Solutions A tiempo completo

    Cloud Security Risk Lead **Location**: Madrid, Spain Salary €60K - €65K plus benefits & bonus A great opportunity for a Cloud Security Risk Lead to join a leading Banking organisation based in the Madrid, Spain. This position will have a strong focus on Business Continuity and Technology Resilience. **As a Cloud Security Risk Lead, you...


  • Madrid, España BNP Paribas A tiempo completo

    The RISK ORM (Operational Risk Management) Technology Risk Intelligence Digital Solutions department is part of the Group Risk Functions within BNP Paribas. It is a part of the 2nd line of defence under the Bank’s Enterprise Risk Management and Chief Operational Risk Officer. The department has responsibility for identification of key technology risks to...


  • Madrid, España Sdi Digital Group A tiempo completo

    Description As IT Risk & Compliance Specialist, your mission is to keep key IT risks away from Hitachi Energy. You are responsible for IT risk monitoring and reporting and IT risk & compliance assurance for the whole organization. You facilitate effective IT risk & compliance decisions by defining, maintaining, communicating and promoting IT risks &...


  • Madrid, España HITACHI ENERGY SERVICES SP. Z O.O. A tiempo completo

    Description : As IT Risk & Compliance Specialist, your mission is to keep key IT risks away from Hitachi Energy. You are responsible for IT risk monitoring and reporting and IT risk & compliance assurance for the whole organization. You facilitate effective IT risk & compliance decisions by defining, maintaining, communicating and promoting IT risks &...


  • Madrid, España Hitachi Automotive Systems Americas, Inc. A tiempo completo

    IT Risk and Compliance Specialist page is loaded IT Risk and Compliance Specialist Apply locations Madrid, Spain time type Full time posted on Posted 2 Days Ago job requisition id R0028491 Location: Madrid, SpainJob ID: R0028491Date Posted: 2023-08-01Company Name: HITACHI ENERGY SERVICES SP. Z O.O.Profession (Job Category): General ManagementJob...


  • Madrid, España Paritas Recruitment - Risk A tiempo completo

    K Posted byManager – Risk Management & Quantitative AnalyticsA dynamic and progressive Consulting firm are seeking a bilingual ESG Risk Manager for their office in Madrid.ESG Risk Manager – Management Consulting (Madrid) A leading boutique Consulting firm is seeking an ESG Risk Manager to join their team in Madrid. You will have recent experience...

  • OT Security Specialist

    hace 1 semana


    Madrid, España dormakaba A tiempo completo

    We are one of the top three companies in the global market for access and security solutions and we are currently looking for an experienced OT Security Specialist who will be working supporting the dormakaba IT/OT Cyber Security team in setting up and operating the organization, processes and technology to implement the IT security goals in the OT...


  • Madrid, España Page Personnel A tiempo completo

    Empresa en pleno crecimiento|Desarrollo y crecimientoMultinational companyLiaise between business users and developers during test period.Take ownership and technical lead for I&AM and cyber security solution and processes.Act as subject matter expert in the area of Identity and Access Management (IGA, Access Management, PAM) and lead roadmap definition with...

  • Cyber Security

    hace 4 semanas


    Madrid, España Apollo Solutions A tiempo completo

    A great opportunity for a Senior Cyber Security IT Risk Assessor  with experience within Cybersecurity to join a leading bank in Madrid, Spain. **You will be part of the team responsible for**: Conducting Independent Technical Tests - Cybersecurity Assessments, including Penetration Testing and Red Teaming. Application & Infrastructure Risk...


  • Madrid, España Hyundai A tiempo completo

    Responsibilities   Ensure that appropriate security guidance is following the company policies. Design and define security solutions if required related to local security. Input into the design and implementation of standards, policies, guidelines, and appropriate architectural principles in line with HQ standards, to ensure the firm’s cyber and...


  • Madrid, Madrid, España Next Ventures A tiempo completo

    Ref: #57470 Practice Cloud & Infrastructure Technologies Cyber Security Location Madrid, Spain Type Contract Application Security Specialist Responsibilities: Conduct security assessments, including code analysis and penetration testing. Collaborate with development teams to promote secure coding practices. Manage and prioritize vulnerabilities, participate...


  • Madrid, España ATG Europe A tiempo completo

    The activities below will include frequent access to classified security areas and systems. They may entail meetings in the other client's premises in Europe, EC premises in Brussels, ESA premises in Noordwijk - ESTEC (The Netherlands) or other European centres, Galileo Control Centres in Fucino (Italy) and Oberpfaffenhoffen (Germany) or other space...


  • Madrid, Madrid, España ING A tiempo completo

    At ING we are looking for a Information Risk Management (IRM) ExpertYour role and work environment:We are looking for a talented and enthusiastic IRM expert to join our Regional Information Risk Management Team in Spain (RegIRM-ES) of Information Risk / Technology Risk.The responsibility of this team is providing direct Information Risk Management (IRM) and...

  • Information Security

    hace 4 semanas


    Madrid, España Verisure A tiempo completo

    Do you want to have an impact every day by making people safe - and bringing them peace of mind? Interested in being part of a dedicated, passionate team which believes that security is a human right? Looking to join a company where innovation and technology are at the heart of its solutions?   What we look for Highly motivated individuals with...

  • Information Security

    hace 4 semanas


    Madrid, España Verisure Sàrl A tiempo completo

    Do you want to have an impact every day by making people safe - and bringing them peace of mind? Interested in being part of a dedicated, passionate team which believes that security is a human right? Looking to join a company where innovation and technology are at the heart of its solutions?   What we look for Highly motivated individuals with...


  • Madrid, Madrid, España BASF SE A tiempo completo

    ABOUT USAt BASF Digital Hub Madrid we develop innovative digital solutions for BASF, create new exciting customer experiences and business growth, and drive efficiencies in processes, helping to strengthen BASF ́s position as the digital leader in the chemical industry. We believe the right path is through creativity, trial and error and great people...


  • Madrid, España IAG Tech A tiempo completo

    Job DescriptionPosition Overview: As a Network Security Specialist, you will be responsible for the Cyber security posture of our Organization´s Network. This includes, designing and  implementing security measures to protect to protect the infrastructure from cyber threats and attacks, working close together with the different stakeholders across the IAG...

  • IT Risk Officer

    hace 1 mes


    Madrid, España Apollo Solutions A tiempo completo

    A great opportunity for a Senior IT Risk / IT Auditor with experience within Cybersecurity to join a leading bank in Madrid, Spain. This would be great for anyone with experience within IT Audit / IT Risk who also has a background in Cybersecurity within a Financial Services Organisation. **You will be part of the team responsible for**: Conducting...