Talent Apply
Log in
All jobs
CL

Security Hardening Engineer

Canonical Ltd.
Remote
Remote

About this role

Job title: Security Hardening Engineer

About the Role This is a unique opportunity to apply software engineering and cryptography skills to build and maintain the security foundation that enables Ubuntu to operate securely and remain compliant with international information security standards such as FIPS 140-3 and Common Criteria. As a member of the Security Hardening team, you will help draft and implement security hardening benchmarks and develop automation to audit deployed systems for DISA-STIG and CIS benchmark compliance.

What You'll Do

  • Collaborate with other engineers in the Security Hardening team to achieve and retain various Security certifications.
  • Extend and enhance Linux cryptographic components (OpenSSL, Libgcrypt, GnuTLS, and others) with the features and functionality required for FIPS and CC certification.
  • Collaborate with external security consultants to test and validate kernel and crypto module components.
  • Work with external partners to develop security hardening benchmarks and audit + remediation automation for Ubuntu.
  • Contribute to Ubuntu mainline and upstream projects to land solutions and benefit the community.
  • Communicate and collaborate within and outside Canonical to identify opportunities to improve our security posture, rapidly resolve issues, and deliver high-quality solutions on schedule.

What We're Looking For

  • Hands-on experience with low-level Linux cryptography APIs and debugging.
  • Excellent software engineering fundamentals, including prior experience with C development, and the ability to demonstrate such.
  • Hands-on experience with Linux system administration and shell scripting.
  • Demonstrated knowledge of security and cryptography fundamentals + direct experience writing secure code and implementing best practices.
  • Significant development experience working with open source libraries.
  • Excellent verbal and written communications to enable efficient collaboration with internal and external partners in a remote-first environment.

Nice to Have

  • Prior experience working on FIPS/Common Criteria certified products and in-depth knowledge of the underlying standards.
  • Prior experience working directly with DISA-STIG or CIS benchmarks, including related audit + remediation tooling (e.g. Compliance as Code).
  • Experience working directly with Linux Kernel.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →