Information Systems Security Compliance Engineer

Canonical - Jobs
Houston, TX, US
Full-time

Job Description

Job Description

The Security Compliance Engineer works in the office of the CISO in the Risk & Compliance team to help Canonical to achieve overall security & compliance goals and relevant certifications, as well as compliance with regulatory frameworks and other relevant standards.

The team's role is to ensure that Canonical conducts its business processes in compliance with laws and regulations, internal policies and procedures defined and international standards / best practices.

This position is for an individual with the knowledge, drive and personal motivation to help build and grow a strong security & compliance governance framework in a fast-growing tech company, as well as help it achieve / maintain the necessary compliance certifications.

This role can be home or office based. Periodic international travel for training and business meetings is required.

Key responsibilities :

  • Collaborate with IT operations, Legal, Security, and Engineering teams to define and implement policies and procedures
  • Help to design and implement controls to strengthen the company's Security Posture
  • Collaborate with various teams to ensure security standards are met across all projects
  • Assess vulnerabilities / risks that could affect the integrity, availability, or confidentiality of data, systems, or services of the company and provide mitigation solutions
  • Conduct regular audits to ensure compliance with internal policies and procedures, relevant security standards best practices, regulations and client requirements to identify gaps and provide remediation solutions
  • Ensure controls are configured correctly and integrated into the security strategy
  • Collaborate with internal teams to respond to Security Questionnaires, Contract Compliance and Security & Compliance posture questions from customers
  • Provide guidance and support to internal stakeholders regarding security & compliance practices
  • Collaborate with internal teams to gather evidence for external audits
  • Participate in the creation and or maintenance of the Information Security Management System
  • Maintain an up-to-date knowledge on Security standards, best practices and trends to ensure ongoing compliance

Required skills and experience :

  • 2+ years of experience within a security and compliance function
  • Experience developing and maintaining policies, procedures, standards, and guidelines to align with company's strategy and best practices
  • Experience with security controls implementation, configuration and maintenance
  • Experience with vulnerability management tooling, remediation, and processes
  • Experience with coding / scripting in one or more languages (Python, C, C++, Java)
  • Experience with Linux operating systems (Ubuntu preferred)
  • Understanding of concepts related to Systems Engineering / DevOps, IaC, IAM, network security, systems security, cryptography
  • Have a wide understanding of cybersecurity and data protection frameworks such as ISO 27001, NIST, SOC2, PCI-DSS, GDPR, CCPA.
  • Experience with third party and external audits

Valuable experience :

  • Bachelor's degree (or equivalent) in Computer Science, Information Systems, or related field
  • Affinity with Open Source software with regards to compliance
  • Knowledge of designing and implementing security processes and solutions with topics ranging from architecture, governance, compliance, and operations
  • Technical or engineering background, including software development, scripting, networking, and cloud architecture

Canonical is a growing international software company that works with the open-source community to deliver Ubuntu, the world's best free software platform.

Our services help businesses worldwide reduce costs, improve efficiency and enhance security with Ubuntu.

About Canonical

Canonical is a pioneering tech firm at the forefront of the global move to open source. As the company that publishes Ubuntu, one of the most important open source projects and the platform for AI, IoT and the cloud, we are changing the world on a daily basis.

We recruit on a global basis and set a very high standard for people joining the company. We expect excellence - in order to succeed, we need to be the best at what we do.

Canonical has been a remote-first company since its inception in 2004. Working here is a step into the future, and will challenge you to think differently, work smarter, learn new skills, and raise your game.

Canonical is an equal opportunity employer

We are proud to foster a workplace free from discrimination. Diversity of experience, perspectives, and background create a better work environment and better products.

Whatever your identity, we will give your application fair consideration.

LI-remote

30+ days ago
Related jobs
Promoted
Raytheon
Houston, Texas

Advanced Degree in Electrical Engineering, Systems Engineering, Mechanical Engineering, Engineering Mechanics, Computer Science, Engineering Science, Business Administration, and/or Robotics. We want you to fulfill a systems engineer role developing Systems Security Engineering (SSE) solutions to se...

Promoted
Storm2
TX, United States

I am seeking a highly skilled and motivated Information Security Specialist to join our team. This is a fantastic opportunity for individuals passionate about ensuring the highest standards of security in our systems and processes. Formulate and implement robust information security policies, proced...

Promoted
Raytheon
Houston, Texas

The Test Equipment Engineering (TEE) includes all of the engineering disciplines responsible for systems design & test with all Raytheon products. Our engineers are responsible for all elements of the development lifecycle for test including: test requirements, test system design, flight simulations...

Promoted
VARITE INC
Houston, Texas
Remote

Conducting regular audits and updates to ensure compliance and security. At least three (3) years of that experience must be in information security analysis. Three (3) years of experience within the last five (5) years as an Information Security Specialist, or similar, supporting an enterprise netw...

Promoted
Raytheon
Houston, Texas

Responsibilities to Anticipate:** Providing Cybersecurity compliance guidance to engineering for production and procurement of TE* Supporting Flight Test capabilities and processes for Raytheon test systems* Developing Cybersecurity compliant TE (Linux, IOS, Windows)* Install software packages/updat...

Lockheed Martin
Texas

As an Information Systems Security Officer (ISSO) you will join the Classified Cyber Security Team supporting Department of Defense (DoD) programs to ensure classified information systems meet cyber security requirements and government directives. Our global reach and technical depth offer an endles...

Promoted
Raytheon
Houston, Texas

Preferred Qualifications*:  * Experience in design, development and fielding of SSE systems* Software, Firmware, & Microelectronics Engineering, Cryptography and FPGA design* *Attack threat modeling / Critical Program Information Assessments** Experience in the implementation and busin...

Apex Systems
Houston, Texas

Build, deploy, and maintain security technologies to ensure the security and integrity of FormFactor, Inc’s information systems according to the current cyber security program. The IT Security Engineer is expected to be fully aware of the companys security infrastructure, framework, risks, and roadm...

Quorum Software
Houston, Texas

Quorum Software is looking for a Senior Information Security Engineer to join our team and provide administration and oversight of our enterprise security technologies. Identify gaps in Information Security infrastructure security and privacy capabilities, working with internal teams to remedy and i...

KASTLE SYSTEMS
Kastle - AustinAustin, Texas

Skills and experience with installing, managing, programming, and troubleshooting: web-based access control systems, video management systems, IP cameras, NVRs, visitor management systems, and physical security system components ( electrified locks, badge readers, intrusion sensors, etc. The Video N...